Wireless & Wi-Fi Penetration Testing
Wireless penetration testing across Europe. We attack your Wi-Fi the way a stranger in the car park would, fixed price with a free retest.
Wireless penetration testing checks whether someone sitting in your car park, the coffee shop next door or the flat upstairs can reach your network without ever walking through the front door. Your Wi-Fi is the one part of your perimeter that leaks past the walls, and it deserves the same scrutiny as anything facing the internet.
A wired network needs physical access to attack. Wi-Fi does not. Its signal spills into the street, and everything an attacker needs is a laptop, a cheap adapter and patience. We put ourselves in that position and test what your wireless actually exposes: the guest network that quietly routes to production, the staff SSID with a shared password half the town knows, the rogue access point an employee plugged in to fix a dead spot.
What wireless penetration testing covers
The engagement looks at every wireless surface you run, not just the corporate SSID. Guest networks, staff networks, the authentication behind them, the clients that connect, and any wireless kit that shouldn’t be there at all.
Guest Wi-Fi is not automatically safe
The most common wireless finding we report is not a broken encryption scheme. It is a guest network that isn’t really isolated. Connect as a visitor, and instead of a walled garden with internet access only, you find a route to internal servers, printers, or the management interfaces of the access points themselves. Guest access should be a dead end. Often it’s a doorway.
What a determined attacker does
They don’t need to break the crypto if they can trick a laptop instead. An evil twin broadcasts your SSID with a stronger signal, a client roams to it automatically, and now the attacker sits between that user and everything they type. We test whether your clients would fall for it and whether your authentication resists it.
How we test your wireless
Wireless penetration testing is fieldwork. We capture and analyse real radio traffic on your premises or from just outside them, using monitor-mode adapters, the Aircrack-ng suite, hcxdumptool and hostapd-based rogue APs, then crack what we capture offline on dedicated hardware. Every attack is hands-on and confirmed, never a checkbox from a config review.
Survey and reconnaissance
First we listen. We map every SSID and access point in range, including ones you didn’t know existed, note the encryption and authentication in use, and identify connected clients. This survey often turns up the surprises: a forgotten test SSID, a personal hotspot bridged to the corporate LAN, an access point still running factory settings.
Attacking the encryption
For pre-shared-key networks we capture the handshake and crack it offline against large wordlists and rule sets. A dictionary word or a company name with a year on the end falls quickly. For WPA2-Enterprise we test the 802.1X exchange, set up rogue authentication endpoints to harvest credentials, and check whether certificate validation is actually enforced on client devices, because when it isn’t, the whole EAP protection collapses.
WPA3 is better, not bulletproof
WPA3 closes several of the classic offline-cracking paths, and we’re glad to see it deployed. It still has transition-mode weaknesses, downgrade opportunities where WPA2 clients are supported alongside it, and it does nothing about a guest network that routes to production. Newer encryption is not a substitute for testing the whole picture.
Client and rogue-AP attacks
We deauthenticate clients to force reconnections, stand up evil-twin access points to see whether devices and users connect to them, and test captive portals for credential capture and bypass. This is where we learn whether your people and their laptops are the weak link, and it’s usually the most eye-opening part of the report.
Segmentation and reporting
Once connected to each network we test where it actually reaches, mapping guest-to-internal exposure and any lateral movement the wireless foothold allows. Then we write it up: what we broke, how, what it would let an attacker do, and the specific configuration changes that shut each path down.
Wireless weaknesses we find most often
Wi-Fi problems repeat across almost every site we test, and they cluster in a few predictable places.
Weak or shared pre-shared keys
A single Wi-Fi password shared across the whole company, printed on a whiteboard and unchanged since the office opened, is the classic. Once it leaks, and it always leaks, anyone in range is on your network. Cracking a weak PSK from a captured handshake is often a matter of minutes.
Guest networks that route inward
As above, this is the finding that surprises clients most. A guest SSID that can reach internal hosts turns the friendliest part of your network into the softest way in. Proper isolation and client-to-client blocking are simple to configure and frequently absent.
Rogue and shadow access points
Employees plug in consumer routers to fix coverage, contractors leave kit behind, and old access points stay powered long after they should. Each is an unmanaged entry point with unknown settings, and each one sits inside your walls where your firewall can’t see it.
Enterprise Wi-Fi without certificate validation
WPA2-Enterprise is only as strong as the client’s willingness to check the server certificate. When devices connect without validating it, a rogue authentication server harvests domain credentials directly, and one captured login can open far more than the Wi-Fi.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
What you get
Clear evidence and a fix list, written so both the boardroom and the network team can act on it.
Executive summary
A short, non-technical read on what an attacker could do from your car park and how serious it is, with the priority fixes stated plainly.
Technical report
Every finding with its impact, a CVSS score, the exact reproduction steps, and a concrete configuration fix your network team can apply. Captured evidence, cracked-key statistics and network diagrams are included where they help.
Attestation and retest
An attestation letter for auditors, clients and insurers, plus a free retest once you have reconfigured, to confirm the changes hold and the guest network really is a dead end now.
Compliance and standards
Wireless testing supports the frameworks European organisations answer to, and we shape the report around the ones that apply to you.
PCI DSS, ISO 27001 and SOC 2
PCI DSS 4.0 sets specific expectations for wireless: quarterly scanning for rogue access points under requirement 11.2 and testing of any wireless in or connected to the cardholder data environment. ISO 27001 Annex A controls on network security and the SOC 2 common criteria both benefit from documented wireless testing. Testing methodology follows OWASP and the PTES wireless guidance.
GDPR and NIS2
Where personal data can be reached over the air, GDPR Article 32’s expectation of appropriate technical measures applies to your wireless just as much as your servers, and NIS2 pushes essential-service operators toward regular testing of exactly these exposed surfaces.
Why manual testing beats a scanner
A scanner cannot stand in your car park with a directional antenna, capture a handshake, or watch whether a real laptop roams to an evil twin. Wireless is physical and behavioural, and the most damaging findings, the guest network that routes inward or the client that trusts any certificate, only show up when a person actually attacks the radio environment. That is what we do, and it’s why our reports contain proven exploits rather than a list of theoretical risks.
The false positives a scanner would give you
Automated wireless assessment tools flood you with warnings about supported cipher suites and theoretical downgrade risks, most of which don’t matter in your environment. A person filters that noise. We report the handshake we actually cracked and the guest network we actually reached, not a page of caveated maybes, and we tell you which of the scary-sounding config options are genuinely a problem for you and which are safe to leave alone.
Where wireless testing fits
Wireless is one leg of a full perimeter picture. It pairs naturally with an internal network test, because once we’re on the Wi-Fi the next question is how far that access reaches, and with a physical or social-engineering assessment, since walking in and plugging into an ethernet port is the wired cousin of joining the wireless from outside. Run wireless testing after any office move, fit-out or access-point refresh, and at least annually if you handle regulated data.
IoT, OT and the devices you forgot
Modern offices and sites carry far more than laptops on the air: badge readers, cameras, building-management sensors, warehouse scanners and printers, many on their own wireless with weak or default credentials. Where these sit in scope, we test them too, because an attacker who owns a camera network often owns a quiet vantage point inside your walls.
| Engagement | What’s included | Timeline | Price |
|---|---|---|---|
| Essential | Single site, guest and staff SSIDs, PSK cracking, segmentation and rogue-AP checks, full report and free retest | 2–4 working days | from €1,800 |
| Standard | Larger site or several SSIDs, WPA2-Enterprise and 802.1X testing, evil-twin and client attacks, exec and technical reporting | 4–6 working days | €2,500–€6,000 |
| Advanced | Multiple offices or a campus, full client-side testing and detailed segmentation mapping across all wireless | 6–10 working days | €6,000–€12,000 |
| Compliance add-on | Rogue-AP and wireless mapping with attestation for PCI DSS, ISO 27001 or SOC 2 | with any tier | from €800 |
| Custom / multi-site | Many locations or a distributed estate, scoped after a call | on scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call, with no hourly surprises and a retest included. Get a fixed quote
FAQ
How much does wireless penetration testing cost?
How long does a Wi-Fi pen test take?
Do you have to come on site to test our Wi-Fi?
Can you crack WPA3, or only older encryption?
Will testing knock our staff off the Wi-Fi?
What do we get at the end?
Do you check for rogue access points?
Does this satisfy PCI DSS wireless requirements?
Related services
Organisations with an office, retail floor, warehouse or campus running staff and guest Wi-Fi: retailers and hospitality businesses subject to PCI DSS, companies with sensitive data reachable over wireless, and any team that offers guest access and wants to be certain it can’t be used as a way inside.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.