External penetration testing examines what an attacker can reach and exploit from outside the agreed network boundary. Internal penetration testing starts with an agreed position inside that boundary and examines what additional access or impact is possible. Choose the perspective that answers your risk question; when you need evidence about both initial entry and the consequences of a foothold, scope both.
For IT directors and MSPs commissioning an assessment, the important decision is the tester's starting position, permissions, and objective. A proposal labeled “penetration test” leaves too much unsaid if those details are missing.
External testing asks what can be reached from outside
An external assessment commonly examines authorized internet-facing systems and services. It can investigate whether exposed weaknesses offer a way into the environment. NIST SP 800-115 distinguishes this outside view from internal testing, which assumes some access already exists.
The useful buying question is specific: “Can an outside attacker compromise the systems supporting this public service under the agreed conditions?” That is more informative than asking whether the organization can pass a generic security test.
If the tester finds no entry path, that result applies to the targets, techniques, and time allowed. It does not establish what a compromised employee device could reach inside the network. Nor does an assessment of listed public addresses automatically cover every application, cloud account, or remote-access route the business uses.
Internal testing asks what an initial foothold enables
An internal assessment begins from a defined network position, sometimes with an ordinary user account. It can examine whether the tester can gain privileges or reach systems beyond the intended access. NIST describes this as a way to assess the consequences of an insider or an attacker who has crossed the perimeter.
“Internal” still needs detail. A guest wireless connection, an employee workstation segment, and a server administration network represent different starting positions. For a useful proposal, name the position that reflects the scenario you want assessed. Giving a tester broad administrative access at the outset answers a different question from starting with an ordinary employee's permissions.
This remains relevant in environments using zero trust principles. NIST SP 800-207 explains that network location alone should not confer trust. Our practical implication for assessment buyers is to identify the resource and access decision being tested, even when the service is in the cloud or users work remotely. An office location is an incomplete description of the security boundary.
Starting position and prior knowledge are separate choices
A tester can assess an internet-facing application while receiving architecture details and authorized user credentials. The external network position does not require a completely uninformed test. Similarly, providing an internal connection does not require granting an administrator account.
The UK's National Cyber Security Centre guidance on penetration testing describes different levels of information supplied to testers and scenario-driven assessments. Less information may better represent a particular attacker, but it can also consume limited testing time on discovery and leave weaknesses unexplored.
Choose that tradeoff deliberately. If the concern is an unknown outsider's opportunity, limited prior knowledge may be useful. If the concern is whether a defined access boundary holds, sharing the design can help focus the engagement. Record the starting assumptions so the findings remain interpretable.
A hypothetical business, two different questions
Consider a hypothetical distributor with a public customer portal and an internal order-management environment. Leadership has two concerns: an outsider gaining access through the portal, and a compromised employee workstation reaching restricted order records.
An external engagement aimed at the portal addresses the first concern. If it finds no usable entry path, the second concern remains open. An internal engagement starting from the employee network can examine the second scenario without spending the whole assessment trying to reproduce the initial compromise.
Conversely, an internal result showing excessive access would establish a problem from that starting position. It would not, by itself, show that the tester could have obtained the foothold from the public internet. The findings should explain which access was supplied and which access was actually gained.
If both concerns matter, commission complementary scopes. If budget requires staging the work, prioritize the question with the most consequential uncertainty and explicitly retain the other as unassessed. Neither perspective substitutes for the other simply because one report has fewer findings.
Buy an answer you can use
Before comparing proposals, write down the question the report must answer in one sentence. Then ask each provider to describe the starting position, included systems, permitted activity, exclusions, and evidence that would support an answer. The NCSC's commissioning guidance emphasizes agreeing technical boundaries, scenarios, effort, and reporting requirements during scoping.
Keep conclusions tied to those conditions. A finding should explain the demonstrated consequence; an excluded system or blocked test should remain a visible limitation. Agree how important fixes will be retested from the relevant starting position. This makes the report useful for a decision, rather than leaving leadership to infer coverage from a finding count.
Network Box USA's Penetration Testing service includes external and internal network testing, proof-of-impact evidence, remediation guidance, and retesting within an agreed scope. To discuss which perspective fits your environment, contact our team with the business question you need the assessment to answer.