Internal vs External Penetration Test: Which Attacker Are You Simulating?
An external pentest attacks what the internet can reach. An internal one starts inside, as a phished employee would. What each finds and when you need which.
Updated This page as Markdown
In short
An external penetration test takes the position of an attacker on the internet and tests everything your organisation exposes: websites, APIs, VPN gateways, mail, cloud services. An internal penetration test starts with a foothold inside, a network port, a standard user account or a compromised laptop, and asks how far an attacker gets from there: to domain admin, to the file servers, to the OT network. External tests protect against the common first step; internal tests decide how bad the breach gets. Companies under NIS2, PCI DSS or with an OT network need both, usually on alternating schedules.
What is the difference?
The difference is where the attacker stands at the start. An external penetration test begins on the internet, with your company name and nothing else, and tests everything an outsider can reach: web applications, APIs, VPN and mail gateways, remote-desktop services, cloud tenants, DNS and the things you forgot you exposed. An internal penetration test begins with a foothold inside: a network cable in a meeting room, a standard user account, or a laptop that is assumed to be compromised. From there the question is how far the attacker gets, how fast, and whether anyone notices.
The two test different failure modes. External tests find the open doors: an outdated VPN appliance, a forgotten test system, an API without authentication, a weak password on a public login. Internal tests find what happens after the door is open: flat networks, legacy protocols that hand over password hashes, service accounts with domain-admin rights, shares full of credentials, and a path from the office network into production or the plant floor. Because most real incidents start with a phished user, the internal view is the one that decides whether an incident is an annoyance or a disaster.
Side by side
| External pentest | Internal pentest | |
|---|---|---|
| What it covers | The attack surface visible from the internet: web, API, mail, VPN, remote access, cloud services, exposed devices | Networks, Active Directory or identity provider, servers, shares, segmentation, client hardening, lateral movement, paths to crown jewels and OT |
| What it misses | Everything behind authentication and inside the perimeter; what a phished user can do | Weaknesses in public services if they are out of scope; the first step of the attack |
| Who does it | Testers from their own infrastructure, with written authorisation and an emergency contact | Testers on site or via an appliance or VPN, with a standard user account and agreed boundaries, often with the IT team informed |
| Duration | Three to ten days depending on the number of hosts and applications | Five to fifteen days depending on network size and number of segments |
| Typical cost | 5,000 to 15,000 euros for a mid-sized company’s external estate; a single web application 6,000 to 15,000; typical ranges for Germany and the EU | 8,000 to 25,000 euros for a mid-sized network; OT segments 12,000 to 25,000; not an offer |
| Frequency | Yearly and after changes to exposed systems | Yearly, and after changes to the identity infrastructure, mergers or new sites |
| Required by | PCI DSS Requirement 11.4 (external at least every 12 months), ISO 27001 and TISAX as a testing control, cyber-insurance questionnaires, NIS2 Art. 21 in practice | PCI DSS Requirement 11.4 (internal at least every 12 months), ISO 27001 and TISAX, NIS2 Art. 21 for essential and important entities in practice, KRITIS audits |
| Output | Report of exposed services and findings with proof and fixes; a list of hosts and applications that were in scope | Report with the attack path step by step, time to domain admin, segmentation results, detection observations, and prioritised fixes |
Choose an external pentest when
- You have never tested and expose logins, APIs or remote access. These are the systems attackers scan every day, and an external test is the fastest way to find the ones that are already in trouble.
- You launch or substantially change a public application or move to a new cloud or identity provider.
- A customer, an insurer or PCI DSS asks for an external test specifically.
- Your internal network is small, mostly cloud-based and already segmented, so the perimeter and the identity provider are where the risk sits.
Choose an internal pentest when
- You want to know what a single phished employee or a vendor’s laptop would cost you. The external test cannot answer that.
- You run an OT or plant network connected to the office network, or hold data whose loss would end the business. The test shows whether the office is one hop from the production line.
- You have an Active Directory grown over fifteen years, many service accounts and a flat network. Internal tests in such environments reach domain admin in days, and that is the finding worth paying for.
- You have set up detection, EDR or a SOC and want to know whether it sees lateral movement.
For organisations with mature external security and an old internal network, the internal test is the better choice even though it costs more, because that is where the damage happens.
Both together
Most companies subject to NIS2 or PCI DSS, and any company with an OT network, need both. A practical rhythm is to alternate: external in spring, internal in autumn, each yearly, and the other one additionally after a major change. An “assumed breach” scenario joins them: the testers start with the foothold a successful phishing attack would provide and work towards the crown jewels, which tests the internal network with a realistic starting point. Give the testers the results of the last test and the network diagram; discovery is not what you want to pay for twice.
Zyberum does external and internal penetration tests for IT and OT networks and tests from a plugged-in appliance or on site. We stop at agreed boundaries, never test production OT without a plan for safe testing, and work only with written authorisation. For OT environments, read how a pentest runs without downtime before deciding the scope.
FAQ
Frequently asked questions
We have a firewall and a VPN. Is an internal pentest still necessary?
Yes, because the firewall is not where breaches start any more. Most incidents begin with a phished account, a malicious attachment or a vendor laptop, all of which are already inside. The internal test tells you whether that single foothold ends in one compromised PC or in the whole domain. In many first internal tests the path to domain admin takes less than two days.
Can the internal test be done remotely?
Usually, yes. The testers connect a small appliance you plug into an office port, or get a VPN account and a virtual machine in the network, plus a standard user account. Only tests that involve physical access, Wi-Fi or a plant network with special protocols need someone on site.
Which comes first with a limited budget?
External, if you have never tested and expose logins or APIs: it is the cheaper of the two and closes the doors that are open to everyone. Internal, if your external surface is small and well maintained, or if you run OT or hold data whose loss would end the business. In the second year, do the other one.
Sources
- PCI Security Standards Council: PCI DSS v4.0, Requirement 11.4 (internal and external penetration testing)
- NIST SP 800-115: Technical Guide to Information Security Testing and Assessment, section 5.2 (penetration testing phases, internal and external)
- BSI: Durchführungskonzept für Penetrationstests, criterion "Ausgangspunkt" (German)
- Directive (EU) 2022/2555 (NIS2), Art. 21(2) risk-management measures
Related pages
- GlossaryAttack SurfaceThe attack surface is every point where an attacker can interact with a system: interfaces, protocols, ports, debug access, people. How to map it and how to shrink it.
- GlossaryZero TrustZero trust is a security model that grants no implicit trust based on network location. What NIST SP 800-207 defines, how it maps to OT and vehicles, and what it is not.
- GlossaryPenetration testA penetration test is an authorised, mostly manual attack on a system to find and prove exploitable vulnerabilities. Definition, types, process and the report.
- ComparisonsBlack Box vs White Box Penetration Test: How Much Should the Tester Know?A black box test starts with no information, a white box test with code, documentation and accounts. What each finds and costs, and why grey box usually wins.
- InsightsHow Often Should You Pentest? Frequencies by System and RuleOnce a year plus after significant changes is the baseline. Pentest frequencies for web, cloud, infrastructure, IoT products, ECUs and OT, legal minimums and triggers.
- InsightsOT Penetration Testing Without Downtime: How It Is DoneHow to test a plant without stopping production: passive analysis, test benches and twins, what belongs in a maintenance window, what is never done on a live plant.
- ServicesA resilient IT foundation for your business.IT security for businesses: infrastructure, web application and cloud penetration testing, managed SOC and incident readiness, including healthcare.
