The corporate wireless password was set in 2019 and has been given to every contractor since.
A wireless audit answers four questions: what is broadcasting from your premises, how does each network authenticate, what can a device on it reach, and would anybody notice an access point that should not be there. Most organisations can answer the first partially and the rest not at all.

- What is broadcastingIncluding what you did not deploy
- How it authenticatesShared key, or certificate per device
- What it reachesSegmentation, tested rather than assumed
- Who would noticeRogue and neighbouring access points
Six areas, and the shared password is only the most visible one.
Authentication, and the shared key problem
A pre-shared key is a credential every device holds and nobody can revoke individually. It is given to contractors, typed into personal phones and written on a whiteboard, and it changes only when somebody undertakes the disruption of changing it everywhere. Certificate-based authentication removes the shared secret entirely and is the single change that most improves wireless security.
What is actually broadcasting from your premises
Corporate, guest, voice, building services, point of sale, plant equipment and whatever a department deployed for a project. The audit surveys what is present rather than working from the controller configuration, because a controller can only tell you about the access points it manages and the interesting ones are the others.
Where the coverage actually reaches
Wireless does not respect a lease boundary. A survey establishes whether your corporate network is usable from the car park, the neighbouring floor, the street or the unit next door. That is not a theoretical concern in dense UAE developments, where several organisations frequently share a building and occasionally share a wall.
Guest isolation, tested rather than assumed
Most organisations have a guest network and assume it is isolated. The audit tests it: whether a guest device can reach the corporate network, other guest devices, management interfaces or the internet only. Client isolation between guests is frequently absent, which turns the guest network into a shared broadcast domain for visitors and their devices.
Segmentation, and what a compromised device could reach
Once a device is on the corporate wireless, what can it reach. In many organisations the answer is everything, because wireless was deployed as an access method rather than as a network segment. Establishing the actual reachable surface, rather than the intended one, frequently reveals that wireless is the least controlled entry point into the core network.
Monitoring, rogue detection and configuration drift
Whether anybody would notice an access point appearing that nobody deployed, a device broadcasting your network name from a laptop, or a configuration change on the controller. Network monitoring and defence is control 13, and wireless is the part of the network most likely to change without a change record because the hardware is small and cheap.
A pre-shared key is a credential you cannot revoke for one person.
It is the most common wireless finding, the best understood, and the least often fixed, because the fix has historically been disruptive.
- Every device that has ever joined holds it. Contractors, former employees, personal phones, the visitor who asked once, and anybody they told. There is no per-device revocation because there is no per-device credential.
- Changing it requires touching every device, which is why it does not happen. In most organisations the corporate key has not changed since the network was deployed, and everybody involved knows this and has quietly accepted it.
- Certificate-based authentication removes the shared secret. Microsoft describes Intune Wi-Fi profiles assigning wireless settings so users get corporate access without configuring it themselves, and certificates authenticating users so they reach resources through Wi-Fi profiles without entering usernames and passwords, using trusted root, Simple Certificate Enrolment Protocol or Public Key Cryptography Standards certificates.
- That combination is what makes the fix practical now. The device management platform delivers both the profile and the certificate, so the disruption that historically prevented this change has largely gone. The audit quantifies the remaining effort against the population that is not managed.
Four things a wireless audit finds that a configuration review does not.
We survey rather than read the controller
A controller can only report on the access points it manages. The interesting findings are the ones it does not know about: a device deployed by a department, a vendor access point installed alongside their equipment, a building services network, or something broadcasting your network name from a laptop. Only a survey finds those.
We establish where the coverage actually goes
Wireless does not stop at a lease boundary. In dense UAE developments where several organisations share a building, establishing whether your corporate network is usable from a corridor, a car park or a neighbouring unit is a physical question with a physical answer, and it changes the risk assessment of a shared key considerably.
We test isolation instead of accepting the design
Guest isolation, client isolation and segmentation from the wireless segment are all things every organisation believes it has. Testing them from a device on each network, rather than reading the intended configuration, is how the exceptions surface, and there is usually at least one path that nobody designed.
We size the migration off shared keys realistically
Certificate-based authentication is the right destination and the practical question is the population that cannot get there easily: unmanaged devices, contractor equipment, printers, scanners, plant hardware and anything without a management agent. Sizing that population honestly is what turns a recommendation into a plan somebody will actually fund.
Six UAE situations where a wireless audit finds something material.
An organisation in a shared or mixed-use building
Common across UAE business districts and free zones. Your coverage reaches the corridor, the parking level and possibly the neighbouring tenancy, and theirs reaches you. Where the corporate network uses a shared key, the physical boundary that made that acceptable does not exist, and establishing the actual coverage footprint is the first useful output.
A retail or hospitality business offering guest wireless
Guest wireless is offered to the public by design, which makes isolation the whole control. The audit tests whether a guest device can reach the corporate network, the point of sale environment, management interfaces or other guest devices. Client isolation in particular is frequently absent, and it is the one visitors are most affected by.
An operator with wireless on plant and handheld equipment
Scanners, handhelds, sensors and control equipment frequently cannot support certificate-based authentication and are therefore the reason the shared key survives. Identifying that population precisely, and designing a separate segment for it with appropriate restrictions, is usually a better answer than keeping the whole estate on a shared credential.
A regulated firm with an obligation covering network access
Where an obligation expects individual accountability for network access, a pre-shared key does not provide it, because there is no per-device credential and therefore no attribution. That is a straightforward finding to state and a straightforward one to remediate with certificate-based authentication delivered through the device management platform.
An organisation with heavy contractor presence
Every contractor who has been given the wireless password still has it, and so does every device they used. Where contractors are numerous and rotate frequently, the shared key becomes a credential held by an unbounded population, and no amount of encryption strength addresses that. Guest or contractor segmentation with individual credentials is the answer.
A healthcare organisation with clinical devices on wireless
Clinical equipment on wireless combines devices that cannot be reconfigured easily with a network that must remain available. The audit establishes which devices constrain the design, whether they are segmented from general corporate traffic, and whether the wireless segment can reach clinical systems it has no need to reach.
How UAE organisations secure their wireless networks.
| Feature | Certificate based and segmented | Modern encryption, shared key | Unmanaged or legacy wireless |
|---|---|---|---|
Per-device credentials | Yes | No | No |
Individual revocation possible | Yes | No | No |
Guest isolated and tested | Yes | Assumed | No |
Client isolation between guests | Yes | Often not | No |
Wireless treated as a network segment | Yes | Sometimes | No |
Coverage beyond premises understood | Yes | No | No |
Rogue access point detection active | Yes | Available, off | None |
Controller hardening verified | Yes | Assumed | No |
Access point additions recorded | Yes | No | No |
Effort to remove one person access | Seconds | Change it for everyone | Not possible |
Ten checks, and where each one usually fails.
| Check | Where it usually fails | |
|---|---|---|
| Every broadcasting network identified | Networks nobody in IT deployed, from departments or vendors | |
| Authentication method per network | A shared key on the corporate network, unchanged for years | |
| Certificate infrastructure where used | Certificates issued once with no renewal or revocation process | |
| Guest isolation from corporate | Tested rarely, and occasionally not actually in place | |
| Client isolation between guests | Frequently absent, so visitors share a broadcast domain | |
| Segmentation from the wireless segment | Wireless treated as an access method, not a network segment | |
| Coverage beyond the premises | Usable signal in car parks, corridors and neighbouring units | |
| Controller and access point configuration | Default management credentials and unpatched firmware | |
| Rogue access point detection | Available in the platform and never enabled | |
| Change control on wireless configuration | Access points added without any record |
Five steps, and one of them happens on site.
- 1
Review the configuration and the intended design
Controller and access point configuration, the networks defined, authentication methods, segmentation intent, guest arrangements, management access and firmware currency. This establishes what was designed, which is the baseline the physical findings are compared against rather than the conclusion.
- 2
Survey what is actually broadcasting, on site
Every network present at each in-scope location, including those the controller does not manage. Departmental deployments, vendor equipment, building services, and anything broadcasting a network name it should not. The gap between the survey and the configuration is the first substantive finding.
- 3
Establish the coverage footprint
Where each network is usable from, including corridors, parking, adjacent floors and neighbouring tenancies where accessible. Wireless does not respect a lease boundary, and in shared buildings the physical extent of the network is a material input to how acceptable a shared credential is.
- 4
Test isolation and segmentation from each network
From a device on guest, from a device on corporate, and from any other network in scope. What can be reached, whether client isolation is present, whether management interfaces are reachable from the wireless they manage, and whether the wireless segment reaches systems it has no business reason to reach.
- 5
Report with a realistic migration path
Findings prioritised, with the shared key question addressed through certificate-based authentication delivered by the device management platform, and the population that cannot support it identified precisely and given its own segment. Plus monitoring recommendations, because rogue detection is usually available and usually switched off.
What organisations ask about wireless security audits.
Fifteen questions worth answering about your wireless.
What exists
- How many networks are you broadcasting?Then compare with what a survey finds.
- Which sites are in scope?Branches and remote facilities included.
- Are there networks IT did not deploy?Departments, vendors and building services.
- Is there wireless on operational equipment?Plant, scanners, cameras, access control.
- Who owns the wireless platform?Frequently facilities rather than IT.
Authentication and reach
- How does corporate wireless authenticate?Shared key, or per-device certificate.
- When did the shared key last change?And who has it.
- Is guest genuinely isolated?Tested, not assumed.
- Is client isolation on for guests?Frequently not.
- What can a wireless device reach?Tested from the segment.
Operations
- Is rogue detection enabled?Usually available, usually off.
- Who is alerted, and do they act?Detection without response is a log.
- Is controller firmware current?Secure configuration, control 4.
- Are management interfaces restricted?Not reachable from the wireless itself.
- Is there change control on access points?They are small, cheap and easy to add.
The pages around this one.
Ask when the corporate wireless password last changed, and who has it.
The first answer is usually a year that surprises people. The second is that nobody knows, which is the actual finding. Both are addressable now in a way they were not five years ago, because the certificate can be delivered by the platform that already manages the device.
Related Services
Explore more solutions that work great with this service
Enterprise WiFi
Survey-first WiFi design with 802.1X auth
Microsoft Cloud PKI
Retire the certificate server, NDES and the Intune connector
Penetration Testing
Black, grey, and white-box penetration testing
Network Monitoring NOC
24/7 NOC monitoring with named engineers
Firewall Rule Audit
What the rule base permits, and what should go
Structured Cabling
Cat6A, fibre, AV, CCTV cabling certified
CIS Controls Assessment
Eighteen controls, assessed and re-assessed
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly