Public Wi-Fi is one of the small conveniences modern work runs on: a cafe, an airport lounge, a hotel room, a client's guest network, and you are online without using your own data. The convenience is real and there is no need to be paranoid about it. But it helps to be clear about what you are actually doing when you join a network you do not control, which is trusting whoever runs it — and potentially other people on it — with whatever your device sends and receives. Most of the time nothing goes wrong. The point of good habits is that they make the times something could go wrong not matter.
The specific risks are worth naming because they are concrete rather than vague. Someone operating or sitting on the same open network can potentially observe traffic that is not encrypted, which is why the single most important protection is that the connection between your device and the sites you use is itself encrypted — the difference an ordinary user sees is whether a web address is secured, and modern browsers and apps handle most of this automatically. A second, sneakier risk is the fake network: an attacker sets up a hotspot with a plausible name, you connect thinking it is the cafe's, and now your traffic flows through their equipment by design. And a device set to automatically rejoin known networks can be coaxed onto a hostile one without you choosing to.
The defences are simple enough to become automatic, which is the goal. Use connections that are encrypted end to end — reputable apps and secured websites — so that even an observer on the network sees scrambled traffic rather than readable content; a virtual private network, which wraps everything your device sends in its own encrypted tunnel, is a straightforward way to get that protection uniformly on an untrusted network. Be wary of network names, confirming the real one with staff rather than joining whichever plausible-sounding hotspot appears. Turn off automatic reconnection to open networks so your device does not silently join something you did not choose. And save the genuinely sensitive actions — moving money, logging into critical business systems — for a network you trust, or your own mobile connection, rather than a shared one.
The mindset that ties this together is to treat any network you do not control as public in the literal sense: assume that what you do on it could be seen, and rely on encryption rather than on the network's goodwill to keep it private. That is not a reason to avoid public Wi-Fi, which is useful and usually fine. It is a reason to build a few habits that hold regardless of whether a particular network happens to be safe — because the whole problem with an untrusted network is that you cannot tell a safe one from a hostile one by looking, and the habits are what make the distinction stop mattering.