FAQ
Frequently asked questions
Substantive answers for both technical evaluators and executive decision-makers.
Understanding the service
What is AI Wi-Fi penetration testing?
AI Wi-Fi penetration testing uses artificial intelligence to assist qualified security professionals with the discovery and analysis of wireless network weaknesses. It accelerates reconnaissance, classifies wireless assets, flags suspicious access points, prioritizes realistic attack paths and organizes evidence, while human experts validate findings and stay in control of all authorized testing.
What is Wi-Fi penetration testing?
Wi-Fi penetration testing is an authorized security assessment of an organization's wireless infrastructure. It evaluates how access points, authentication, encryption, segmentation and client behaviour would hold up against a realistic attacker, and produces prioritized, actionable remediation guidance.
How is AI used during a wireless security assessment?
AI assists with reconnaissance analysis, asset classification, anomaly and rogue-access-point detection, target prioritization, command sequencing suggestions and evidence organization. It reduces repetitive manual work and improves consistency. Every active technique still requires prior written authorization and human validation.
Does AI replace the penetration tester?
No. AI supports the engagement but does not replace qualified penetration testers. Authorization, oversight, validation, risk interpretation and final reporting remain the responsibility of human security professionals. Business risk cannot be determined solely by an automated model.
Remote delivery & the appliance
Can a Wi-Fi penetration test be performed remotely?
Yes. A preconfigured wireless assessment appliance is shipped to your facility. Once connected, it establishes a secure, authenticated connection to our cloud platform, allowing our team to assess the on-site wireless environment remotely under the agreed scope — reducing travel while keeping human oversight throughout.
How does the Raspberry Pi assessment appliance work?
The appliance contains the authorized wireless-testing hardware and sensors required for the engagement. After you power it on and connect it using simple instructions, it authenticates to the cloud platform over an encrypted channel. All activity is logged and bounded by the approved scope and rules of engagement.
What does the customer need to do after receiving the appliance?
Very little. You place the appliance in the agreed location, connect power and, where required, a network uplink, then power it on. You follow the short setup instructions we provide. No specialist wireless knowledge is needed on your side.
Can the device be shipped worldwide?
Yes, subject to applicable customs, sanctions, export, import and local regulatory requirements. Worldwide delivery is a core part of the model and lets us assess distributed international locations without on-site travel to every site.
Is the cloud connection secure?
The appliance connects to the platform over an authenticated, encrypted channel. Activity is logged and governed by the approved scope. We do not publish sensitive infrastructure implementation details, but security controls and least-privilege access are core to the design.
Techniques & technologies
Which wireless technologies can be assessed?
Common enterprise wireless environments, including WPA2-Personal, WPA2-Enterprise, WPA3, guest networks, captive portals and enterprise authentication (such as 802.1X/EAP) configurations, can be assessed where they are in scope and authorized.
Can WPA2 and WPA3 networks be tested?
Yes. We review WPA2 and WPA3 configuration, authentication controls, transition modes and enterprise authentication where they are in scope. The goal is to identify weak configurations and realistic risks, not to encourage unauthorized access.
What is a rogue access point?
A rogue access point is an unauthorized wireless device connected to, or impersonating, your network. It may be an unsanctioned employee device, a misconfigured access point or a malicious impersonator designed to capture traffic or credentials. Identifying rogue APs is a core part of a wireless assessment.
What is an Evil Twin assessment?
An Evil Twin is a malicious access point that imitates a legitimate SSID to lure clients into connecting. Where explicitly authorized, an Evil Twin resilience assessment evaluates how susceptible your environment and users are to this class of impersonation, and what controls reduce the risk.
Does the assessment include client deauthentication?
Controlled client deauthentication testing is performed only when it is explicitly authorized in the signed rules of engagement, within agreed windows and safety limits. It is never carried out by default and is subject to stop conditions.
Can social-engineering exercises be included?
Yes, when explicitly approved. Authorized wireless phishing simulations, security-awareness exercises and social-engineering scenarios can be scoped in. These are optional and governed by the same authorization and safety requirements as technical testing.
How are Wi-Fi passwords assessed?
Where authorized, we assess the resilience of authentication material captured during the engagement — for example the strength of pre-shared keys against dictionary and known-pattern attacks. Password-analysis activities apply only to customer-authorized authentication material and comply with the signed scope and applicable law.
Is cloud-assisted password auditing safe?
Cloud-assisted password auditing accelerates the analysis of captured authentication material against known patterns and dictionaries. It is applied only to material we are authorized to test, handled according to the engagement's evidence-handling terms, and never used to access systems outside the agreed scope.
Data, evidence & reporting
Is employee traffic or personal data collected?
The assessment focuses on wireless security posture, not on monitoring employees. Data handling is defined in the rules of engagement, minimized to what the assessment requires, and governed by the engagement terms and applicable privacy law.
How is evidence protected?
Evidence is collected, stored and transmitted according to the evidence-handling requirements agreed in the statement of work. Access is limited to the engagement team, and handling follows least-privilege and data-minimization principles.
How long does a Wi-Fi penetration test take?
Timing depends on the number of facilities, wireless coverage, number of SSIDs, authentication architecture, approved techniques, social-engineering scope, shipping and reporting requirements. We provide an indicative timeline as part of your scoped proposal.
What is included in the technical report?
The technical PDF report includes an executive summary, scope, methodology, limitations, asset observations, findings with evidence and severity, technical and business impact, a reproduction overview appropriate for your team, remediation guidance, strategic recommendations and retesting recommendations.
What is included in the executive presentation?
The executive PowerPoint focuses on business risk without unnecessary jargon. It summarizes critical observations, explains likely impact, prioritizes remediation and supports leadership decision-making for both technical and non-technical stakeholders.
Scope, outcomes & commercials
What industries benefit from Wi-Fi penetration testing?
Any organization that relies on wireless connectivity benefits — including manufacturing, healthcare, financial services, retail, hospitality, warehousing, logistics, education, government, technology, corporate offices and critical infrastructure.
How is the scope authorized?
Before any testing begins, we agree the scope, authorized techniques, testing windows, safety limits, escalation contacts, evidence-handling requirements, success criteria and stop conditions in a signed statement of work. No testing starts until written authorization is complete.
What happens if no critical vulnerability is found?
Under the outcome-linked commercial model, the remaining balance is payable only when a critical vulnerability is identified according to the definition and success criteria agreed in the signed statement of work. Final contractual language always takes precedence.
How is a critical vulnerability defined?
A critical vulnerability must be defined before testing, as part of the rules of engagement and success criteria. The definition is agreed jointly so both sides share a clear, objective standard for what qualifies.
Can multiple facilities be assessed?
Yes. The remote-appliance model is designed to scale across distributed and international locations, which is one of its key advantages over travel-dependent on-site testing.
Can remediation be retested?
Yes. Retesting to validate that remediation was effective can be included in scope, and the technical report provides retesting recommendations to support this.
How much does Wi-Fi penetration testing cost?
Cost depends on the number of facilities, wireless coverage, number of SSIDs, authentication architecture, approved techniques, social-engineering scope, shipping, reporting and retesting requirements. Request a quote and we will prepare a scoped proposal for your environment.
How can an organization request a quote?
Submit the quote-request form with your first name, company name and business email. We will follow up to scope your engagement. You will also receive a short confirmation email shortly after submitting.
Understand Your Wireless Risk Before an Attacker Does
Request a scoped Wi-Fi security assessment for a single facility or a distributed international environment.
All testing is conducted under written authorization and an agreed scope.