Service
Network penetration testing, from the internet edge to the inside
Network penetration testing asks two questions. What can a stranger on the internet reach, and how far can someone get once they are already inside? We answer both by hand, inside a scope you sign.
- Named tester before day one
- One retest within 30 days
- OWASP WSTG and NIST SP 800-115
The two halves of network penetration testing
An external test looks at everything you expose to the internet: VPN gateways, mail servers, forgotten hosts and admin panels. An internal test, by contrast, starts from a foothold inside, such as a laptop or a contractor account. That is where most real damage happens, because internal networks are usually flat and trusted.
Many buyers need both. However, if your auditor or customer named only one, we scope only that one.
What network penetration testing tries to do
The tester behaves like an attacker who has time but no luck. So the work follows a familiar path.
- Discover live hosts and the services they run
- Find weak or default credentials and unpatched services
- Abuse misconfigured file shares and directory services
- Move from one host to another and escalate privileges
- Show the shortest route to the data that matters
Every step is logged, because the report has to show the path, not just a list of open ports.
Network penetration testing readiness check
These answers decide most of the scope. Tick the ones you can already give us.
Your result appears here as you tick, so you can see what is still open.
Internal or external first?
If you are new to testing, start with the edge. It is smaller, cheaper and closest to what an opportunistic attacker sees. Then add the internal view once the obvious doors are shut.
| External | Internal | |
|---|---|---|
| Starting point | The public internet. | A device or account inside your network. |
| Typical findings | Exposed services, weak edge devices, old hosts. | Flat networks, reused passwords, excessive privileges. |
| Published range | $4,000 to $20,000. | $5,000 to $35,000. |
| Usually asked by | Customers and SOC 2 auditors. | Banks, insurers and PCI DSS assessors. |
How network penetration testing is kept safe
We agree testing windows, out-of-scope hosts and a stop word before day one. In addition, nothing destructive runs without a separate written approval. The method follows NIST SP 800-115, so your auditor can match each stage to a published standard.
What you receive after network penetration testing
You get an executive summary a director can read in ten minutes, followed by each finding with proof and a specific fix. There is also a one-page attestation letter you can share without exposing the details. Finally, one retest inside 30 days confirms the fixes.
Network penetration testing questions
How long does network penetration testing take?
Hands-on testing usually runs three to ten days depending on the number of hosts, with the report a few days after.
Can it run during office hours?
Yes, most of it can. We agree windows for anything noisy, such as password spraying, so your team is not surprised.
Is network penetration testing the same as a vulnerability scan?
No. A scan lists possible issues. A test proves which ones lead somewhere and shows the route.
Do you need to be on site?
Usually not. Internal work normally runs through a VPN account or a small device you connect for us.
Related guides
Scope your network penetration testing in writing
Send us your public ranges and a rough host count. We return a written scope and a fixed fee within the published range, with no call needed.
Get my estimate