Internal vs External Penetration Testing: What's the Difference?
Reviewed: 24 August 2026 — reviewed quarterly
Quick Answer
External testing assesses what an attacker sees from outside your network — your internet-facing hosts and cloud configuration. Internal testing assumes an attacker (or malicious insider) already has a foothold inside your network and tests privilege escalation, lateral movement, and Active Directory attack paths. Almost every organisation should start with external testing; internal testing becomes relevant once you have significant internal systems, an AD domain, or a compliance scope that names it explicitly.
What Does External Testing Cover?
External testing simulates an attacker who has no prior access to your organisation — only what's visible from the public internet. This is the attack surface most real-world breaches originate from, and the one almost every compliance framework asks about first.
What Does Internal Testing Cover?
Internal testing starts from the opposite assumption: that an attacker (via phishing, a compromised laptop, or a malicious insider) already has a foothold somewhere inside your network. The question it answers is "how far could they get from there?"
Side-by-Side Comparison
| External | Internal | |
|---|---|---|
| Attacker vantage point | Outside your network — the public internet | Inside your network — an already-compromised device, or a malicious/negligent insider |
| What it tests | External IPs/hosts, perimeter services (mail, DNS, VPN), cloud environment configuration (AWS/Azure/GCP) | Assumed-breach scenarios, privilege escalation paths, lateral movement, Active Directory attack paths |
| Most common trigger | First independent security test; ISO 27001/NIS2/GDPR baseline evidence; vendor questionnaire | Mature security programme; Windows AD domain in place; sensitive internal systems; specific NIS2/DORA scope naming it |
| Typical starting point | Almost always tested first | Added once external testing is already in place |
| Our service | External Infrastructure & Cloud Security Assessment, €899 | Individually scoped and quoted (domain size, environment complexity) |
Why Companies Almost Always Start External
External testing is cheaper, faster to scope, and directly addresses the attack surface most breaches actually originate from — an exposed service, a misconfigured cloud storage bucket, or a weak perimeter control. It's also what most compliance frameworks ask about first: ISO 27001 Annex A.8.20 (network security), GDPR Article 32, and NIS2 Article 21 all expect evidence that your network-facing systems have been assessed, without specifically mandating internal testing as a baseline. Our External Infrastructure & Cloud Security Assessment (€899) is scoped as that starting point.
When Does Internal Testing Become Necessary?
Start with external network and cloud testing — see our External Infrastructure & Cloud Security Assessment (€899) — and read our cloud configuration review checklist to see exactly what's assessed. Internal/Active Directory testing is quoted individually once you're ready to go further.
See External Assessment