How Often Should You Run a Wi-Fi Penetration Test?

Run a Wi-Fi penetration test once a year, and again after any change to the wireless estate: a new access point vendor, a move to 802.1X, an office relocation or an acquisition that brings someone else’s kit onto your floor. Wireless is the one part of your perimeter that leaks past the walls. Anyone sitting in the car park is inside radio range, and they never have to get through your firewall to start.

How Often Should You Run a Wi-Fi Penetration Test?

What a wireless test actually looks for

A wireless test checks how your networks authenticate users and what an attacker within range can reach once associated. On a pre-shared key network the tester captures a PMKID or a handshake and takes it away for offline cracking, which on a corporate passphrase chosen in 2019 tends to end badly. On an 802.1X network the attack shifts to the client: stand up an access point with the same SSID, present a certificate the supplicant has not been told to validate, and collect domain credentials from laptops that connect automatically. Beyond authentication, the tester checks what the guest network can actually see and whether management interfaces on the access points answer from a user VLAN they should never appear on.

Why an annual Wi-Fi penetration test is the sensible baseline

You should treat once a year as the minimum and add a test whenever the wireless configuration changes materially. NIST’s Guidelines for Securing Wireless Local Area Networks, published as Special Publication 800-153, recommends periodic technical assessments of WLAN security rather than reliance on monitoring alone, and the reasoning holds up. Wireless configuration drifts quietly. A contractor stands up a temporary SSID for a project, or an office refit moves the guest VLAN onto a switch with different rules. None of those appear in a change advisory board record, and none of them show up in an external scan.

“The finding that comes up most often on wireless work is not weak encryption, it is a guest network that reaches internal systems through a printer or a firewall rule written years ago. We have collected a domain user hash from a car park inside an hour on a properly configured 802.1X network, purely because the laptops were set to trust any certificate presented to them. Check the client supplicant settings, not just the controller.”

William Fieldhouse, Director, Aardwolf Security Ltd

Laptop displaying a network attack path from wireless access into internal systems

Wireless findings that lead somewhere worse

Wireless access only matters to an attacker if it leads inwards. That is why a good report follows the chain rather than stopping at the radio layer. From a guest SSID that should be isolated, the tester will look for printers holding LDAP credentials on a readable configuration page, and for file shares that answer to any authenticated user. This is where wireless work overlaps with internal network penetration testing, and it is why the two are often booked together for the same visit. If your segmentation holds, the test proves it in an afternoon. If it does not, you would rather find out from a report than from an incident.

What to prepare before the tester arrives

You should give the tester a floor plan, a list of your SSIDs, the access point vendor and model, and a named contact who can confirm which radios belong to you. That last point is not bureaucracy. In a shared building or a serviced office your neighbours’ networks are within range, and testing them is illegal, so the boundary has to be agreed in writing before anyone switches on a wireless adapter. Tell your landlord and building security that someone will be walking the floors with an aerial. Decide whether the deauthentication elements of the work run out of hours, because kicking a warehouse scanner off the network at eleven in the morning makes you unpopular. Wi-Fi penetration testingis on-site work, so book the days when the office is occupied and behaving normally.

Frequently asked questions about wireless testing

Two practical questions come up whenever a wireless assessment is being planned.

Can wireless testing be done remotely?

No. Radio work needs a tester physically within range of your access points. Some configuration review can happen remotely against the controller, but the attacks that matter require someone on site or in the car park.

How long does a site take?

Budget one to two days for a single office with a handful of SSIDs. Large sites, warehouses and multi-building campuses take longer, mainly because coverage walking eats time, and multi-site estates are usually sampled rather than tested in full.