Pillar 04
Two of the quietest ways into a business: the network reachable from the car park, and the password reused across five systems.
Wireless and credentials are grouped because attackers group them. A weak pre-shared key gets someone onto the network; a reused password moves them off it and into everything else. Testing one without the other leaves the chain intact.
What we check
Encryption in use, key strength, management frame protection, and whether the configuration matches what you believe is deployed.
Whether guest wireless genuinely reaches nothing, or quietly routes into the same flat network as your servers.
Unauthorised access points on your premises, and how convincingly yours can be impersonated.
Not the policy document — the passwords actually in use, and how they hold up against a real cracking rig.
Captured hashes attacked on GPU hardware, giving you a truthful measure of how long your credentials would survive.
Whether passwords seen in public breach corpora are still in use on your systems, checked without ever storing your users’ plaintext.
How it works
Which sites, SSIDs and accounts are in scope. Wireless testing is bounded geographically as well as logically.
Signal footprint, access point inventory, and what reaches beyond your walls.
Configuration weaknesses probed, captured material attacked offline on dedicated hardware, never on your equipment.
Findings with the exact configuration changes required, then verification once applied.
What we usually find
Wireless and credential findings are unusually consistent, because both tend to be configured once during a move or an upgrade and then left alone for years while the business around them changes.
The guest network hands out an address on the same flat network as the servers, or routes to it. Anyone in the car park with the guest key is inside. This is the most common wireless finding and among the most serious.
Pre-shared keys made of the company name and a year, or a phone number, or the street address. These fall to a wordlist in seconds because attackers generate exactly those candidates first.
An older access point in a back office still running weak encryption or with WPS enabled, quietly offering a route around whatever was done properly everywhere else.
The same password on a corporate account and a personal one already present in a public breach corpus. We check for this without ever holding your users’ plaintext credentials.
What you get
How long your actual credentials survive against dedicated hardware, expressed in time rather than a policy score.
Every access point found, authorised or otherwise, and how far each one reaches beyond your walls.
Precisely what the guest and untrusted networks can reach, tested rather than assumed from the configuration.
The exact settings to change on the exact equipment, then verification once applied.
A twenty-minute call is enough to agree what gets checked and what it costs. Nothing on your systems is touched until you have signed to say we may.
Book a free callarrow_forward