Get a free audit

Internal Penetration Testing · United Kingdom

Internal network penetration testing. One laptop falls. We show you the rest.

Assume an attacker already phished someone. That is not pessimism, it is what happened to 38% of UK businesses last year. We start from that position and map every step from one ordinary user account to your crown jewels.

CREST-certified operators · assumed-breach methodology · every finding human-verified

What is internal network penetration testing?

Internal network penetration testing measures how far an attacker travels once they are already inside. The tester starts from a realistic foothold, usually a standard user account on a standard workstation, and works toward the systems that would actually hurt you: the finance share, the customer database, domain admin.

This is called an assumed-breach test, and it is the honest one. Phishing reached 38% of UK businesses in the last year, and among firms that were breached, 69% named phishing as their most disruptive attack, according to the Cyber Security Breaches Survey 2025/2026 (DSIT). Somebody will click eventually. The question your board should be asking is what happens in the ninety minutes afterwards.

In most engagements the answer is uncomfortable. A single ordinary account, with no special privileges, reaches domain admin through a chain of small misconfigurations that no individual scanner flags as critical.

What we attack

The path from one user to everything

Every assessment starts where an attacker would: outside, watching, looking for the one door left ajar. We find it, then we show you the walk-through.

SurfaceWhat we look for
Active DirectoryKerberoasting, AS-REP roasting, unconstrained delegation, ACL abuse and the privilege chains that lead to domain admin.
Credential harvestingCached credentials, service accounts with weak passwords, secrets sitting in scripts, shares and Group Policy.
Network segmentationWhether your user network can actually reach your server network, your card environment and your backup infrastructure. Segmentation that exists on a diagram often does not exist on the wire.
File shares and dataWhat an ordinary account can read. Payroll, contracts, customer data and credentials sitting in a folder that inherited the wrong permission in 2019.
Host securityLocal privilege escalation, unpatched workstations and servers, missing application allow-listing, and endpoint protection that can be bypassed.
Backups and recoveryWhether the account we compromised can reach, encrypt or delete your backups. This is the finding that turns an incident into a crisis.

What you get

The full path, step by step, with the break points

Every assessment starts where an attacker would: outside, watching, looking for the one door left ajar. We find it, then we show you the walk-through.

Your deliverable
  • A narrated attack path from the starting account to the crown jewels, with timestamps
  • The exact misconfigurations that made each step possible, in order
  • The break points: which single fix collapses the longest chain
  • What we could reach: named shares, named systems, named data
  • Verified by a CREST-certified operator before it reaches you
  • A year of unlimited re-tests through RTP Robin as your estate changes
CRESTISO/IEC 27001Cyber EssentialsOffensive Security OSCPGIAC GXPNGIAC GWAPTGIAC Advisory BoardCompTIAOWASPNISTCRESTISO/IEC 27001Cyber EssentialsOffensive Security OSCPGIAC GXPNGIAC GWAPTGIAC Advisory BoardCompTIAOWASPNIST

Before you ask

Internal penetration testing, answered

Every assessment starts where an attacker would: outside, watching, looking for the one door left ajar. We find it, then we show you the walk-through.

What is internal network penetration testing?

Internal network penetration testing is an authorised attack carried out from inside your network, starting from a position an attacker would realistically occupy after a successful phish or a stolen laptop. The tester works from that foothold toward your most sensitive systems, proving which privilege escalation and lateral movement paths actually work. It answers the question an external test cannot: once somebody is in, how far do they get, and how fast?

What is an assumed breach test?

An assumed breach test skips the initial compromise and begins from the assumption that an attacker already has a foothold, typically one standard user account on one standard workstation. It is efficient, because the initial compromise is the part you can be most confident will eventually succeed, and because it puts the whole engagement into the part of the attack chain that most organisations have never tested.

Do you need domain admin access to run the test?

No, and asking for it would defeat the purpose. We start with the access an ordinary employee has, because that is what an attacker starts with. If we reach domain admin during the test, that is a finding rather than a prerequisite. We agree the starting position with you before we begin, and we can run it from a supplied laptop, a virtual machine on your network, or a standard account, whichever reflects your real risk.

How is this different from a vulnerability scan of our internal network?

An internal vulnerability scan returns a list of missing patches, host by host. It has no concept of a path. The findings that matter in an internal test are almost never single critical vulnerabilities. They are chains: a readable share leads to a service account password, which leads to a server, which leads to a delegation misconfiguration, which leads to domain admin. Every individual step in that chain often rates as low or medium on a scanner. Together they end your week.

Find out how far one clicked link actually travels.

Get a free audit