Nobody has changed the corporate wireless password since 2019, and every contractor since has been handed it.
Four questions define this work. What is actually broadcasting from your building, how does each of those networks authenticate anyone, what can a device reach once it has joined, and would a single person notice an access point that nobody deployed. Most companies can answer the first one partially and the other three not at all.

- What is broadcastingIncluding what you did not deploy
- How it authenticatesShared key, or certificate per device
- What it reachesSegmentation, tested rather than assumed
- Who would noticeRogue and neighboring access points
Six areas, and the shared password is merely the most obvious of them.
Authentication, and the shared key problem
A shared key is one credential held by every device, revocable for nobody in particular. It gets given to contractors, typed into personal phones, and written on a whiteboard in a meeting room, and it only ever changes when somebody accepts the pain of changing it on everything at once. Certificate-based authentication removes the shared secret altogether, and it remains the single change that improves wireless security most.
What is actually broadcasting from your premises
Corporate, guest, voice, building services, registers, plant equipment, and whatever a department stood up for a project two years ago. The survey records what is genuinely broadcasting rather than reading the controller configuration, because a controller only knows about the access points it manages and the interesting ones are always the others.
Where the coverage actually reaches
Wireless does not respect a lease boundary. A survey establishes whether your corporate network is usable from the parking lot, the neighboring floor, the street, or the suite next door. That is not a theoretical concern in the dense office buildings and mixed-use developments where many US businesses operate, where several organizations frequently share a building and occasionally share a wall.
Guest isolation, tested rather than assumed
Nearly every company runs a guest network and assumes it is isolated. We test the assumption from a device sitting on it: can a visitor reach the corporate network, other visitors, a management interface, or genuinely nothing but the internet. Client isolation between guests is missing more often than not, which quietly turns your guest network into a shared broadcast domain for everybody who walks through the door.
Segmentation, and what a compromised device could reach
Once something has joined the corporate wireless, where can it go. In a great many companies the honest answer is everywhere, because wireless was built as a way to get online rather than as a network segment in its own right. Measuring what is actually reachable, rather than what was intended, regularly shows wireless to be the least controlled way into the core.
Monitoring, rogue detection, and configuration drift
Would anyone notice an access point appearing that nobody ordered, a laptop broadcasting your own network name, or a configuration change on the controller. Network monitoring and defense is Control 13, and wireless is the part of the network most likely to change with no change record at all, because the hardware is small, cheap, and fits in a drawer.
A shared key is a credential you cannot take away from one person.
This is the most common wireless finding, the one everybody already understands, and the one fixed least often, because historically the fix hurt.
- Every device that has ever connected still holds it: contractors, people who left two years ago, personal phones, the visitor who asked once at reception, and anybody those people passed it to. Revoking it for one device is impossible, because no device has a credential of its own.
- Changing it means touching every single device, which is precisely why nobody does. In most companies the corporate key has not moved since the day the network went in, everybody involved knows that perfectly well, and everybody has quietly made peace with it.
- Certificates remove the shared secret entirely. Intune wireless profiles push the settings out so nobody has to configure anything, and certificates handle the authentication so people reach resources without ever typing a username or password, using trusted root, SCEP, or PKCS certificates depending on how your environment is built.
- That combination is why this is finally practical. The management platform delivers the profile and the certificate together, so the disruption that blocked this change for a decade has largely disappeared. What the audit does is quantify the effort remaining against whatever population is not managed.
Four things this finds that reading the configuration never will.
We survey rather than read the controller
A controller reports only on the access points it manages, which means every interesting finding is invisible to it: something a department installed to fix a coverage complaint, a vendor access point that arrived alongside their equipment, a building services network, or a laptop broadcasting your own network name. Only a survey turns those up, and we run it as a structured exercise directed remotely with your people on site.
We establish where the coverage actually goes
Radio does not respect a lease. In a shared building with several companies on different floors, whether your corporate network is usable from the corridor, the parking garage, or the suite next door is a physical question with a physical answer, and it changes the risk calculation around a shared key considerably.
We test isolation instead of accepting the design
Guest isolation, client isolation, and segmentation away from the wireless are all things every company is confident it already has. Testing each from a device actually sitting on that network, rather than reading what the configuration intended, is how the exceptions appear. There is nearly always at least one path nobody designed on purpose.
We size the migration off shared keys realistically
Certificates are the right destination, and the real question is always the population that cannot easily get there: unmanaged devices, contractor equipment, printers, scanners, plant hardware, and anything with no management agent on it. Sizing that group honestly is what converts a recommendation into a plan somebody will actually fund.
Six US situations where a wireless audit finds something material.
An organization in a shared or mixed-use building
Ordinary in a downtown tower and just as ordinary in a suburban office park. Your signal carries into the corridor, down into the parking structure, and quite possibly into the suite next door, while theirs carries into yours. Where the corporate network runs on a shared key, the physical boundary that once made that acceptable does not exist, and mapping the real coverage footprint is the first genuinely useful output.
A retail or hospitality business offering guest wireless
Guest wireless is handed to the public deliberately, which leaves isolation carrying the entire control. We test whether a guest device can reach the corporate network, the register environment, a management interface, or the other guests. Where card data is involved, segmentation away from the payment environment is a PCI DSS scoping question as much as a security one, and getting it wrong widens your assessment scope considerably.
An operator with wireless on plant and handheld equipment
Scanners, handhelds, sensors, and control equipment frequently cannot handle certificates at all, and they are the reason the shared key survives everywhere else. Identifying exactly which devices those are and building them a separate segment with tight restrictions is almost always a better answer than holding the entire company on one shared credential because a minority of hardware demands it.
A regulated firm with an obligation covering network access
Wherever a regulator expects individual accountability for network access, and GLBA examiners, NYDFS Part 500 assessments, and CMMC audits against NIST 800-171 all reach into this, a shared key cannot deliver it. No device holds a credential of its own, so nothing can be attributed to anyone. That is an easy finding to write and an equally easy one to close, using certificates pushed out by the platform already managing the devices.
An organization with heavy contractor presence
Every contractor ever handed the wireless password still has it, as does every device they used while they were on site. Where contractors are numerous and rotate constantly, that key becomes a credential held by a population nobody can count, and no amount of encryption strength touches the problem. A separate contractor segment with individual credentials is the answer.
A healthcare organization with clinical devices on wireless
Clinical equipment on wireless pairs devices that cannot easily be reconfigured with a network that cannot go down. Meanwhile HIPAA expects access to systems holding protected health information to be both controlled and attributable. The audit establishes which devices are constraining the design, whether they sit apart from general corporate traffic, and whether the wireless can reach clinical systems it has no business reaching.
How US organizations secure their wireless networks.
| Feature | Certificate based and segmented | Modern encryption, shared key | Unmanaged or legacy wireless |
|---|---|---|---|
Per-device credentials | Yes | No | No |
Individual revocation possible | Yes | No | No |
Guest isolated and tested | Yes | Assumed | No |
Client isolation between guests | Yes | Often not | No |
Wireless treated as a network segment | Yes | Sometimes | No |
Coverage beyond premises understood | Yes | No | No |
Rogue access point detection active | Yes | Available, off | None |
Controller hardening verified | Yes | Assumed | No |
Access point additions recorded | Yes | No | No |
Effort to remove one person's access | Seconds | Change it for everyone | Not possible |
Ten checks, and where each one usually fails.
Check
Every broadcasting network identified
- Where it usually fails
- Networks nobody in IT deployed, from departments or vendors
Check
Authentication method per network
- Where it usually fails
- One shared key across the corporate network, untouched for years
Check
Certificate infrastructure where used
- Where it usually fails
- Certificates issued once with no renewal or revocation process
Check
Guest isolation from corporate
- Where it usually fails
- Tested rarely, and occasionally not actually in place
Check
Client isolation between guests
- Where it usually fails
- Frequently absent, so visitors share a broadcast domain
Check
Segmentation from the wireless segment
- Where it usually fails
- Wireless built as a way to get online rather than as a segment in its own right
Check
Coverage beyond the premises
- Where it usually fails
- Usable signal in parking lots, corridors and neighboring suites
Check
Controller and access point configuration
- Where it usually fails
- Default management credentials and unpatched firmware
Check
Rogue access point detection
- Where it usually fails
- Available in the platform and never enabled
Check
Change control on wireless configuration
- Where it usually fails
- Access points added without any record
Five steps, and the survey steps need someone at the site.
- 1
Review the configuration and the intended design
The controller and access point configuration, every network defined on it, how each authenticates, what the segmentation was meant to do, the guest arrangements, how management access works, and how current the firmware is. This tells us what was designed, which becomes the baseline the physical findings get measured against rather than the conclusion itself.
- 2
Survey what is actually broadcasting, at each site
Every network broadcasting at each location in scope, including everything the controller knows nothing about. Departmental installations, vendor equipment, building services, and anything announcing a network name it has no right to. The distance between what the survey finds and what the configuration claims is the first substantive finding of the engagement.
- 3
Establish the coverage footprint
Where each network can actually be used from: the corridor, the parking structure, the floor above, and the neighboring suite where we can reach it. Radio ignores lease boundaries entirely, and in a shared building the physical extent of your network is a material input into whether a shared credential is defensible at all.
- 4
Test isolation and segmentation from each network
Tested from a device on the guest network, from one on corporate, and from every other network in scope. What can be reached from each, whether client isolation is actually on, whether a management interface answers from the wireless it controls, and whether the wireless segment can touch systems it has no business reason to touch.
- 5
Report with a realistic migration path
Findings ranked by risk, with the shared key answered through certificates delivered by the platform already managing your devices, and the population that cannot support them identified precisely and given a segment of its own. Monitoring recommendations come with it, because rogue detection is usually already licensed and usually switched off.
What organizations ask about wireless security audits.
Fifteen questions worth answering about your wireless.
What exists
- How many networks are you broadcasting?Then compare with what a survey finds.
- Which sites are in scope?Branches and remote facilities included.
- Are there networks IT did not deploy?Departments, vendors, and building services.
- Is there wireless on operational equipment?Plant, scanners, cameras, access control.
- Who owns the wireless platform?Frequently facilities rather than IT.
Authentication and reach
- How does corporate wireless authenticate?Shared key, or per-device certificate.
- When did the shared key last change?And who has it.
- Is guest genuinely isolated?Tested, not assumed.
- Is client isolation on for guests?Frequently not.
- What can a wireless device reach?Tested from the segment.
Operations
- Is rogue detection enabled?Usually available, usually off.
- Who is alerted, and do they act?Detection without response is a log.
- Is controller firmware current?Secure configuration, Control 4.
- Are management interfaces restricted?Not reachable from the wireless itself.
- Is there change control on access points?They are small, cheap, and easy to add.
The pages around this one.
Microsoft Intune
The device management platform that delivers the Wi-Fi profiles and certificates, which is how the shared key goes away.
Firewall rule audit
The other half of the network position: what the wired configuration permits.
Penetration testing
Demonstrating impact, alongside the audit that establishes the position.
Two questions: when did the corporate wireless password last change, and who holds it now.
The answer to the first is usually a year that visibly startles somebody in the room. The answer to the second is that nobody knows, and that is the real finding. Both are fixable now in a way they simply were not five years ago, because the certificate arrives through the platform already managing the device.
Related Services
Explore more solutions that work great with this service
Firewall Rule Base Audit
Rule bases reviewed, tightened and documented
Learn morePenetration Testing
Penetration testing for US businesses across external, internal, web
Learn moreMicrosoft Intune
Device management and endpoint security
Learn moreManaged IT Services
Complete outsourced IT department
Learn more