Penetration testing in NZ splits into two distinct exercises, internal and external, and they answer different questions about your security. This guide explains the difference, which one a New Zealand SMB should run first, what testing costs, how often to test, and how the results support cyber insurance applications and SMB1001 certification.
It is written for IT managers and owners in regulated sectors such as finance, health, legal and professional services who need a defensible testing programme rather than a sales pitch. If you want the fundamentals first, our broader guide to penetration testing for NZ businesses covers why testing matters at all; this article goes deeper on the internal versus external decision.
What is the difference between internal and external penetration testing?
External penetration testing attacks your internet-facing perimeter, the firewalls, VPN endpoints, email services, web applications and cloud entry points visible to anyone online. Internal penetration testing starts from an assumed breach inside your network and measures how far an attacker can move laterally, escalate privileges and reach your sensitive data.
An external test answers the question every board asks first: can someone break in from the internet? The tester works from outside with no access at all, exactly as an opportunistic attacker would. They map your exposed services, probe firewall rules and remote access, test Microsoft 365 and other cloud entry points for weak authentication, and attempt to exploit any public web applications.
An internal test assumes the perimeter has already failed, which is realistic given that most breaches start with a phishing email rather than a firewall exploit. The tester connects a device inside your network, or works from a standard staff account, and attempts lateral movement between systems, privilege escalation towards administrator rights, and access to the finance shares, client records or clinical data that would cause real damage to your organisation.
Put simply, external testing proves whether attackers can get in, and internal testing proves what they could take once they are in. A mature security programme eventually needs both views.
Which does a NZ SMB need?
Most NZ SMBs should run an external penetration test first, because the internet-facing perimeter is where automated, opportunistic attacks land every day. Add internal testing once the external result is clean, or earlier where a regulator, insurer or board requires assumed-breach assurance. Regulated verticals such as finance and health generally need both.
The internal vs external pen testing decision comes down to exposure. The National Cyber Security Centre, which now incorporates CERT NZ, consistently reports phishing, credential attacks and business email compromise among the most common incidents affecting New Zealand small businesses, and all of them arrive through the perimeter you show the internet. Testing that perimeter first removes the cheapest attack paths.
Internal testing earns its place in three situations. First, when your external test comes back clean and you want to know what a phished staff account could actually reach. Second, when an insurer, regulator or board asks for assumed-breach assurance rather than perimeter assurance. Third, when you hold data whose loss would be material: patient records, trust accounts, client files or payment data.
If the question is still whether you need a pen test at all, insurers and enterprise customers are increasingly answering it for you by asking for recent test reports in proposal forms and supplier questionnaires. Our penetration testing service covers both types, and most engagements for regulated clients combine them into a single scoped programme so the report reads as one risk picture.
How much does penetration testing cost?
On international benchmarks, external penetration testing typically costs USD $5,000 to $20,000 and internal testing typically USD $7,000 to $35,000. New Zealand pricing varies with scope rather than tracking those figures directly. The practical answer comes from scoping: the size of your external footprint, your internal host count, and whether a retest is included.
Three factors move the number more than anything else:
- External footprint size. A business with one office firewall, a VPN and Microsoft 365 sits at the small end of the range. Multiple public IP ranges, several web applications and legacy remote access push the effort up.
- Internal host count. Internal testing effort scales with the number of servers, workstations and network segments in scope, which is why internal engagements carry the wider price range.
- Retest inclusion. A retest after remediation verifies that fixes closed the findings. Some quotes include it, some price it separately, and the difference matters when you compare proposals.
When comparing penetration testing cost across NZ providers, confirm each quote covers the same scope and includes the retest. Be cautious of very cheap offers, which are usually a rebadged vulnerability scan rather than genuine hands-on testing. OxygenIT does not publish a flat price because footprints differ so much; we scope your environment on a discovery call and give a fixed quote with the retest included, so there is no meter running.
How often should you run a pen test?
Run a penetration test at least annually, and after any major change such as a cloud migration, a new public-facing application or a merger. Regulated industries and higher-risk environments move to quarterly or continuous testing. Always retest after remediation so you can prove the fixes worked, not just that they were made.
Annual testing is the baseline insurers and certification assessors expect, but the calendar is not the real trigger. Change is. A migration to new cloud infrastructure, a new customer portal, an acquisition that joins two networks, or a new integration with a partner all create fresh attack surface that the previous report never saw.
A penetration test is also a point-in-time exercise: it proves your position on the day of testing and nothing after. Between tests, continuous monitoring closes the gap, which is why many clients pair an annual test with a managed SOC that watches for the attacks a report can only predict.
Penetration testing vs vulnerability scanning: what is the difference?
A vulnerability scan is an automated sweep that lists known weaknesses, while a penetration test is a human-led engagement that exploits weaknesses to prove real impact. Scans run monthly or continuously at low cost; penetration tests run annually and demonstrate what an attacker could actually achieve in your environment.
| Aspect | Vulnerability scan | Penetration test |
|---|---|---|
| Method | Automated tooling matching known signatures | Human-led attack simulation supported by tools |
| Depth | Surface level, flags known CVEs and misconfigurations | Chains weaknesses into full attack paths |
| Human exploitation | None, findings remain theoretical | Yes, testers exploit findings and document impact |
| Output | Long automated list with severity scores and false positives | Prioritised report of proven, exploitable issues with remediation steps |
| Frequency | Monthly or continuous | Annually and after major change |
| Cost band | Low, often bundled with managed IT | USD $5,000 to $35,000 depending on scope |
| What it proves | Known weaknesses exist | Weaknesses are exploitable, and what an attacker could reach |
The two are complements, not substitutes. Scanning keeps a continuous baseline between tests, and a penetration test validates that the scanner and your patching programme are not missing something a human attacker would find. If a vendor quotes a suspiciously cheap penetration test, ask whether a person will actually attempt exploitation; if not, you are buying a scan.
How does pen testing support cyber insurance and SMB1001?
Penetration testing gives insurers and certification assessors independent evidence that your security controls actually work. NZ cyber insurance proposal forms increasingly ask whether you test and how findings are remediated, and for SMB1001 Gold, penetration test results give a company director the confidence to attest that the required controls are genuinely in place.
On the insurance side, underwriters have moved from asking whether you have a firewall to asking for evidence that your controls are tested. A current penetration test report, plus proof that the findings were remediated, answers that line of questioning directly and supports better terms. If you need a pen test for cyber insurance, run it well before renewal so remediation is complete when the proposal form arrives. Our guide to cyber insurance requirements in NZ breaks down what underwriters now ask of SMBs.
SMB1001 is a five tier cyber security certification standard developed by Dynamic Standards International and certified through the CyberCert platform, and it has become a recognised certification path for NZ SMBs. Bronze, Silver and Gold are certified by director attestation, which means a director personally signs off that the controls exist. A recent penetration test is exactly the evidence a prudent director wants before signing at Gold, because it tests the controls rather than the paperwork. Our SMB1001 Gold certification guide covers the full control list.
Treat testing as evidence, not box ticking. A report commissioned to satisfy a form and then filed unread does nothing for the organisation; the same report driving a remediation plan satisfies the insurer, strengthens the attestation and actually reduces risk.
Common scoping mistakes, and how internal and external tests work together
The most common scoping mistake is treating internal and external testing as substitutes rather than complements. External testing shows what an outsider can reach from the internet; internal testing shows what happens once someone, or something, gets past that perimeter. Skipping one leaves a real gap: a business that only ever tests externally has no evidence of what a phished employee or a compromised device could actually do once inside.
The second common mistake is an incomplete asset list. A scope built from memory rather than a current inventory misses shadow IT, forgotten test servers, and recently added cloud services, exactly the kind of overlooked asset an attacker finds first. Confirm your asset list against your actual environment, not last year’s network diagram, before a test starts.
Run internal and external results together, not as separate reports filed apart. The real risk picture is the combination: an external finding shows the entry point, an internal finding shows how far that entry point could carry an attacker, and remediation should be prioritised against that combined path rather than each report’s list in isolation.
Penetration testing NZ: frequently asked questions
Do small NZ firms really get targeted by attackers?
Yes. Most attacks on small firms are automated and opportunistic rather than targeted. Scanners sweep the whole internet for exposed services, weak VPN endpoints and unpatched applications, and NZ addresses appear in those sweeps every day. Attackers do not check company size before trying a door; they exploit whatever responds. Size is not a defence.
Will a penetration test disrupt our operations?
A well scoped test rarely disrupts operations. Testers agree rules of engagement up front, covering which systems are in scope, which hours testing runs in and how fragile systems are handled. Denial of service is excluded by default. Most clients notice nothing beyond a small amount of extra network traffic during the testing window.
What is included in a penetration test report?
A good report contains an executive summary written for directors, a technical findings section with severity ratings, evidence of each successful exploit, and clear remediation steps ranked by risk. It should also state the scope, the methodology and the dates tested, because insurers and auditors check those details when the report is used as evidence.
What is the difference between a penetration test and a red team exercise?
A penetration test measures how many exploitable weaknesses exist within an agreed scope over one or two weeks. A red team exercise simulates a specific adversary over a longer period, testing detection and response as well as prevention, often without warning defenders. Most NZ SMBs get far more value from penetration testing first.
Do we need consent from cloud providers before a pen test?
Usually no formal approval is needed, but policies differ. Microsoft and AWS allow penetration testing of your own tenant and workloads without prior notice, provided testers follow their published rules and avoid denial of service. Some SaaS platforms still require notice or prohibit testing, so your tester should confirm each provider policy during scoping.
How should we prepare for a penetration test?
Agree the scope and objectives, nominate a contact for the testing window, confirm backups are current and tell your tester about fragile systems. Decide whether to inform staff, since unannounced tests give a truer picture. If you are unsure where to start, contact OxygenIT and we will walk you through scoping in plain language.
Book a penetration test with OxygenIT
OxygenIT has run IT and security for New Zealand businesses since 2005, more than 20 years. We are ISO 27001 and ISO 42001 certified, Christchurch based with coverage in Wellington. Penetration testing is scoped to your actual footprint, quoted as a fixed price, and every engagement includes a retest of remediated findings.
Book a discovery call and we will map your external footprint and internal environment, then give you a fixed quote and a start date. Or call us on 0800 101 095.