Skip to content
Zyberum Cyber Security Firm
Menu
ComparisonsPenetration testing

Internal vs External Penetration Test: Which Attacker Are You Simulating?

An external pentest attacks what the internet can reach. An internal one starts inside, as a phished employee would. What each finds and when you need which.

Updated This page as Markdown

In short

An external penetration test takes the position of an attacker on the internet and tests everything your organisation exposes: websites, APIs, VPN gateways, mail, cloud services. An internal penetration test starts with a foothold inside, a network port, a standard user account or a compromised laptop, and asks how far an attacker gets from there: to domain admin, to the file servers, to the OT network. External tests protect against the common first step; internal tests decide how bad the breach gets. Companies under NIS2, PCI DSS or with an OT network need both, usually on alternating schedules.

What is the difference?

The difference is where the attacker stands at the start. An external penetration test begins on the internet, with your company name and nothing else, and tests everything an outsider can reach: web applications, APIs, VPN and mail gateways, remote-desktop services, cloud tenants, DNS and the things you forgot you exposed. An internal penetration test begins with a foothold inside: a network cable in a meeting room, a standard user account, or a laptop that is assumed to be compromised. From there the question is how far the attacker gets, how fast, and whether anyone notices.

The two test different failure modes. External tests find the open doors: an outdated VPN appliance, a forgotten test system, an API without authentication, a weak password on a public login. Internal tests find what happens after the door is open: flat networks, legacy protocols that hand over password hashes, service accounts with domain-admin rights, shares full of credentials, and a path from the office network into production or the plant floor. Because most real incidents start with a phished user, the internal view is the one that decides whether an incident is an annoyance or a disaster.

Side by side

External pentestInternal pentest
What it coversThe attack surface visible from the internet: web, API, mail, VPN, remote access, cloud services, exposed devicesNetworks, Active Directory or identity provider, servers, shares, segmentation, client hardening, lateral movement, paths to crown jewels and OT
What it missesEverything behind authentication and inside the perimeter; what a phished user can doWeaknesses in public services if they are out of scope; the first step of the attack
Who does itTesters from their own infrastructure, with written authorisation and an emergency contactTesters on site or via an appliance or VPN, with a standard user account and agreed boundaries, often with the IT team informed
DurationThree to ten days depending on the number of hosts and applicationsFive to fifteen days depending on network size and number of segments
Typical cost5,000 to 15,000 euros for a mid-sized company’s external estate; a single web application 6,000 to 15,000; typical ranges for Germany and the EU8,000 to 25,000 euros for a mid-sized network; OT segments 12,000 to 25,000; not an offer
FrequencyYearly and after changes to exposed systemsYearly, and after changes to the identity infrastructure, mergers or new sites
Required byPCI DSS Requirement 11.4 (external at least every 12 months), ISO 27001 and TISAX as a testing control, cyber-insurance questionnaires, NIS2 Art. 21 in practicePCI DSS Requirement 11.4 (internal at least every 12 months), ISO 27001 and TISAX, NIS2 Art. 21 for essential and important entities in practice, KRITIS audits
OutputReport of exposed services and findings with proof and fixes; a list of hosts and applications that were in scopeReport with the attack path step by step, time to domain admin, segmentation results, detection observations, and prioritised fixes

Choose an external pentest when

  • You have never tested and expose logins, APIs or remote access. These are the systems attackers scan every day, and an external test is the fastest way to find the ones that are already in trouble.
  • You launch or substantially change a public application or move to a new cloud or identity provider.
  • A customer, an insurer or PCI DSS asks for an external test specifically.
  • Your internal network is small, mostly cloud-based and already segmented, so the perimeter and the identity provider are where the risk sits.

Choose an internal pentest when

  • You want to know what a single phished employee or a vendor’s laptop would cost you. The external test cannot answer that.
  • You run an OT or plant network connected to the office network, or hold data whose loss would end the business. The test shows whether the office is one hop from the production line.
  • You have an Active Directory grown over fifteen years, many service accounts and a flat network. Internal tests in such environments reach domain admin in days, and that is the finding worth paying for.
  • You have set up detection, EDR or a SOC and want to know whether it sees lateral movement.

For organisations with mature external security and an old internal network, the internal test is the better choice even though it costs more, because that is where the damage happens.

Both together

Most companies subject to NIS2 or PCI DSS, and any company with an OT network, need both. A practical rhythm is to alternate: external in spring, internal in autumn, each yearly, and the other one additionally after a major change. An “assumed breach” scenario joins them: the testers start with the foothold a successful phishing attack would provide and work towards the crown jewels, which tests the internal network with a realistic starting point. Give the testers the results of the last test and the network diagram; discovery is not what you want to pay for twice.

Zyberum does external and internal penetration tests for IT and OT networks and tests from a plugged-in appliance or on site. We stop at agreed boundaries, never test production OT without a plan for safe testing, and work only with written authorisation. For OT environments, read how a pentest runs without downtime before deciding the scope.

FAQ

Frequently asked questions

We have a firewall and a VPN. Is an internal pentest still necessary?

Yes, because the firewall is not where breaches start any more. Most incidents begin with a phished account, a malicious attachment or a vendor laptop, all of which are already inside. The internal test tells you whether that single foothold ends in one compromised PC or in the whole domain. In many first internal tests the path to domain admin takes less than two days.

Can the internal test be done remotely?

Usually, yes. The testers connect a small appliance you plug into an office port, or get a VPN account and a virtual machine in the network, plus a standard user account. Only tests that involve physical access, Wi-Fi or a plant network with special protocols need someone on site.

Which comes first with a limited budget?

External, if you have never tested and expose logins or APIs: it is the cheaper of the two and closes the doors that are open to everyone. Internal, if your external surface is small and well maintained, or if you run OT or hold data whose loss would end the business. In the second year, do the other one.

Sources

Related pages

Get started

Not sure which test you need?

Describe your product or environment in a 15-minute call. You get a clear recommendation and, if you want one, a fixed-price offer.

  • A recommendation, not a sales pitch
  • Scope and effort estimate on the spot
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usGet a recommendation

Pick a time that suits you

Open in a new tab