Internal Network Penetration Testing
When a breach happens, attackers move fast. Let's find out how far they'd get.

Who Needs This
Who needs internal penetration testing?
Organisations with on-premise infrastructure
Businesses with hybrid AD environments
Post-breach validation and hardening
Compliance-driven internal security reviews
What We Test
What does an internal pentest include?
Active Directory Security
Lateral Movement
Privilege Escalation
Credential Exposure
Internal Web Applications
Network Architecture Review
Our Pentest Methodology
How we approach internal penetration testing
Scoping & Rules of Engagement
Reconnaissance & Mapping
Vulnerability Identification
Exploitation & Post-Exploitation
Reporting & Debrief
Pricing
From £2,850
for internal network penetration testing
Not sure where your network fits? A 30-minute scoping call is free and gets you a fixed written quote.
No obligation · Strictly confidential · Quote within one business day
Pricing Examples
| Small office network (1-2 subnets, local servers) | £2,850 - £3,300 |
| Medium enterprise network (multiple subnets) | £3,800 - £4,200 |
| Large network (multiple subnets/zones) | £4,750 - £6,600 |
| Complex multi-site enterprise | £7,500+ |
What's Included
- Fixed-price proposal within one business day
- Manual, consultant-led testing. Not automated scans
- Report within 2 business days of testing completion
- Debrief call with your team to talk through findings and risk
- No obligation quote, all enquiries are fully confidential
Key Deliverables
What's included in the assessment
Executive Report
A non-technical summary of findings with risk ratings and recommendations suitable for board and senior management stakeholders.Technical Report
Detailed findings with reproduction steps, severity scoring, remediation guidance, and mappings to CVE, CVSS, and MITRE ATT&CK where applicable.Debrief Session
An offer of a debrief call to walk through findings, discuss remediation priorities, and answer questions from both technical and executive stakeholders.Attack Path Narrative
A walkthrough of the attack chain from initial access to maximum privilege, showing precisely how findings chain together to produce real-world risk.Attack Surface Center Access
Complimentary access to our Attack Surface Center ASM platform for live finding visibility, collaborative tracking, and remediation management.Consultant-led Testing
All testing is consultant-led by in-house staff. Your consultant works with you from scoping through to debrief - nothing is outsourced or subcontracted.
Ready to test your internal network security?
Common Questions
Internal network penetration testing - frequently asked questions
Internal network penetration testing simulates an attack from inside your network perimeter. This could represent a malicious insider, a compromised employee account, or an attacker who has gained initial access through phishing or other means. We assess what an attacker could achieve once inside, including lateral movement, privilege escalation, and access to sensitive data.
To request an internal penetration testing quote, tell us about the size of your network and we'll respond with a fixed-price proposal within one business day.
Yes, PCI DSS Requirement 11.4 explicitly requires internal penetration testing for all organisations with in-scope systems. It must be conducted at least annually and after significant changes to the environment.
External testing simulates an attack from the internet, testing your perimeter defences. Internal testing assumes the attacker is already inside your network. Internal testing typically uncovers different vulnerabilities: weak domain credentials, misconfigured Active Directory, unpatched internal systems, and excessive file share permissions.
Most organisations benefit from running both network penetration testing engagements.
Not necessarily. Internal testing can be conducted remotely via a VPN connection or a small testing appliance we ship to your site. On-site testing is also available where preferred.
Assumed breach testing starts from the position that an attacker already has a foothold - a low-privilege domain account, for example - and focuses on what they can do from there. Rather than spending testing time on initial access, the assessment concentrates on post-compromise activity: privilege escalation, lateral movement, Active Directory abuse, and whether a limited starting position can lead to domain compromise or access to sensitive data.
This makes assumed breach a more efficient model for organisations that already have confidence in their external perimeter and want to understand what happens if an attacker gets through anyway. It is also well-suited to post-incident validation, where the goal is confirming that an attack path has been closed. See our article on assumed breach penetration testing for a full explanation of when it is the right choice and what to expect from the process.
