Skip to content

Network

Wireless
Penetration Testing

On-site corporate Wi-Fi testing in the New York metro

From $3,800 for one office, fixed scope, free retest. See all pricing →

Get a fixed quote

Reply in one business day

Senior certified testers, manual-first185+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology

When you need it

When an office needs a wireless penetration test

The situations that bring teams to this engagement, and where it fits alongside the rest of your program.

  • Staff, guests, and IoT devices share the airspace and nobody has tested whether the guest network can reach corporate systems.
  • You moved to WPA3 or 802.1X and want to know the enterprise authentication actually resists an evil twin.
  • A PCI merchant must look for rogue wireless access points on a schedule and needs the evidence.
  • A clinic, store, or warehouse runs critical systems over Wi-Fi where an outage would hurt, common on logistics floors.
  • Your internal test came back clean over the wire and the next question is whether the radios are a way in.

Definition

What is a wireless penetration test?

A wireless penetration test is an on-site assessment of your Wi-Fi: the corporate network staff log into, the guest network visitors use, and the IoT network your devices sit on. A tester in the space attacks the radios the way an attacker parked outside would, from evil twins that harvest enterprise credentials to a check of whether the guest network can reach the systems inside.

Testing is on site in the New York metro from $3,800 for one office of up to three SSIDs. Sites outside the metro are quoted, and many can be tested through a device we ship. It complements the internal network test, which covers the wired side, and our infrastructure penetration testing guide shows how the two fit.

What we look for

Wireless weaknesses we hunt for

Wi-Fi extends your network past the walls, into the street and the floors above and below. We test the radios the way an attacker parked outside would, and prove whether the airspace is a route to the systems inside.

Enterprise authentication (802.1X)

The WPA2 and WPA3-Enterprise setup most offices rely on, and the evil twin that harvests credentials from it.

We test for

  • Evil twin credential capture against 802.1X or RADIUS
  • EAP method downgrade and weak configurations
  • Server-certificate validation gaps on clients
  • RADIUS and authentication-server exposure
  • Machine and user certificate handling

Pre-shared key and WPA3

The shared-password networks, and the WPA3 transition modes that quietly fall back to something weaker.

We test for

  • Handshake capture and offline PSK cracking
  • Weak, default, and never-rotated pre-shared keys
  • WPA3 transition-mode downgrade to WPA2
  • Management-frame protection coverage
  • PMKID and related capture attacks

Rogue and evil twin access points

The access points that should not be there, and the fake ones an attacker stands up to lure clients.

We test for

  • Rogue access-point discovery across the space
  • Evil twin and karma-style client attacks
  • Captive-portal bypass and impersonation
  • Open and misconfigured broadcast SSIDs
  • PCI DSS 11.2.1 rogue-AP evidence

Guest isolation and segmentation

The finding that matters most: whether the guest or IoT network can reach the corporate systems it should never touch.

We test for

  • Guest-to-corporate reachability testing
  • Wireless-to-internal segmentation and VLAN gaps
  • Client isolation on shared networks
  • IoT and BYOD network boundaries
  • Reachability of sensitive zones from the air

Client-side and RF exposure

The laptops and phones that trust the wrong network, and the signal that reaches further than you think.

We test for

  • Client probe-request and preferred-network abuse
  • Targeted deauthentication of agreed test clients, within the rules of engagement
  • Signal reach beyond the building footprint
  • Hidden-SSID and MAC-filtering weaknesses
  • Wi-Fi Direct and ad hoc networks broadcast by printers and devices

The airspace

Corporate, guest, and IoT, each tested differently

One RF survey covers all of it; the attacks differ by how each network authenticates and what it connects to.

Corporate (enterprise auth)

The WPA2 or WPA3-Enterprise network staff join with their accounts. The headline attack is an evil twin that impersonates the network, captures credentials, and tests whether clients validate the server certificate before they hand them over.

Guest and captive portal

The network visitors use. We test whether it is truly isolated, whether the captive portal can be bypassed, and, most importantly, whether a device on it can reach the corporate systems on the other side of the switch.

IoT and BYOD

Cameras, sensors, printers, and personal devices often sit on a shared SSID with weak, never-rotated keys. We test the keys, the client isolation, and whether a compromised device becomes a foothold into the internal network.

Device radios such as Bluetooth Low Energy and sub-GHz on a specific product are tested under hardware and IoT testing, not here. This page is about the corporate wireless estate.

PCI DSS

Rogue wireless and PCI DSS 11.2.1

PCI DSS Requirement 11.2.1 requires in-scope merchants and service providers to test for the presence of wireless access points, and to detect and identify authorized and unauthorized ones, at least once every three months. It applies even where a policy bans wireless, because a rogue access point is easy to attach and hard to spot. The rogue access-point sweep in this test is evidence of that check for the quarter it runs in, with the findings and a map of what was on the air.

The requirement repeats every three months, so one sweep does not cover the year, and the report says so. Where cardholder data is in scope, pair the wireless test with our PCI DSS testing so segmentation testing proves the boundary between the wireless networks and the cardholder data environment as well.

Pricing

How wireless penetration testing is priced

Wireless scopes are sized by SSIDs and sites, not by the hour, and fixed in writing before work begins.

One office

One NYC-metro office of up to three SSIDs, such as corporate, guest, and IoT, tested on site: $3,800.

Larger or multi-floor

Up to eight SSIDs, a larger or multi-floor office, several controllers or certificate-based authentication, or two NYC-metro sites with the same configuration: $5,500.

Campus or multi-site

A campus, three or more sites, or more than eight SSIDs, quoted from the scope and still fixed before work begins.

The published prices cover on-site testing in the New York metro. Sites outside the metro are quoted from the scope, tested through a device we ship or on an agreed trip.

Methodology

Wireless penetration testing methodology

Full methodology →

Every engagement follows the Penetration Testing Execution Standard and the relevant OWASP guides.

These are the phases your wireless penetration testing runs through.

  1. 01

    Scope & logistics

    Sites, SSIDs, authentication types, and on-site windows agreed, with the fixed price in writing. Outside the metro, a testing device can be shipped instead.

  2. 02

    RF survey & discovery

    The space swept for every access point and SSID, authorized and rogue, and mapped.

  3. 03

    Authentication attacks

    Enterprise, PSK, and WPA3 networks tested for the credential-capture and cracking paths an attacker uses.

  4. 04

    Segmentation testing

    Guest-to-corporate and wireless-to-internal reachability proven, showing what the radios expose inside.

  5. 05

    Report & retest

    A report with access-point maps and proof, then a free retest on site or via the shipped device.

How it works

How your engagement runs

From scope through the final retest, your team stays in the loop at every step, with findings tracked live in our platform.

  1. 01

    Scope & kickoff

    Targets, roles, and rules of engagement defined in writing, with a fixed scope and timeline.

  2. 02

    Testing goes live

    Findings post to your live platform dashboard the moment our testers confirm them.

  3. 03

    Track remediation

    Follow every finding from open to fixed, with severity, evidence, and status in one place.

  4. 04

    Report & retest

    Executive and technical reports land, then request a free retest in one click.

Proof

Proof in the field

Every engagement is confidential, so the work below is anonymized to sector and engagement type.

All case studies →

Free

Retest on every penetration test

185+

Years combined experience

14

Senior in-house specialists

24h

Onboarding after signing

Fintech · Payments

Web Application Penetration Test

High risk

Critical: a remote code execution flaw in the application’s web framework that could have given an attacker full control of the server. We escalated it to the development team while the test was still running.

Outcome. The critical RCE was reported and remediated during the engagement via an emergency framework upgrade, which also closed the server-side request forgery, and the remaining findings were retested to confirmation.

1

Critical (RCE)

Mid-test

Critical remediated

2

High

Read the case study

HR & Payroll SaaS

Web Application Penetration Test

High risk

Critical: a file-inclusion flaw that let an attacker read sensitive files from the server through the application itself. High: stored cross-site scripting capable of session theft, insecure direct object references, and an authorization bypass that let an administrator create or delete organization owners.

Outcome. Delivered a remediation plan sequenced by real business impact, critical and high findings first, with a complimentary retest to verify every fix.

28

Findings

1

Critical

5

High

Read the case study

FAQ

Frequently asked questions

What teams most often ask before scoping wireless penetration testing.

Still have questions? 
01What does a wireless penetration test cover?

It covers your corporate, guest, and IoT Wi-Fi from inside the space: an RF survey and rogue access-point sweep, attacks on WPA2 and WPA3-Enterprise and 802.1X or RADIUS authentication (including evil twin credential capture), pre-shared-key and WPA3 checks, captive-portal and client-side attacks, and, most importantly, whether the guest or IoT network can reach the corporate systems it should be isolated from. The report maps every access point and SSID found and proves each finding.

02Do you test WPA3?

Yes. WPA3 is stronger than WPA2, but the way it is deployed is where the findings are. We test whether transition mode quietly falls back to WPA2, whether management-frame protection is enforced, whether clients validate the server certificate on WPA3-Enterprise, and whether the pre-shared keys on WPA3-Personal are still weak or shared. The report tells you whether the upgrade actually changed your exposure.

03Will the test disrupt our network?

No. Most of the work is passive listening and authorized connection attempts, and there is no denial-of-service testing. Anything that could briefly disconnect a device, such as deauthenticating a client to capture a handshake, is aimed at agreed test clients and run only in the windows you approve in writing.

04How long are you on site?

For one office of up to three SSIDs, two to three on-site days, followed by a reporting day. Larger or multi-floor offices and multi-site scopes take longer, and we agree the schedule during scoping.

05Can you test our office outside the New York metro?

Yes. Inside the metro, testing is on site from our Manhattan base with no travel line. Sites outside the metro are quoted from the scope: many can be tested through a device we ship to the site, and some need an on-site visit. We agree which during scoping.

06Does this satisfy PCI DSS rogue wireless requirements?

For the quarter it runs in, yes. PCI DSS Requirement 11.2.1 requires testing for authorized and unauthorized wireless access points at least once every three months, even where a policy bans wireless. Our rogue access-point sweep and map are the evidence for that check. The requirement repeats every quarter, so one test does not cover the year. Where cardholder data is in scope, pair it with our PCI DSS testing so the segmentation from wireless to the cardholder data environment is proven too.

07How much does a wireless penetration test cost?

One NYC-metro office of up to three SSIDs is $3,800, fixed before work begins, with a free retest. Up to eight SSIDs, a larger or multi-floor office, or two same-configuration NYC-metro sites is $5,500. A campus, three or more sites, or more than eight SSIDs is quoted from the scope. Our wireless testing cost page explains what moves the price.

08Can you pair it with an internal network test?

Yes, and the two overlap. A wireless test proves whether the radios reach the internal network; an internal network test then shows how far that reach goes, through Active Directory and toward your sensitive systems. Scoped together, they share the segmentation work and tell one story from the airspace to Domain Admin.

Ready to test your defenses?

Talk to our team about scoping wireless penetration testing.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.