Wireless network penetration testing
We test your Wi-Fi from the car park inwards: who can connect, what they can reach, and whether your users can be lured onto a network that is not yours.
Your network does not stop at the walls
Wireless networks extend your network beyond your building. A weak pre-shared key, a misconfigured enterprise network or a guest network that reaches internal systems gives an attacker a way in without ever touching your firewall.
Wireless attacks also target people. Rogue access points that copy your network name can capture credentials from staff devices that connect automatically. We test the infrastructure and the behaviour of the devices that use it.
What we test
Discovery and signal
Which networks are visible, from where, and how far your signal reaches outside the building.
Encryption and authentication
WPA2 and WPA3 configuration, pre-shared key strength, and enterprise 802.1X authentication including certificate validation.
Rogue and evil twin access points
Whether staff devices connect to a lookalike network and give up credentials.
Guest networks
Client isolation, and whether guests can reach internal systems or management interfaces.
Segmentation
What each wireless network can reach once a device is connected.
Unauthorised devices
Personal hotspots and unmanaged access points plugged into your network.
How the engagement runs
Plan the visit
We agree locations, networks in scope and timings, and confirm who on site knows we are coming.
Survey
We map networks and signal coverage from inside and outside the building.
Attack
We test authentication, attempt to capture and crack keys, and run controlled rogue access point attacks against in-scope networks.
Report and retest
Findings with the configuration changes to make, the report within five working days, and a retest of changed settings.
What you get
- A map of the networks we found and where each can be reached from.
- Findings per network, with the configuration change that fixes each one.
- Retest results after you make the changes.
When to commission it
- When opening a new office or changing wireless vendor.
- If you offer guest Wi-Fi to visitors or the public.
- When moving from pre-shared keys to enterprise authentication.
- Yearly for sites that handle sensitive data.
Questions we get asked
Do you need to be on site?
Will testing disconnect our users?
Is WPA3 secure?
How long does it take?
Related
Physical intrusion
Physical penetration testing: tailgating, badge cloning, reception pretexts and access to server rooms. Could someone walk in and leave with your data?
Read more →Infrastructure and networks
External and internal network penetration testing, including Active Directory. See how far an attacker could get from the internet or inside your network.
Read more →Social engineering
Social engineering assessments that test how your people and processes respond to phishing, phone pretexting, impersonation and physical intrusion.
Read more →SavountThe Key to Robust IT Security
The basics that stop most attacks: least privilege, password hygiene, patching, email controls and training, and why regular testing matters.
Read the article →