Technical review by Volodymyr Garbar, CISO & Tech Lead
Updated: 6 October 2026
Network penetration testing services assess internal or external network infrastructure to find vulnerabilities that an attacker could exploit and determine how far an attack could go. Testing can cover internet-facing systems, internal networks, firewalls, VPNs, servers, network services, Active Directory, and other infrastructure included in the agreed scope.
The important bit is what happens after a weakness is found.
A vulnerability scanner might identify an exposed service, outdated software, or a configuration problem. During a penetration test, a tester can investigate whether that weakness is actually exploitable and whether it provides a route to something more important.
Sometimes one vulnerability is the problem. Sometimes it is just the first door.
Q-Sec provides both external and internal network penetration testing, with scope defined around the environment and the attack scenarios the organization needs to understand. We will get into the difference between the two below.
Free playbook
Preparing for network penetration testing under PCI DSS?
The PCI DSS Penetration Testing Playbook covers scoping, internal and external testing domains, pre-engagement preparation, and the evidence to keep after the assessment.
Get the PCI DSS Penetration Testing PlaybookNetwork penetration testing is a controlled security assessment in which testers identify and attempt to exploit weaknesses in network infrastructure to determine what an attacker could access, compromise, or move through.
It can be performed from outside the organization, simulating an attacker starting on the internet, or from inside the network, where the starting point might represent a compromised employee account, workstation, or other internal foothold.
The distinction matters because the questions are different.
An external network test asks whether someone outside the organization can find a way in through exposed infrastructure. An internal test starts further along: assume an attacker already has some access. What can they reach now?
Depending on the environment, testing can involve servers, network services, firewalls, VPNs, remote-access systems, segmentation controls, identity infrastructure, and other connected assets.
NIST SP 800-115 describes penetration testing as security testing where assessors attempt to circumvent security features based on their understanding of the system design and implementation. It places penetration testing within a broader assessment process that includes planning, execution, analysis, and mitigation.
For organizations still deciding what kind of assessment they need, our guide to Penetration Testing Consulting explains how scope and testing objectives are defined before the technical work begins.
External network penetration testing focuses on infrastructure reachable from outside the organization, while internal network penetration testing examines what an attacker could do after gaining access to the internal environment.
| External network pentest | Internal network pentest | |
|---|---|---|
| Typical starting point | Internet | Internal network or provided internal access |
| Main question | Can an outside attacker get in? | What can an attacker do once inside? |
| Typical targets | Public IPs, VPNs, gateways, exposed services, internet-facing infrastructure | Internal hosts, services, identity systems, network segments, administrative interfaces |
| Common attack paths | Exposed services, weak configurations, vulnerable remote access | Privilege escalation, credential abuse, lateral movement, weak segmentation |
| Useful when | Assessing internet-facing exposure | Assessing impact of a compromised user, device, or account |
Many organizations need both.
A well-defended perimeter does not tell you what happens if an employee's credentials are stolen. An internal test does not tell you whether a forgotten internet-facing server provides a much easier route into the organization.
If external exposure is the immediate concern, our guide to External Penetration Testing Companies explains what to compare when choosing a provider specifically for that type of assessment.
A network penetration testing service typically includes scoping, reconnaissance and enumeration, vulnerability analysis, controlled exploitation, impact analysis, reporting, remediation guidance, and retesting where agreed.
That sounds fairly orderly on paper. Real networks usually make it less tidy.
A tester may find an exposed service during enumeration, discover that its configuration allows an initial foothold, obtain credentials, and then find that those credentials work somewhere they should not. One moderate-looking issue has now become part of a much more interesting attack path.
The exact techniques depend on whether the engagement is external or internal and what the rules of engagement allow.
Typical network testing can include:
Q-Sec's network penetration testing covers both external and internal scenarios and can be combined with Active Directory, cloud, Microsoft 365, application, or other testing where those systems form part of the relevant attack path.
A network penetration testing service usually moves through five practical stages: scoping, discovery, controlled exploitation, impact analysis, and reporting with remediation guidance. Retesting can follow after the identified vulnerabilities have been fixed.
The exact sequence is not always neat. Testing is iterative. A credential discovered halfway through an assessment can open a new attack path, or a supposedly isolated system can turn out to have access somewhere it should not.
NIST describes penetration testing in similar terms: testers can use the access they gain to attempt greater access, including through privilege escalation. It also distinguishes external testing from insider scenarios where testers begin behind the firewall with some level of internal access.
A typical Q-Sec engagement looks like this:
| Stage | What happens |
|---|---|
| Scoping | The client and testing team agree on targets, exclusions, objectives, testing windows, permitted techniques, and rules of engagement. |
| Discovery | Testers map hosts, services, network exposure, and other information relevant to the scope. |
| Vulnerability analysis | Potential weaknesses are identified and investigated rather than simply copied from scanner output. |
| Controlled exploitation | Testers attempt to exploit validated weaknesses within the agreed boundaries. |
| Post-exploitation and impact analysis | Where permitted, the team investigates privilege escalation, lateral movement, segmentation, and what compromised access could lead to. |
| Reporting | Findings are documented with evidence, severity, impact, and remediation guidance. |
| Retesting | Fixed vulnerabilities can be tested again to confirm that remediation worked. |
There should also be a way to report serious findings before the engagement ends. If a tester discovers an easy route to a critical production system on Tuesday, Friday's final report is not the ideal moment to mention it.
Network penetration testing can uncover exploitable software vulnerabilities, insecure configurations, weak authentication, excessive privileges, exposed services, segmentation failures, credential problems, and attack paths between systems.
The interesting findings are not always dramatic on their own.
An old service on one server may provide initial access. A permissions problem may expose credentials. Those credentials may work on another system, where the account has more privileges than expected.
Looked at separately, the findings can seem manageable. Put together, they may provide a practical route through the network.
This is one reason a penetration test and a vulnerability scan should not be treated as interchangeable. Regular scanning is useful and should happen much more frequently. NIST explicitly describes periodic penetration testing alongside more regular network and vulnerability scanning as complementary activities.
A network penetration testing report should give you validated findings, technical evidence, affected assets, risk and impact, remediation guidance, and a clear record of what was and was not tested.
That sounds obvious until you receive a report containing forty scanner findings and very little explanation of which ones actually matter.
Technical teams need enough detail to understand the issue and work on the fix. Security leadership needs a clearer view of the attack paths and the exposures that deserve attention first.
A useful deliverable normally includes:
Q-Sec’s penetration testing engagements include manually validated findings, technical and executive reporting, and remediation guidance. A technical walkthrough can also help the people fixing the problems understand what the testers actually did.
A report should make remediation easier. If your engineers need another meeting just to work out what Finding 17 means, something has gone wrong.
A focused network penetration test commonly takes several days to a few weeks of active work, while the complete engagement can take around 2–4 weeks once scoping, testing, reporting, and review are included. Larger networks and more complex internal assessments can take longer.
There is a fairly big difference between testing a handful of public IP addresses and assessing a large internal environment with several network segments, Active Directory, multiple privilege levels, and hundreds of hosts.
Access also matters. So do testing windows.
If production systems can only be tested overnight or particular techniques are prohibited, the calendar gets longer even if the amount of testing work has not changed much.
Rather than asking a network penetration testing company only for a completion date, ask how many tester-days are allocated and what those days cover. That gives you a much better idea of the depth of the proposed assessment.
A network penetration test often costs roughly €3,000–€15,000 (£2,500–£13,000) in the European market, although a small external scope can cost less and a large internal network assessment can cost substantially more.
Treat that as a budgeting range.
The biggest pricing factors are usually the number and type of assets, external versus internal scope, network complexity, testing depth, tester-days, access levels, reporting requirements, and whether remediation support and retesting are included.
An external assessment of 15 public IP addresses and an internal assessment of 500 hosts should not cost the same. More importantly, they are not remotely the same job.
When comparing quotes, ask what is actually included before deciding which provider is expensive.
Our Penetration Testing Vendor Evaluation guide has a side-by-side framework for comparing scope, testing depth, reporting, retesting, and price across providers.
Choose a network penetration testing company based on its experience with your type of network, the depth of manual testing, the proposed scope, reporting quality, and what happens after vulnerabilities are found.
Price belongs in the comparison, but not at the top of it.
I would check six things before signing:
If you are comparing several providers rather than choosing a testing model, the Penetration Testing Vendor Evaluation guide goes deeper into proposal comparison and procurement questions.
Q-Sec provides external and internal network penetration testing for organizations that need to understand both whether an attacker can get in and what could happen after access is gained.
External testing focuses on internet-facing infrastructure and exposed services. Internal testing can examine privilege escalation, lateral movement, segmentation, identity infrastructure, and other attack paths from an assumed internal foothold.
Network testing can also be combined with web and API testing, Active Directory, Microsoft 365, cloud penetration testing, or adversary simulation when the environment crosses those boundaries. That matters because real attack paths have an annoying habit of ignoring service categories.
For European organizations, the engagement can also be scoped around security and compliance requirements such as NIS2, DORA, PCI DSS, and ISO 27001 where relevant.
The goal is fairly simple: find out what is actually exploitable, document the evidence, and give the people responsible for the systems enough information to fix it.
Need to test your network against a real attack path?
If you already know which networks or systems need testing, Q-Sec can scope an external, internal, or combined network penetration test around your environment.
A network penetration testing service is a controlled assessment of network infrastructure in which security testers identify vulnerabilities, attempt exploitation within an agreed scope, and investigate what access or impact those weaknesses could provide.
External testing starts from outside the organization and looks for ways into internet-facing infrastructure. Internal testing begins with access inside the network and examines what an attacker could reach through privilege escalation, credential abuse, lateral movement, or weak segmentation.
In Europe, a network penetration test often falls around €3,000–€15,000, although small external tests can cost less and large internal assessments considerably more. Network size, complexity, testing depth, and tester-days have a major effect on price.
A focused test can take several days, while a complete engagement commonly runs for a few weeks once scoping, testing, reporting, and review are included. Large internal networks or restricted testing windows can extend the timeline.
No. Vulnerability scanning primarily identifies potential weaknesses using automated tools. Penetration testing adds manual investigation and controlled exploitation to determine whether vulnerabilities are exploitable and what an attacker could do with them.
It can. Active Directory is often relevant to internal network testing because identity, credentials, privileges, and domain relationships can become part of an attack path. Confirm explicitly whether AD testing is included in the proposed scope.
Not every engagement needs both. External testing answers whether an attacker can get in through exposed infrastructure. Internal testing asks what could happen after internal access has already been obtained. Organizations concerned about both scenarios can include both in the scope.