WiFi Penetration Testing
Your wireless network is the one part of your perimeter that leaves the building. It reaches the car park, the floor above and the café next door, and anyone within range can attack it without ever passing reception. We test yours on site: what it broadcasts, whether its authentication holds, and — if we get on — how far the network lets us go once we are.
Who this is for
- Your offices run corporate, guest and device networks and nobody has checked they are genuinely separate
- You have inherited access points from an office move, a refit or an acquisition and cannot say who configured them
- Staff and visitors share space with other tenants, so your signal is reachable by people you have no relationship with
- You are already booking an internal test and want the wireless layer covered while an engineer is on site
- An auditor or insurer has asked specifically whether your wireless network has been tested
What we test
Coverage runs in depth, not breadth alone — each stage goes past where the one above it stops.
- Survey
What the air is telling everyone
Every ESSID and BSSID in range, with channel configuration and signal strength mapped across the site. This routinely turns up networks the client did not know were theirs — an old access point from a refit, or a device somebody plugged in and forgot.
- Configuration
What it will accept
The encryption and authentication mechanisms each network supports, including whether a weaker legacy option is still accepted alongside the one you intended. A network is only as strong as the worst method it will still negotiate.
- Authentication
Whether the door holds
Pre-shared keys attacked offline under controlled conditions with the same cracking capability as our password audit, and, where 802.1X is deployed, whether certificate validation is enforced or a client can be persuaded to authenticate elsewhere.
- Segregation
What the network lets you reach
Once connected, whether guest is genuinely isolated from corporate, whether device and voice networks are separated as designed, and what a wireless client can actually route to. Segregation is the control most often assumed and least often verified.
- Impact
How far a foothold goes
What is reachable from a wireless position: internal services, management interfaces, file shares. This is where a wireless finding stops being a configuration note and becomes a route into the estate.
What you get
The package in three parts — what you read, what you act on, and what happens after.
What you read
Measured on site, not inferred from a config export.
- A site-by-site inventory of networks in range, with yours identified
- A verdict on each network's encryption and authentication, including weaker methods still accepted
- A segregation map: what each network reaches, against what it was designed to reach
What you act on
Specific to your kit, not a generic hardening list.
- Every finding with business impact, severity and a specific remediation
- What a recovered pre-shared key says about how your keys are chosen
- Findings your engineers can reproduce, with location and conditions recorded
What happens after
The fix is verified.
- Free remediation retest of the wireless findings once configuration changes land*
* Free remediation retesting applies to penetration testing engagements. It is subject to the size of the assessment and available for three months from delivery of your report. A web application test is typically covered; a large engagement — an internal test across hundreds of systems, for example — is scoped and quoted, and a full re-assessment is always chargeable.
How it runs

The same six phases, every engagement
Threat Model Development
We agree what the exercise is replicating: the credible threats to your organisation, the starting position, the objectives, and which controls are in scope. It is also where disruption is bounded, so the test does not cost you a working day.
Information Gathering
Enumerating the systems and services actually in play from that starting point, so the attack surface is mapped as it is rather than as the asset register describes it — and choosing tools and techniques that suit it.
Vulnerability Identification
Examining that surface for weakness, using automated tooling for breadth and manual technique for everything a scanner cannot reason about. Neither finds what the other does, which is why the blend is deliberate.
Attack Vector Development
Weighing each weakness against your actual environment — how exploitable it really is, what skill it demands, what it would cost you. The output is the routes that are practical here, not the ones theoretically possible somewhere.
Exploitation
Where it is appropriate, we exploit, which usually opens a fresh attack surface and sends us back round the cycle. Where exploiting would cause harm we verify the finding is genuine rather than a stale banner, and assume the worst case.
Reporting
One document for two audiences: an executive summary your board can act on, and the technical chain your engineers can reproduce step by step, each finding carrying its severity and its remediation.
Prerequisites
- Site access for a testing engineer, and the addresses of every location in scope — this assessment cannot be delivered remotely
- The names of the networks that belong to you, so anything else in range is correctly identified as a neighbour rather than tested
- Written confirmation from whoever controls the building where you share premises with other tenants
- Guest-network credentials if guest access is in scope, and a test account for any network using enterprise authentication
- A signed Laneden authorisation form. On-site attendance is quoted separately from the assessment itself
Frequently asked questions
Can you do this remotely?
No, and be wary of anyone who says they can. Wireless is a radio problem: the whole point is what is reachable from a physical position — the car park, the floor above, the café next door. An engineer has to stand in those places with the right hardware. It is the reason we usually pair it with an internal infrastructure test, so one visit covers both.
Will you knock our staff off the network?
No. Deauthentication and jamming techniques disrupt service, so we do not use them, and disrupting availability sits outside our standard engagement terms in any case. We observe, we analyse what the networks advertise, and we attempt to authenticate as a client would. If a scenario ever warranted anything more intrusive, it would be agreed in writing and scheduled first.
We use a pre-shared key everyone knows. Is there any point testing?
Yes, and that is often the finding rather than the obstacle. A shared key that has not changed since the last office move, is known to former staff, and grants the same access as a corporate laptop is a real exposure — and until it is written down with an impact next to it, it tends not to get fixed. We also test what that key actually gets you, which is usually the more uncomfortable answer.
How does this differ from an internal infrastructure test?
An internal test starts from a position on your network — we are already inside. Wireless testing asks how someone gets there in the first place without being handed a cable, and whether the network they land on is the one you intended. They answer different halves of the same question, which is why they are commonly scoped together.
Do you need to test every office?
Not necessarily. Where sites share a standard build, testing a representative sample tells you whether the build is sound; where sites were configured independently — very common after acquisitions — each one is genuinely a separate question. We will tell you honestly which situation you are in during scoping.
Related services
Internal Infrastructure Testing
When an attacker gets past the perimeter — through phishing, a compromised laptop or a rogue device — how far can they go?
Learn more →
Active Directory Security Audit
Active Directory is the key to almost everything else you own, and in most organisations it has been quietly accumulating accounts, permissions and exceptions for a decade or more.
Learn more →
Active Directory Password Audit
Your password policy says fourteen characters with complexity.
Learn more →
Ready to test your defences?
Tell us about your wifi penetration testing requirement — we'll come back with a scoped proposal within two working days.
Free remediation retesting* to confirm your fixes (subject to assessment size).
