In short
Getting in is only step one. Internal testing measures how far an intruder could move once they have a foothold, and whether they could reach your servers, your backups and your finance data. It answers the question that decides whether an incident is an inconvenience or a shutdown.
Most of the damage does not come from the break-in. It comes from what happens next.
A single phished laptop is not, by itself, a disaster. It becomes one when that laptop turns out to have a route to the file server, then to the domain controller, then to the backups. Internal penetration testing measures that distance before an attacker does.
The assumption the test starts from
Internal testing begins where external testing ends: somebody is already inside. Perhaps a member of staff clicked something, perhaps a contractor's device was compromised, perhaps a supplier's credentials were reused.
We do not argue about how likely that is. Verizon's 2026 report puts the human element in 62% of breaches, so the honest planning assumption is that it will happen eventually. The useful question is what it would cost when it does.
What we look for
The work is about movement rather than individual flaws:
- Lateral movement. Can a standard user's machine reach systems it has no business reaching? Flat networks are the single most common finding, and the one with the widest blast radius.
- Privilege escalation. How quickly does an ordinary account become an administrator? Cached credentials, over-permissioned service accounts and legacy group memberships are the usual routes.
- Reach to the things that matter. Finance systems, personal data, and above all the backups. If a foothold on a receptionist's PC leads to the backup platform, ransomware stops being recoverable.
That last item is the one we test hardest, because it decides whether an incident is a bad week or an existential one.
Where the surprises usually are
Two patterns come up repeatedly in Irish SMEs, and neither is exotic.
The first is accumulated trust. A printer VLAN that can reach the servers because of a rule added during an install. An old management network that was never decommissioned. Individually reasonable decisions that compound into a route nobody designed.
The second is service accounts. Accounts created for an application years ago, granted broad rights to make a deployment work, never reviewed, with a password that has not changed since. They are rarely monitored, because nothing ever goes wrong with them until it does.
How the engagement runs
Testing follows a recognised structure: scoping, reconnaissance, vulnerability discovery, exploitation where explicitly authorised, post-exploitation and impact analysis, then reporting with remediation guidance. We work to the CREST methodology for infrastructure testing.
The exploitation stage is bounded by written agreement. We demonstrate that a path exists and document how far it goes; we do not disrupt production to prove a point. Where a proof would be destructive, the report explains the route and stops short.
Timing is agreed in advance, and there is a named contact on both sides for the duration.
What comes back
Findings are ordered by business impact rather than by technical severity, because the two are not the same. A medium-rated flaw on the path to your accounting system outranks a high-rated one on an isolated test box.
For each finding you get the route taken, the evidence, and a specific fix. Segmentation changes, account clean-ups and monitoring gaps tend to dominate the list, and most cost time rather than money.
The relationship with segmentation
Almost every internal test ends with the same recommendation in some form: separate things that do not need to talk to each other.
Network segmentation has come back into focus for exactly this reason. It does not prevent the initial compromise. It contains it, so that one compromised device is a contained problem rather than a company-wide one. If you want the fuller argument, we wrote about Wi-Fi and network segmentation separately.
How often
Annually is a reasonable baseline for most businesses. Sooner if you have changed something structural: a new site, a merger, a move to or from a cloud platform, or a significant change to who administers your environment.
The cost of finding out this way is a fixed fee and a planned week. The cost of finding out the other way is measured against the €50,000 a year the average Irish SME already loses to cyber disruption, according to eir Business research supported by Microsoft.
To scope an internal test, get in touch, or read more about penetration testing and vulnerability scanning.