Show Notes
Why shadow networks become an operational problem
Modern buildings rarely stay exactly as designed. Over time, unofficial connectivity shows up in places that were never part of the documented plan: a tenant access point in a closet, a contractor device left behind after validation, an IoT bridge installed to solve a local problem, or a payment setup that depends on a consumer-grade wireless link. In this episode of Built, Wired & Secured, Alex and Michael Harrington break down why these “shadow networks” are so common and why they create more than just minor wireless interference.
The conversation opens with a scenario many property and technology teams will recognize. Help desk tickets pile up, video calls start dropping, and badge readers lag. The root cause turns out to be an undocumented access point in a tenant closet using the same channel as the building Wi-Fi. That example frames the real issue: hidden connectivity decisions can trigger business impact far beyond the device itself.
One of the episode’s key themes is that these setups are often not malicious. They usually come from speed, convenience, or unclear ownership. Someone needs service to work, timelines are tight, and a quick fix becomes a long-term part of the environment without proper documentation. The trouble appears later, when nobody is sure who owns it, who supports it, or what depends on it.
The three downstream costs of unofficial connectivity
Michael outlines three practical consequences that matter in day-to-day operations:
Troubleshooting friction. Teams lose time because they do not have visibility into what is deployed or who is responsible for it.
Security exposure. Unmanaged devices often go unpatched and can create unintended pathways into production environments.
Business continuity risk. Critical services such as payments and access control may be running on gear that sits outside documented standards and outside any meaningful SLA.
Taken together, those issues create a serious reliability problem. A single device can create a building-wide impact when it interferes with shared infrastructure or supports a business function no one knew was attached to it. That is why shadow networks are not just an IT hygiene issue. They affect tenant experience, recovery speed, and accountability across facilities, IT, and vendors.
Start simple with detection
A useful part of the discussion is the pushback against overcomplicating discovery. The first step does not have to be a full RF survey. Instead, the recommendation is to begin with practical, low-friction methods that can be completed floor by floor:
Passive wireless sweeps
Wiring closet checks
Interviews with frontline staff
The point is not just to find SSIDs. It is to understand footprint and likely impact. Michael recommends recording not only the SSID, but also channel, approximate RSSI, and whether the access point appears clustered across floors. That helps teams distinguish between a one-off device and a broader interference pattern.
The people closest to the site can also provide missing context quickly. Reception, security, and help desk staff often know where temporary gear lives or which spaces have recurring connectivity workarounds. Technical teams may find the signal, but frontline staff often explain why the device is there and who relies on it.
A field-ready checklist for discovery
For teams that want something actionable, the episode offers a clean documentation standard for each discovery. Record:
SSID name
Channel
Approximate RSSI
Physical location
Floor and room
Photo of the device and serial number
Contact person, if available
That list matters because it turns informal sightings into usable operational records. If the same device shows up in a future incident, teams are not starting from zero. They have enough information to evaluate ownership, impact, and next steps without repeating the entire discovery process.
How to manage tenant access points without creating conflict
Once unofficial devices are found, the episode argues against a simple “find and remove” mindset. Pulling a device can disrupt tenant operations if business services depend on it. The better approach starts with documentation and a friendly notice that explains the observed impact on building systems. From there, teams should offer a remediation window and clear alternatives.
The alternatives discussed in the episode are practical and familiar:
A managed guest SSID
A segregated VLAN
A managed access point option
This matters because a policy is only useful if people can comply with it without losing service. Blanket bans may sound simple, but they tend to push tenants toward workarounds. A stronger model is standards-based governance: approved equipment, registration requirements, and managed alternatives. That shifts enforcement into a last resort instead of the default operating model.
When immediate action is justified
The episode also draws a clear line around emergency cases. Immediate removal is warranted when safety or critical continuity is at risk. Examples include interference with life safety systems, disruption to emergency communications, or a device that actively compromises a production OT network. Those situations are described as rare, but when they occur, the guidance is straightforward: act quickly and document why.
That distinction is important for building teams because it keeps response proportional. Not every rogue device needs a hard shutdown, but some conditions do require decisive action.
A real-world example from a commercial property
To make the guidance concrete, Michael walks through a case involving lunchtime latency spikes across three floors near a food court. Passive scans revealed a cluster of consumer SSIDs all using the same channel. The team confirmed the pattern with wiring room logs and then reached out to vendors with polite notices.
The proposed path forward included a managed guest SSID and a dedicated VLAN for payments. One vendor said its payment terminal required the local access point, so the team negotiated a short exception instead of forcing immediate removal. During that transition window, they moved the terminal to a wired port and verified firmware and encryption. Once service was confirmed, the access point was removed and interference dropped significantly.
That sequence captures the tone of the entire episode: negotiate first, mitigate technically, verify before declaring success.
Three actions to take on your next site walk
The episode closes with three simple actions listeners can put into practice immediately:
Perform a passive wireless sweep and log SSIDs, channels, and RSSI by floor.
Inventory devices in wiring closets and common areas, and photograph unknown hardware while capturing serial numbers.
Send a friendly tenant notice that explains the observation, the impact, and the available remediation path or managed alternative.
There is also one final reminder that applies to any cleanup effort: always verify after remediation. Run the same passive sweep again and confirm that the tenant-facing services people actually care about are still functioning. That is the difference between a change that looks complete in documentation and one that is truly resolved in the field.
If your building environment includes undocumented connectivity, this episode offers a practical playbook for locating it, reducing friction, and improving reliability without alienating tenants in the process.
Shadow networks are usually created by convenience, but they fail at scale
In commercial buildings, unofficial connectivity often arrives quietly. A contractor brings in a temporary access point to validate service. A tenant installs a consumer wireless device to improve throughput. A department adds an IoT bridge to solve a local problem. None of those choices necessarily look dangerous in the moment. They are fast, cheap, and useful. The trouble starts later, when those devices remain in place without documentation, ownership, or support.
That is the core issue explored in this Built, Wired & Secured episode on shadow networks. The conversation focuses on what building and technology leaders should do when unofficial connectivity begins affecting tenant experience, help desk workload, uptime, and security. The big takeaway is that these devices are rarely just “extra Wi-Fi.” They are often part of a much larger operational problem.
Why shadow networks become invisible until something breaks
The episode begins with a scenario that immediately makes the risk feel real: a Tuesday morning filled with help desk tickets, dropped video calls, and lagging badge readers. After the usual scramble through logs and radios, the cause turns out to be an undocumented access point in a tenant closet using the same channel as the building Wi-Fi.
That example captures why shadow networks are so disruptive. They usually do not show up as a formal project. They emerge through improvisation. Someone needs connectivity. A timeline is tight. A workaround goes in. Then the ownership gap at handoff takes over. Contractors assume tenants will manage the device. Tenants assume facilities or IT will absorb it. Over time, the building accumulates equipment that nobody officially owns but everybody is affected by.
This is what makes shadow networks difficult. The problem is not only technical interference. It is the combination of hidden dependencies and unclear accountability.
The real cost goes beyond wireless noise
One of the most useful parts of the discussion is the way it reframes the impact. The issue is not simply that unofficial devices create RF congestion. The downstream costs show up in three areas that building operators and technology teams feel every day.
First, there is troubleshooting friction. When no one has visibility into what is deployed, incident response slows down immediately. Teams start pointing fingers because they are all working with incomplete information. Time that should be spent restoring service gets burned on basic discovery.
Second, there is security exposure. Unmanaged devices frequently sit outside normal patching, monitoring, and governance. They may not be intentionally hostile, but they can still create breach paths or unsafe connectivity between environments that should remain separated.
Third, there is business continuity risk. The episode points out that critical functions such as payments or access control can end up depending on gear that is outside building standards and outside service-level expectations. That means a seemingly minor device can become a major outage trigger.
When those three issues overlap, the result is bigger than an IT nuisance. It becomes a tenant service problem and a building operations problem.
Do not overcomplicate discovery
A strong point in the episode is the recommendation to start simple. There is a tendency to assume a full RF survey is the only serious first step. Michael pushes back on that. His advice is practical: begin with floor-by-floor passive sweeps, wiring closet checks, and frontline interviews. Those steps will reveal most of the common problems without delaying action.
That matters because many teams postpone discovery while they wait for a perfect assessment. In reality, meaningful visibility often comes from a disciplined walkthrough and consistent note-taking. The episode stresses that teams should capture more than just SSIDs. Recording channel and approximate RSSI provides a better sense of signal footprint and interference potential. Noting whether an access point appears clustered across multiple floors also helps separate isolated devices from broader patterns.
The lesson here is simple. You do not need to begin with a massive project. You need to begin with a repeatable process.
Context often lives with nontechnical staff
Another practical insight is the reminder to talk to people who occupy the building every day. Reception, security, and help desk teams frequently know where temporary gear is hidden or which spaces have recurring connectivity exceptions. A technical sweep may identify the device, but it may not explain why it exists or who depends on it.
This is especially important in mixed-use or tenant-heavy environments where unofficial workarounds may have become normal over time. The people closest to day-to-day operations often provide the fastest path to understanding business impact.
A better way to document what you find
The episode provides a straightforward field checklist for each discovery: capture the SSID name, channel, approximate RSSI, physical location, floor and room, a photo of the device and serial number, and a contact person if one is available.
This may sound basic, but it solves a major operational gap. Too many discoveries remain anecdotal. Someone sees a device, mentions it, and moves on. That does not help when the next outage happens. Structured documentation turns a one-time observation into something the team can use for remediation, follow-up, and future troubleshooting.
For property teams, this is where shadow network management starts becoming a governance function rather than a reactive clean-up exercise.
Why blanket bans usually backfire
Once unofficial tenant access points are found, the temptation is to impose a hard rule and remove them all. The episode argues that this approach is usually brittle. While owners may want a clean policy, tenants will often respond by finding new workarounds, especially if their business need has not actually been addressed.
That is why the recommended sequence begins with documentation and a friendly notice. Explain the impact the device is having on building systems. Offer a remediation window. Provide realistic alternatives, such as a managed guest SSID, a segregated VLAN, or a managed access point option.
This is a better operational model because it aligns compliance with continuity. Tenants are far more likely to cooperate when they are given a path that preserves service instead of a rule that simply removes it.
The larger principle is worth repeating: standards work better than bans when they are paired with approved equipment, registration, and managed alternatives.
When immediate removal is the right call
The episode does not suggest that every situation should be negotiated slowly. There are cases where immediate action is justified. If a device interferes with life safety systems, disrupts emergency communications, or actively compromises a production OT network, the answer is not a long remediation window. The answer is to act and document why.
This distinction helps teams respond proportionally. A consumer access point supporting a local business workflow may need a transition plan. A device threatening safety or critical continuity needs immediate intervention.
The food court example shows what good remediation looks like
The discussion becomes especially useful when it moves from principle to example. Michael describes a commercial property with lunchtime latency spikes across three floors. Passive scans showed a cluster of consumer SSIDs near the food court, all using the same channel. Wiring room logs helped confirm the issue.
From there, the team did not start by pulling hardware. They sent polite notices to vendors and offered a managed guest SSID plus a dedicated VLAN for payments. One vendor insisted its payment terminal required the local access point. Instead of creating unnecessary disruption, the team granted a short exception during a transition period. They moved the payment terminal to a wired port, verified firmware and encryption, and only then removed the access point. Interference dropped significantly afterward.
That example highlights a practical remediation sequence:
Detect and document the problem
Confirm scope and likely impact
Communicate clearly with affected stakeholders
Provide an operationally realistic alternative
Verify service before final removal
It is a strong model because it reduces risk without treating tenants as the enemy.
Three actions for the next site walk
If there is one part of the episode most listeners can use immediately, it is the closing checklist. On your next site walk:
Perform a passive wireless sweep and log SSIDs, channels, and RSSI by floor.
Inventory devices in wiring closets and common areas. Photograph unknown devices and capture serial numbers.
Send a friendly tenant notice explaining the observation, the impact, and the remediation path or managed alternative.
Those actions are simple enough to complete quickly, but disciplined enough to create real operational improvement.
Verification is what separates cleanup from real resolution
The final lesson in the episode is one that applies well beyond wireless cleanup: always verify. After remediation, run the same passive sweep again and confirm that the tenant-facing services people care about are actually functioning.
That is a valuable operational mindset. A change is not successful because the undocumented device is gone. It is successful when interference is reduced, services still work, and the environment is better documented than it was before.
For commercial real estate teams, facilities leaders, and IT operators, that is the real value of addressing shadow networks. The goal is not just to remove unofficial gear. The goal is to create a building environment that is easier to support, easier to recover, and less vulnerable to surprise outages.
If this topic hits close to home, listen to the full episode for the full discussion and practical examples. It is a concise guide for anyone responsible for keeping shared building technology reliable without turning tenant relationships into a constant enforcement battle.