Why Wireless Security Matters
Attackers do not need to be in the building. From the car park, from the cafe next door, from a drone overhead. Poorly designed WiFi is a gift: default passwords, WPA2 with weak PSK, guest networks bridged to corporate, and rogue APs harvesting credentials at the coffee shop down the road.
WiFi Standards and Bands
WiFi 7 (802.11be)
Latest. Multi-link operation, 320 MHz channels, very high throughput. Worth designing in for greenfield.
WiFi 6E / 6 (802.11ax)
Current standard. Adds 6 GHz band (6E), OFDMA, better density. Recommended baseline.
WiFi 5 (802.11ac)
Still widely deployed. Acceptable for existing fleets. Plan WiFi 6 refresh.
WiFi 4 (802.11n)
End of life. Replace.
2.4 GHz for range and legacy, 5 GHz for speed, 6 GHz for density. Modern APs run all three.
Encryption: WPA2, WPA3, WPA-Enterprise
WPA2-PSK
Shared password. Legacy devices. Acceptable only with long random PSK and limited scope.
WPA3-SAE
Forward secrecy. Better offline-attack resistance. Use for all modern deployments.
WPA2/3-Enterprise (802.1X)
Per-user credentials via RADIUS. Centralised revocation. Required for corporate networks.
Good Network Design
Segmentation and Guest Networks
Never put everyone on the same WiFi. Segment by purpose.
Corporate
WPA3-Enterprise via RADIUS. Domain-joined devices only. Full internal access per role.
BYOD
Separate SSID. Limited access to internal resources. Device posture checks where possible.
Guest
Internet only. Isolated from all internal VLANs. Captive portal with T&Cs. Rate-limited.
IoT / OT
Separate SSID and VLAN. No internet where not required. Deny all-to-all by default.
Kiosk / POS
Locked-down SSID. Access only to the specific back-end service. MAC filtering as secondary control.
Wireless Surveys: What They Are, What You Get
A proper wireless survey measures signal, interference, throughput, and coverage across the whole facility with calibrated tools. The output is a coverage heatmap, a design recommendation, and a rogue AP report.
Common Mistakes
Guest on the same VLAN as corporate
One compromised guest device, full lateral access. Always a separate VLAN with deny rules.
Default admin passwords on APs
Still common. Attackers scan for them the moment a device is online.
WPA2-PSK with a shared password
Password walks out the door with every ex-employee. Use Enterprise or a passpoint PSK solution.
Guessing AP placement
Under-coverage, dead spots, overlap, interference. Survey first.
No firmware updates
APs are network devices. Unpatched firmware is an initial access vector.
SSID hiding as a security control
Trivially discovered. Provides no security, causes connectivity issues.
Get a Professional Wireless Survey
We run spectral analysis, coverage heatmaps, and full wireless designs using UniFi, Cisco, Aruba, and others. Includes security review and design recommendations.

Remote Support