WiFi and wireless network security audit
A misconfigured corporate WiFi network is a direct gateway into your internal network. We assess the security of your wireless infrastructure using the OWISAM methodology.
Why is corporate WiFi a common attack vector?
60% of companies have at least one insecurely configured WiFi network. Weak WPA2 passwords susceptible to dictionary attacks, unsegmented guest networks, rogue access points installed without authorization, or a lack of Evil Twin detection are real vectors attackers exploit to gain initial access to the corporate network.
Scope of the WiFi audit
- Inventory and mapping of access points: authorized and unauthorized (rogue AP)
- Protocol assessment: WEP, WPA/WPA2-Personal, WPA2/WPA3-Enterprise (802.1X)
- WPA2 handshake capture and cracking attacks (dictionary, PMKID)
- Evil Twin and KARMA attack detection
- Segmentation: corporate vs. guest vs. IoT networks
- RADIUS and 802.1X authentication assessment
- Deauthentication and wireless denial-of-service attacks
- Coverage analysis and exposure beyond the physical perimeter
- OWISAM methodology (Open Wireless Security Assessment Methodology)
OWISAM methodology
- Wireless reconnaissance: Identification of every WiFi network within the client's perimeter: SSIDs, BSSIDs, channels, signal strength and protocols.
- Configuration analysis: Assessment of authentication protocols, encryption and wireless controller configuration.
- Attack testing: Controlled attacks: handshake capture, Evil Twin, captive-portal bypass, attacks against 802.1X.
- Post-exploitation: If access is obtained, we verify the network's real segmentation and the potential for lateral movement.
- Report and remediation: Findings mapped by severity, photographic/technical evidence and configuration recommendations for the wireless systems.
Deliverables
- Complete map of WiFi infrastructure (authorized and unauthorized)
- Technical report with findings classified by severity
- Evidence of access obtained (if applicable)
- Vendor-specific configuration recommendations (Cisco, Aruba, Ubiquiti, etc.)
- Wireless network segmentation guide
Use cases
- Corporate offices with multiple SSIDs and BYOD policies
- Hotels, hospitals or shopping centers with guest WiFi
- Industrial environments with WiFi-connected IoT devices
- Companies with remote workers using uncontrolled networks
- Organizations that must comply with PCI-DSS with wireless payment terminals
Frequently asked questions
Do you need to be physically on our premises?
For the full assessment, yes. Wireless network analysis requires physical presence. We schedule visits at times that minimize disruption to your operations.
Does the WiFi audit include guest networks?
Yes, we include every wireless network within the perimeter: corporate, guest, IoT and any unauthorized network we detect.
Do you also assess the security of devices connected to the WiFi?
The standard scope covers the wireless infrastructure. If you want to include an assessment of connected devices (IoT, PCs, printers), we extend it as part of an internal network pentest.