Managed IT
Every other part of your network has a door. Wireless does not. It leaves the building through the walls, reaches the parking lot, and admits anyone holding a passphrase that has been shared with several hundred people over six years. The gaps below are the ones that turn up most often, and none of them require sophistication to exploit.
Wired network security has a useful assumption behind it: to plug something in, you have to be in the building. Wireless removes that assumption and almost nothing in the average setup replaces it. The access point does not know or care where the client is standing.
Why wireless fails differently
Fortinet puts 70% of organizations on wireless networks that lack enterprise-grade security controls, which makes this the normal condition rather than an unusual lapse. Verizon's DBIR finds one in four SMB network breaches involving an unsecured or misconfigured wireless access point as the initial entry vector.
What makes those numbers stick is that wireless problems are quiet. A misconfigured firewall rule usually breaks something and gets noticed. A wireless network with a passphrase that half the county knows works perfectly for everyone, including whoever should not have it. Nothing degrades, nothing alerts, and there is no moment where it stops functioning and prompts a look.
The boundary is physical, and it is not the wall
Signal does not stop at the property line. An access point mounted near an exterior wall and turned up to full power is offering a login prompt to the sidewalk. Attacking that requires no network access and no foothold, only proximity and patience, and there is no log anywhere showing that somebody sat outside and tried.
This is also why wireless gaps tend to sit unresolved for years. The controls that would close them are configuration choices rather than purchases, so nothing prompts a review, no invoice arrives, and no vendor calls to ask.
The three gaps that show up most
What We Find
Wireless assessments turn up plenty of small things. Three findings account for most of the actual exposure, and all three are configuration and process problems rather than hardware ones.
Most common
The shared password
One passphrase for all staff · No rotation · No per-device revocation · Survives departures
Most business wireless runs on a single pre-shared key. Everyone who has ever worked there knows it, along with their families, the contractor who came for a week in 2021, and anyone who photographed the sticky note on the reception desk. It cannot be revoked for one person, so when somebody leaves, the only real option is changing it for everybody and re-enrolling every device. That is enough friction that it almost never happens.
The version worth understanding is that this is not a WPA2 problem. WPA2-Enterprise is still perfectly reasonable. The weakness is the shared secret model underneath it. Moving to per-user or per-device authentication, so credentials can be revoked individually, is the change that matters, and it is what makes a departure a five-minute task instead of a project nobody schedules.
Least visible
The rogue access point
Unmanaged hardware · Often no encryption · Plugged into a live port · Nobody's asset
Rogue access points are usually not malicious. Somebody in a corner office with no signal bought a router, plugged it into the wall port under the desk, and fixed their own problem. It works, so nobody mentions it. What it also does is bridge an unmanaged and frequently unencrypted wireless network straight into your internal wired network, past everything you configured at the edge.
The malicious version exists too, and looks identical from the outside. Either way the detection question is the same: would you know? Without wireless monitoring, a rogue AP announces itself to everyone in radio range and to nobody in IT. This is one of the strongest arguments for shutting down unused wall ports, since a rogue AP needs a live one.
Most deferred
Stale access point firmware
No update schedule · No end-of-support tracking · Silent failure mode · Ships insecure by default
Access point firmware is deferred more reliably than almost anything else in the stack, because nothing ever prompts it. The AP keeps serving clients on four-year-old code exactly as well as it would on current code, so there is no symptom and no complaint, and the update stays at the bottom of the list indefinitely.
Two things make this worse than it sounds. Wireless vulnerabilities are attackable from outside the building, so a stale AP is exposed to a wider set of people than a stale server. And access points quietly age out of vendor support while continuing to work perfectly, at which point no update is coming regardless of who remembers to look.
The pattern behind all three
Each of these persists because the network keeps working. There is no outage, no error, no user complaint and no invoice, so nothing schedules the review. Wireless is the part of the stack most likely to be silently wrong, which is exactly why it needs a calendar rather than a trigger.
Coverage is a security problem too
Coverage usually gets filed under performance, and that is where the obvious cost sits. Aruba Networks estimates $4,700 in lost productivity per employee per year from unreliable wireless. The less obvious cost is that bad coverage generates security problems, because people route around it.
Dead zones create their own workarounds
A team member who cannot get signal where they work does not file a ticket and wait. They tether to their phone, or they bring in a range extender, or they move to a spot with signal and take the confidential call there. Each of those moves work onto infrastructure you do not manage, cannot see and cannot secure. The rogue access point above is usually a coverage problem wearing a hardware costume.
This is why a wireless assessment starts with a site survey rather than a configuration review. Coverage designed around where cable happened to run, instead of where people actually sit, produces gaps that get solved locally and invisibly.
The opposite problem is real too
Compensating for weak spots by turning every access point to maximum power is common and counterproductive. It pushes usable signal well past the building, so the login prompt is now available from the parking lot and the street. It also makes access points interfere with each other, which degrades performance in the middle of the space while extending reach where you least want it.
Correct placement is more access points at lower power rather than fewer at maximum. That improves capacity and coverage at the same time as it pulls the usable boundary back toward the walls.
Guest access, briefly
Guest wireless belongs in its own network segment with no route to anything internal, and a separate SSID does not accomplish that on its own. If both SSIDs land in the same place, you have separated the login and not the network. The mechanics of that sit at the switch layer rather than the wireless one, and are covered in the segmentation guide. The wireless-side point is narrower: check it rather than assume it, because it takes five minutes and fails more often than people expect.
Wireless Readiness Checklist
The Checklist
Fifteen questions across coverage, access control, rogue device detection and hardware age. Tick the ones you can answer without going and asking someone, and the score updates as you go. Use it yourself or share it with your team.
Tick what you can answer without checking. The blanks are the gaps.
Coverage & Placement
Has anyone surveyed the building, or were APs placed where cable ran?
Coverage designed around the cabling plan rather than the floor plan produces predictable gaps.
Where do people lose signal in the places they actually work?
Corridors are easy. Corner offices, warehouses and stairwells are where the workarounds start.
How far outside the building is your network still usable?
Walk the perimeter. If it reaches the street, so does the login prompt, and nothing logs the attempt.
Is anyone tethering or using a personal hotspot to get work done?
Work moving onto infrastructure you cannot see is a coverage symptom before it is a policy one.
Access & Encryption
When was the wireless passphrase last changed?
A date. If the answer is the install, everyone who has ever worked here still has access.
Can you revoke one person's wireless access without changing it for everyone?
With a single shared key you cannot, which is why departures rarely trigger a change.
What encryption standard is each SSID actually running?
Worth checking per SSID rather than assuming. Legacy ones set up for old equipment tend to linger.
Is the access point admin interface still on its default credentials?
Fast to check, and the finding that makes every other control on the device moot.
Rogue Device Detection
Would you know if someone plugged in their own access point?
It broadcasts to everyone in radio range and, without monitoring, to nobody in IT.
How many wireless networks are broadcasting in your space right now?
Most teams can name two or three. A scan usually finds more, and some of them are yours.
Are unused wall ports live?
A rogue access point needs a live port. Shutting them down removes the easiest path.
Could you list the devices connected to wireless right now?
Not the count. The list, with something identifying each one.
AP Age & Firmware
How old are the access points, and are any past vendor support?
They keep serving clients perfectly while no longer receiving security fixes at all.
When was access point firmware last updated?
Nothing prompts this one. No symptom, no complaint, no invoice, so it waits indefinitely.
Is any consumer-grade wireless hardware still in production use?
Usually at a small site, usually bought to solve one problem, usually still there years later.
Frequently asked questions
Three findings account for most of the exposure in small and mid-sized businesses. A single shared passphrase that everyone who has ever worked there still knows and that cannot be revoked for one person. Rogue access points, usually somebody solving their own coverage problem with a router from home, bridging an unmanaged wireless network into the internal wired one. And stale access point firmware, deferred more reliably than almost anything else because nothing ever prompts it. All three are configuration and process problems rather than hardware ones.
WPA2-Enterprise remains in wide and reasonable use, and the protocol version is rarely the weak part. The problem in most businesses is the shared secret underneath it: one pre-shared key issued to everybody, never rotated, and impossible to revoke for a single person. Moving to per-user or per-device authentication does more for security than the version number does, because it makes removing one person's access a five-minute task rather than a project that gets scheduled and then does not happen.
A rogue access point is wireless hardware on your network that you did not deploy and do not manage. Most are not malicious. Somebody with no signal in a corner office buys a router, plugs it into the wall port under the desk and fixes their own problem. What it also does is bridge an unmanaged and often unencrypted wireless network straight into your internal wired network, past the controls configured at the edge. The malicious version looks identical from the outside, so the detection question is the same either way.
On a schedule, because nothing else will trigger it. An access point running four-year-old code serves clients exactly as well as one running current code, so there is no symptom, no complaint and no invoice to prompt the work. Two things make the delay worse than it sounds: wireless vulnerabilities are attackable from outside the building, so a stale access point is exposed to a wider set of people than a stale server, and access points age out of vendor support while continuing to work perfectly.
With a single shared passphrase, that is the only way to remove their access, and it means changing it for everybody and re-enrolling every device. That is enough friction that it almost never happens, which is why most business wireless is still running the key it was set up with. The better answer is to remove the need for the question by moving to per-user or per-device authentication, where one person's credentials can be revoked without touching anyone else's.
Indirectly, and more often than people expect. Somebody who cannot get signal where they work does not file a ticket and wait. They tether to a phone, bring in a range extender, or move somewhere with signal and take the confidential call there. Each of those shifts work onto infrastructure nobody manages or monitors. Rogue access points in particular are usually a coverage problem in hardware form, which is why an assessment starts with a site survey rather than a configuration review.
Routinely, and it is worth measuring rather than assuming. Signal does not stop at the property line, and an access point mounted near an exterior wall at full power offers a login prompt to the sidewalk. Attacking it needs no network access and no foothold, only proximity, and nothing logs the attempt. Turning every access point to maximum power to cover weak spots makes this worse while also causing access points to interfere with each other. More access points at lower power is the better answer.
Not meaningfully. A hidden network still broadcasts, and any device already configured for it announces the name while looking for it, so the name is discoverable with freely available tools. What hiding the SSID reliably does is make life harder for legitimate users, who now have to enter it manually on every device. It is better understood as a minor inconvenience to a casual observer than as a security control, and it does nothing about shared passphrases, rogue access points or stale firmware.
Not sure what's broadcasting?
Get a free wireless assessment. We'll survey your coverage, scan for access points you don't own, and check what the network looks like from the parking lot.



