Royalty-free stock photograph created by Briana Tozour and Unsplash.
Cybersecurity in Business Travel
Investment banking giant Morgan Stanley has adopted a strict new cybersecurity policy, requiring its bankers to use an alternative, "clean" mobile phone when traveling to China. The measure, leaked by internal sources, establishes a new de facto standard for digital risk management for companies operating in the Asian giant.
The investment banking giant Morgan Stanley has taken a significant step in protecting its sensitive information, instructing its bankers and executives to carry a separate, specially prepared mobile phone for their business trips to ChinaThis directive, communicated internally and revealed to the agency by a source familiar with the situation, ReutersThis reflects the growing concern in the Western corporate sector about the risk of cyber espionage and digital surveillance in the country.
Although not an official public policy, the measure underscores a growing trend among multinational corporations operating in strategic markets with complex security regulations. The objective is clear: minimize the digital attack surface and prevent critical corporate data, customer information, or intellectual property from being compromised through regular personal or work devices.
The 'reason' for the measure: an environment of distrust
The decision Morgan Stanley This is not an isolated incident. It is part of a context of geopolitical and technological tensions between Estados Unidos y China, exacerbated since the beginning of the administration of Donald Trump In 2025, US companies, especially those in strategic sectors such as finance and technology, operate under the assumption that their communications and data may be monitored by Chinese authorities.
The national security laws of China They grant the government broad powers to access data stored on devices within its borders. This creates a legal and operational risk For foreign companies, the use of a "travel phone" or "burner phone" allows executives to maintain a strict separation between sensitive company information and the device they use on Chinese soil, which is considered potentially vulnerable.
Implications for Spanish companies operating in China
The practice adopted by a benchmark such as Morgan Stanley serves as a clear indicator of good practices for any Spanish company with interests in ChinaRegardless of its size. International cybersecurity experts consulted by Empresa Exterior They warn that the risk is not limited to large financial corporations.
An executive from a Spanish industrial SME traveling to a trade fair in Shanghái or to visit a supplier in Shenzhen They carry high-value information on their smartphones: customer contacts, negotiation strategies, product designs, or access to the corporate network. The exfiltration of this data can have devastating consequences.
The recommendations for Spanish exporters and managers are as follows:
- Use 'clean' devices: Use a smartphone or laptop with the minimum information and applications necessary for the trip, without access to critical personal or corporate accounts.
- Limit connectivity: Avoid using public Wi-Fi networks and use trusted virtual private networks (VPNs), although their effectiveness in China may be limited.
- Staff training: Raise awareness among traveling employees about the risks of social engineering, phishing, and the security of their devices.
- Assume monitoring: Operating under the premise that all digital communication made from the country can be intercepted.
As one risk analyst consulted points out, "the decision of Morgan Stanley It normalizes a practice that until now was considered 'high security'. Today, it's simply a prudent measure of digital hygiene for doing business in the 21st century. It's no longer a question of if they're going to try to spy on you, but when and how..
Key points and frequently asked questions about cybersecurity when traveling to China
Why is China a high-risk destination for cybersecurity?
Due to a combination of factors: an advanced state cyber espionage capability, a legal framework (Cybersecurity Act and National Security Act) that can compel companies to hand over data, and a history of attacks aimed at stealing intellectual property and trade secrets from foreign companies.
Does this measure only affect large multinationals like Morgan Stanley?
No. The risk affects any company, regardless of size. SMEs can be even more attractive targets because they generally have fewer cybersecurity resources. An SME's information (designs, client portfolios, strategies) is equally valuable, and its theft can jeopardize its viability.
What immediate practical steps should a Spanish manager take before traveling to China?
Purchase a mid-range smartphone for exclusive use during the trip. Install only essential apps and create new email accounts for that purpose. Do not bring your usual work laptop; if necessary, use a formatted one with no direct access to the company servers. Finally, upon your return, have the travel device checked by a professional and never reconnect to the corporate network.





