Network penetration testing is an authorised, simulated attack on your network by a skilled tester. An external test looks at what anyone on the internet can reach; an internal test assumes an attacker is already inside. You get proof of what could be reached and a prioritised list of fixes.
Internal vs external network testing
| External test | Internal test | |
|---|---|---|
| Starting point | The public internet | Inside your network, like a compromised laptop or a visitor's device |
| Looks at | Firewalls, VPNs, mail servers and anything internet-facing | Servers, shared drives, user accounts and how far an attacker could move |
| Answers | Can someone break in from outside? | If someone gets in, how much damage could they do? |
What do testers look for?
- Missing security updates on servers and network devices.
- Weak, default or reused passwords.
- Services exposed to the internet that shouldn't be.
- Poor separation between parts of the network.
- Paths from an ordinary user account to administrator access.
What do you get at the end?
A short summary for leaders, a technical report with evidence for each finding, and a prioritised fix list. A retest afterwards confirms the fixes worked.
How often should you test your network?
At least once a year, and after significant changes such as a new office, a new firewall, a cloud migration or merging networks. Regular vulnerability scanning in between keeps on top of new weaknesses.
Frequently asked questions
It is planned to avoid disruption: testing windows and limits are agreed in advance, and testers contact you immediately if anything unexpected happens.
Usually a few days of testing for a small or medium network, followed by the report. The scope sets the timeline.
Most businesses benefit from both. External testing shows how hard it is to get in; internal testing shows what an attacker could do once inside, which is how most serious incidents unfold.