Skip to content
Digital Security Consulting

Operations manager, office or shop floor

“Anyone in the parking lot has the same Wi-Fi password we gave a client in 2019”

Request a consultation Typical timeline: Assessment in a week, segmentation and deployment within two to three

Does this sound familiar?

  • One Wi-Fi password, shared with everyone, unchanged for years
  • Guest network is a second name on the same flat network
  • Staff have plugged in their own routers because coverage is poor
  • Printers, cameras and smart devices sit alongside company laptops
  • Nobody knows what is actually connected right now

What it costs to ignore

Wireless is the only part of your network reachable without entering the building — a car in the lot, the unit next door, the floor above. On a flat network, one compromised laptop, one guest who kept the password, or one camera with factory credentials has a route to your file server, your accounting system and your backups.

How the engagement runs

  1. 1

    Test it the way an attacker would

    From outside the building, from the lobby as a guest, and as an impostor network. Weak pre-shared keys, evil twins, captive portal bypass and guest-to-internal pivoting.

  2. 2

    Survey coverage properly

    Predictive modelling plus on-site measurement and heat mapping. Poor coverage is what causes staff to plug in their own unmanaged access points, so fixing it is a security control.

  3. 3

    Segment for real

    Guest, staff, payment, IoT and operational traffic on separate VLANs with enforced rules — not just different network names on the same flat segment.

  4. 4

    Authenticate properly

    Certificate-based authentication for staff instead of a shared password, WPA3 where devices support it, and isolated guest access with no route inward.

  5. 5

    Watch for rogue access points

    Detection for access points that should not be there, whether an employee's convenience router or something left behind deliberately.

The one part of your network that leaves the building

Everything else requires an attacker to get through the door or through the firewall. Wireless broadcasts past your walls by design — that is what it is for.

That does not make Wi-Fi dangerous. It makes it worth engineering rather than plugging in.

What we actually find

Rarely anything sophisticated. Usually:

  • A pre-shared key from years ago that half the former staff still know
  • A “guest” network on the same flat segment as the accounting server
  • One legacy printer forcing the whole network onto weaker encryption
  • An access point somebody added because the warehouse had no signal
  • Cameras and smart devices with factory credentials, fully routable

Segmentation is the control that matters

If we could change one thing in a typical small business network, it would be this. Guest traffic, staff laptops, payment systems, IoT and operational equipment all sharing one flat network means a single compromised device — or one thermostat with a default password — has a path to everything.

Proper segmentation turns a breach into a contained incident rather than a company-wide one. Paired with tested backups, it is the difference between a bad afternoon and a bad quarter.

What you get

  • A written report of what is reachable from outside your walls
  • Genuine network segmentation with enforced boundaries
  • Certificate-based staff authentication, no more shared password
  • Guest access that is isolated and rate-limited
  • Coverage that works across the building, measured
  • Rogue access point detection

Frequently asked questions

Is a shared Wi-Fi password really that bad?

It is one of the most common serious findings we report. A pre-shared key cannot be revoked for one person — every former employee, contractor, client and visitor who ever had it still has it, and it is almost certainly saved on devices you do not control. Certificate-based authentication removes access per person, which is what you actually need.

We have a separate guest network. Are we fine?

Only if the separation is enforced at the network layer, and frequently it is not. We regularly find 'guest' networks that are simply a second SSID on the same flat segment — meaning a guest, or anyone holding the guest password, can reach file servers, printers and management interfaces. Testing it takes minutes and the answer is often uncomfortable.

Our Wi-Fi is slow in parts of the building. Is that a security issue?

Indirectly, and importantly so. When coverage is poor, people solve it themselves by plugging in a consumer router or a hotspot. Those become unmanaged, unmonitored, badly configured entry points. Fixing coverage removes the incentive, which is why we treat design and security as one engagement rather than two.

What is an evil twin attack?

An attacker broadcasts a network using your network's name. Devices that have connected before may associate automatically, putting the attacker between your staff and the internet. A shared password does not protect against this; certificate-based authentication does, because the device validates the network rather than the other way round.

Can you test without disrupting the business?

Yes. Most of the work is passive observation and authentication analysis, which is non-disruptive. Anything with disruption potential is scheduled with you in advance, usually outside business hours, and nothing runs without your written authorisation.

Services involved

Cybersecurity

Incident response, ransomware recovery, and hardening that holds up under audit.

Learn more

Infrastructure & Backup

Servers, clusters and backups designed so that failure is survivable and boring.

Learn more

Wireless & Networks

Wi-Fi and network infrastructure designed, deployed, then attacked to prove it holds.

Learn more

Tell us what is breaking — or what you are trying to build.

You get a senior engineer on the first call, not a salesperson. If we are not the right fit, we will say so and point you somewhere better.

Active incident? Write “URGENT” in your message and we prioritise it.