Skip to main content
Strengthening Password Security with Leaders in Healthcare

Wireless Penetration Test

About the Client

The client is a leader in healthcare in the Upper Midwest.

Objectives

The primary objective of the Wireless Penetration Test was to identify weaknesses in the authentication of clients to access points, the individual access point's ability to segment guests from corporate networks, and test the overall configuration of the wireless access points. Testing was performed in the context of an unknown external threat actor, as well as a malicious user with access. Six SSIDs were identified as "in-scope" for the engagement.

Findings

Testing was performed on the strength of passwords used for access, network segmentation, cryptographic implementations, and the ability of the network to prevent the construction of rogue access points. Though the network configuration was robust, it was still possible to create rogue access points and use this access point in an attempt to hijack a wireless device's connection. As a result, RedTeam Security provided the client with recommendations to ensure the improved security and integrity of the client's network, associated environment, and intellectual properties.

Key Takeaways

After the engagement, the client was able to take recommendations outlined in their report and begin remediation efforts to improve their security. Every engagement with RedTeam Security provides clients with:

  • A clear understanding of the effectiveness of their existing information security program, training, monitoring, and system updating to keep things current.
  • How well their vendors manage the security posture of networks and web applications (for those with a 3rd party IT vendor).
  • A statement of assurance to provide to their customers that they are doing everything they should to keep their data and systems secure.
  • Outlined areas of focus for improving their overall security posture.

All identifying information has been changed to protect our clients and ensure absolute confidentiality.

Hear What Our Clients Are Saying

"Saint Paul College hired RedTeam consultants to perform Web Applications vulnerability scanning and assessment. It was one of best group of people I worked with - from beginning to the end. Everyone I worked with was extremely cooperative, friendly, professional, and knowledgeable. They understand IT security very well. They worked around our schedules, were available when we needed them, and always on time. My staff and I thoroughly enjoyed our relationship with them. The consultants were focused/committed, pointed out the vulnerabilities and worked with my team to remediate them. Red Team also gave us detailed report about each web application. In all, it was a great experience working with Red Team and we will not hesitate to hire them again if needed."

Najam Saeed, CIO at Saint Paul College