HomeBlogsNetwork Penetration Testing in Australia 2026: Internal vs External, What Each Covers, and Which One You Need

Network Penetration Testing in Australia 2026: Internal vs External, What Each Covers, and Which One You Need

Updated: September 30, 2026|4.2 min read
Network Penetration Testing in Australia 2026: Internal vs External, What Each Covers, and Which One You Need
Network Penetration Testing in Australia 2026

The most useful way to hold the distinction between internal and external network penetration testing is this: external testing reduces the chance of a breach; internal testing reduces the impact of one. Both answer different, essential questions. Neither substitutes for the other.

Most AU organisations commission external network testing because it is what compliance frameworks mention first and what auditors typically ask for first. But most modern breaches do not fail at the perimeter. The initial foothold is often easy. The damage comes from what the attacker can reach afterward.

Internal testing answers the question that determines breach severity: when an attacker gets inside, how much damage can they do and how fast?

What an External Network Penetration Test Covers

What an External Network Penetration Test Covers

External network penetration testing assesses what an attacker can reach from the internet with no prior access: perimeter firewalls, VPN gateways, exposed RDP or SSH endpoints, and any service that got published to a public IP address by mistake.

The tester starts from outside the network with no credentials and attempts to reach internal systems. The scope is the organisation's internet-facing IP range and any publicly accessible service. An external test simulates an outsider trying to break in and answers: can they get in?

What external testing finds: exposed management interfaces (RDP, SSH, Telnet) that should not be public, VPN gateways with known vulnerabilities or weak authentication, misconfigured mail or DNS services that allow enumeration or relay, unpatched internet-facing software, and certificate or TLS configuration weaknesses that allow interception or downgrade.

What external testing does not answer: whether your internal network is segmented, whether a compromised workstation can reach your domain controller, how far an attacker can move once they have any internal access, or whether your Active Directory configuration contains lateral movement paths that would turn a phished employee into a domain-wide incident.

For AU organisations preparing for a government contract, Essential Eight assessment, or cyber insurance renewal, external and internal network penetration testing together form the standard scope expectation.

What an Internal Network Penetration Test Covers

What an Internal Network Penetration Test Covers

Internal network penetration testing simulates an attacker who has already gained access inside your environment, whether through a compromised endpoint, a malicious insider, or a successful phishing campaign. The tester starts with a foothold inside the network, typically a standard user account position, and works outward.

Lateral movement simulation starts from a standard user position and tests how far an attacker can move through the environment. Credential reuse across systems, SMB relay opportunities, and service account over-permissioning are the most frequently exploited lateral movement paths.

Active Directory Attack Path Mapping

Active Directory is the highest-impact finding category in most internal engagements. Active Directory mapping uses tools like BloodHound to analyse relationships, permissions, and trust paths within AD. The attack path from a standard domain user to Domain Administrator often runs through misconfigured delegation settings, Kerberoastable service accounts with weak passwords, or ACL-based privilege escalation paths that no individual policy review would surface. A single misconfigured service account can represent a full domain compromise path.

Windows networks that still have LLMNR and NBT-NS enabled will respond to any host claiming to be the resource being searched for. A tool listening passively captures NTLMv2 hashes from every workstation that mistypes a share name or has a misconfigured proxy setting. Those hashes get cracked offline, generating no failed-login noise, at whatever speed the hardware supports.

Disabling LLMNR and NBT-NS is one of the most common and highest-value recommendations from internal network penetration tests. It is also one of the most frequently deferred because it requires a GPO change that can break legacy behaviour in environments that have not been audited for dependency.

For how findings at this depth connect to remediation and the compliance evidence that APRA and ISO 27001 auditors check, the guide to what happens after a penetration test covers the re-testing cycle that confirms an Active Directory finding is genuinely closed, not just patched at the surface.

What am I risking by not acting?

Your Last Pentest Is Already Out of Date

Every week you ship without continuous testing is a week a vulnerability goes unseen. See what Capture The Bug finds in your first engagement.

AU Compliance: Which Test Each Framework Requires

AU Compliance Network Penetration Testing Requirements

APRA CPS 234 requires regulated entities to test controls regularly. Internal network testing is strongly recommended for organisations with complex internal environments. Entities that cannot evidence regular testing face supervisory scrutiny. For APRA-regulated organisations retaining Active Directory alongside cloud workloads, both cloud and internal network testing are expected annually.

The ASD Essential Eight incorporates penetration testing at Maturity Level 2 and above. Organisations targeting ML2 or ML3 must regularly test network segmentation and privilege management under adversarial conditions.

For SOC 2, scope should map to systems that process, store, or transmit data covered by Trust Services Criteria. Both internal and external tests produce accepted evidence, provided findings are tracked, remediated, and retested. PCI DSS Requirement 11.3 mandates both internal and external testing annually and after any significant infrastructure change. For AU card-processing organisations, both are mandatory, not optional.

The guide to continuous penetration testing for SOC 2 and ISO 27001 compliance covers how testing programmes produce evidence at the cadence that modern compliance frameworks require.

Book a scoping consultation to confirm whether internal testing, external testing, or both are the right engagement for your AU compliance requirements and network environment.

Plan Security Better

Plan Your Annual Pentesting Strategy the Right Way

Learn how modern SaaS companies structure pentesting across the year to reduce risk, stay compliant, and avoid last-minute panic before audits.

Frequently Asked Questions

What is the difference between internal and external network penetration testing in Australia?

External network penetration testing starts from outside the organisation's network and tests what an attacker can reach from the internet: perimeter firewalls, VPN gateways, exposed management interfaces, and misconfigured internet-facing services. Internal network penetration testing starts from inside the network with a standard user position and tests how far an attacker can move, escalate privileges, and reach sensitive systems. External testing reduces the chance of a breach. Internal testing reduces the impact of one. Most AU compliance frameworks require both.

Does APRA CPS 234 require internal network penetration testing?

APRA CPS 234 requires regulated entities to maintain information security capabilities and test controls regularly. Internal network testing is strongly recommended for APRA-regulated entities with complex internal network environments. Entities that cannot evidence regular testing are increasingly subject to APRA supervisory scrutiny and remediation directions. Financial services organisations that have migrated workloads to cloud but retain internal Active Directory environments should include both internal network and cloud penetration testing in their annual assurance programme.

What does Active Directory testing find in an internal network penetration test?

Active Directory testing maps the relationships, permissions, and trust paths within the AD environment to identify privilege escalation paths from a standard user to Domain Administrator. Common findings include Kerberoastable service accounts with weak passwords that can be cracked offline, misconfigured delegation settings, ACL-based privilege escalation paths, and domain trust relationships that allow lateral movement between domains. A single misconfigured service account can represent a full domain compromise path. Tools like BloodHound are used to visualise and confirm these paths.

What does the Essential Eight require for network penetration testing in Australia?

The ASD Essential Eight incorporates penetration testing as a validation mechanism at Maturity Level 2 and above. Organisations targeting ML2 or ML3 are expected to conduct regular testing of network segmentation and privilege management. Both external and internal network penetration testing together form the standard scope expectation for government entities and private sector organisations preparing for an Essential Eight assessment.

How much does network penetration testing cost in Australia in 2026?

External network penetration testing for a standard scope (defined IP range, perimeter assessment) typically costs between AUD $8,000 and AUD $18,000. Internal network penetration testing for a mid-market environment typically costs between AUD $12,000 and AUD $30,000, with cost scaling by the number of active hosts, network segments, and whether Active Directory depth testing and lateral movement simulation are included in scope. Organisations running both engagements annually can often negotiate combined scope pricing with their CREST-certified provider.

Manu Kumar Singh

Manu Kumar Singh

Security Researcher & Bug Bounty Hunter

Security Researcher & Bug Bounty Hunter focused on Web Security, API Security, Business Logic Vulnerabilities, Broken Access Control, and Attack Surface Discovery. Experienced in reconnaissance, vulnerability research, and offensive security testing.

- 07 / RESOURCES

Read Industry Insights

Security that works like you do.

Flexible, scalable PTaaS for modern product teams.