Coreย argumentย
Traditional internal penetration tests gives executives false confidenceย becauseย it’sย typically scope-limited, scheduled,ย doesn’tย reflect real attacker behaviourย and ignores the AI threats with user access.
Would you feel comfortable boarding a plane if the pilot had practised emergency landings but had never actually simulated an engine failure?ย
So, why do businesses specifically exclude their most critical systems from the testing scope, especially when those systems are part of the veryย exploitation pathย attackers use?ย
ย Key angles across the series:ย
- Theย real-worldย difference between “can we break in” vs “will we detect and respond when they do”ย
- What cannot be seen is not understoodย
- Why annual tests create 364 days of unknown vulnerabilityย and exposureย
- The problem with “safe” testing that avoids business disruptionย
- Red teaming vs pen test vs continuousย securityย validationย
What is an External Penetration Test?
An external penetration test simulates a cyberattack from outside an organisationโs network to identify vulnerabilities in internet-facing systems such as websites, servers and remote access services.
Security experts attempt to safely exploit weaknesses to assess risk and provide remediation guidance, helping organisations reduce exposure to real-world attacks originating from the internet.
The Monday Morning Questionย
Let’s put this into business context. The annual penetration test report arrives. ย
- Twenty pages, executive summary up front.ย ย
- “Low risk” findings only.ย ย
- A handful of configuration tweaks recommended.ย ย
Nothing critical.ย All good.ย ย You feel relieved. ยฃ10,000 well spent. Boardย update will be straight-forward.ย The auditors will be satisfied.ย ย Here’sย what the reportย doesn’tย tell you:ย You have no idea ifย you’dย detect a real breach.ย
The Comfortable Fiction of Scheduled Securityย
Let me tell you about aย businessย last year.ย They’dย receivedย clean pen test results for three consecutive yearsย and just completed the latest one.ย ย Security wasย “validated”ย annuallyย for ISOย 27001.ย They were confidentย with minor follow ups.ย
An inquisitive new COO posed a questionย โ โDoes that really reflect a real-world attack though?โย The CISO reached out.ย We ran a purple team exercise,ย a cooperative test, not known to others took place,ย where attackers and defenders work together to improve detection.ย ย
Within four hours, we had:ย
- Compromised a user account via aย credential stuffing attackย (their MFAย wasn’tย enforced onย aย legacy VPN)ย
- We found an unpatched development AWS instance with storage services and recovered keysย ย
- We moved laterally to a domain controller, without detectionย
- Weย exfiltratedย unclassified data whichย transpiredย wasย sensitiveย ย
- Weย establishedย persistent access through three different backdoorsย
- Weย deepfakedย the Chief People Officerโs email account with a new employee benefits emailย to allย staff,ย we got a 23% click through rate and 47 email addresses and contact details.ย ย
The security endpoint and SIEM solutions detected nothingย unusual.ย ย
- One alert firedย during the emailย campaignย but it was classified as only medium severity.ย ย
- The SOC team wasย monitoringย dashboards that were showing green while we methodicallyย progressed.ย
Situation Analysis
None of the techniques we used were sophisticated.ย All real-world.ย No zero-days. No advanced malware. Just patient, methodical exploitation of common misconfigurations andย gaps in visibilityย with some standard automations.ย
Theย previousย pen tests had all been “clean” because those tests never asked the critical question:ย “If we bypass your prevention, will you notice?”ย
Related article: Continuous Security Validation: Why Security Investments Fail Under Real Attack Conditions
What do External Penetration Tests Actually Test?
Traditional penetration testing focuses onย “can we get in”ย rather thanย “will you notice when someone does?”.ย ย
Some look at how far an exploitation path progression but this needs to be correlated against monitoring services.
This creates a dangerous gap:ย
- What external penetration tests validate:ย Presence of vulnerabilitiesย and exploitation pathwaysย
- What they rarelyย validate:ย Detection capabilities,ย monitoring andย response effectiveness,ย correlation processes,ย recovery proceduresย
The Bad Actors know these gaps exist and actively target them:ย
- 68% of organisationsย rely primarily on annual penetration testing for security validationย
- Less than 20%ย test their security operations ability to detect real attack techniquesย
- 12%ย haveย validatedย their incident response plan under realistic breach conditions (having an IR plan on paper does not prepare you for the real thing!)
- Average dwell time for breaches:ย 194ย daysย
- Persistence is now a primary attackย breach head inย 24% of attacksย
Put another way, ifย yourย Organisation testsย for vulnerabilitiesย once a year, but real attackersย maintainย access for seven months on average, how do you know they are there?ย
Attack vectors against large UK companies through 2025 all confirmed persistence and presence wasย establishedย at least 12 months previously.ย ย
You’ve been breached, can you answer these questions?
The mostย common questionsย initially asked of usย in the event ofย a detected breach are:ย
- How did they access our network?ย
- Are they still here?ย
- What have they taken?ย
External penetration testing would only seek to validate part of question 1. These are patient, informed (from research) and motivated adversaries who don’t operate to your schedule.ย
ย
Next in the Series
If your penetration testing happens once a year, and the average attacker remains undetected for over six months, then for most of the year your organisation is operating on assumption, not evidence. And assumption is not security.
In the next article I’ll break down five ways penetration tests can unintentionally create false confidence, from scope exclusions and pre-announced testing to the fundamental gap between finding vulnerabilities and validating detection. Find out about CloudGuard’s penetration testing UK services.ย