
Wireless in Manufacturing: Legacy Handhelds and Old Encryption
Factory wireless carries devices that cannot be upgraded, on a network where downtime is measured in pounds per minute. Barcode scanners, forklift terminals and machine controllers often support only a shared passphrase, sometimes only an old encryption standard, and replacing them means replacing working equipment. The security answer is containment rather than a rebuild, and it starts with knowing what is actually connected.
Why the usual advice does not apply
Standard guidance says move to 802.1X with certificates, and a device from 2014 with a fixed firmware image cannot do it. NIST’s guide to operational technology security, SP 800-82 in its third revision published in 2023, is explicit that OT environments need controls adapted to availability and safety constraints rather than the enterprise playbook applied unchanged. In practice that means accepting a weaker authentication method on a segment that is watched closely and reaches almost nothing, instead of pretending the estate can be upgraded on an IT timetable.
The passphrase nobody has changed
Shared keys age badly in industrial settings. The passphrase is written on a card in the goods-in office, it was set when the network was installed, and every contractor who has configured a scanner since knows it. Changing it means touching every device, so it never changes. Assume it is known outside the business and design accordingly: put those clients on a segment with a firewall in front of it, allow only the ports the application needs, and log connections. That converts a shared secret from a security control into an inconvenience for an attacker who is already in the car park.
“Production sites tell me a test is impossible because the line cannot stop, and they are usually right about the line. We work around it: passive capture during a shift, active testing during a planned changeover, and no deauthentication near anything that moves. A tester who insists on running the same script they use in an office should not be in a factory.”
William Fieldhouse, Director, Aardwolf Security Ltd

Segmentation that survives a real incident
Draw the boundary between production and everything else, then test that it holds. The wireless serving handhelds should not reach the office file server, the finance system or the internet, and the office network should not reach the controllers. Where a supplier needs remote access to machinery, route it through a jump host with logging and time-limited accounts rather than a permanent tunnel. Then verify from the production side: internal network security testing from a handheld’s network position tells you what an attacker who cloned a scanner could actually touch.
Planning testing around production
Book the work around your shift pattern and be specific about the constraints. Share the site layout, the device inventory and any equipment that must not be disturbed. Agree the techniques in advance, since coverage surveys and passive capture are safe at any time while active attacks against clients belong in a maintenance window. Wireless network penetration testing in an industrial setting is as much about the plan as the tools, and a supplier who has worked in these environments will ask about the process before they ask about the network.
Frequently asked questions about industrial wireless
These questions come up on every manufacturing site visit.
Can old devices be protected without replacing them?
Yes, by isolating them. A separate SSID, its own VLAN, a firewall policy allowing only the required traffic and monitoring on that segment give you most of the benefit without touching the devices.
Is it safe to test a live production network?
With planning, yes. Passive work carries almost no risk, and anything that could interrupt a client is scheduled for a changeover. The alternative, leaving it untested, is what turns a weakness into a stoppage.


