Network

Wireless network pentest

On-site testing of the wireless you run — corporate, guest, BYOD and device networks — including whether an attacker in the car park can capture credentials or land inside your corporate network.

8
areas covered
5
stages, scoping to retest
In-house
testers, never subcontracted
portal.cyberlysecure.com/acme-health/coverage
Acme Health — Test coverage4 practices · 15 services · one team
In-house
Web app
API
SaaS
Mobile
Client-side
External
Internal
Segment test
Wireless
Cloud config
Hardware & IoT
AI & LLM
Social eng.
Physical
Red team
ApplicationsNetworkCloud & devicesPeople & premises
6 in scope · one team · one report
In-house testers 0 subcontracted
Every surface one team
What this is

What the test covers.

Wireless extends your network past your walls. An attacker does not need to get through reception; they need to be within range, and with enterprise Wi-Fi the prize is often a domain credential rather than just internet access.

We test each network you broadcast, at each site in scope, and we check that the separation between them is real.

PTES NIST SP 800-115 OWASP Wireless testing guidance

What we test

  • WPA2 and WPA3 configuration, personal and enterprise
  • Enterprise authentication: EAP method, certificate validation and client configuration
  • Evil-twin and rogue access point attacks against real client behaviour
  • Handshake and PMKID capture, and passphrase strength
  • Guest network isolation and client-to-client separation
  • BYOD, printer, camera and IoT networks
  • Signal reach beyond your premises
  • Access point and controller management interfaces
How it runs

From scoping call to retest, here’s what happens.

Typically two to four days per site, confirmed at scoping.

1

Scope and authorize

We agree sites, networks and dates, and confirm which networks belong to you — neighbours are never in scope.

2

Survey on site

We map what is broadcasting, from inside and from the perimeter, including anything broadcasting that you did not deploy.

3

Test each network

Each network is tested on its own terms — passphrase strength, client trust behaviour, isolation and management access.

4

Follow it inward

Where wireless access leads to internal access, we show how far it reaches.

5

Report, readout and retest

Findings are reported per site, with a readout and a retest once configuration changes land.

What it surfaces

The kind of thing this test tends to find.

Real examples of what this engagement uncovers — anonymized, and never every time. What matters is that you find out before somebody else does.

Client devices that hand over credentials to an access point presenting any certificate

Guest networks that can reach printers, cameras or internal ranges

Pre-shared keys that survive an offline cracking attempt in hours

Access point management reachable from the user network with default credentials

Old or forgotten SSIDs still broadcasting with weak configuration

Getting started

What you get, and what we need from you.

What you get

  • Technical report — Every finding, the evidence behind it and clear guidance your engineers can act on.
  • Executive summary — Your risk explained in plain language for leadership and the board.
  • Attestation letter — Signed confirmation of testing to hand your auditors.
  • Readout call — A walkthrough with the people who tested your systems.
  • Retest — Confirmation your fixes worked, documented for whoever needs to see it.

What we need from you

  • Site addresses, dates and on-site contacts
  • The list of SSIDs that belong to you
  • Permission from the building owner where you do not own the site
  • Escort arrangements if any area needs one

Missing something on this list? Bring it to the call — we scope around what you have.

Free attack-surface snapshot

Give us a domain. See what an attacker sees.

Not sure where to start? One of our testers reviews your internet-facing footprint and sends you a short summary of what an attacker would see — free. Nothing you don’t own is ever touched, and there’s no sales sequence.

  • Internet-facing hosts
  • Exposed services
  • Leaked credentials
  • TLS certificate hygiene

Request your snapshot

Free. No obligation.

We only ever test assets you own, with your written authorization.