Written by the Infronest Security Research Team — certified security professionals (CEH, OSCP, CISM) with 10+ years of hands-on delivery. Reviewed against PTES, NIST SP 800-115, and PCI DSS v4.0 Requirements 11.3 and 11.4.
Internal vs External Penetration Testing: Which Do You Need?
A clear, practical comparison of internal and external penetration testing — what each covers, what threats they simulate, compliance implications, and how to decide which your organisation needs now.
External penetration testing attacks your organisation from outside your network, simulating a remote attacker with no prior access. Internal penetration testing operates from inside your network, simulating a compromised employee, malicious insider, or attacker who has already breached your perimeter. Most mature security programmes need both. IBM's Cost of a Data Breach Report 2025 found that 53 percent of breaches involved customer PII, and that the mean time to identify and contain a breach was 258 days for organisations without AI-assisted security tools — the longer an attacker moves laterally undetected, the more expensive the eventual breach.
External
External penetration testing: what it is and what it finds
External penetration testing simulates an attacker who has no inside knowledge of or access to your environment. The tester starts from the public internet, using only information available to anyone, and attempts to breach your perimeter. Assets typically in scope include public IP addresses and internet-facing servers, web applications and customer-facing portals, email servers (SMTP, IMAP, webmail), VPN endpoints and remote access portals, externally exposed APIs, and DNS infrastructure.
Common findings include unpatched internet-facing services with known CVEs, exposed administrative interfaces, weak VPN authentication, SSL/TLS misconfigurations, subdomain takeover vulnerabilities, and open redirects that enable phishing.
External testing simulates a criminal attacker scanning your IP range, a competitor or nation-state actor targeting external-facing systems, an opportunistic attacker exploiting a known CVE within hours of publication, and a phishing attacker using your domain infrastructure against your own users.
Internal
Internal penetration testing: what it is and what it finds
Internal penetration testing assumes that an attacker already has a foothold inside your network. The tester operates from within your environment — connected to an internal network port or via VPN — and attempts to escalate privileges, move laterally, and reach the most sensitive systems and data. Assets typically in scope include Active Directory and domain controllers, internal servers, file shares and databases, workstations and endpoints, internal web applications, network segments and VLAN configurations, and internal APIs.
Common findings include weak Active Directory configurations, Kerberoastable service accounts, misconfigured network shares with excessive permissions, unpatched internal servers, weak local administrator passwords, and flat network architectures that allow unrestricted lateral movement.
Internal testing simulates a phishing attack that delivers malware to an employee workstation, a compromised contractor or third-party vendor with legitimate access, a malicious insider using normal access to escalate and exfiltrate, and a post-breach attacker who has already bypassed perimeter controls.
Comparison
Side-by-side comparison
- Starting position — External: internet, no prior access. Internal: inside the network, standard user access or a network port.
- Threat simulated — External: remote attacker, opportunistic hacker, nation-state. Internal: insider threat, compromised account, post-breach attacker.
- Primary targets — External: perimeter, internet-facing services, public IPs. Internal: Active Directory, lateral movement paths, internal servers.
- Key techniques — External: public-facing CVE exploitation, VPN credential attacks, DNS attacks. Internal: Kerberoasting, Pass-the-Hash, BloodHound AD mapping, VLAN hopping.
- Compliance driver — External: PCI DSS Req. 11.4 external scope, ISO 27001 perimeter testing. Internal: PCI DSS Req. 11.4 internal scope, HIPAA, SOC 2 insider risk.
- Typical cost — External: USD 3,000 to 15,000 for a mid-size scope. Internal: USD 8,000 to 30,000 depending on scope and AD complexity.
Compliance requirements: what each framework mandates
- PCI DSS v4.0 — Requirement 11.4 mandates annual penetration testing of both the external perimeter and the internal network. Both scopes are explicitly required.
- ISO 27001:2022 — Annex A Control 8.8 requires vulnerability management; testing of both internal and external surfaces is expected of a mature programme.
- SOC 2 — CC7.1 and CC7.2 require risk monitoring and vulnerability response; both internal and external testing provide evidence.
- HIPAA — Security Rule 164.308(a)(8): external testing is the minimum; internal testing is required for covered entities handling ePHI.
- DORA (EU financial) — Article 26 requires Threat-Led Penetration Testing (TLPT) covering both external and internal scenarios.
Decision framework
Which do you need first?
The correct answer for most organisations is both. But if resources require prioritisation:
- Internet-facing systems and never tested — External first (highest probability of finding immediately exploitable vulnerabilities).
- Already ran external and found no critical issues — Internal next (your perimeter may be solid but internal controls need validation).
- Recently suffered a breach or phishing incident — Internal urgently (understand how far an attacker with a foothold could go).
- Pursuing PCI DSS, ISO 27001, or SOC 2 — Both (most frameworks require both scopes for certification).
- MSP managing client networks — Both per client (clients face both external threats and insider risk).
- Deployed zero-trust — Internal (zero-trust assumptions need adversarial validation from an inside position).
Infronest
Conclusion
Whether your team is running external-only assessments or full internal and external VAPT programmes across multiple clients, Infronest's Security and VAPT module manages both engagement types in the same tenant-isolated workspace. Separate finding logs, evidence management, and audit-ready reports for each engagement scope keep every client's data correctly attributed and isolated.
Start your free trial at infronest.com — no credit card required.
Sources
- IBM — Cost of a Data Breach Report 2025
- PCI DSS v4.0 Requirement 11.4
- PTES — Penetration Testing Execution Standard
- ISO/IEC 27001:2022 Annex A Control 8.8
Frequently Asked Questions
- Can a single penetration tester do both internal and external testing?
- Yes. Most professional engagements combine both. The tester typically begins with external testing and, if perimeter access is achieved, transitions to demonstrating internal impact. If the perimeter holds, internal testing begins from a separate assumed-breach starting position.
- Is internal penetration testing legal if the tester uses real attack techniques?
- Yes, provided it is covered by a signed rules of engagement document that specifies the scope, permitted techniques, and authorisation from the asset owner. This written agreement is what distinguishes authorised penetration testing from illegal computer access.
- What happens if a real vulnerability is found during the engagement?
- A Critical or High finding triggers an immediate notification to the contacts named in the rules of engagement document. The tester documents the finding with proof-of-concept evidence and pauses exploitation of that specific vulnerability pending client confirmation to proceed.