The wireless network is the only part of your perimeter that leaves the building. An attacker does not need to walk through the door: standing in the car park, in the office next door or on the street is enough.
What we check
Authentication robustness: WPA2 and WPA3, personal and enterprise. On 802.1X networks we review the client configuration, which is where the real flaw usually sits.
Rogue access points and evil twins: how far your network can be impersonated and who would connect to the fake one.
Segmentation: what someone reaches after joining the guest WiFi. It is the most repeated finding: the visitor network reaches places it should not.
Coverage and signal leakage beyond your premises.
Access point configuration: default credentials, exposed management interfaces, unpatched firmware and legacy protocols still enabled.
Connected devices: what is actually on that network, including what nobody inventoried.
How we work
1
Passive reconnaissance
We listen without interfering: visible and hidden networks, associated clients, ciphers and signal leakage outside the building.
2
Configuration review
Review of the wireless infrastructure and of how clients are configured.
3
Active testing
Within an agreed scope: access attempts, network impersonation and credential capture in a controlled environment.
4
Segmentation test
Once inside each wireless network, how far it goes. This is what decides whether a finding is an annoyance or a serious problem.
5
Report and remediation
With the concrete configuration change required, not a generic recommendation.
What you get
A map of your wireless networks and their real reach outside the building.
Technical report with every finding, its evidence and its fix.
Documented segmentation test: what each network reaches.
Inventory of detected devices and access points, including rogue ones.
Retest after remediation.
Who does the work. The same team that audits, not an account manager. Governance, risk and compliance: CISSP, CISM, ISO 27001 Lead Auditor, ENS and Risk Analysis (CCN), certified DPO, CCSP and CDPP (ISMS Forum) and PMP (PMI). On the technical side: OSCP, CRTO II and eWPTX, ranked in the top 1% of the CCN-CERT Atenea platform. We have run compliance projects for crypto exchanges, universities and public administrations.
Questions we get asked
Do you need to be on site?
Yes. A serious wireless audit requires being physically within range of the signal. What can be done remotely is the configuration review, which is only one part.
Will you disrupt the network?
Tests that could affect availability are agreed and run within an arranged window. Most of the work is passive and goes unnoticed.
We have WPA3. Are we safe?
WPA3 fixes known WPA2 weaknesses, but most of the findings we report are not in the protocol: they are in client configuration, in segmentation and in the guest network.
What about the guest network?
That is where most problems appear. It gets set up in a hurry, the password is shared everywhere and it often reaches internal resources. It is always in scope.
Check how far your signal reaches
Half an hour with an auditor to agree sites, networks and dates.
Phone: +34 686 250 244 (Mon-Fri, 9:00 to 18:00 CET) · Email: info@jaymonsecurity.com
We reply within 2 working hours.

