Managed IT

Every other part of your network has a door. Wireless does not. It leaves the building through the walls, reaches the parking lot, and admits anyone holding a passphrase that has been shared with several hundred people over six years. The gaps below are the ones that turn up most often, and none of them require sophistication to exploit.

Aureon · Managed IT & Managed WiFi

Wired network security has a useful assumption behind it: to plug something in, you have to be in the building. Wireless removes that assumption and almost nothing in the average setup replaces it. The access point does not know or care where the client is standing.

Why wireless fails differently

Fortinet puts 70% of organizations on wireless networks that lack enterprise-grade security controls, which makes this the normal condition rather than an unusual lapse. Verizon's DBIR finds one in four SMB network breaches involving an unsecured or misconfigured wireless access point as the initial entry vector.

What makes those numbers stick is that wireless problems are quiet. A misconfigured firewall rule usually breaks something and gets noticed. A wireless network with a passphrase that half the county knows works perfectly for everyone, including whoever should not have it. Nothing degrades, nothing alerts, and there is no moment where it stops functioning and prompts a look.

The boundary is physical, and it is not the wall

Signal does not stop at the property line. An access point mounted near an exterior wall and turned up to full power is offering a login prompt to the sidewalk. Attacking that requires no network access and no foothold, only proximity and patience, and there is no log anywhere showing that somebody sat outside and tried.

This is also why wireless gaps tend to sit unresolved for years. The controls that would close them are configuration choices rather than purchases, so nothing prompts a review, no invoice arrives, and no vendor calls to ask.

Worth saying plainly
None of the gaps below are advanced. They are the wireless equivalent of an unlocked side door: unremarkable individually, and the reason a quarter of SMB breaches start here.

The three gaps that show up most

What We Find

Wireless assessments turn up plenty of small things. Three findings account for most of the actual exposure, and all three are configuration and process problems rather than hardware ones.

Most common

The shared password

One passphrase for all staff · No rotation · No per-device revocation · Survives departures

Most business wireless runs on a single pre-shared key. Everyone who has ever worked there knows it, along with their families, the contractor who came for a week in 2021, and anyone who photographed the sticky note on the reception desk. It cannot be revoked for one person, so when somebody leaves, the only real option is changing it for everybody and re-enrolling every device. That is enough friction that it almost never happens.

The version worth understanding is that this is not a WPA2 problem. WPA2-Enterprise is still perfectly reasonable. The weakness is the shared secret model underneath it. Moving to per-user or per-device authentication, so credentials can be revoked individually, is the change that matters, and it is what makes a departure a five-minute task instead of a project nobody schedules.

The pattern behind all three

Each of these persists because the network keeps working. There is no outage, no error, no user complaint and no invoice, so nothing schedules the review. Wireless is the part of the stack most likely to be silently wrong, which is exactly why it needs a calendar rather than a trigger.

Coverage is a security problem too

Coverage usually gets filed under performance, and that is where the obvious cost sits. Aruba Networks estimates $4,700 in lost productivity per employee per year from unreliable wireless. The less obvious cost is that bad coverage generates security problems, because people route around it.

Dead zones create their own workarounds

A team member who cannot get signal where they work does not file a ticket and wait. They tether to their phone, or they bring in a range extender, or they move to a spot with signal and take the confidential call there. Each of those moves work onto infrastructure you do not manage, cannot see and cannot secure. The rogue access point above is usually a coverage problem wearing a hardware costume.

This is why a wireless assessment starts with a site survey rather than a configuration review. Coverage designed around where cable happened to run, instead of where people actually sit, produces gaps that get solved locally and invisibly.

The opposite problem is real too

Compensating for weak spots by turning every access point to maximum power is common and counterproductive. It pushes usable signal well past the building, so the login prompt is now available from the parking lot and the street. It also makes access points interfere with each other, which degrades performance in the middle of the space while extending reach where you least want it.

Correct placement is more access points at lower power rather than fewer at maximum. That improves capacity and coverage at the same time as it pulls the usable boundary back toward the walls.

Two tests worth running
Walk the building with a phone and note where signal drops, particularly in the places people actually work rather than the corridors. Then walk the perimeter outside and see how far your network is still usable. Most organizations are surprised by one of the two, and often by both.

Guest access, briefly

Guest wireless belongs in its own network segment with no route to anything internal, and a separate SSID does not accomplish that on its own. If both SSIDs land in the same place, you have separated the login and not the network. The mechanics of that sit at the switch layer rather than the wireless one, and are covered in the segmentation guide. The wireless-side point is narrower: check it rather than assume it, because it takes five minutes and fails more often than people expect.

Wireless Readiness Checklist

The Checklist

Fifteen questions across coverage, access control, rogue device detection and hardware age. Tick the ones you can answer without going and asking someone, and the score updates as you go. Use it yourself or share it with your team.

0 of 15 answered confidently

Tick what you can answer without checking. The blanks are the gaps.

Coverage & Placement

Has anyone surveyed the building, or were APs placed where cable ran?

Coverage designed around the cabling plan rather than the floor plan produces predictable gaps.

Where do people lose signal in the places they actually work?

Corridors are easy. Corner offices, warehouses and stairwells are where the workarounds start.

How far outside the building is your network still usable?

Walk the perimeter. If it reaches the street, so does the login prompt, and nothing logs the attempt.

Is anyone tethering or using a personal hotspot to get work done?

Work moving onto infrastructure you cannot see is a coverage symptom before it is a policy one.

Access & Encryption

When was the wireless passphrase last changed?

A date. If the answer is the install, everyone who has ever worked here still has access.

Can you revoke one person's wireless access without changing it for everyone?

With a single shared key you cannot, which is why departures rarely trigger a change.

What encryption standard is each SSID actually running?

Worth checking per SSID rather than assuming. Legacy ones set up for old equipment tend to linger.

Is the access point admin interface still on its default credentials?

Fast to check, and the finding that makes every other control on the device moot.

Rogue Device Detection

Would you know if someone plugged in their own access point?

It broadcasts to everyone in radio range and, without monitoring, to nobody in IT.

How many wireless networks are broadcasting in your space right now?

Most teams can name two or three. A scan usually finds more, and some of them are yours.

Are unused wall ports live?

A rogue access point needs a live port. Shutting them down removes the easiest path.

Could you list the devices connected to wireless right now?

Not the count. The list, with something identifying each one.

AP Age & Firmware

How old are the access points, and are any past vendor support?

They keep serving clients perfectly while no longer receiving security fixes at all.

When was access point firmware last updated?

Nothing prompts this one. No symptom, no complaint, no invoice, so it waits indefinitely.

Is any consumer-grade wireless hardware still in production use?

Usually at a small site, usually bought to solve one problem, usually still there years later.

Frequently asked questions

Three findings account for most of the exposure in small and mid-sized businesses. A single shared passphrase that everyone who has ever worked there still knows and that cannot be revoked for one person. Rogue access points, usually somebody solving their own coverage problem with a router from home, bridging an unmanaged wireless network into the internal wired one. And stale access point firmware, deferred more reliably than almost anything else because nothing ever prompts it. All three are configuration and process problems rather than hardware ones.

WPA2-Enterprise remains in wide and reasonable use, and the protocol version is rarely the weak part. The problem in most businesses is the shared secret underneath it: one pre-shared key issued to everybody, never rotated, and impossible to revoke for a single person. Moving to per-user or per-device authentication does more for security than the version number does, because it makes removing one person's access a five-minute task rather than a project that gets scheduled and then does not happen.

A rogue access point is wireless hardware on your network that you did not deploy and do not manage. Most are not malicious. Somebody with no signal in a corner office buys a router, plugs it into the wall port under the desk and fixes their own problem. What it also does is bridge an unmanaged and often unencrypted wireless network straight into your internal wired network, past the controls configured at the edge. The malicious version looks identical from the outside, so the detection question is the same either way.

On a schedule, because nothing else will trigger it. An access point running four-year-old code serves clients exactly as well as one running current code, so there is no symptom, no complaint and no invoice to prompt the work. Two things make the delay worse than it sounds: wireless vulnerabilities are attackable from outside the building, so a stale access point is exposed to a wider set of people than a stale server, and access points age out of vendor support while continuing to work perfectly.

With a single shared passphrase, that is the only way to remove their access, and it means changing it for everybody and re-enrolling every device. That is enough friction that it almost never happens, which is why most business wireless is still running the key it was set up with. The better answer is to remove the need for the question by moving to per-user or per-device authentication, where one person's credentials can be revoked without touching anyone else's.

Indirectly, and more often than people expect. Somebody who cannot get signal where they work does not file a ticket and wait. They tether to a phone, bring in a range extender, or move somewhere with signal and take the confidential call there. Each of those shifts work onto infrastructure nobody manages or monitors. Rogue access points in particular are usually a coverage problem in hardware form, which is why an assessment starts with a site survey rather than a configuration review.

Routinely, and it is worth measuring rather than assuming. Signal does not stop at the property line, and an access point mounted near an exterior wall at full power offers a login prompt to the sidewalk. Attacking it needs no network access and no foothold, only proximity, and nothing logs the attempt. Turning every access point to maximum power to cover weak spots makes this worse while also causing access points to interfere with each other. More access points at lower power is the better answer.

Not meaningfully. A hidden network still broadcasts, and any device already configured for it announces the name while looking for it, so the name is discoverable with freely available tools. What hiding the SSID reliably does is make life harder for legitimate users, who now have to enter it manually on every device. It is better understood as a minor inconvenience to a casual observer than as a security control, and it does nothing about shared passphrases, rogue access points or stale firmware.

Related
Most of what wireless can enforce depends on what sits behind it. The segmentation guide covers where guest and device traffic should actually land, and why a separate SSID on its own does not get you there.

Not sure what's broadcasting?

Get a free wireless assessment. We'll survey your coverage, scan for access points you don't own, and check what the network looks like from the parking lot.

Talk to an Expert
Share