Why You Need Internal Penetration Testing

Ajay Unni
Ajay Unni CEO,StickmanCyber
October 6, 2026 5 min read

It’s not just your external IT environment, but also internal networks and applications that must be secured against breaches. While external penetration testing has become common practice, compliance with the Payment Card Industry Data Security Standard (PCI DSS) also requires the lesser known internal penetration testing. Internal pen testing should be performed at least annually, and following any significant modification or upgrade to applications or infrastructure.

Internal pen testing needs to be standard practice

External pen testing highlights potential breaches coming from outside, such as an attack on exposed web applications. Internal pen testing mimics an attack from inside your organisation’s internal networks and applications, and assesses its potential impact. There are two main types of internal cyber-attack patterns:

  • An attack by a malicious individual with access to your Ethernet network, internal server or even a workstation. It can be even more devastating when the attacker already knows where to find sensitive organisational information. Internal pen testing is the most direct way to identify vulnerabilities to attack from within.
  • Release of a new application and its interaction with operating systems and processes can introduce security holes. Internal pen testing exposes potential vulnerabilities due to improper software and hardware configuration, or application perimeter defence susceptibility. Because installation of new software and changes to system configuration alter the whole system environment, scheduled internal penetration tests are essential to sustaining IT security.

Individuals with ‘insider’ access, and updating applications, are common situations that carry potential risk of security breach. For this reason, internal pen testing needs to become routine, alongside external pen testing.

Even SAP users of shared business-critical applications – such as Enterprise Resource Planning (ERP), Human Capital Management (HCM) and Supply Chain Management (SCM) – are finding security gaps to be a common issue. These gaps often arise from the lack of visibility in SAP and uncoordinated internal security procedures, without proper security strategies in place. This is why routine internal pen testing is strongly recommended for SAP users.

Another scenario would be when an attacker compromises one of the servers in your cloud environment and there is a communication channel open between the cloud environment and your network (e.g. a VPN tunnel). An attacker could use that as an entry point into your network.

Cyber security issues with cloud computing

Cloud computing has exploded into the mainstream, and has evolved to a preferred solution for data storage, service on-demand and infrastructure. Many organisations use shared, multi-tenant environment cloud services, which is where the issue of cyber security arises. There are several challenges to securing cyber assets within the cloud.

Who is responsible for cloud security?

First, it’s important to consider who is responsible for cloud security. There have been several incidents of breached cloud environments by cyber attackers. In many of these instances, the Cloud Service Providers (CSPs) cannot be blamed exclusively for the security breaches.

It’s a common misconception that CSPs are solely responsible for the cyber security of information in the cloud. In fact, responsibility also falls to the organisation itself. It is your obligation to ensure that what you upload to the cloud is secure – whether it’s customer information, platform and internal applications, internal network, access management and data encryption. CSPs are generally responsible for securing the underlying infrastructure that supports the cloud, with the exact split depending on the service model (IaaS, PaaS or SaaS). ASD’s ACSC cloud shared responsibility model guidance makes the same point for Australian organisations: as the customer, you always retain some responsibilities, and you can’t outsource the risk to your CSP. Internal penetration testing should, therefore, be applied to your cloud environments as well.

How internal penetration testing works

Internal networks and applications

  • Detailed information about the network and applications is collected using ‘white box’ techniques. Potential security weak spots are identified through DNS queries and traffic analysis. A full-fledged vulnerability assessment is also performed before the exploit phase.
  • An attack is executed by exploiting the weak spots, to gain unauthorised access to active directories, databases, web applications and network services. The organisation’s critical assets are then located by mimicking a real breach scenario, demonstrating how devastating an insider attack can be. Common targets for insider attacks are tax file numbers, electronic payment card numbers, employee personal information and an organisation’s proprietary information.
  • A detailed test report highlights any vulnerabilities that need to be addressed.

Internal pen testing your cloud environment

Internal pen testing for in-house infrastructure can be performed by a highly skilled internal IT team or a trusted third-party service. Pen testing a cloud environment is, however, somewhat different. Because CSPs run multi-tenant platforms, a test could affect the security of other user organisations, so CSPs set rules on what customers may test. Major providers such as AWS and Microsoft now permit customers to test their own cloud resources under published rules of engagement, while prohibiting activities that could affect other customers, such as denial-of-service testing.

Here are the options for internal pen testing cloud environments:

  1. Check your CSP’s penetration testing policy and, where it requires approval, obtain its permission for a pen test, although it may limit the testing of internal applications and data.
  2. CSPs usually carry out their own cloud pen testing for compliance with security standards. You can request a copy of these results, along with any related technology audit reports, and consolidate with your own pen tests.
  3. Alternatively, a pen tester can exploit a system or application, and use that as a pivot point for further test attacks on other applications and systems. This allows ethical hackers to attack from the insider’s point-of-view. This type of testing is usually allowed by CSPs with Platform-as-a-Service (PaaS) and Infrastructure-as-a-Service (IaaS) models. Because pen testing can affect the configuration of Software-as-a-Service (SaaS) models, CSPs with SaaS may not permit pen testing. In other words, pen testers need to take extra care when exploiting their own IPs, ports, instances and applications to avoid violating their CSP’s terms and conditions.

Summary

Internal penetration testing is equally important as external penetration testing. It allows your organisation to find – and address – potential vulnerability to cyber-attack by malicious insiders. It is also essential to apply pen testing to internal applications, whether they’re on-premises or in a cloud environment.

It’s important to understand the limitations and types of pen tests Cloud Service Providers allow, and to seek authorisation before performing them. Security of applications and data in the cloud is still a process that needs meticulous planning and constant vigilance.

Looking to identify the vulnerabilities in your cybersecurity setup? StickmanCyber's penetration testing services, accredited by CREST, comb through your systems, identify possible gaps, and prepare a comprehensive list of action items to mitigate risks.

Ready to proactively take charge of your cybersecurity? Book a penetration test today!

Ajay Unni

Ajay Unni

CEO,StickmanCyber Ajay Unni is CEO of StickmanCyber, leading the team in delivering cybersecurity, risk, and compliance solutions. He holds a Master of IT and a Bachelor of Computer Science, is a PCI Qualified Security Assessor and Certified Information Systems Auditor, and has served as CREST Vice Chairman and a member of the NSW Government Cyber Security Taskforce. With over 25 years in the industry, Ajay is a sought-after voice on the Australian cyber threat landscape.

Master of IT B. Computer Science PCI Qualified Security Assessor Certified Information Systems Auditor (CISA) CREST Vice Chairman NSW Gov Cyber Security Taskforce

Cybersecurity As A Service for Australian Organisations

StickmanCyber helps mid-market businesses across Australia and New Zealand reduce cyber risk, strengthen compliance, and build security maturity without the cost and complexity of managing it all internally.

Combining experienced cybersecurity specialists with AI-powered delivery, StickmanCyber provides practical, Cyber Done support across risk assessments, compliance, remediation, and ongoing protection — acting as a trusted partner from strategy through to certification and beyond.

CREST Accredited PCI-DSS ISO 27001 Essential Eight Since 2006
Book a free consultation
Risk Assessment & Essential EightUnderstand your current maturity and gaps
Compliance & CertificationISO 27001, PCI DSS, SOC 2 and more
Penetration & VAPTFind gaps, strengthen controls, build resilience
24/7 Monitoring via StickSecureContinuous visibility across your environment

Recent Posts