In a serviced office or a shared floor, your wireless network is one of a dozen in range and anybody in the building can sit within a few metres of your staff. A rogue access point advertising your network name can be plugged in three desks away by somebody with a legitimate pass. NIST’s guidance on securing wireless networks assumes you control the physical space, and in a shared building you do not.

What changes when you share the space

Three things. Your radio coverage extends into space you do not control, so capture and impersonation attacks need no special access. Other tenants’ networks appear alongside yours in every device list, which makes an evil twin harder for staff to spot. And the wired infrastructure is often shared, with meeting room ports and building wireless provided by a landlord whose security you cannot inspect. Each of these is manageable, and none of them is addressed by the controls that work in a building you occupy alone. Physical security is somebody else’s responsibility, which changes what your own controls have to achieve.

Protecting devices rather than the network

The practical answer is to stop depending on the network being trustworthy. Certificate-based wireless authentication means a device will not connect to an impersonating access point, because the server certificate will not validate. An always-on VPN or zero trust access layer protects traffic even when the connection is a stranger’s network. Device compliance requirements mean a laptop that has joined something unexpected still cannot reach your data, because access depends on the device state rather than the network it sits on. Together these make the surrounding radio environment mostly irrelevant, which is the goal in a shared space.

“Testing in a shared building needs a written scope more than anywhere else, because attacking a neighbour’s network is a criminal offence regardless of intent. We agree exactly which network names and addresses are yours, we work from your suite, and we do not use containment against anything we have not confirmed belongs to you.”

William Fieldhouse, Director, Aardwolf Security Ltd

Talking to the landlord

Ask what the building provides and who administers it. Shared wireless, meeting room network ports, door entry systems and camera networks are usually managed by the landlord or a facilities contractor, and their security is your exposure while your staff use them. Establish whether building wireless is separated from tenant networks, who holds administrative access, and what happens if you report a suspicious device to the building team. Get the answer in writing at the point of signing a lease, since afterwards it becomes a favour rather than an obligation.

What testing can cover

Plenty, within a defined boundary. Wireless penetration testing for shared offices confirms whether your clients validate certificates, whether your guest network is isolated, whether your access points are correctly configured, and whether an impersonating device operating from your own suite would succeed. External network assessments cover the internet-facing side of the connection, which in serviced offices is frequently shared with other tenants and worth understanding before you rely on it.

Frequently asked questions about shared building wireless

These questions come up whenever a company moves into serviced space.

Should you use the building’s wireless at all?

For guests, it is often fine. For staff handling company data, run your own network with enterprise authentication, or require an always-on VPN if you must use the building’s service.

Can you detect a rogue access point in a busy building?

Yes, with classification work. The platform will see dozens of neighbouring networks, so the value comes from marking known neighbours as external and alerting only on devices impersonating your own network names.

Leave a Comment

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *