On-site, by hand, against your real Wi-Fi
A senior specialist tests on your premises against your actual access points, SSIDs and controllers. No config-only review, no false positives, only what genuinely works over the air.
Your corporate Wi-Fi reaches past your walls, into the car park, the lobby, the building next door. From there, an attacker can clone it, capture a staff login, or pivot from your guest network into the corporate one. We attack your wireless the way someone parked outside would.
How a wireless pentest worksProtected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
Request received.
We’ll be in touch within one business day with next steps.
No se ha podido enviar. Inténtalo otra vez o escríbenos.















Radio does not respect your reception desk. If your Wi-Fi is reachable from the car park, so is your attack surface, and the attacker can take their time, unseen, from a laptop in a parked car.
The classic wireless attack is simple to picture. An attacker stands up a fake copy of your corporate Wi-Fi. A staff laptop, if it does not properly check it is talking to the real Wi-Fi server, connects and hands over a domain login. We prove each step your network team can reproduce.
A wireless pentesting is normally a rogue access point found in the office, a new site, a PCI DSS wireless requirement, a controller upgrade, or a near-miss in a branch forces the question.
The question is not ‘do we have findings’ but ‘are there other paths’. We focus the engagement on the suspected exposure, confirm it is closed, and surface every adjacent path an attacker could take.
With PCI DSS 4.0 wireless requirements, DORA or NIS2 connectivity evidence or SOC 2 network controls on the line, the report has to survive scrutiny: traceable scope, a recognised methodology and signed retest evidence.
When the ask is for assurance, you need an external, expert-led wireless pentest and a deliverable that turns what reaches past your walls into business impact, in language a non-technical stakeholder can read.
Every rollout changes what reaches past your walls and what it can reach back. We test on site the way someone parked outside would: the SSIDs, the way logins are checked, and the walls to the corporate network.
Each site fails differently. We test yours where it lives, and where the inventory is incomplete we start by finding what is actually broadcasting before testing what it reaches.
Seven steps, run on site by the same operator you meet on the first call. What we do, in the order we do it.
Most wireless reviews check the controller settings and stop. Here is where we go further.
A senior specialist tests on your premises against your actual access points, SSIDs and controllers. No config-only review, no false positives, only what genuinely works over the air.
We model the real worst case: Evil Twin, 802.1X bypass, captive-portal harvest, segmentation breach and the pivot from guest Wi-Fi to internal systems. You get proof of reach, not theory.
Every finding maps to PTES, NIST SP 800‑115 and the PCI DSS 4.0 wireless requirements, the evidence your auditors and enterprise customers actually ask for.
Optional multi-site mode: after a controller, RADIUS or SSID change, we re-test the diff against the same configuration to confirm closure and catch anything the change introduced.
We at Etnia highly value our collaboration with Asperis Security.
Names, roles and companies on the record.
We at Etnia highly value our collaboration with Asperis Security. Their professionalism, approachability, quick response and ability to adapt to our needs have been key in every project. The quality of service and continuous support always give us peace of mind. Without a doubt, it is a pleasure to have them as technology partners.
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives. Thanks to their advice, we took the strategic step of completing our Microsoft ecosystem and reinforcing it with CrowdStrike for advanced mobile device protection, significantly raising our security level.
At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive. We especially value their ability to adapt to our needs and the depth with which they approach each project. Results are clear, structured and useful for decision-making and continuous security improvement. We like working with Asperis for the judgment and value they bring to every collaboration. Their work has helped us strengthen our security level.
With Asperis you don’t hire a service. You hire a partner. They don’t look to bill a project. They look to establish a relationship of trust, caring about the key points that affect your organisation’s security. Professionalism, know-how and diligence.
Tell us your sites, your SSIDs and whether guest and corporate share hardware. An experienced consultant will reply.
Wireless penetration testing is a manual security assessment of your Wi-Fi networks, performed on-site from the position of an attacker within radio range but outside your building. It checks whether your corporate Wi-Fi can be cloned, whether staff logins can be captured, whether guest and device networks are truly isolated, and whether a foothold on Wi-Fi leads into your internal network. The deliverable is a set of proven attack paths, ranked by business impact, each with a reproducible proof of concept.
No. A configuration review checks whether your controller and access-point settings match a standard or vendor best practice. A wireless pentest proves what an attacker actually achieves over the air: standing up an Evil Twin, capturing a domain login because a device does not verify the server certificate, or reaching an internal system from the guest network. A clean configuration and an exploitable network can coexist, which is why regulated multi-site estates run both, the review on the controller release cycle and the pentest against sites and segmentation.
An Evil Twin is a fake copy of a trusted Wi-Fi network, stood up by an attacker to trick devices into connecting to it instead of the real one. When a staff device connects, if it does not properly verify it is talking to the genuine Wi-Fi login server, it can hand over the user’s credentials. It is one of the most common and damaging wireless attacks because it needs no access to your network, only proximity, and we test your resistance to it directly.
Yes, at least in part, and that is by design. Wi-Fi is a radio medium, so an attacker has to be within range and so do we; a genuine wireless test means a specialist physically present at your site, with proper equipment across the 2.4, 5 and 6 GHz bands. Some preparation and reporting happen remotely, but the testing itself is on-site. For estates with many locations we agree a representative sample of sites during scoping rather than visiting every one, which keeps the engagement proportionate.
No, not without your consent. We work under documented Rules of Engagement, agreed windows and no-impact criteria, and our default posture is passive listening plus targeted, controlled tests rather than anything that floods the spectrum or disrupts users. Techniques that could affect availability are only used with prior approval and your team informed. We test on your real network without taking it down.
A single site typically takes a few days of on-site testing plus scoping and the retest; multiple sites, or a complex controller and segmentation setup, run one to two weeks. Travel and site access shape the schedule, so we plan it with you. We confirm the timeline in the proposal, delivered within 48 hours of the first call.
Price follows the number of sites, the number of SSIDs and the complexity of your authentication and segmentation. We quote a fixed price with no hidden fees and no obligation to renew. A single-site assessment sits at the bottom of the range; multi-site estates scale from there, with travel agreed up front. The retest that confirms your fixes is always included.
Grey box fits most engagements: you tell us your SSIDs and segmentation design, so we spend the time testing rather than discovering the basics. Black box mirrors a stranger in the car park with no prior knowledge, best for an honest exposure baseline. White box adds controller and RADIUS configuration for the deepest review. We work out which one fits you on the introductory meeting.
The senior specialist you meet on the first call runs it on-site, end to end. Our team holds OSCP, OSCE³, OSWE and OSEP credentials, works by hand with proper wireless equipment across 2.4, 5 and 6 GHz, and we are NASA Bug Bounty verified contributors. The same person scopes, executes and retests. That person is your point of contact throughout.
Start with a no-obligation introductory meeting. We will review your sites, your SSIDs, your authentication and your segmentation, and define the right wireless pentest before the project begins.
Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
Request received.
Request received. A senior specialist will reply within one business day with scope, a fixed quote and a timeline.
No se ha podido enviar. Inténtalo otra vez o escríbenos.
Or email [email protected] directly.
OUR CLIENTS HAVE ALREADY DONE IT
We at Etnia highly value our collaboration with Asperis Security.
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives.
At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive.
With Asperis you don’t hire a service. You hire a partner.
Pick a time that suits you. You tell us what you need and where you are, and we explain how we work and how we can help.