Wi-Fi Pentesting

... > Pentesting Services > Wi-Fi Pentesting

Wi-Fi Pentesting

Wireless technology remains a weak spot in many infrastructures. A Wi-Fi penetration test, or pentest, will reveal wireless weak points, exploit the vulnerabilities and provide clear advice on how to mitigate the risks to an acceptable level.

WiFi and other wireless technologies such as Bluetooth, 2G/3G/4G and Zigbee or WirelessHart in the industrial domain, remain a weak point in many infrastructures. Some wireless technologies can be easily disrupted or taken over, even remotely. Bureau Veritas Cybersecurity has developed specific testing protocols for such technologies. Combined with physical access testing or site surveys, knowing the susceptibility of your wireless infrastructure to attack is an important aspect of becoming more resilient. Bureau Veritas Cybersecurity will investigate on-site if the Wi-Fi (wireless) networks are adequately secured. For this, Bureau Veritas Cybersecurity will use laptops with IEEE 802.11a/b/g/n/ac/ax-network adapters and test access points.

How We Test

Bureau Veritas Cybersecurity will intercept and analyze traffic of available wireless networks. In this phase, it will be determined if the traffic is encrypted and how it is encrypted. If it is unencrypted, Bureau Veritas Cybersecurity will analyze the content of the traffic to determine if it belongs to the customer’s network and if it contains sensitive and/or useful information.

Only Wi-Fi networks that are positively attributable to our customers are subjected to the tests.
 

After a Wi-Fi security test, Bureau Veritas Cybersecurity will be able to answer the following questions:

  • Which Wi-Fi networks are available?
  • What security measures are in place and are they sufficient?
  • Is it possible to access internal systems through a public/guest Wi-Fi network?
  • Is it possible to access other guests systems through the public/guest Wi-Fi network?
  • Can traffic be intercepted and decrypted?

When we encounter networks that should be segregated, we will investigate whether they are configured correctly to prevent connections between the networks. Bureau Veritas Cybersecurity will identify vulnerabilities on the access points and attempt to exploit these.
 

A typical example would be a situation where Bureau Veritas Cybersecurity investigates possibilities of breaking out of a guest network into the office automation network, of if guests can attack each other’s system.
 

When a weaker encryption technology is used, Bureau Veritas Cybersecurity will attempt to exploit known vulnerabilities or weaknesses and crack the Wi-Fi key.

If Bureau Veritas Cybersecurity is requested to also check the security of the implemented security measures for authorized users, we should be provided with the correct login credentials. This way we can connect to the Wi-Fi network, just like a normal user would, using passwords and certificates.

Additional tests we can perform:

  • How are users separated from each other?
  • Can information sensitive areas of the office automation network be reached?

I'd like to know more about Wi-Fi Pentesting

USP

Related Services

CLOUD Pentesting

Pentest services

A Cloud penetration test (or pentest) assesses the strong and weak points in cloud-based systems to improve the overall cloud security level.

Hardware / IoT Pentesting

Pentest services

Hardware, firmware and (cloud dwelling) backends are all targets for attackers and often not very well understood. Bureau Veritas Cybersecurity can test all these aspects, and also apply reverse engineering and firmware hacking techniques to find out which weaknesses exist.

Infrastructure Pentesting

Pentest services

External, internet visible IT systems are attacked daily. It is therefore often required to test these systems periodically or when significant changes are applied.

Industrial Vulnerability Assessment / Pentest

Pentest services

Within industrial environments, cybersecurity testing requires a specialized approach. This is mainly due to the different risks and threat models within Operational Technology (OT).

Why choose Bureau Veritas Cybersecurity

Bureau Veritas Cybersecurity is your expert partner in cybersecurity. We help organizations identify risks, strengthen defenses and comply with cybersecurity standards and regulations. Our services cover people, processes and technology, ranging from awareness training and social engineering to security advice, compliance and penetration testing.

We operate across IT, OT and IoT environments, supporting both digital systems and connected products. With over 300 cybersecurity professionals worldwide, we combine deep technical expertise with a global presence. Bureau Veritas Cybersecurity is part of the Bureau Veritas Group, a global leader in testing, inspection and certification.