Penetration Testing Hub · cyberlabs.ie

Wi-Fi Security Checklist

Nine checks you can run on your own wireless estate before hiring anyone. Tick what's true; every unticked box is somewhere to look.

Before you test — Only test wireless networks you own or have explicit written permission to test. Unauthorised access is a criminal offence in Ireland under the Criminal Justice (Offences Relating to Information Systems) Act 2017.

Encryption & authentication

No WEP or open SSIDs anywhere on the estate.
Business SSIDs use WPA3, or WPA2-Enterprise (802.1X) with individual logins — not one shared password.
Any WPA2-PSK key is long and random, not a company name, postcode or phone number.

Access points

WPS is disabled on every access point.
AP admin passwords have been changed from the default.
Firmware is up to date on every access point.

Segmentation & exposure

The guest network is genuinely isolated and cannot reach internal VLANs or management interfaces.
No unexpected SSIDs are broadcasting your organisation's name.
Management interfaces are not reachable from the guest or client VLAN.
Educational, not legal advice. Test only what you own or are authorised to test.
Full guide: Wi-Fi Penetration Testing
© CyberLabs · cyberlabs.ie