Skip to content

External vs Internal Penetration Testing: What's the Difference?

External penetration testing attacks your perimeter from outside; internal testing starts from a foothold inside. What each finds, and when you need both.

Invadel TeamSeptember 2, 20266 min read

Every network penetration test starts from one of two positions: outside your perimeter, or already within it. That single choice, external versus internal, changes what the test simulates, what it finds, and what it costs. Buyers mix the two up constantly, and some vendors are happy to leave the confusion in place. Here is the clean version of the difference, and how to decide which one you need this year.

What is external penetration testing?

External penetration testing is a security assessment of everything your organization exposes to the internet, performed from the position of an outside attacker with no access and no credentials. The tester sees exactly what a real adversary sees: your public IP ranges, VPN gateways, mail servers, web applications, cloud endpoints, and anything else answering from the outside.

The engagement works through discovery first, mapping your actual internet footprint (which is almost always larger than the one you think you have), then probes and attempts to exploit what it finds: exposed management interfaces, unpatched perimeter systems, weak VPN and portal authentication, misconfigured TLS and DNS, and forgotten hosts from projects past.

The question an external test answers: can an attacker on the internet get in?

What is internal penetration testing?

Internal penetration testing starts from the opposite assumption: the perimeter has already failed. The tester begins with a foothold inside your network, the position of an attacker who phished an employee, walked in with a rogue device, or compromised a single workstation, and also the position of a malicious insider.

From there, the test measures blast radius. Can that one foothold spread? Does network segmentation actually hold, or is the network flat once you are past the firewall? Can Active Directory be escalated from a standard user to domain admin through Kerberoasting, delegation abuse, or weak group policy? Where do harvested credentials get reused? How close can an attacker get to the systems and data that would actually end your week?

The question an internal test answers: once someone is in, how bad does it get?

The difference at a glance

External Internal
Attacker position Internet, no access Foothold inside the network
Simulates Opportunistic and targeted outside attackers Post-phishing compromise, malicious insiders
Core question Can they get in? How far can they spread?
Typical targets Public IPs, VPNs, mail, web apps, cloud edge Segmentation, Active Directory, internal services
Common critical findings Exposed services, unpatched perimeter, weak portal auth Domain privilege escalation, lateral movement, flat networks
Access needed from you Usually none beyond scope approval A device, VM, or appliance inside the network
Invadel fixed price From $4,200 From $6,000

Why the distinction matters more than it looks

The two tests fail in different directions, and passing one says nothing about the other.

A company with a hardened perimeter can be one phishing email away from total compromise if the internal network is flat and Active Directory is a decade of accumulated misconfiguration. We see this profile constantly: a clean external report, and an internal test that reaches domain admin in a day.

The reverse profile exists too: strong internal segmentation behind a perimeter with one forgotten, exploitable appliance. The attacker only needs the one door.

That is why mature security programs treat them as two halves of one answer rather than competing options, and why frameworks that take testing seriously, such as PCI DSS, NYDFS 23 NYCRR 500, and the enclave scoping behind CMMC Level 2, explicitly expect both internal and external testing rather than letting you pick one.

Which one should you do first?

If you have never had a penetration test, start external. It is the attack surface every adversary on the internet can already reach, it requires almost nothing from your team to set up, and it is the cheaper of the two. An exploitable perimeter is the most urgent kind of finding there is.

Move internal testing up the list when any of these are true:

  • You rely on Active Directory and it has never been formally tested
  • Your workforce is a phishing target (every workforce is), and you want to know what a single compromised laptop costs you
  • Compliance applies: PCI DSS requires internal and external testing, NYDFS 500 expects both, and SOC 2 auditors increasingly ask what happens past the perimeter
  • A vendor, auditor, or cyber insurer has asked about segmentation and you do not have evidence it holds

Most organizations that run both discover the internal report is the more sobering document. The perimeter gets attention because it is visible. The inside rarely does.

Can they be combined?

Yes, and it is often the efficient buy. A combined engagement tests the perimeter, then continues from an assumed foothold inside, giving you the full attack path in one report: how they get in, and what happens next. We scope combined network engagements routinely, and a full-chain exercise with phishing and objectives on top is essentially a red team engagement. For the broader landscape of engagement types, see our guide to network penetration testing.

What each costs

Fixed prices, published, no hourly billing:

Both include a free retest of remediated findings, and larger environments are quoted after scoping. Market-wide numbers and what drives them are in our penetration testing cost guide.

Frequently asked questions

Is external or internal penetration testing more important? Neither is universally more important; they answer different questions. External is the more urgent first test because that attack surface is exposed to everyone on the internet right now. Internal usually produces the more severe findings once run, because internal networks accumulate years of untested trust.

Do I need to be on-site for an internal test? Usually not. Most internal tests run remotely through a small appliance or virtual machine placed inside your network, which keeps logistics and cost down. On-site testing is available when the scope calls for it.

How often should each be run? At least annually for both, plus after significant changes: a new public application or VPN for external, a domain migration or major restructuring for internal. Regulated environments often test more frequently, and some frameworks mandate the cadence.

Is an external penetration test the same as a vulnerability scan? No. A scan enumerates known weaknesses automatically; an external penetration test has a human validate, chain, and exploit them to prove real impact. The difference is covered in penetration testing vs vulnerability scanning.

The short version

External testing asks whether an attacker can get in. Internal testing asks what happens once they are in. One tests your doors, the other tests your rooms, and a serious security program eventually needs the answer to both. If you only budget for one this year, test the surface an attacker can already reach, then plan the internal test before your Active Directory gets another year older.

Ready for either? Scope your assessment and we will return a fixed quote for external, internal, or a combined engagement within one business day.

Written by

Invadel Team

Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →

Find out what an attacker sees.

Tell us what to test and see your fixed price.

Prefer the full scoping questionnaire? 
Start the conversation