🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
Resource · Penetration Testing

Internal vs External Penetration Testing: What's the Difference?

Reviewed: 24 August 2026 — reviewed quarterly

Quick Answer

External testing assesses what an attacker sees from outside your network — your internet-facing hosts and cloud configuration. Internal testing assumes an attacker (or malicious insider) already has a foothold inside your network and tests privilege escalation, lateral movement, and Active Directory attack paths. Almost every organisation should start with external testing; internal testing becomes relevant once you have significant internal systems, an AD domain, or a compliance scope that names it explicitly.

What Does External Testing Cover?

External testing simulates an attacker who has no prior access to your organisation — only what's visible from the public internet. This is the attack surface most real-world breaches originate from, and the one almost every compliance framework asks about first.

Up to 20 external IPs/hosts — what's actually reachable from the internet
One cloud environment's configuration (AWS, Azure, or GCP) — IAM roles, storage permissions, network exposure
Perimeter services: mail, DNS, VPN, and other internet-facing infrastructure
Aligned with NIST SP 800-115 (network) and CIS Benchmarks (cloud)

What Does Internal Testing Cover?

Internal testing starts from the opposite assumption: that an attacker (via phishing, a compromised laptop, or a malicious insider) already has a foothold somewhere inside your network. The question it answers is "how far could they get from there?"

Assumed-breach testing — starting from a compromised low-privilege account, not from zero access
Privilege escalation paths toward Domain Admin or equivalent
Lateral movement between systems and network segments
Network segmentation review between trust zones (e.g. office network vs production)

Side-by-Side Comparison

ExternalInternal
Attacker vantage pointOutside your network — the public internetInside your network — an already-compromised device, or a malicious/negligent insider
What it testsExternal IPs/hosts, perimeter services (mail, DNS, VPN), cloud environment configuration (AWS/Azure/GCP)Assumed-breach scenarios, privilege escalation paths, lateral movement, Active Directory attack paths
Most common triggerFirst independent security test; ISO 27001/NIS2/GDPR baseline evidence; vendor questionnaireMature security programme; Windows AD domain in place; sensitive internal systems; specific NIS2/DORA scope naming it
Typical starting pointAlmost always tested firstAdded once external testing is already in place
Our serviceExternal Infrastructure & Cloud Security Assessment, €899Individually scoped and quoted (domain size, environment complexity)

Why Companies Almost Always Start External

External testing is cheaper, faster to scope, and directly addresses the attack surface most breaches actually originate from — an exposed service, a misconfigured cloud storage bucket, or a weak perimeter control. It's also what most compliance frameworks ask about first: ISO 27001 Annex A.8.20 (network security), GDPR Article 32, and NIS2 Article 21 all expect evidence that your network-facing systems have been assessed, without specifically mandating internal testing as a baseline. Our External Infrastructure & Cloud Security Assessment (€899) is scoped as that starting point.

When Does Internal Testing Become Necessary?

You run a Windows Active Directory domain with meaningful internal attack surface
A specific compliance scope names internal/assumed-breach testing explicitly (some NIS2 and DORA engagements do)
Your cyber insurance underwriter's questionnaire asks about internal network testing specifically, not just external
You've already had external testing and want to validate your defence-in-depth beyond the perimeter

Start with external network and cloud testing — see our External Infrastructure & Cloud Security Assessment (€899) — and read our cloud configuration review checklist to see exactly what's assessed. Internal/Active Directory testing is quoted individually once you're ready to go further.

See External Assessment

Frequently Asked Questions

Do I need internal network testing too, or is external enough?+
It depends on your requirement. External testing covers what an attacker sees from outside your network and cloud provider — the perimeter most compliance frameworks ask about first, and the right starting point for almost every organisation. Internal testing becomes relevant once you have sensitive internal systems, a Windows Active Directory domain, or a specific compliance requirement (some NIS2 and DORA scopes) that names internal testing explicitly.
Which one should I do first?+
External, in almost every case. It's cheaper, faster, and addresses the attack surface most incidents actually originate from — an internet-facing service or misconfigured cloud resource. Internal testing is a natural second step once your external perimeter has already been assessed, not a replacement for it.
Is internal testing the same as a web application penetration test?+
No. A web-application pentest (our Focused, Standard, or Enterprise tiers) targets your application's code and API surface, regardless of where it's hosted. Internal network testing targets your corporate/production network itself — assumed-breach scenarios, Active Directory, lateral movement — a different asset class from both external network testing and web-application testing.
Why don't you publish a fixed price for internal network testing?+
Internal/Active Directory testing scope varies far more than external testing: domain size, number of trust zones, forest complexity, and the number of internal systems in scope all materially change the effort required. We quote it individually once we understand your environment, rather than publishing a fixed price that would be wrong for most environments.
Does NIS2 or DORA require internal testing specifically?+
Neither Directive/Regulation names "internal network testing" as a standalone requirement in the way a checklist might expect. NIS2 Article 21(2)(f) asks for effectiveness-assessment measures generally; DORA's Threat-Led Penetration Testing (TLPT), where it applies to designated significant entities, is intelligence-led and typically includes both external and internal attack paths as part of a single simulated-attacker engagement. Check your specific scope rather than assuming either mandates internal testing on its own.
Can the external assessment be upgraded to include internal testing later?+
Yes. Most clients start with the €899 External Infrastructure & Cloud Security Assessment, then add internal/Active Directory testing as a follow-on engagement once we've scoped the internal environment together — you don't need to commit to both at once.