CREST-Certified Internal Network Penetration Testing for UK Organisations
We model an attacker already inside the perimeter, a stolen laptop, a rogue insider or a phished employee, and prove how far they could move across your servers, Active Directory and internal services. Live findings during testing, free retests after remediation, fixed-price scope within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
compromised device is all it takes. Internal testing measures the blast radius of a single foothold before a real attacker does.
Perimeter testing checks the front door. Internal testing assumes someone is already inside.
External and perimeter testing checks what an outsider can reach. An internal infrastructure penetration test starts inside the perimeter, where a phished user, a lost laptop or a contractor’s device becomes the attacker’s foothold.
A CREST-certified tester attempts lateral movement, privilege escalation and Active Directory compromise by hand. Every technique is mapped to MITRE ATT&CK, from a standard foothold to a measured blast radius and a clear path to close each route.
ISO 27001 (A.8.8), PCI DSS internal testing, SOC 2 and Cyber Essentials Plus assurance all expect independent technical evidence. Scan-only evidence is generally insufficient.
WHAT WE TEST INTERNALLY
What We Test on Your Internal Network
Manual-led, assumed-breach testing across the techniques that turn one foothold into domain compromise. Every finding is verified, reproducible and mapped to MITRE ATT&CK, with a clear path to close each route.
Network Discovery & Enumeration
Host discovery and service enumeration across the in-scope internal subnets to build a complete picture of the estate before the manual phase begins.
Name-Resolution Poisoning
LLMNR, NBT-NS and mDNS poisoning to capture authentication on flat networks. We test SMB-signing posture and where a single response becomes reusable access.
NTLM Relay
Relay across SMB, LDAP and HTTP to turn captured authentication into hands-on access, then chain it toward higher-value systems.
Active Directory Attack Paths
BloodHound-led analysis of the shortest route from a standard user to domain admin, covering delegation, nested-group and ACL weaknesses.
Kerberos Attacks
Kerberoasting, AS-REP roasting and ticket manipulation against the domain to escalate from a low-privilege foothold.
Certificate-Services Abuse
Active Directory Certificate Services misconfigurations (ESC1 onward) for privilege escalation and persistence.
Credential & Secret Capture
Credential and ticket extraction under controlled conditions, plus review of reused, default and over-permissioned service-account secrets.
Lateral Movement & Pivoting
Host-to-host movement across the internal estate to reach the systems and data that matter most, demonstrating real blast radius.
Segmentation & Baseline Coverage
Authenticated vulnerability scanning to establish coverage, plus segmentation testing of user, server and sensitive VLAN boundaries.
ASSUMED-BREACH METHODOLOGY
Internal Network Penetration Testing: From Foothold to Attestation
CREST-aligned, assumed-breach methodology mapped to MITRE ATT&CK and NCSC penetration-testing guidance. From a standard foothold to a measured blast radius, then a clear remediation path.
Reconnaissance
Scoping, rules of engagement and a safe-word. Then host discovery and service enumeration across the in-scope subnets to map the internal estate.
Vulnerability Assessment
Authenticated vulnerability scanning to establish coverage, plus targeted manual checks for name-resolution weaknesses, SMB signing and exposed services.
Manual Exploitation
Hands-on testing by a CREST-certified tester. NTLM relay, Kerberos attacks, AD CS abuse, lateral movement and privilege escalation toward domain admin.
Reporting + Retest
CVSS-rated findings, an attack-path narrative, executive summary, a remediation debrief call, and a free retest of every fix.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a fixed Internal Network Test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Internal Network Testing Reports Mapped to Every Framework
An internal network penetration test gives you the independent technical evidence auditors and frameworks expect. It does not award a certificate; it produces the proof.
Cyber Essentials Plus
Deeper internal assurance beyond the authenticated CE Plus assessment. It does not grant certification, which only a licensed IASME body awards.
ISO 27001 (A.8.8)
Evidence supporting technical-vulnerability management within your ISMS, feeding independent review (A.5.35) and security testing (A.8.29).
PCI DSS (v4.0.1)
Independent internal testing of the cardholder data environment (Req 11.4.3) and segmentation validation (Req 11.4.5), at least annually.
SOC 2
Supporting evidence toward the Security (Common Criteria) Trust Services Criteria, in particular vulnerability identification (CC7.1).
NIS2 & DORA
Supports security-testing obligations under NIS2 (Art. 21) and DORA resilience testing. DORA Threat-Led Penetration Testing is a separate exercise.
Cyber Insurance & Audits
An independent CREST-certified report that insurers and enterprise security questionnaires increasingly require before binding cover or onboarding.
PRICING
Transparent Internal Network Penetration Testing Pricing
Priced by scope: as a rule of thumb we cover around 50 live hosts per tester-day. Every tester is senior or principal grade, so price reflects the size of your estate, not who we send. The included deliverables stay the same across all engagements.
Depends on app complexity
Up to around 150 hosts on one site with a single Active Directory domain. The common starting point for SMEs.
Get a fixed quoteDepends on app complexity
Around 150 to 400 hosts across several sites or multiple Active Directory domains, with trust relationships to follow.
Get a fixed quoteDepends on app complexity
400 hosts or more across a large, multi-domain estate, with segmentation testing and sensitive systems in scope.
Get a fixed quoteBY SECTOR
Internal Network Penetration Testing for Your Sector
Sector-specialist internal-network scoping for UK organisations with sector-specific compliance regimes and threat models.
Fintech & FCA-Regulated
FCA SYSC and PSD2 scrutiny, PCI segmentation testing, internal AD compromise paths.
Fintech sector pageSaaS Companies
Multi-tenant internal estates, SSO/SAML/OIDC back-ends, SOC 2 internal-testing evidence.
SaaS sector pageLaw Firms
SRA Cyber Standard alignment, privileged client data, partner-tier scrutiny on internal systems.
Law firm sector pageHealthcare
NHS DSPT, NHS DTAC, EHR and telehealth back-ends, patient-data PII on the internal network.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, claims-data systems, cyber-underwriting evidence from internal testing.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, PSN-compliance scrutiny, SC-cleared testers available.
Public sector pageWHY EJN LABS
What You Get
Not a scanner export. A clear account of how far an intruder could get inside your network, and exactly how to stop them.
Technical Report With CVSS-Rated Findings
Every issue rated, evidenced and reproducible, in the format your engineers and auditors expect.
Plain-English Executive Summary
The business risk in language the board and your insurer can read without a translator.
An Attack-Path Narrative
The story of how one foothold became domain compromise, step by step, so the fix is obvious.
Prioritised Remediation Guidance
What to fix first for the biggest reduction in risk, with practical, tested advice.
A Live Debrief Call With the Tester
Time with the person who did the work, to walk your team through every finding.
A Free Retest of Every Fix
We re-test everything you remediate, at no extra cost, so you can prove it is closed.
FAQ
Frequently Asked
What is internal network penetration testing?
An internal network penetration test simulates an attacker who already has access inside your network, then attempts to move laterally, escalate privileges and compromise Active Directory. It measures how far a single foothold, a phished user or a lost laptop, could spread before it reaches your most sensitive systems.
How much does an internal network penetration test cost in the UK?
Most UK internal network penetration tests fall between £1,200 and £14,400, priced by scope at a CREST-certified day rate of £1,100 to £1,400. As a rule of thumb we cover around 50 live hosts per tester-day, with every tester senior or principal grade. See our UK pen test pricing guide or get a fixed quote.
Do you test Active Directory?
Yes. Active Directory is usually the heart of an internal test. We assess Kerberoasting, AS-REP roasting, certificate-services abuse, delegation weaknesses and attack paths from a standard user to domain admin, using tools such as BloodHound and Impacket.
Will the test disrupt our network or services?
No. Testing is controlled, agreed in advance and run with a safe-word so we can pause instantly. Disruptive techniques are excluded by default and intrusive checks are scheduled out of hours where needed. Tell us your scope and we will plan around your operations.
What information do you need to scope an internal network pen test?
Usually just the approximate number of live hosts, the number of sites, how many Active Directory domains you run and your objectives. As a rule of thumb we cover around 50 live hosts per tester-day, then turn that into a fixed-price scope. Send us your rough scope for a quote within 24 hours.
What tools do you use?
Our testing is manual-led and consultant-driven. We use industry-standard tooling including Nmap, Responder, NetExec, BloodHound, Impacket, Certipy and Nessus, but the findings that matter come from a CREST-certified tester chaining them by hand.
What is the difference between internal and external penetration testing?
External or perimeter testing assesses what an outsider can reach from the internet, such as firewalls, VPNs and public services. Internal testing assumes that perimeter is already breached and tests what an attacker can do once inside. Most organisations scope both.
What is an assumed-breach test?
An assumed-breach test starts with the attacker already inside, for example with a standard user account or a device on your network. It skips the time and cost of bypassing the perimeter and focuses budget on what matters most: how far a real intruder could get.
How long does an internal network penetration test take?
A single-site internal test typically takes 3 to 5 working days. Larger estates with multiple sites or Active Directory domains take 6 to 12 days. We agree the exact duration during scoping based on host count and objectives.
Can an internal network pen test be done remotely?
Yes. We can ship a preconfigured testing device or use a secure jump host, so most internal tests run remotely with no tester on site. On-site testing is available where you prefer it.
Does internal network testing help with Cyber Essentials Plus, ISO 27001 or PCI DSS?
Internal network testing produces independent technical evidence that supports several frameworks: technical vulnerability management under ISO 27001 (A.8.8), internal penetration testing under PCI DSS (Req 11.4.3) and assurance beyond the Cyber Essentials Plus assessment. It does not award certification, which only a licensed body can grant.
What is internal infrastructure penetration testing?
Internal infrastructure penetration testing is another name for internal network testing. It assesses the servers, network devices, Active Directory and internal services that run your business, from the position of an attacker who is already inside the perimeter.
20+ CREST-certified testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed Internal Network Test quote in 24 hours
A CREST-certified pen tester will contact you within one business day with a fixed price, a realistic timeline, and the named consultant. No sales pipeline.



