Wireless Penetration Testing
Senior-led testing of your Wi-Fi for what it really is — a door into your network an attacker can approach from the car park, the lobby or the building next door. We attack your wireless the way they would, then test what they can reach once inside — and hand you a prioritised, evidence-backed report with a free retest.
- On-site RF & over-the-air testing
- WPA2 / WPA3 & 802.1X (EAP) coverage
- OSCE / OSCP-certified testers
- Free remediation retest included
Your network perimeter now extends to the car park.
Wi-Fi doesn't stop at your walls — its signal reaches the street, the lobby and the floor above, so an attacker never has to get past reception. A weak pre-shared key, a spoofable SSID or a flat guest network turns a coffee-shop laptop into a foothold on your internal LAN. We test the radio and what sits behind it, the way a real attacker would, before they do.
The radio, the authentication, and the network behind it.
A wireless assessment is only useful if it follows the signal all the way to what it protects — so we test the air, the auth and the pivot, not just a scan of nearby SSIDs.
-
Rogue APs & Evil Twin
Spoofed access points, captive-portal phishing and forced-deauthentication attacks against your users.
-
WPA2 / WPA3 & PMKID
Handshake and PMKID capture, offline cracking, and downgrade or KRACK-class weaknesses.
-
802.1X / Enterprise (EAP)
PEAP / EAP-TLS configuration, certificate validation and credential-relay weaknesses.
-
Pre-Shared Key
PSK strength, shared-key reuse and the blast radius of a single leaked passphrase.
-
Client-Side Attacks
Karma / known-network attacks, probe-request abuse and man-in-the-middle against roaming devices.
-
Guest & Segmentation
Guest-to-corporate isolation, VLAN hopping and whether wireless can reach systems it shouldn't.
-
Segmentation & Pivot
What an attacker on the wireless can actually reach on the internal network once associated.
-
Rogue & Shadow Devices
Unauthorised APs, hotspots and IoT radios extending your attack surface without approval.
From site survey to retest — a disciplined, four-phase engagement.
-
01
Scope & site survey
We agree the sites, SSIDs, in-scope networks and constraints, and plan safe on-site testing windows.
-
02
Recon & capture
On location we map the RF environment, identify APs and clients, and capture the handshakes we need.
-
03
Manual exploitation
We hand-test each attack class and, where authorised, pivot from the wireless onto the internal network.
-
04
Report & free retest
You get a prioritised, evidence-backed report; after you remediate, we retest to confirm every fix — at no extra cost.
A report your engineers can act on — and your auditors accept.
-
Prioritised findings
Every issue risk-rated by real business impact and ordered so you fix what matters first.
-
Reproducible evidence
Step-by-step proof-of-concept per finding — captures, positions and ranges, not vague claims.
-
Developer-ready remediation
Specific, actionable fix guidance for your network and identity teams, not a generic checklist.
-
Executive summary
A plain-language overview for leadership, boards and clients requesting assurance.
-
Free remediation retest
We re-test your fixes and confirm they hold — included with every engagement.
-
Attestation letter
A summary letter you can share with customers, partners and auditors on request.
Evidence that maps to the frameworks you report against.
One engagement, structured so its output slots straight into the assurance work you already have to do.
| Framework | How this engagement maps |
|---|---|
| PCI-DSS 11.3 & 11.2 | Satisfies the wireless penetration-testing and rogue-AP detection requirements for cardholder environments. |
| SOC 2 | Provides the independent pentest evidence auditors expect for the Security trust-services criteria. |
| ISO 27001 (A.8.20-8.21) | Supports the network-security and network-controls requirements in your ISMS. |
| Essential Eight | Evidence for the network-hardening and access-restriction expectations of the ACSC maturity model. |
| Wireless policy | Validates that your wireless security policy holds up under real over-the-air attack. |
What teams ask before a wireless test.
Does the test have to be done on-site?
Yes — wireless is a radio-frequency attack surface, so we test over the air on location. That's the only way to prove real signal range, rogue-AP exposure and what an attacker within range can actually do.
Do you test WPA3 and 802.1X / enterprise Wi-Fi?
Yes. We cover WPA2 and WPA3, pre-shared-key and 802.1X / EAP (PEAP, EAP-TLS) networks, including certificate validation and credential-relay weaknesses.
Will you try to pivot into our internal network?
Where you authorise it, yes — the real risk of weak Wi-Fi is what it exposes behind it, so we test what an attacker who gets onto the wireless can then reach internally.
Is the testing safe for our users and business?
Yes. We agree rules of engagement and testing windows up front and use controlled, targeted techniques — we don't indiscriminately knock your users offline.
How long does a wireless penetration test take?
Most engagements run a few days per site depending on the number of SSIDs, networks and locations. We confirm timing and travel at scoping.
Can we use the report for PCI-DSS, SOC 2 or ISO 27001?
Yes. The report and optional attestation letter are written to satisfy auditor, customer and PCI wireless-testing requirements.
Do you provide wireless penetration testing across Australia?
Yes — on-site anywhere in Australia, scheduled from our Sydney base. See penetration testing across Australia for coverage, methodology and the engagement process.
Get a fixed-price scoping quote.
A senior tester scopes the right engagement and sends a fixed quote — no automated sales funnel, no obligation.