The Auditor Asked to See the Guest Network: Captive Portal and Network Separation at a Hong Kong Firm
A Hong Kong firm's guest Wi-Fi worked fine, until a client's supplier review asked for evidence that visitors could not reach the file server. Why "we have guest Wi-Fi" and "guest Wi-Fi is segregated" are different claims, what a captive portal does and does not prove, what auditors actually ask for and what tends to satisfy them, an honest look at rolling out 802.1X, and a realistic five-week response sequence.
Published
In short: The guest Wi-Fi worked. That was never the question. The auditor wanted proof that a visitor on it could not reach the file server, and a record of who had changed the configuration and when. The honest answer was a shared password written on a meeting-room whiteboard — and a finding that landed weeks before the response was due.
"We Have Guest Wi-Fi" and "Guest Wi-Fi Is Segregated" Are Two Different Claims
There is a particular kind of Hong Kong firm that gets audited by people who are not its regulator. A 40-person advisory practice whose corporate clients send a supplier security questionnaire every year. A boutique asset manager preparing for an investor's operational due-diligence visit. A specialist clinic group whose insurer asks for a controls attestation at renewal. A professional-services firm that holds client documents and has just been told a client's internal audit team wants to see "evidence of network segregation for visitor access."
None of these firms thinks of itself as having a wireless problem. The Wi-Fi works. Visitors get online, staff get online, nobody complains. And that is exactly why the question catches them out, because the auditor is not asking whether the Wi-Fi works. The auditor is asking whether a control exists — and a control is only a control if it can be shown.
Two sentences sound almost identical in a questionnaire response and mean completely different things:
- "We provide guest Wi-Fi." A statement about convenience. It is almost always true, and it tells a reviewer nothing.
- "Guest Wi-Fi is segregated from our internal network." A statement about a control. It implies that a visitor's laptop cannot reach the systems that hold client data, that someone configured this deliberately, and that the firm could demonstrate it on request.
Only the second sentence is the one being asked about, and only the second one can get a firm into trouble if it is written down without being true. This article is about the distance between the two — and about why closing it is mostly a configuration-and-evidence exercise rather than a shopping trip for a security product.
The Scenario: One Network, One Passphrase, One Whiteboard
This is an illustrative composite, not a named client, but its shape will be familiar to anyone who has sat on the receiving end of an audit request at a small Hong Kong firm.
The firm occupies half a floor in a Sheung Wan office tower: around 40 staff, two meeting rooms, a reception desk, a small comms cupboard. The office was fitted out several years ago. The fit-out contractor's IT subcontractor installed an internet router from the broadband provider, a switch, and a handful of ceiling-mounted access points, and configured a single wireless network named after the firm.
There is one passphrase. It has not changed since the fit-out, because changing it would mean reconnecting every laptop, every phone and the two multifunction printers, and nobody has ever had a reason to take that on. It is written in marker in the corner of the whiteboard in the larger meeting room, so that clients and candidates can get online without interrupting anyone. Over the years it has also been read by couriers, contractors, interns, departing staff, the landlord's maintenance team and every visitor who ever sat in that room for a meeting.
Visitors and staff use the same network. The file server, the network storage box that holds scanned engagement documents, the printers and the partners' desktops all sit on the same flat address range as the phone of whoever is waiting in reception. Nobody decided this. It is simply what happens when a network is set up to "work" and never revisited.
And there is no record of who set it up. The person who managed the fit-out left two years ago. The subcontractor's invoice says "network installation." The router's admin password is on a label on the router.
Then the request arrives. A major client's supplier review includes a line that reads, in substance: "Describe how visitor and guest wireless access is segregated from systems that store or process our data, and provide supporting evidence." The fieldwork conversation happens in the first week. The written response, with evidence, is due in five weeks. The finding — "guest wireless access is not segregated from the internal network" — is effectively written the moment someone in the room says "well, visitors use the same Wi-Fi."
What Actually Goes Wrong When the Auditor Asks
The finding itself is not the real damage. Findings happen, and a clear remediation plan usually lands better than a defensive answer. The damage is in what the firm discovers about its own position in the days that follow.
You Cannot Evidence a Control You Cannot Demonstrate
The first instinct is to reach for a sentence: "Guests use a separate network." Sometimes that is even partly true — at some point somebody may have turned on the broadband router's built-in guest network. But the reviewer's next question is always the same: "Show me." Show me the setting. Show me that a guest device cannot reach the file server. Show me when it was configured and by whom.
If the only person who could answer has left, and the only interface is a consumer router page that nobody has logged into for years, the firm cannot show anything. It can assert, and assertions are exactly what an audit is designed to discount. Worse, an assertion that later turns out to be wrong is a far bigger problem than an honest gap: it converts a configuration finding into a credibility finding.
A Whiteboard Credential Cannot Be Meaningfully Rotated
Reviewers routinely ask how often shared wireless credentials are changed. For a passphrase shared by staff and visitors alike, there is no good answer. Changing it breaks every staff device at once, so it is not done. When it is not done, every person who has ever read the whiteboard keeps access indefinitely — including people who no longer have any relationship with the firm.
This is the uncomfortable structural point: a shared credential used by staff cannot be rotated as often as a visitor credential should be, and a visitor credential cannot be kept as stable as a staff credential needs to be. Putting both populations behind one secret guarantees that the secret is wrong for at least one of them. The fix is not a better password policy; it is separating the two populations so that each can have the right kind of credential.
Nobody Can Say What Has Changed
An audit trail is not only about the original setup. The question "who changed the configuration, and when?" presumes there is a configuration someone could have changed, and a place where changes are written down. In the flat-network firm there is neither. If a well-meaning staff member created a "Guest" network on the router last year and then deleted it when a printer stopped working, there is no way to know. The firm cannot demonstrate that the network is in a known state, only that it seems to be working today.
The Clock Runs Faster Than the Fix
Five weeks sounds like a long time. It is not, once the firm realises that the fix involves decisions — who issues visitor access, what staff devices authenticate with, what to do about the printers — and that the evidence has to show the control operating, not merely being switched on the afternoon before the response is sent. The temptation at that point is to do something quick and visible, such as renaming the network or adding a second one, and write "segregated" in the response. That is how firms end up with the worst of both positions: a changed configuration nobody fully understands, and a claim they still cannot evidence.
Why This Is a Configuration-and-Evidence Problem Before It Is a Product Problem
When a firm first hears "network segregation finding," the reflex is to look for something to buy — a new firewall, a network access control appliance, a security product with "compliance" in its brochure. Sometimes a genuine gap in the firm's perimeter does turn up along the way. But for guest wireless in a small office, the control the auditor is asking about is usually made of four ordinary things, and none of them is a new product category.
A captive portal, so visitor access is issued rather than overheard. A captive portal is the page a visitor's device lands on after joining the guest network and before it is allowed onto the internet. Its job is to put a deliberate step between "I can see the network name" and "I am online": a voucher code handed over at reception, or another authentication method. A voucher can be time-limited, so access expires on its own when the meeting ends rather than lingering for years. What a portal does not do on its own is keep visitors away from internal systems. That is the next item's job, and conflating the two is one of the most common mistakes in questionnaire answers.
VLAN separation, so the guest network is actually a different network. A separate wireless network name is a label. Separation happens when guest traffic is placed in its own VLAN and the routing and firewall rules between that VLAN and the internal ones stop a guest device from reaching the file server, the storage box, the printers or anything else internal. This is the part that turns "guest Wi-Fi" into "segregated guest Wi-Fi," and it is the part the reviewer actually wants demonstrated.
RADIUS / 802.1X, so staff connect with an account instead of a shared secret. Once visitors have their own path, staff no longer need a passphrase that the whole building can read. With 802.1X, each person authenticates with their own credentials, checked by a RADIUS server against a directory of accounts. When someone leaves, disabling their account removes their wireless access — no passphrase change, no reconnecting forty devices. It is the right end state, and it is also the item that needs the most honest planning, which we come back to below.
A change trail, because evidence is a by-product of process. The reason a firm can show who changed what and when is not that someone remembers to take screenshots. It is that changes go through a process that writes them down: a request, an assessment, an approval, a scheduled window, a backup taken first, and a recorded outcome. Firms that try to produce change evidence retrospectively for an audit find it nearly impossible. Firms whose changes already run through a ticketed process find it is simply there.
Brocent's view is that the order matters. A firm that buys a product before it has a separated guest network, a way of issuing visitor access and a change process will still be unable to answer "show me." A firm that has those four things in place can usually answer it with ordinary screenshots, a short test and its own change records — whatever else it later decides to buy.
Comparison: Shared Passphrase on a Whiteboard vs Separate Guest SSID With No Portal vs Captive Portal + VLAN Separation + Change Trail
Three positions a small Hong Kong firm typically finds itself in, judged the way a reviewer will judge them.
Shared Passphrase on a Whiteboard
- What the reviewer sees: one wireless network for everyone, no separation to demonstrate, and a credential visible to anyone who has used the meeting room.
- Separation: none. Visitors and internal systems share an address range; the only barrier is whatever authentication each internal system happens to have.
- Credential rotation: effectively impossible, because rotating it disconnects every staff device, so it is never done and former visitors and staff retain access indefinitely.
- Change trail: none. Nobody can say who configured it, whether it has changed or what state it is in.
- Likely outcome: a clear segregation finding, plus a follow-up question about credential management.
Separate Guest SSID With No Portal
- What the reviewer sees: a second network name, often created on the broadband router, with its own shared password — frequently also on a card or whiteboard.
- Separation: uncertain until tested. Some router guest modes do isolate guests; others simply broadcast a second name onto the same network. Without a configuration export and a test, the firm does not actually know which it has.
- Credential rotation: better than a single shared secret, since the guest password can change without touching staff devices — but in practice it rarely does, and staff often still share one passphrase among themselves.
- Change trail: usually none; the setting was changed by whoever had the router password that afternoon.
- Likely outcome: a finding that becomes an observation if a test proves the isolation works, and a finding that stands if it does not — plus the risk of having claimed segregation that was never there.
Captive Portal + VLAN Separation + Change Trail (Brocent Model)
- What the reviewer sees: a guest network behind a branded portal with vouchers or another method, placed in its own VLAN, with the separation visible in the controller configuration; staff authenticating with accounts through RADIUS / 802.1X where that has been rolled out.
- Separation: demonstrable — by a dated configuration view and by a test from a guest device that fails to reach an internal host.
- Credential rotation: visitor access expires with the voucher; staff access follows their account, so a leaver is removed by disabling one account rather than by changing a shared secret.
- Change trail: every change raised, assessed, approved, executed in a window after a configuration backup, and recorded — so "who changed what, and when" has an answer.
- Likely outcome: a response that shows the control and its history rather than describing it, with any remaining gap (for example, printers not yet moved) stated with a date.
What Auditors Actually Ask For — and What Tends to Satisfy Them
Every reviewer is different, and the scope of a supplier review, an internal audit and an insurer's questionnaire are not the same. Nothing below is a guarantee that a particular reviewer will accept a particular item. But across the requests small firms receive, the questions about guest wireless tend to fall into five groups, and each has a kind of evidence that usually answers it far better than a paragraph of prose.
"Show Me the Configuration"
The reviewer wants to see that the guest network exists as a distinct thing and is set up to be separated. What usually works is a dated configuration export or screenshot from the management interface showing the guest wireless network, the VLAN it is bound to, the guest portal settings, and the isolation or firewall rules that prevent guest traffic reaching internal networks. A vendor datasheet saying the product supports guest isolation is not the same thing: the reviewer is asking what is configured in your office, not what is possible.
"Show Me That It Works"
A configuration can be set and still not do what everyone thinks it does — a missing rule on the gateway, a switch port not carrying the VLAN correctly. So a well-prepared firm pairs the configuration with a test. Connect a laptop to the guest network through the portal, then try to reach an internal host — the file server's address, the storage box's admin page, a printer — and record that the attempt fails, with the date and time visible. Then do the positive control: a staff device on the internal network reaching the same host. It takes a few minutes, it is easy for a reviewer to understand, and it is worth repeating after any significant change to the network.
"Show Me Who Changed It, and When"
This is where most small firms stumble, because the answer only exists if changes have been recorded as they happened. The strongest evidence is a set of change records for the period under review: what was requested, who assessed and approved it, when it was executed, and what the outcome was. A record showing that the guest network was introduced through a change request, in a scheduled window, with a backup taken beforehand, answers not only "is it separated" but "is it under control."
"Show Me the Credentials Are Not Forever"
Reviewers who ask about wireless credentials are really asking whether access ends when it should. Evidence here depends on the design: for visitors, that access is issued per visitor or per meeting through time-limited vouchers rather than a standing password; for staff on 802.1X, that access follows the account and is removed in the leaver process. If a shared staff passphrase does still exist during a transition, a dated record of when it was last rotated is better than nothing — and a stated date for retiring it is better still.
"Show Me It Is Operated Over the Period, Not Just on the Day"
A screenshot proves the state of a network on one afternoon. Some reviewers, particularly for annual supplier reviews, want some assurance that the environment is watched and maintained continuously. This is where a period report is useful, as long as nobody overstates what it is.
For networks Brocent operates, that report is the monthly availability monitoring report delivered through Report Central. It is an availability report, not a compliance certificate. It shows availability by monitored item — access points included — the outage record with cause and resolution for each event, the planned maintenance windows used in the period, and findings with a named owner and a target date. The published sample includes exactly the kind of wireless finding a reviewer finds reassuring: an access point logging repeated unexpected restarts, traced to power delivery on the switch feeding it, with a recommendation and a date. What the report demonstrates is that the network is monitored and run through a process across the whole period. It does not, by itself, prove that guests are separated — the configuration and the test do that. Attached together, they tell a coherent story: the control exists, it works, it was changed under control, and the environment it lives in is watched.
What Usually Does Not Satisfy
A sentence in the questionnaire with nothing attached. A screenshot with no date and no indication of which office it came from. A product brochure. "Our IT contractor set it up." An email from a former employee. And, most dangerously, a claim of segregation made before anyone has tested whether it is true.
Five Weeks: A Realistic Response Sequence
For the firm in the scenario, the useful question is not "how do we become perfect by the deadline" but "what can we honestly show by the deadline, and what do we commit to after it." A sequence that tends to hold up:
- Week one — establish the real current state. Inventory what is actually there: access points, router, switch, what connects to what. Test whether a visitor device can reach internal hosts today. Write the honest answer down, because it becomes the baseline the reviewer will compare against.
- Week two — separate visitors. Introduce a guest network behind a captive portal, in its own VLAN, with isolation from internal networks, and remove the passphrase from the whiteboard. Run it as a recorded change, in a window, with a backup first.
- Week three — test and fix. Run the guest-device test against the file server, storage and printers. Fix whatever the test reveals. Record the result with dates.
- Week four — decide the staff side. Either begin a phased 802.1X rollout, or at minimum rotate the staff passphrase now that visitors no longer use it, and set a date for moving to accounts.
- Week five — assemble the evidence. Configuration export, test results, change records, the credential approach, and a short remediation plan for anything not yet complete, each with an owner and a date.
A response built this way does not pretend the finding never happened. It shows that the gap was understood, closed in the part that matters most, and put under a process that will keep producing evidence — which is usually what the reviewer was trying to establish in the first place.
Is 802.1X Worth It for a 40-Person Office? An Honest Look at the Rollout
802.1X is the right destination for staff access, and it is supported on the controller Brocent runs. It is also the part of this work most likely to be undersold, so it is worth being direct about what it involves.
- It needs an identity source. The RADIUS server has to check each login against a directory of staff accounts. Deciding which directory, and making sure the joiner and leaver process keeps it accurate, is real work — and it is the part that delivers the benefit, since wireless access that follows the account is only as good as the account list.
- Every device has to be onboarded. Each laptop and phone needs the network profile configured, and in certificate-based designs a certificate as well. Company-managed laptops are straightforward; personal phones and a partner's tablet are where the time goes.
- Some devices cannot do it at all. Multifunction printers, meeting-room displays, door and card readers and assorted smart-building devices often do not support 802.1X. They need a separate arrangement — typically their own restricted network segment that allows only the traffic they need — rather than being left on a shared passphrase with everything else.
- It should be phased. Run the old staff network and the new one side by side, move one team at a time, and retire the shared passphrase on a date that is written into the change record.
None of this makes 802.1X unrealistic for a 40-person firm. It makes it a small project rather than a setting. For many firms facing an audit deadline, the sensible order is guest separation first, because that closes the finding, and staff 802.1X second, on a plan the response can cite.
What It Looks Like When Someone Actually Operates It
The four ingredients above are not exotic, but they only produce evidence if someone runs them as a service rather than as a one-off job. That is the gap Brocent's managed wireless network service is designed to close.
Brocent runs a UniFi Network controller on its own platform. A firm's UniFi access points are adopted into it — either access points the firm already owns, or, under the hardware-included model, access points supplied as part of the subscription. The difference between those two buying models, and the ways a controller can be run at all, are covered in our serviced-office wireless article; this article is only concerned with what the service produces when an auditor asks.
- Guest portal. Branded guest authentication with vouchers and other methods, with guests kept off the internal network.
- SSID and VLAN. Wireless networks and VLAN separation pushed per site or per floor, so guest separation is a demonstrable controller configuration rather than a setting on a consumer router.
- RADIUS / 802.1X. Supported, so staff can connect with an account instead of a shared password — rolled out on a plan, as described above.
- Change process. A change is raised at the service desk or by a monitoring alert; an engineer assesses the blast radius and rollback plan and proposes a window; the client approves; a configuration backup is taken, the change runs inside the window and is verified; the outcome is written to the change record. Who changed what, and when, is auditable.
- Configuration backup. Taken daily and retained for three years, so the firm can show — and restore — the state of its wireless configuration on any given day.
- Engineer access. Brocent engineers are authorised per client, and their access is logged. A reviewer asking "who at your provider can change this?" gets a real answer.
- Tenant isolation, stated precisely. Isolation between clients on the platform is logical: the underlying runtime is shared, while each client's sites, devices, data, credentials and logs are scoped to its own tenant. If a firm's own obligations require a dedicated instance or a specific data jurisdiction, that should be raised before a quote rather than assumed.
- Monthly availability report. Delivered through Report Central, as described above, with a 99% controller availability commitment behind the service.
On price, since it tends to come up once a finding makes the work urgent: as read from Brocent's pricing source on 17 September 2026, controller hosting for access points a firm already owns is offered at US$1.20 per access point per month on a 12-month contract, excluding tax, under promo code YE26-UNIFIAP, with the offer window ending 30 November 2026; outside that window it is a custom quote. Check the service page for the current figure rather than relying on this article. For a half-floor office with a handful of access points, that is a small number — which is the point worth taking from it. The cost of operating the network in a way that produces evidence is rarely what stands between a small firm and a defensible answer. What stands in the way is that nobody has been made responsible for it.
A Note on the PDPO — Without Overreaching
Firms that hold client personal data often ask whether this is "a PDPO requirement." The Personal Data (Privacy) Ordinance is principles-based: it does not prescribe wireless configurations, and no configuration of a guest network makes a firm compliant with it. What can be said is that keeping visitors' devices away from systems that hold personal data is the kind of practical safeguard a firm may reasonably point to when describing how it protects that data — and that whether a firm's overall arrangements are adequate is a question for its own data protection lead and legal advisers, not for a wireless configuration. Where an IT provider is involved, the questions that matter more are contractual; our PDPO checklist for outsourcing IT in Hong Kong covers those. Nothing in this article is legal advice.
Frequently Asked Questions
Is a guest VLAN enough on its own?
Not by itself. Placing guests in their own VLAN gives their traffic a separate lane, but separation is only enforced if the routing and firewall rules between that VLAN and the internal networks actually block it, and the switches carry the VLAN correctly. A guest VLAN that the gateway happily routes to the office subnet is a label, not a control. That is why a configuration export should always be paired with a test from a guest device that fails to reach an internal host.
What is a captive portal, and do we need one?
A captive portal is the page a device sees after joining the guest network and before it gets internet access, where the visitor enters a voucher code or completes another authentication step. You do not strictly need one to separate guests — separation is a VLAN and firewall question — but a portal changes how access is issued: deliberately, per visitor or per meeting, and time-limited, rather than via a password anyone can read. For firms that are asked how visitor access is controlled, that difference is usually what the question is about.
How do voucher-based guest logins work in practice?
Someone at reception issues a code when a visitor arrives or a meeting is booked. The visitor joins the guest network, the portal page appears, they enter the code, and they are online for the period the voucher allows. When it expires, access ends without anyone having to change a password. The practical decisions are about the workflow — who issues codes, how long they last, whether a meeting gets one code or each attendee gets their own — and those are worth settling before the guest network goes live, not after.
Is 802.1X realistic for a 40-person office?
Yes, as a planned project rather than a quick setting. It needs a RADIUS identity source kept accurate by the joiner-leaver process, each staff device onboarded, and a separate restricted arrangement for printers and other devices that cannot authenticate individually. Many firms phase it: separate visitors first to close the audit finding, then move staff from a shared passphrase to accounts one team at a time.
How do we show an auditor that the guest network is separated?
Usually with three things together: a dated configuration export or screenshot showing the guest network, its VLAN and its isolation rules; a recorded test from a guest device failing to reach an internal host such as the file server; and the change record showing when and how the configuration was introduced. Reviewers vary, so ask early what format they prefer — but a configuration, a test and a change record answer the question far more convincingly than a written description.
Who keeps the change records?
Whoever executes the changes should keep the records as part of doing them, and the firm should be able to obtain them on request. When Brocent operates the network, changes run through its service desk process and the outcome is written to the change record, so the trail exists without anyone reconstructing it for the audit. If changes are still being made by several people with a shared admin password, that — not the lack of a spreadsheet — is the thing to fix first.
Does this apply under the PDPO?
The PDPO does not specify how guest Wi-Fi must be configured, and no network configuration makes a firm PDPO compliant. Separating visitor devices from systems that hold personal data is a reasonable, practical safeguard that a firm may choose to describe as part of how it protects that data, but whether its arrangements are adequate overall is a judgment for its own advisers. For the questions the Ordinance raises when an IT provider is involved, see our PDPO outsourcing checklist.
What if our access points came from the landlord or the building operator?
Then the first question is who controls their configuration, because you can only evidence what you, or a provider acting for you, can actually configure and record. If the landlord or a serviced-office operator runs the wireless, ask them for the configuration evidence, the test and the change records described above. If they cannot provide them, the usual answers are either a contractual commitment from the operator or a network segment the firm controls for its own staff and systems. Brocent's hosted controller works with UniFi access points the firm owns or subscribes to; it cannot take over equipment that belongs to someone else without that party's agreement.
Evidence Is a Property of How IT Is Run, Not of One Network
The firm in the scenario did not have a wireless problem. It had an operations problem that happened to surface through the wireless network, because that was the first place a reviewer looked. Next year the same reviewer will ask the same kind of question about patching, about administrator accounts, about backups and whether a restore has ever been tested. Each one has the same shape: a control that has to exist, work, be changed under control, and leave evidence behind as a matter of routine.
That is why evidence-producing operations belong at the level of the IT plan, not a single feature. The wireless control plane is simply the cheapest place a firm finds out what "managed" actually means — someone watching it outside office hours, a change that goes through a window instead of a chat group, a report that says what happened and what to do about it. The same engine runs every other part of a managed estate. Wireless is the sample; the plan is the meal.
Brocent has had a Hong Kong office since 2016, as part of a business founded in Beijing in 2007 and headquartered in Singapore since 2021. The per-user plans, and what each tier covers across the help desk, security and infrastructure, are set out on managed IT support. Every published rate — including the Network & Wireless add-on, which Hong Kong plan clients can add at HK$808.07 per month for up to ten devices — is on the pricing page. If an audit request is already sitting in your inbox, start there: the plan is where the evidence comes from.
Share:
Ready to take action?
Turn these insights into a roadmap for your business.
Book a 15-minute no-obligation consultation with our APAC IT experts. We'll review your current setup and provide a tailored IT roadmap within 24 hours.
Free Checklist
10 Critical Checks Before Expanding IT to Greater China
PIPL compliance, network segmentation, bilingual helpdesk setup, and more — everything your IT team needs before Day 1 in China.
Request the checklist →📬 Monthly Asia IT Insights
China compliance updates, cybersecurity alerts, and IT tips for APAC teams — once a month.
No spam. Unsubscribe anytime.