Skip to content
Breakpoint Labs
Authorised systems only. Breakpoint Labs works only on authorised scope, so rules of engagement are agreed in writing first.

Coverage note

Internal penetration testing: what an intruder could reach once inside

Internal penetration testing starts from a foothold inside your network. So it answers the question a perimeter test cannot: once someone is in, how far can they get, and how quickly would anyone notice?

  • Manual exploit chains
  • PTES and the OWASP testing guide
  • Authorised scope only
Internal penetration testing: agree the foothold, test the estate and report the paths

What internal penetration testing covers

The scope is your internal estate rather than the internet edge. Therefore the work looks at how systems trust each other, not only at each system alone.

  • Segmentation between networks that should stay apart
  • Directory services and the privileges they grant
  • The lateral paths between workstations, servers and backups
  • Sensitive data stores and who can read them

How internal penetration testing starts

Every engagement needs an agreed starting point. So the foothold is chosen with you and written into the rules of engagement before anything begins.

Starting pointWhat it simulatesAgreed in writing
Testing virtual machineA device already on the network.Placement and removal date.
Standard user accountA compromised employee login.Privileges and monitoring.
Guest network seatA visitor or contractor.Which segments are in scope.

Ready for internal penetration testing?

Tick what you can arrange. Open items become part of the written scope.

Your result appears here as you tick, so you can see what is still open.

Why internal penetration testing finds chains

Inside a network, small weaknesses tend to connect. For example, a stale permission, a reused service account and a flat network are each minor. However, together they can form a route to the systems that matter. Therefore the report shows routes rather than a list, because that is what an attacker would use.

Safety during the engagement

Testing windows, escalation contacts and a stop procedure are agreed first. In addition, every action is logged with a timestamp for your incident team. Then every artefact placed during testing is removed at the end. Our method follows the Penetration Testing Execution Standard and NIST SP 800-115.

Fees and the report

The report is written by the penetration hacker who ran the work, with evidence, business risk and prioritised remediation. Also, the retest is included once you apply the fixes. Full engagements run from $35,000 to $120,000, while the floor is $25,000. Also, the bounded Attack Surface Diagnostic starts at $4,500. Moreover, its fee is credited in full against a full engagement commissioned within ninety days.

Internal penetration testing questions

How long does internal penetration testing take?

It depends on the size of the estate. The fixed fee and timeline are both agreed in the written scope.

Does internal penetration testing need someone on site?

Usually not. A testing virtual machine or an agreed account is often enough.

Will internal penetration testing disrupt users?

Testing windows and a stop procedure keep it controlled, and fragile systems can be excluded.

Is a perimeter test enough on its own?

No. It shows the way in, but not how far someone could go once inside.

Related guides

Scope internal penetration testing

Describe the estate and the foothold you want simulated. The penetration hacker who would lead the work replies with a written scope and one fixed fee.

Send the brief