Home/Services/Wireless & Wi-Fi Penetration Testing
security service

Wireless & Wi-Fi Penetration Testing

Wireless penetration testing across Europe. We attack your Wi-Fi the way a stranger in the car park would, fixed price with a free retest.

Manual, expert-ledEvidence-based findingsFree remediation retest

Wireless penetration testing checks whether someone sitting in your car park, the coffee shop next door or the flat upstairs can reach your network without ever walking through the front door. Your Wi-Fi is the one part of your perimeter that leaks past the walls, and it deserves the same scrutiny as anything facing the internet.

A wired network needs physical access to attack. Wi-Fi does not. Its signal spills into the street, and everything an attacker needs is a laptop, a cheap adapter and patience. We put ourselves in that position and test what your wireless actually exposes: the guest network that quietly routes to production, the staff SSID with a shared password half the town knows, the rogue access point an employee plugged in to fix a dead spot.

What wireless penetration testing covers

The engagement looks at every wireless surface you run, not just the corporate SSID. Guest networks, staff networks, the authentication behind them, the clients that connect, and any wireless kit that shouldn’t be there at all.

WPA2 and WPA3 handshake capture and offline cracking
WPA2-Enterprise and 802.1X EAP credential attacks
Evil-twin and rogue access point attacks against clients
Guest-to-internal segmentation and network isolation testing
Rogue and misconfigured access point discovery on your premises
Client-side attacks: forced deauthentication and captive-portal abuse
PSK strength, key management and shared-password hygiene

Guest Wi-Fi is not automatically safe

The most common wireless finding we report is not a broken encryption scheme. It is a guest network that isn’t really isolated. Connect as a visitor, and instead of a walled garden with internet access only, you find a route to internal servers, printers, or the management interfaces of the access points themselves. Guest access should be a dead end. Often it’s a doorway.

What a determined attacker does

They don’t need to break the crypto if they can trick a laptop instead. An evil twin broadcasts your SSID with a stronger signal, a client roams to it automatically, and now the attacker sits between that user and everything they type. We test whether your clients would fall for it and whether your authentication resists it.

How we test your wireless

Wireless penetration testing is fieldwork. We capture and analyse real radio traffic on your premises or from just outside them, using monitor-mode adapters, the Aircrack-ng suite, hcxdumptool and hostapd-based rogue APs, then crack what we capture offline on dedicated hardware. Every attack is hands-on and confirmed, never a checkbox from a config review.

Survey and reconnaissance

First we listen. We map every SSID and access point in range, including ones you didn’t know existed, note the encryption and authentication in use, and identify connected clients. This survey often turns up the surprises: a forgotten test SSID, a personal hotspot bridged to the corporate LAN, an access point still running factory settings.

Attacking the encryption

For pre-shared-key networks we capture the handshake and crack it offline against large wordlists and rule sets. A dictionary word or a company name with a year on the end falls quickly. For WPA2-Enterprise we test the 802.1X exchange, set up rogue authentication endpoints to harvest credentials, and check whether certificate validation is actually enforced on client devices, because when it isn’t, the whole EAP protection collapses.

WPA3 is better, not bulletproof

WPA3 closes several of the classic offline-cracking paths, and we’re glad to see it deployed. It still has transition-mode weaknesses, downgrade opportunities where WPA2 clients are supported alongside it, and it does nothing about a guest network that routes to production. Newer encryption is not a substitute for testing the whole picture.

Client and rogue-AP attacks

We deauthenticate clients to force reconnections, stand up evil-twin access points to see whether devices and users connect to them, and test captive portals for credential capture and bypass. This is where we learn whether your people and their laptops are the weak link, and it’s usually the most eye-opening part of the report.

Segmentation and reporting

Once connected to each network we test where it actually reaches, mapping guest-to-internal exposure and any lateral movement the wireless foothold allows. Then we write it up: what we broke, how, what it would let an attacker do, and the specific configuration changes that shut each path down.

48h
typical time to first confirmed findings
100%
manual, on-site verification of every attack
Free
retest after you reconfigure

Wireless weaknesses we find most often

Wi-Fi problems repeat across almost every site we test, and they cluster in a few predictable places.

Weak or shared pre-shared keys

A single Wi-Fi password shared across the whole company, printed on a whiteboard and unchanged since the office opened, is the classic. Once it leaks, and it always leaks, anyone in range is on your network. Cracking a weak PSK from a captured handshake is often a matter of minutes.

Guest networks that route inward

As above, this is the finding that surprises clients most. A guest SSID that can reach internal hosts turns the friendliest part of your network into the softest way in. Proper isolation and client-to-client blocking are simple to configure and frequently absent.

Rogue and shadow access points

Employees plug in consumer routers to fix coverage, contractors leave kit behind, and old access points stay powered long after they should. Each is an unmanaged entry point with unknown settings, and each one sits inside your walls where your firewall can’t see it.

Enterprise Wi-Fi without certificate validation

WPA2-Enterprise is only as strong as the client’s willingness to check the server certificate. When devices connect without validating it, a rogue authentication server harvests domain credentials directly, and one captured login can open far more than the Wi-Fi.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

What you get

Clear evidence and a fix list, written so both the boardroom and the network team can act on it.

Executive summary

A short, non-technical read on what an attacker could do from your car park and how serious it is, with the priority fixes stated plainly.

Technical report

Every finding with its impact, a CVSS score, the exact reproduction steps, and a concrete configuration fix your network team can apply. Captured evidence, cracked-key statistics and network diagrams are included where they help.

Attestation and retest

An attestation letter for auditors, clients and insurers, plus a free retest once you have reconfigured, to confirm the changes hold and the guest network really is a dead end now.

Compliance and standards

Wireless testing supports the frameworks European organisations answer to, and we shape the report around the ones that apply to you.

PCI DSS, ISO 27001 and SOC 2

PCI DSS 4.0 sets specific expectations for wireless: quarterly scanning for rogue access points under requirement 11.2 and testing of any wireless in or connected to the cardholder data environment. ISO 27001 Annex A controls on network security and the SOC 2 common criteria both benefit from documented wireless testing. Testing methodology follows OWASP and the PTES wireless guidance.

GDPR and NIS2

Where personal data can be reached over the air, GDPR Article 32’s expectation of appropriate technical measures applies to your wireless just as much as your servers, and NIS2 pushes essential-service operators toward regular testing of exactly these exposed surfaces.

Why manual testing beats a scanner

A scanner cannot stand in your car park with a directional antenna, capture a handshake, or watch whether a real laptop roams to an evil twin. Wireless is physical and behavioural, and the most damaging findings, the guest network that routes inward or the client that trusts any certificate, only show up when a person actually attacks the radio environment. That is what we do, and it’s why our reports contain proven exploits rather than a list of theoretical risks.

The false positives a scanner would give you

Automated wireless assessment tools flood you with warnings about supported cipher suites and theoretical downgrade risks, most of which don’t matter in your environment. A person filters that noise. We report the handshake we actually cracked and the guest network we actually reached, not a page of caveated maybes, and we tell you which of the scary-sounding config options are genuinely a problem for you and which are safe to leave alone.

Where wireless testing fits

Wireless is one leg of a full perimeter picture. It pairs naturally with an internal network test, because once we’re on the Wi-Fi the next question is how far that access reaches, and with a physical or social-engineering assessment, since walking in and plugging into an ethernet port is the wired cousin of joining the wireless from outside. Run wireless testing after any office move, fit-out or access-point refresh, and at least annually if you handle regulated data.

IoT, OT and the devices you forgot

Modern offices and sites carry far more than laptops on the air: badge readers, cameras, building-management sensors, warehouse scanners and printers, many on their own wireless with weak or default credentials. Where these sit in scope, we test them too, because an attacker who owns a camera network often owns a quiet vantage point inside your walls.

Engagement What’s included Timeline Price
Essential Single site, guest and staff SSIDs, PSK cracking, segmentation and rogue-AP checks, full report and free retest 2–4 working days from €1,800
Standard Larger site or several SSIDs, WPA2-Enterprise and 802.1X testing, evil-twin and client attacks, exec and technical reporting 4–6 working days €2,500–€6,000
Advanced Multiple offices or a campus, full client-side testing and detailed segmentation mapping across all wireless 6–10 working days €6,000–€12,000
Compliance add-on Rogue-AP and wireless mapping with attestation for PCI DSS, ISO 27001 or SOC 2 with any tier from €800
Custom / multi-site Many locations or a distributed estate, scoped after a call on scoping custom

Every engagement is fixed-price, quoted after a free 20-minute scoping call, with no hourly surprises and a retest included. Get a fixed quote

FAQ

How much does wireless penetration testing cost?
Wireless penetration testing starts from €1,800 for a single site and is priced by the number of locations, SSIDs and access points, and whether WPA2-Enterprise is in scope. You get a fixed quote after a free scoping call.
How long does a Wi-Fi pen test take?
A single site usually runs 2–4 working days plus the report, with larger campuses taking longer. Offline password cracking runs in parallel on dedicated hardware, so it doesn’t stretch the on-site time.
Do you have to come on site to test our Wi-Fi?
For the radio attacks, yes, because wireless is physical and the signal has to be captured near your premises. We travel across Europe for on-site work, and any segmentation or configuration analysis after connection can continue remotely.
Can you crack WPA3, or only older encryption?
WPA3 is stronger and closes several classic cracking paths, but we still test its transition-mode and downgrade weaknesses, client trust, and the segmentation behind it. Newer encryption reduces some risks; it does not remove the need to test.
Will testing knock our staff off the Wi-Fi?
Some techniques, such as deauthentication to capture a handshake, cause brief reconnections for the targeted clients. We schedule anything disruptive with you, keep it short, and can run it out of hours to avoid affecting the working day.
What do we get at the end?
An executive summary, a technical report with every finding scored and reproducible, the exact configuration fixes, an attestation letter and a free retest after you reconfigure. As a European wireless penetration testing company we deliver proven exploits, not a scan export.
Do you check for rogue access points?
Yes. We survey everything broadcasting on your premises and flag rogue or shadow access points, personal hotspots bridged to your LAN, and any kit still running factory settings, which is a specific PCI DSS wireless requirement.
Does this satisfy PCI DSS wireless requirements?
Yes. The report and attestation are written to support PCI DSS 4.0 wireless expectations, including rogue-AP detection and testing of wireless connected to the cardholder data environment, alongside ISO 27001 and SOC 2 network controls.

Related services

Who needs this

Organisations with an office, retail floor, warehouse or campus running staff and guest Wi-Fi: retailers and hospitality businesses subject to PCI DSS, companies with sensitive data reachable over wireless, and any team that offers guest access and wants to be certain it can’t be used as a way inside.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "Wireless & Wi-Fi Penetration Testing"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.