Skip to main content
Precursor Security
Internal & External Coverage, One CREST-Accredited Team

Network & Infrastructure Penetration Testing

Network penetration testing is a CREST-accredited manual security assessment that simulates a real attacker against your network infrastructure, covering both external testing (your internet-facing perimeter) and internal testing (your Active Directory and internal estate, simulating an attacker who is already inside). Precursor delivers external network penetration testing from £2,500 and internal network penetration testing from £6,250, fixed-price, with UK-based, DBS-checked, CREST-accredited testers.

Your network is the foundation everything else sits on: firewalls, VPN gateways, servers, and the Active Directory domain that controls access to every system you run. We test it from both sides, as an internet-based attacker probing your perimeter, and as an attacker who has already gained a foothold inside. One scoping call, fixed-price quotes for either engagement or both, delivered by CREST-accredited, UK-based testers.

External from £2,500
Internal from £6,250
Fixed-price quote within 24 hours
CREST Accredited Testers
Scroll
3,000+ Assessments DeliveredTriple-CREST Accredited24/7 UK SOC in NewcastleReports Accepted by Insurers & RegulatorsEst. 2018
Network Pen Testing, Explained
Updated August 2026

What is network
penetration testing?

A manual, human-led security assessment of your network infrastructure, run from two vantage points: outside your perimeter, and from inside it.

The Definition

Network penetration testing (also called infrastructure penetration testing) is a controlled, manual attack simulation against your network infrastructure. CREST-accredited testers attempt to gain unauthorised access, move between systems, and escalate privileges, then report exactly how, so you can fix it before a real attacker finds it.

It splits into two distinct disciplines, run from opposite vantage points:

External testing
Attacker on the open internet, no prior access. Firewalls, VPN gateways, mail servers, cloud perimeter.
Internal testing
Attacker already has a foothold inside. Active Directory, lateral movement, privilege escalation.

Unlike automated vulnerability scanning, which flags issues by matching software versions against CVE databases, network penetration testing involves a human tester who actively exploits weaknesses, chains low-severity issues into meaningful attack paths, and demonstrates real business impact. It is one of the core penetration testing services we deliver, alongside web application, API, and cloud engagements.

At a Glance
Fixed-price from
£2,500
External. Internal from £6,250. Approximately £1,200 per CREST-accredited consultant day.
Typical duration
2 to 5 days (external) · 5 to 8 days (internal, single domain)
Delivered by
Triple CREST-accredited, UK-based, DBS-checked testers
Included
Retest, executive summary, fixed-price quote within 24 hours
Methodology

The five phases of a network penetration test, whether internal or external.

01

Reconnaissance

Passive and active information gathering: mapping IP ranges, domains, exposed services, and (for internal engagements) hosts and Active Directory structure, before any exploitation begins.

02

Scanning

Enumeration of open ports, running services, and software versions against known vulnerability databases, building the target list for manual exploitation.

03

Exploitation

Manual, human-led exploitation of confirmed weaknesses: authentication bypass, chaining low-severity issues, and (internally) lateral movement and privilege escalation.

04

Post-Exploitation

Demonstrating real business impact: how far an attacker could reach, what data or systems they could access, and whether domain-level compromise is achievable.

05

Reporting

A technical report with CVSS-scored findings and reproduction steps, plus an executive summary for the board. Remediation retesting is included.

Choose Your Engagement

Two Disciplines. One Team.

Most organisations need both external and internal testing to cover their full network attack surface. Scope either individually, or together for complete perimeter and internal assurance.

Not sure which you need? Book a free scoping call and we will recommend the right combination based on your compliance requirements and threat model. Most organisations preparing for PCI DSS, ISO 27001, or cyber insurance renewal commission both as a single network and infrastructure penetration testing engagement.

What's Covered

The Full Infrastructure
Estate.

Combined, external and internal network penetration testing cover the infrastructure that sits beneath every application you run. Exact scope is confirmed during the free scoping call.

Internal Scope

Active Directory & Segmentation

Internal testing covers Active Directory security (Kerberoasting, AS-REP roasting, ACL abuse, GPO misconfiguration), lateral movement (Pass-the-Hash, Pass-the-Ticket, NTLM relay), privilege escalation from standard user to Domain Admin, and network segmentation (VLAN boundary verification, legacy firewall rule audit). See the full internal network penetration test scope.

External Scope

Firewalls, VPN & Perimeter

External testing covers firewall and router interfaces, VPN gateways (including SSL VPN), mail servers, DNS infrastructure, and cloud management consoles. See the full external network penetration test scope.

Why Precursor

CREST accreditation, without the wait.

Every network penetration test is delivered by triple CREST-accredited, UK-based, DBS-checked testers, and quoted within 24 hours of your scoping call.

Triple CREST Accredited

Company and individual tester accreditation, verifiable at crest-approved.org.

UK-Based, DBS-Checked

Every tester is based in the UK and vetted for sensitive engagements.

Retest Included

Remediation retesting is included in every fixed-price engagement.

24-Hour Quote

Fixed-price quote delivered within 24 hours of your scoping call.

CREST

Globally Accredited Consultants

All network testing is conducted by CREST-accredited professionals.

Verify Accreditation
After Testing

Close the Loop.
After the Test.

Your network penetration test identifies what is exploitable today. We feed those exact findings into our 24/7 Managed SOC, building custom detection rules for the exact paths found in your internal and external testing.

See the Closed-Loop Model
Service Catalogue

Full Penetration Testing Catalogue

Comprehensive penetration testing services tailored to your environment.

Related security terms

Plain-English definitions of the concepts behind this service, from our security glossary.

Ready to Secure

The best time to test your defences is now.

Join the high-growth companies relying on Precursor for continuous offensive and defensive security.

CREST Triple Accredited|Fixed Price Quotes|Free Scoping Call|UK Based Team

Frequently Asked Questions

Common questions about this service, methodologies, and deliverables.

Network penetration testing is a manual security assessment where CREST-accredited testers simulate a real attacker to find exploitable weaknesses in your network infrastructure: firewalls, VPN gateways, servers, Active Directory, and network segmentation controls. It covers two distinct disciplines. External network penetration testing simulates an attacker on the open internet with no prior access, targeting your internet-facing perimeter. Internal network penetration testing simulates an attacker who already has a foothold inside your network, testing lateral movement, Active Directory security, and privilege escalation. Most organisations need both to cover their full attack surface.

It depends on what you have not yet tested. External testing covers your internet-facing perimeter (firewalls, VPN gateways, mail servers, cloud management interfaces) and simulates an attacker with no prior access. Internal testing covers your inside-the-firewall environment (Active Directory, lateral movement, privilege escalation) and simulates an attacker who has already breached the perimeter, via phishing, a compromised VPN credential, or a malicious insider. Most compliance frameworks, including PCI DSS Requirement 11.3, require both as separate annual engagements. If you have only tested one side, your other attack surface has never been validated.

External network penetration testing starts from £2,500 for a small perimeter (2-3 days). Internal network penetration testing starts from £6,250 for a single Active Directory domain (5-8 days). Both are quoted at approximately £1,200 per CREST-accredited consultant day, fixed-price after a free scoping call, with no day-rate overruns. Organisations commissioning both tests together typically receive a combined fixed-price quote covering the full internal and external estate.

We recommend annual testing at minimum for both internal and external network penetration testing, or after any material infrastructure change: cloud migrations, new VPN endpoints, firewall rule changes, new office locations, or Active Directory domain changes. PCI DSS Requirement 11.3 mandates annual internal and external testing. ISO 27001:2022 Annex A.8.8 requires a managed programme of technical vulnerability testing, and cyber insurance underwriters increasingly require annual evidence of both.

Infrastructure penetration testing is the same discipline as network penetration testing, often used interchangeably by UK organisations to describe the broader category covering both internal network testing (the corporate LAN, Active Directory, internal servers) and external network testing (public-facing perimeter, firewalls, VPN gateways). When UK organisations request an infrastructure penetration test, they typically mean an assessment of the servers, endpoints, Active Directory environment, and network segmentation controls that make up their internal and external IT infrastructure, as distinct from a web application or API test.