Enterprise Wi-Fi Security

Why a shared password is not enough, what 802.1X provides, and how to separate guest, corporate and device networks.

Wireless is where physical access control ends: the signal leaves the building and is reachable from the car park. Yet in many organisations the same shared password has protected it for three years.

The problem with shared passwords

WPA2-Personal (and WPA3-Personal) works on a single password everyone knows. Several problems follow:

Not attributable. You cannot tell who connected, only that somebody did.

Not individually revocable. When someone leaves, the password must change for everyone, so it never changes.

It spreads. A password known to fifty people will be known to outsiders within months.

Interceptable. With WPA2, capturing the handshake allows traffic to be decrypted retrospectively once the password is known.

The alternative: 802.1X

Enterprise Wi-Fi (WPA2-Enterprise or WPA3-Enterprise) uses individual authentication. Each user or device connects with its own identity, typically a certificate or their domain account.

From this it follows that:

  • you can see who connected, when, and via which access point
  • a user's access is individually revocable
  • traffic keys are unique per session

The certificate-based variant is stronger than password-based, because it cannot be shared or leaked.

Network separation

At least three separate networks, routed into separate segments.

Corporate. With 802.1X authentication and access to internal resources.

Guest. Fully isolated with internet access only. With client isolation so guests cannot reach each other. Time-limited or single-use codes.

Devices. Printers, IP cameras, building automation, meeting room equipment. These cannot do 802.1X and typically run with default passwords and old firmware. They belong in their own segment with restricted outbound traffic. We covered this in our internal segmentation article.

The most common guest network mistake is running on the same physical infrastructure, separated by VLAN, but with unfiltered routing between VLANs. Guests then technically reach the internal network. Worth verifying.

What else to watch

Rogue access points. An attacker broadcasts your network name and connecting devices hand over credentials. Certificate-based authentication defends against this, because the client validates the server certificate. This must be enforced on clients, otherwise users simply accept it.

Legacy protocols. WEP and the original WPA are breakable. Where they survive, it is typically because of one old device nobody dared replace.

WPS. Push-button pairing is convenient and vulnerable. Disable it in enterprise environments.

Access point administration. Default passwords, outdated firmware, management interfaces reachable from the internet. The same rules apply as to any other network device.

Coverage beyond the walls. If the signal is strong in the car park, the attack surface extends outside the building. Transmit power and antenna placement are security questions too.

Quick check

  • When was the Wi-Fi password last changed, and how many people know it?
  • Can anything on the internal network be reached from the guest network?
  • Are printers and cameras on the same network as workstations?
  • Does WPA or WEP survive anywhere?
  • Do access point management interfaces run with default passwords?

Our IT security services include reviewing network architecture.

Back to Insights
Related content

Related content

Questions on this topic?

Our specialists are happy to discuss what this means in your organisation's environment.