24/7 SOC monitoring & incident responsesales@bugfoe.com
BestPentestingby BugFoe
Network

Internal vs. External Penetration Testing

External tests ask whether attackers can get in. Internal tests ask what happens once they do. Most organisations need both.

Updated October 20263 min readBy the BestPentesting Security Research Team

Network penetration tests come in two flavours: external, which looks at what anyone on the internet can reach, and internal, which assumes an attacker is already inside your network. They answer different questions, and most organisations need both. This guide explains what each covers, what typically goes wrong, and how to decide where to start.

External penetration testing

An external test simulates an attacker with no access other than the internet. Testers start from your domains and IP ranges — and often discover assets you forgot you had.

What it covers

  • Discovery of internet-facing assets: subdomains, cloud-hosted services, forgotten test servers
  • Exposed services such as remote desktop, SSH, databases, admin panels and file shares
  • VPN, remote-access and email gateways (a frequent initial access route for ransomware groups)
  • Unpatched software with known vulnerabilities
  • Weak authentication: default credentials, password spraying against SSO or VPN, missing MFA
  • TLS configuration, DNS issues and email security records (SPF, DKIM, DMARC)

Typical findings

The most serious external findings are rarely sophisticated: an unpatched VPN appliance, a remote desktop service exposed to the internet, a staging server with default credentials, or a single-factor login page vulnerable to password spraying. Each of these has been the starting point of major real-world breaches.

Internal penetration testing

An internal test assumes the attacker already has a foothold — through phishing, a compromised laptop, a malicious insider or a rogue device plugged into the office network. The question becomes: how far can they get from there?

What it covers

  • Network segmentation between user, server, production and sensitive zones
  • Active Directory (or Entra ID hybrid) attack paths to domain or tenant admin
  • Credential exposure: cleartext passwords in shares and scripts, weak service-account passwords, reused local admin passwords
  • Legacy protocols and poisoning attacks on the local network
  • Unpatched internal servers and management interfaces
  • Access to crown-jewel systems: finance, HR, databases, backups

Typical findings

In most internal tests of Windows environments, experienced testers find a path to domain administrator — often within days. Common root causes are misconfigured certificate services, over-privileged service accounts, credential reuse and flat networks with little segmentation.

Comparison at a glance

ExternalInternal
Attacker starting pointThe internetInside the network (assumed breach)
Main questionCan someone get in?What happens once they're in?
Key targetsPerimeter services, VPN, exposed appsActive Directory, segmentation, sensitive servers
DeliveryFully remoteRemote via VPN/test device, or on-site
Typical effort2–8 tester-days5–20 tester-days
Required by PCI DSSYes (Req. 11.4.3)Yes (Req. 11.4.2)

Which should you do first?

  • Start with external if you have a large or poorly inventoried internet footprint, or you've never tested before. It's cheaper and closes the most obvious doors.
  • Start with internal if you're mainly worried about ransomware. Most ransomware incidents involve an attacker gaining an initial foothold (often via phishing or stolen credentials) and then moving laterally — internal testing shows how resilient you are to that.
  • Do both annually if you handle card data, regulated data, or have more than a few dozen employees.

How internal tests are delivered remotely

Internal testing no longer requires testers on site. Most providers ship a small pre-configured device or provide a virtual machine you deploy on your network, which connects back to the testers over an encrypted tunnel. This is cheaper, faster to schedule and works well for multiple locations.

Preparing for a network pentest

  • Confirm the IP ranges and domains you own and are authorised to test (including cloud-hosted IPs)
  • Tell your hosting and managed service providers if their terms require notification
  • Decide whether your SOC should be told (to avoid incident escalations) or not (to test detection)
  • Provide a standard user account for assumed-breach internal testing
  • Agree on exclusions: fragile legacy or OT systems, production databases during business hours

Frequently asked questions

Can internal penetration tests be done remotely?

Yes. Most providers ship a small test device or provide a virtual machine that connects securely back to testers, avoiding travel costs.

Does an external pentest include web applications?

Usually only at a surface level. Full authenticated web application testing is normally scoped separately.

Will testing affect our production network?

Professional testers avoid disruptive techniques unless agreed. Discuss fragile or legacy systems during scoping so they can be excluded or handled carefully.

See typical prices in our pricing guide, or request a network pentest quote.

BestPentesting Security Research Team
Written and technically reviewed by practising penetration testers and SOC analysts. Last reviewed October 2026. See our methodology.

Ready to find your risks before attackers do?

Tell us what you need tested or monitored. A senior consultant replies within one business day with a scoped, fixed-price proposal.

  • Fixed-price proposal
  • Reply within 1 business day
  • NDA on request