In range is in scope
A wireless network is a perimeter you cannot put a fence around. Anyone in the lot, the lobby, or the office next door can see it, and a surprising number of the controls people trust on that perimeter — a pre-shared key, a MAC whitelist, a hidden SSID — do not do what the policy says they do.
We test that estate from the position of someone who is close, not someone who already has a port. The question is whether they can join, whether they can listen, and whether that foothold is a dead end or a path into the rest of the network.
What we test
Association and encryption. Which SSIDs are reachable, how they authenticate, and whether the secret that protects them would survive a determined neighbour.
Controls that look like locks. MAC filtering, hidden networks, captive portals, client isolation. We have walked past a MAC whitelist in minutes on a live engagement — the address is broadcast, and copying it is not a feat. That write-up is MAC Address Whitelisting Failure.
Rogue and evil-twin conditions. Whether a lookalike access point would be noticed, and what a client would hand it.
What the foothold is worth. Getting on the WLAN is the opening. The finding is what that position can reach — a file share, a management interface, a path that belongs on an internal network penetration test.
What this is not
It is not IoT penetration testing. Device radios, firmware, and companion apps are a different engagement.
It is not a promise that we will “audit the controller config” and leave. A configuration dump is useful homework. This is a test of whether the air, as deployed, holds.
What you receive
A report of which networks we could join, which controls failed, and what that position was worth inside the estate — with the change that closes each path. We retest once you have remediated, the same as any other penetration test.