leaving the WAN port disconnected is not a security whole. That's like saying disconnecting your ethernet cable from the network is a security hole.
if it's a business environment, and he's wanting to use the dlink as an access point / switch, then it's obvious he has some other firewall in place, weather it's integrated into his DC or has a rackmount dedicated hardware firewall or simliar.
So if he wanted wireless access, normal security practice would be employed for wireless security, the DHCP server will be disabled, and he would have to make a decision on where to put the router within his network setup, But definatly behind the firewall.
He currently has his network seperated in two segments (minus the voip), so it depends WHO he wants to access the wireless network. He will only be able to have one, but not both, since the dir-655 does not support vlans. OR he would use the wan port, configure local address in the internet setup page, and set a two or 3 static routes, which then wireless clients will be on a differnet subnet.