Insights

How to Define Rules of Engagement for a Wi-Fi Pentest

A practical checklist for scoping a wireless penetration test: what to authorize, what to prohibit, and how to set safety limits and stop conditions.

The rules of engagement (RoE) are the contract that makes a penetration test safe and legitimate. They define exactly what testers may do, where, when and within what limits. Getting them right protects everyone — and it is the step that no testing may begin without. This is a practical guide to defining strong rules of engagement for a Wi-Fi pentest.

Why the RoE matters so much

Wireless testing touches live environments where people are working. A clear RoE prevents disruption, sets expectations, and ensures that everything done during the engagement is authorized in writing. Without it, even well-intentioned testing is risky and, potentially, unlawful. With it, both sides share a precise, objective understanding of the engagement.

The elements to define

A complete set of rules of engagement covers the following.

Targets and locations

  • Which facilities and locations are in scope.
  • Which wireless networks are in scope — corporate, guest, IoT, operational — and which are explicitly out of scope.

Timing

  • Authorized dates and testing windows.
  • Any blackout periods (for example, during critical operations).

Techniques

Decide, explicitly, which techniques are permitted. Some are routinely acceptable (asset discovery, configuration review). Others require deliberate authorization because they can affect availability or people:

  • Whether client deauthentication testing is permitted.
  • Whether rogue access point activity is permitted.
  • Whether Evil Twin simulations are permitted.
  • Whether employee social engineering is permitted.
  • Whether physical interaction with facilities is permitted.

Anything not explicitly authorized should be treated as prohibited.

Safety and control

  • Safety limits that must not be exceeded.
  • Escalation contacts who are reachable during testing windows.
  • Stop conditions — the circumstances under which testing pauses or halts immediately.

Evidence and outcomes

  • Evidence-handling requirements: how evidence is collected, stored and transmitted.
  • Success criteria for the engagement.
  • The definition of a critical vulnerability, agreed jointly and in advance.

The critical-vulnerability definition

This deserves special attention, particularly under outcome-linked commercial models. “Critical” must mean the same thing to both sides before testing begins. Define it objectively — in terms of the impact and conditions that qualify — so there is no ambiguity later. Ambiguity here is the most common source of disputes, and it is entirely avoidable.

Authority to authorize

The person signing the RoE must actually have the authority to authorize testing of the in-scope networks and facilities. For leased premises, shared buildings or third-party-managed networks, confirm that authority explicitly. This is a governance point, not a formality.

A simple sequence

  1. Draft scope: locations and networks in and out.
  2. Set windows and blackout periods.
  3. Decide each optional technique: permitted or prohibited.
  4. Define safety limits, escalation contacts and stop conditions.
  5. Agree evidence handling and success criteria.
  6. Agree the critical-vulnerability definition.
  7. Confirm authority and sign.

Only then does testing begin.

The takeaway

Strong rules of engagement are what turn offensive security from a risk into a controlled, valuable exercise. They are worth the time. If you are preparing for an engagement, our guide to getting ready covers the practical steps, and our responsible-testing policy explains the commitments we hold ourselves to.

Portrait placeholder for Ferran Verdés, Project Lead

Ferran Verdés

Project Lead — Application, AI and Wireless Security

Application, AI and wireless security engineer; published Wi-Fi security author. Full profile →

Understand Your Wireless Risk Before an Attacker Does

Request a scoped Wi-Fi security assessment for a single facility or a distributed international environment.

All testing is conducted under written authorization and an agreed scope.

Assess your wireless risk Request a Quote