All Guides
Network Infrastructure

Wireless Security and Network Design

WiFi is often the softest way into a business. This guide covers WPA3, WPA-Enterprise, segmentation, guest networks, rogue AP detection, and how a proper wireless survey prevents every common design mistake.

Last reviewed August 2026

Why Wireless Security Matters

Attackers do not need to be in the building. From the car park, from the cafe next door, from a drone overhead. Poorly designed WiFi is a gift: default passwords, WPA2 with weak PSK, guest networks bridged to corporate, and rogue APs harvesting credentials at the coffee shop down the road.

WiFi Standards and Bands

WiFi 7 (802.11be)

Latest. Multi-link operation, 320 MHz channels, very high throughput. Worth designing in for greenfield.

WiFi 6E / 6 (802.11ax)

Current standard. Adds 6 GHz band (6E), OFDMA, better density. Recommended baseline.

WiFi 5 (802.11ac)

Still widely deployed. Acceptable for existing fleets. Plan WiFi 6 refresh.

WiFi 4 (802.11n)

End of life. Replace.

2.4 GHz for range and legacy, 5 GHz for speed, 6 GHz for density. Modern APs run all three.

Encryption: WPA2, WPA3, WPA-Enterprise

WPA2-PSK

Shared password. Legacy devices. Acceptable only with long random PSK and limited scope.

WPA3-SAE

Forward secrecy. Better offline-attack resistance. Use for all modern deployments.

WPA2/3-Enterprise (802.1X)

Per-user credentials via RADIUS. Centralised revocation. Required for corporate networks.

Good Network Design

Proper AP placement based on site survey, not guesswork
Matching AP count to user density, not just square metres
Band steering (push capable devices to 5/6 GHz)
Channel planning to avoid co-channel interference
PoE+ switching for all APs
Redundant controllers (cloud or on-prem)
Firmware management and scheduled updates
RF scanning for rogue APs and interference

Segmentation and Guest Networks

Never put everyone on the same WiFi. Segment by purpose.

Corporate

WPA3-Enterprise via RADIUS. Domain-joined devices only. Full internal access per role.

BYOD

Separate SSID. Limited access to internal resources. Device posture checks where possible.

Guest

Internet only. Isolated from all internal VLANs. Captive portal with T&Cs. Rate-limited.

IoT / OT

Separate SSID and VLAN. No internet where not required. Deny all-to-all by default.

Kiosk / POS

Locked-down SSID. Access only to the specific back-end service. MAC filtering as secondary control.

Wireless Surveys: What They Are, What You Get

A proper wireless survey measures signal, interference, throughput, and coverage across the whole facility with calibrated tools. The output is a coverage heatmap, a design recommendation, and a rogue AP report.

Predictive survey before deployment (CAD-based)
On-site survey with spectrum analyser and heatmap tool
Post-install validation survey
Coverage heatmap at 2.4, 5, and 6 GHz
Rogue AP and neighbour SSID report
Channel and interference map
AP placement and power recommendations
Throughput and roaming test across the floor

Common Mistakes

Guest on the same VLAN as corporate

One compromised guest device, full lateral access. Always a separate VLAN with deny rules.

Default admin passwords on APs

Still common. Attackers scan for them the moment a device is online.

WPA2-PSK with a shared password

Password walks out the door with every ex-employee. Use Enterprise or a passpoint PSK solution.

Guessing AP placement

Under-coverage, dead spots, overlap, interference. Survey first.

No firmware updates

APs are network devices. Unpatched firmware is an initial access vector.

SSID hiding as a security control

Trivially discovered. Provides no security, causes connectivity issues.

Get a Professional Wireless Survey

We run spectral analysis, coverage heatmaps, and full wireless designs using UniFi, Cisco, Aruba, and others. Includes security review and design recommendations.