We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Audit and compliance
  2. Wireless security audit
Wireless security audit for US businesses

Nobody has changed the corporate wireless password since 2019, and every contractor since has been handed it.

Four questions define this work. What is actually broadcasting from your building, how does each of those networks authenticate anyone, what can a device reach once it has joined, and would a single person notice an access point that nobody deployed. Most companies can answer the first one partially and the other three not at all.

Book a wireless security auditSee what we assess
Wireless security audit for US organizations
  • What is broadcastingIncluding what you did not deploy
  • How it authenticatesShared key, or certificate per device
  • What it reachesSegmentation, tested rather than assumed
  • Who would noticeRogue and neighboring access points
What we assess

Six areas, and the shared password is merely the most obvious of them.

Wireless cuts across several CIS Critical Security Controls in version 8.1: asset inventory at Control 1, secure configuration at Control 4, access control at Control 6, network infrastructure at Control 12, and network monitoring and defense at Control 13. An audit of the wireless is where all five of those collide with an actual building.

Authentication, and the shared key problem

A shared key is one credential held by every device, revocable for nobody in particular. It gets given to contractors, typed into personal phones, and written on a whiteboard in a meeting room, and it only ever changes when somebody accepts the pain of changing it on everything at once. Certificate-based authentication removes the shared secret altogether, and it remains the single change that improves wireless security most.

What is actually broadcasting from your premises

Corporate, guest, voice, building services, registers, plant equipment, and whatever a department stood up for a project two years ago. The survey records what is genuinely broadcasting rather than reading the controller configuration, because a controller only knows about the access points it manages and the interesting ones are always the others.

Where the coverage actually reaches

Wireless does not respect a lease boundary. A survey establishes whether your corporate network is usable from the parking lot, the neighboring floor, the street, or the suite next door. That is not a theoretical concern in the dense office buildings and mixed-use developments where many US businesses operate, where several organizations frequently share a building and occasionally share a wall.

Guest isolation, tested rather than assumed

Nearly every company runs a guest network and assumes it is isolated. We test the assumption from a device sitting on it: can a visitor reach the corporate network, other visitors, a management interface, or genuinely nothing but the internet. Client isolation between guests is missing more often than not, which quietly turns your guest network into a shared broadcast domain for everybody who walks through the door.

Segmentation, and what a compromised device could reach

Once something has joined the corporate wireless, where can it go. In a great many companies the honest answer is everywhere, because wireless was built as a way to get online rather than as a network segment in its own right. Measuring what is actually reachable, rather than what was intended, regularly shows wireless to be the least controlled way into the core.

Monitoring, rogue detection, and configuration drift

Would anyone notice an access point appearing that nobody ordered, a laptop broadcasting your own network name, or a configuration change on the controller. Network monitoring and defense is Control 13, and wireless is the part of the network most likely to change with no change record at all, because the hardware is small, cheap, and fits in a drawer.

The finding that is present almost everywhere

A shared key is a credential you cannot take away from one person.

This is the most common wireless finding, the one everybody already understands, and the one fixed least often, because historically the fix hurt.

  • Every device that has ever connected still holds it: contractors, people who left two years ago, personal phones, the visitor who asked once at reception, and anybody those people passed it to. Revoking it for one device is impossible, because no device has a credential of its own.
  • Changing it means touching every single device, which is precisely why nobody does. In most companies the corporate key has not moved since the day the network went in, everybody involved knows that perfectly well, and everybody has quietly made peace with it.
  • Certificates remove the shared secret entirely. Intune wireless profiles push the settings out so nobody has to configure anything, and certificates handle the authentication so people reach resources without ever typing a username or password, using trusted root, SCEP, or PKCS certificates depending on how your environment is built.
  • That combination is why this is finally practical. The management platform delivers the profile and the certificate together, so the disruption that blocked this change for a decade has largely disappeared. What the audit does is quantify the effort remaining against whatever population is not managed.
Ask us to scope certificate-based wireless
How we approach it

Four things this finds that reading the configuration never will.

The controller configuration records what was deployed. This audit is about what is actually present, how far it reaches, and who would notice something changing. None of those three is visible from the management console.

We survey rather than read the controller

A controller reports only on the access points it manages, which means every interesting finding is invisible to it: something a department installed to fix a coverage complaint, a vendor access point that arrived alongside their equipment, a building services network, or a laptop broadcasting your own network name. Only a survey turns those up, and we run it as a structured exercise directed remotely with your people on site.

We establish where the coverage actually goes

Radio does not respect a lease. In a shared building with several companies on different floors, whether your corporate network is usable from the corridor, the parking garage, or the suite next door is a physical question with a physical answer, and it changes the risk calculation around a shared key considerably.

We test isolation instead of accepting the design

Guest isolation, client isolation, and segmentation away from the wireless are all things every company is confident it already has. Testing each from a device actually sitting on that network, rather than reading what the configuration intended, is how the exceptions appear. There is nearly always at least one path nobody designed on purpose.

We size the migration off shared keys realistically

Certificates are the right destination, and the real question is always the population that cannot easily get there: unmanaged devices, contractor equipment, printers, scanners, plant hardware, and anything with no management agent on it. Sizing that group honestly is what converts a recommendation into a plan somebody will actually fund.

Where this matters most

Six US situations where a wireless audit finds something material.

Wireless is the only entry point where physical proximity and network access meet, which makes the surroundings matter every bit as much as the configuration.

An organization in a shared or mixed-use building

Ordinary in a downtown tower and just as ordinary in a suburban office park. Your signal carries into the corridor, down into the parking structure, and quite possibly into the suite next door, while theirs carries into yours. Where the corporate network runs on a shared key, the physical boundary that once made that acceptable does not exist, and mapping the real coverage footprint is the first genuinely useful output.

A retail or hospitality business offering guest wireless

Guest wireless is handed to the public deliberately, which leaves isolation carrying the entire control. We test whether a guest device can reach the corporate network, the register environment, a management interface, or the other guests. Where card data is involved, segmentation away from the payment environment is a PCI DSS scoping question as much as a security one, and getting it wrong widens your assessment scope considerably.

An operator with wireless on plant and handheld equipment

Scanners, handhelds, sensors, and control equipment frequently cannot handle certificates at all, and they are the reason the shared key survives everywhere else. Identifying exactly which devices those are and building them a separate segment with tight restrictions is almost always a better answer than holding the entire company on one shared credential because a minority of hardware demands it.

A regulated firm with an obligation covering network access

Wherever a regulator expects individual accountability for network access, and GLBA examiners, NYDFS Part 500 assessments, and CMMC audits against NIST 800-171 all reach into this, a shared key cannot deliver it. No device holds a credential of its own, so nothing can be attributed to anyone. That is an easy finding to write and an equally easy one to close, using certificates pushed out by the platform already managing the devices.

An organization with heavy contractor presence

Every contractor ever handed the wireless password still has it, as does every device they used while they were on site. Where contractors are numerous and rotate constantly, that key becomes a credential held by a population nobody can count, and no amount of encryption strength touches the problem. A separate contractor segment with individual credentials is the answer.

A healthcare organization with clinical devices on wireless

Clinical equipment on wireless pairs devices that cannot easily be reconfigured with a network that cannot go down. Meanwhile HIPAA expects access to systems holding protected health information to be both controlled and attributable. The audit establishes which devices are constraining the design, whether they sit apart from general corporate traffic, and whether the wireless can reach clinical systems it has no business reaching.

Three positions

How US organizations secure their wireless networks.

The middle column is where most companies live. The network was designed competently, the encryption is current, and the credential is a password everybody holds and nobody can withdraw.
Per-device credentials
Certificate based and segmentedYes
Modern encryption, shared keyNo
Unmanaged or legacy wirelessNo
Individual revocation possible
Certificate based and segmentedYes
Modern encryption, shared keyNo
Unmanaged or legacy wirelessNo
Guest isolated and tested
Certificate based and segmentedYes
Modern encryption, shared keyAssumed
Unmanaged or legacy wirelessNo
Client isolation between guests
Certificate based and segmentedYes
Modern encryption, shared keyOften not
Unmanaged or legacy wirelessNo
Wireless treated as a network segment
Certificate based and segmentedYes
Modern encryption, shared keySometimes
Unmanaged or legacy wirelessNo
Coverage beyond premises understood
Certificate based and segmentedYes
Modern encryption, shared keyNo
Unmanaged or legacy wirelessNo
Rogue access point detection active
Certificate based and segmentedYes
Modern encryption, shared keyAvailable, off
Unmanaged or legacy wirelessNone
Controller hardening verified
Certificate based and segmentedYes
Modern encryption, shared keyAssumed
Unmanaged or legacy wirelessNo
Access point additions recorded
Certificate based and segmentedYes
Modern encryption, shared keyNo
Unmanaged or legacy wirelessNo
Effort to remove one person's access
Certificate based and segmentedSeconds
Modern encryption, shared keyChange it for everyone
Unmanaged or legacy wirelessNot possible
Feature
Certificate based and segmented
Modern encryption, shared key
Unmanaged or legacy wireless
Per-device credentials
YesNoNo
Individual revocation possible
YesNoNo
Guest isolated and tested
YesAssumedNo
Client isolation between guests
YesOften notNo
Wireless treated as a network segment
YesSometimesNo
Coverage beyond premises understood
YesNoNo
Rogue access point detection active
YesAvailable, offNone
Controller hardening verified
YesAssumedNo
Access point additions recorded
YesNoNo
Effort to remove one person's access
SecondsChange it for everyoneNot possible
The audit scope

Ten checks, and where each one usually fails.

Below are the checks we actually run. The failure column reflects what we most often find ourselves, not a statistic lifted from somebody else research.

Check

Every broadcasting network identified

Where it usually fails
Networks nobody in IT deployed, from departments or vendors

Check

Authentication method per network

Where it usually fails
One shared key across the corporate network, untouched for years

Check

Certificate infrastructure where used

Where it usually fails
Certificates issued once with no renewal or revocation process

Check

Guest isolation from corporate

Where it usually fails
Tested rarely, and occasionally not actually in place

Check

Client isolation between guests

Where it usually fails
Frequently absent, so visitors share a broadcast domain

Check

Segmentation from the wireless segment

Where it usually fails
Wireless built as a way to get online rather than as a segment in its own right

Check

Coverage beyond the premises

Where it usually fails
Usable signal in parking lots, corridors and neighboring suites

Check

Controller and access point configuration

Where it usually fails
Default management credentials and unpatched firmware

Check

Rogue access point detection

Where it usually fails
Available in the platform and never enabled

Check

Change control on wireless configuration

Where it usually fails
Access points added without any record
CheckWhere it usually fails
Every broadcasting network identifiedNetworks nobody in IT deployed, from departments or vendors
Authentication method per networkOne shared key across the corporate network, untouched for years
Certificate infrastructure where usedCertificates issued once with no renewal or revocation process
Guest isolation from corporateTested rarely, and occasionally not actually in place
Client isolation between guestsFrequently absent, so visitors share a broadcast domain
Segmentation from the wireless segmentWireless built as a way to get online rather than as a segment in its own right
Coverage beyond the premisesUsable signal in parking lots, corridors and neighboring suites
Controller and access point configurationDefault management credentials and unpatched firmware
Rogue access point detectionAvailable in the platform and never enabled
Change control on wireless configurationAccess points added without any record
How an engagement runs

Five steps, and the survey steps need someone at the site.

Typically two to four weeks. The configuration review is delivered remotely. The survey and isolation testing require physical presence at each location, which we run as a remotely directed exercise with your on-site staff using a structured survey process, or scope differently per engagement where that does not fit.
  1. 1

    Review the configuration and the intended design

    The controller and access point configuration, every network defined on it, how each authenticates, what the segmentation was meant to do, the guest arrangements, how management access works, and how current the firmware is. This tells us what was designed, which becomes the baseline the physical findings get measured against rather than the conclusion itself.

  2. 2

    Survey what is actually broadcasting, at each site

    Every network broadcasting at each location in scope, including everything the controller knows nothing about. Departmental installations, vendor equipment, building services, and anything announcing a network name it has no right to. The distance between what the survey finds and what the configuration claims is the first substantive finding of the engagement.

  3. 3

    Establish the coverage footprint

    Where each network can actually be used from: the corridor, the parking structure, the floor above, and the neighboring suite where we can reach it. Radio ignores lease boundaries entirely, and in a shared building the physical extent of your network is a material input into whether a shared credential is defensible at all.

  4. 4

    Test isolation and segmentation from each network

    Tested from a device on the guest network, from one on corporate, and from every other network in scope. What can be reached from each, whether client isolation is actually on, whether a management interface answers from the wireless it controls, and whether the wireless segment can touch systems it has no business reason to touch.

  5. 5

    Report with a realistic migration path

    Findings ranked by risk, with the shared key answered through certificates delivered by the platform already managing your devices, and the population that cannot support them identified precisely and given a segment of its own. Monitoring recommendations come with it, because rogue detection is usually already licensed and usually switched off.

Straight answers

What organizations ask about wireless security audits.

Encryption strength and credential model are two entirely separate questions. Modern encryption protects the traffic in flight. A shared key means every device carries the identical credential, nobody can be individually revoked, and nothing anyone does can be attributed to a specific machine. Making the password longer addresses neither of those, which is why moving to certificates is the change that actually matters.

Certificates delivered through whichever platform already manages your devices. Intune wireless profiles push the settings so nobody configures anything by hand, and certificates handle authentication so people reach resources without ever entering a username or password, using trusted root, SCEP, or PKCS certificates depending on how the environment is built.

Those devices are the genuine constraint, and the audit names them precisely: printers, scanners, handhelds, plant equipment, older hardware, and anything with no management agent. The answer is nearly always a separate segment for that group with severely restricted reach, rather than holding your whole company on a shared credential because a minority of machines demand one.

The configuration review, the analysis, and the reporting are all delivered remotely. The survey and isolation testing genuinely require someone at the location, so we run those as a structured, remotely directed exercise: your on-site staff follow our survey process with our live direction, using ordinary equipment, and the captures come back to us for analysis. For multi-site estates we select representative locations plus any site with a known concern rather than surveying everything. Where a directed survey does not fit, we say so at scoping and agree an alternative per engagement.

It stops devices on the same network talking to one another. Without it on a guest network, every visitor device shares a broadcast domain with every other visitor device, including whatever happens to be running on the laptop of the person waiting in reception. It is one setting, it is very often left off, and the consequences fall entirely on your guests.

That is precisely what gets tested rather than assumed. Every company believes it is isolated, and the exception we find is nearly always a single deliberate path somebody created for a perfectly good reason: a printer made reachable so visitors could print, a management interface left answering on guest, or a route that quietly survived a network redesign. Testing from an actual guest device is the only way to find out.

It matters enormously where the credential is shared, because physical distance was the only thing making that credential defensible. In a building with several companies in it, a corporate network usable from the corridor or the parking structure extends the population who could try to join it far beyond anyone you have any relationship with at all.

Any wireless device broadcasting in your building that you did not put there. Intent varies enormously: a department that fixed a coverage complaint themselves, a vendor who installed their own connectivity alongside their equipment, an employee running a personal hotspot, or something deliberately impersonating your network name to collect credentials. Most platforms can detect all of it, and most have the feature turned off.

It ought to be a network segment and in many companies it is merely a way to get online. Where a device joining the wireless lands in the same broadcast domain as the servers, that wireless is functionally an unauthenticated network port sitting in a public space. Establishing what it can genuinely reach is among the more consequential parts of this work.

Very much in scope, because a beautifully designed wireless network running on a poorly secured controller is not a control at all. Management interface exposure, whether that interface answers from the wireless it governs, administrative credentials, firmware currency, and whether adding an access point goes through change control all sit under secure configuration, Control 4 in the CIS Critical Security Controls at version 8.1.

A wireless penetration test tries to get in and prove what that would cost you. This audit establishes the whole position: what exists, how each network authenticates, how far the signal carries, what a joined device can reach, and whether anybody is watching. The two complement each other, and the audit is usually the better first engagement because it produces a complete picture rather than one successfully demonstrated route.

One shared key on the corporate network, unchanged for years, held by a population nobody can count. We find it in the substantial majority of companies we audit, the team invariably already knows about it, and it survives because the fix used to be genuinely disruptive. Device management platforms have largely taken that disruption away. Scoping runs on the number of sites, since the survey and the isolation testing happen per location. For a distributed estate we select representative sites plus anywhere with a known concern, rather than surveying every building you own.
Before the audit

Fifteen questions worth answering about your wireless.

The first set establishes what exists at all. The second covers how each network authenticates and how far it reaches. The third is the operational half, which decides whether any of it still holds true next year.

What exists

  • How many networks are you broadcasting?
    Then compare with what a survey finds.
  • Which sites are in scope?
    Branches and remote facilities included.
  • Are there networks IT did not deploy?
    Departments, vendors, and building services.
  • Is there wireless on operational equipment?
    Plant, scanners, cameras, access control.
  • Who owns the wireless platform?
    Frequently facilities rather than IT.

Authentication and reach

  • How does corporate wireless authenticate?
    Shared key, or per-device certificate.
  • When did the shared key last change?
    And who has it.
  • Is guest genuinely isolated?
    Tested, not assumed.
  • Is client isolation on for guests?
    Frequently not.
  • What can a wireless device reach?
    Tested from the segment.

Operations

  • Is rogue detection enabled?
    Usually available, usually off.
  • Who is alerted, and do they act?
    Detection without response is a log.
  • Is controller firmware current?
    Secure configuration, Control 4.
  • Are management interfaces restricted?
    Not reachable from the wireless itself.
  • Is there change control on access points?
    They are small, cheap, and easy to add.
Related reading

The pages around this one.

Microsoft Intune

The device management platform that delivers the Wi-Fi profiles and certificates, which is how the shared key goes away.

Learn more

Firewall rule audit

The other half of the network position: what the wired configuration permits.

Learn more

Penetration testing

Demonstrating impact, alongside the audit that establishes the position.

Learn more
Next step

Two questions: when did the corporate wireless password last change, and who holds it now.

The answer to the first is usually a year that visibly startles somebody in the room. The answer to the second is that nobody knows, and that is the real finding. Both are fixable now in a way they simply were not five years ago, because the certificate arrives through the platform already managing the device.

Book a wireless security auditSee the audit practice

Related Services

Explore more solutions that work great with this service

Firewall Rule Base Audit

Rule bases reviewed, tightened and documented

Learn more

Penetration Testing

Penetration testing for US businesses across external, internal, web

Learn more

Microsoft Intune

Device management and endpoint security

Learn more

Managed IT Services

Complete outsourced IT department

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA