Protocol and authentication
WPA2 and WPA3 configuration, weak keys, enterprise authentication via 802.1X and legacy protocols that should be disabled.
Corporate wireless penetration testing: segmentation between guest and internal Wi-Fi, WPA2/WPA3 configuration, captive portals and resistance to rogue access points.

Application and external infrastructure tests rarely cover the office wireless network. Weak configuration, incomplete segmentation between guests and the internal network, or poorly built captive portals can offer a way in that no remote test would find.
Offices with corporate and guest Wi-Fi
Before network infrastructure changes
Environments with multiple branches
Periodic validation of segmentation
Execution is usually on site, given the limited range of the radio signal.
WPA2 and WPA3 configuration, weak keys, enterprise authentication via 802.1X and legacy protocols that should be disabled.
Effective isolation between guest Wi-Fi, the corporate network and critical environments, preventing VLAN hopping.
Resistance to authentication bypass, MAC spoofing and unauthorized access through the guest portal.
How devices and users behave when faced with a fake access point impersonating the legitimate network.
From technical alignment to delivery, the work has to leave context, evidence and next steps visible to everyone involved.




The scope accounts for locations, schedules and operational limits agreed in advance.
We document assets, access, limits, execution window and owners before any activity starts.
Vorvex specialists carry out the work, with Apex supporting reconnaissance, correlation and evidence handling.
Findings are analyzed for exploitability, technical impact and consequence for the business.
We deliver reproducible evidence and recommendations and, when contracted, validate the fixes you applied.

The delivery separates configuration risk, segmentation risk and device behavior.
Exposure summary, priority impacts and next steps to support decisions and investment.
Technical detail, context, reproduction steps and practical remediation guidance.
Scope, period, methodology and finding status documented for audit and accountability.
If your question isn't here, talk to the team directly.
Ask on WhatsAppUsually yes, since the assessment depends on radio signal range at the company's physical premises.
Yes, as long as each location and its network are described in the authorized scope.
They are related but distinct scopes. Physical social engineering can be combined when the company also wants to assess on-site access controls.
It depends on the configuration. WPA3 is preferable, but a well-configured WPA2-Enterprise can be adequate; obsolete protocols such as WEP, and features like WPS, should be disabled.
Tell us the locations, how many Wi-Fi networks exist and whether captive portals are in use.
Ready to assess your company's risk?