Network penetration tests come in two flavours: external, which looks at what anyone on the internet can reach, and internal, which assumes an attacker is already inside your network. They answer different questions, and most organisations need both. This guide explains what each covers, what typically goes wrong, and how to decide where to start.
External penetration testing
An external test simulates an attacker with no access other than the internet. Testers start from your domains and IP ranges — and often discover assets you forgot you had.
What it covers
- Discovery of internet-facing assets: subdomains, cloud-hosted services, forgotten test servers
- Exposed services such as remote desktop, SSH, databases, admin panels and file shares
- VPN, remote-access and email gateways (a frequent initial access route for ransomware groups)
- Unpatched software with known vulnerabilities
- Weak authentication: default credentials, password spraying against SSO or VPN, missing MFA
- TLS configuration, DNS issues and email security records (SPF, DKIM, DMARC)
Typical findings
The most serious external findings are rarely sophisticated: an unpatched VPN appliance, a remote desktop service exposed to the internet, a staging server with default credentials, or a single-factor login page vulnerable to password spraying. Each of these has been the starting point of major real-world breaches.
Internal penetration testing
An internal test assumes the attacker already has a foothold — through phishing, a compromised laptop, a malicious insider or a rogue device plugged into the office network. The question becomes: how far can they get from there?
What it covers
- Network segmentation between user, server, production and sensitive zones
- Active Directory (or Entra ID hybrid) attack paths to domain or tenant admin
- Credential exposure: cleartext passwords in shares and scripts, weak service-account passwords, reused local admin passwords
- Legacy protocols and poisoning attacks on the local network
- Unpatched internal servers and management interfaces
- Access to crown-jewel systems: finance, HR, databases, backups
Typical findings
In most internal tests of Windows environments, experienced testers find a path to domain administrator — often within days. Common root causes are misconfigured certificate services, over-privileged service accounts, credential reuse and flat networks with little segmentation.
Comparison at a glance
| External | Internal | |
|---|---|---|
| Attacker starting point | The internet | Inside the network (assumed breach) |
| Main question | Can someone get in? | What happens once they're in? |
| Key targets | Perimeter services, VPN, exposed apps | Active Directory, segmentation, sensitive servers |
| Delivery | Fully remote | Remote via VPN/test device, or on-site |
| Typical effort | 2–8 tester-days | 5–20 tester-days |
| Required by PCI DSS | Yes (Req. 11.4.3) | Yes (Req. 11.4.2) |
Which should you do first?
- Start with external if you have a large or poorly inventoried internet footprint, or you've never tested before. It's cheaper and closes the most obvious doors.
- Start with internal if you're mainly worried about ransomware. Most ransomware incidents involve an attacker gaining an initial foothold (often via phishing or stolen credentials) and then moving laterally — internal testing shows how resilient you are to that.
- Do both annually if you handle card data, regulated data, or have more than a few dozen employees.
How internal tests are delivered remotely
Internal testing no longer requires testers on site. Most providers ship a small pre-configured device or provide a virtual machine you deploy on your network, which connects back to the testers over an encrypted tunnel. This is cheaper, faster to schedule and works well for multiple locations.
Preparing for a network pentest
- Confirm the IP ranges and domains you own and are authorised to test (including cloud-hosted IPs)
- Tell your hosting and managed service providers if their terms require notification
- Decide whether your SOC should be told (to avoid incident escalations) or not (to test detection)
- Provide a standard user account for assumed-breach internal testing
- Agree on exclusions: fragile legacy or OT systems, production databases during business hours
Frequently asked questions
Can internal penetration tests be done remotely?
Yes. Most providers ship a small test device or provide a virtual machine that connects securely back to testers, avoiding travel costs.
Does an external pentest include web applications?
Usually only at a surface level. Full authenticated web application testing is normally scoped separately.
Will testing affect our production network?
Professional testers avoid disruptive techniques unless agreed. Discuss fragile or legacy systems during scoping so they can be excluded or handled carefully.
See typical prices in our pricing guide, or request a network pentest quote.