Network penetration testing in Canada
External network testing is what most companies buy and internal network testing is what most companies need. The two answer different questions, and only one of them tells you what happens after somebody clicks a link.
A network penetration test in Canada runs between $6,000 and $35,000 CAD. An external test of a small internet footprint sits at the bottom of that, around $6,000 to $15,000, and an internal test across an office network with a directory service and a few hundred hosts sits at the top, $12,000 to $35,000. The gap is not a quality difference. External and internal network testing are two different engagements that share a name, and buying the cheaper one because the words look similar is the most common scoping mistake here.
$6,000 to $15,000 External network test, CAD
$12,000 to $35,000 Internal network test, CAD
Internal Finds more, and is bought less often
External and internal are not two sizes of the same test
An external network penetration test starts from the public internet with nothing but your domain names and IP ranges. It answers one question: what can a stranger reach and exploit without any foothold. In 2026 the honest answer for a company that has moved to cloud hosting is usually "not much": the perimeter is a load balancer, a VPN appliance and a mail gateway. That is a short report, and a short report is a legitimate outcome.
An internal network penetration test starts from inside, normally under an assumed-breach premise: the tester is given a network drop or a standard laptop build and asked what an attacker who already phished one employee can reach from there. This is where the findings are, because internal networks were built for convenience over two decades and almost nobody has re-examined them since. Domain privilege escalation, credentials cached on file shares, service accounts with passwords that never rotate, printers and building systems sitting on the same segment as finance.
The uncomfortable ratio
Across the industry, external tests of a modern cloud-hosted company produce mostly low-severity findings about TLS configuration and information disclosure, while internal tests of the same company routinely produce a path to domain administrator. Companies buy the external test far more often because it is cheaper and because "external" sounds like the threat. If you can only fund one and you still run an office network with Active Directory, buy the internal test.
What an external network test actually covers
The work is discovery, service enumeration, and then attempts against what was found. A competent engagement spends real time on the discovery half. The finding that matters is normally something nobody knew was published: a forgotten staging host, an administrative interface exposed because a firewall rule outlived the project it was written for, a legacy VPN concentrator that never got decommissioned.
| Area | What the tester is looking for |
|---|---|
| Perimeter discovery | Hosts, subdomains and services you did not know were reachable |
| Edge devices | VPN gateways, firewalls and remote access appliances behind on patches |
| Exposed management | Administrative panels, database ports, remote desktop and file transfer services |
| Authentication surfaces | Password spraying against portals, multi-factor gaps, account lockout behaviour |
| Mail and name services | Domain-based message authentication records, zone transfer, relay abuse |
| Third-party edge | Services in your name run by someone else, which are still your exposure |
What an external test does not cover is your application logic. If the thing behind the firewall is a web product with logins and roles, an external network test will tell you the ports are closed and nothing about whether one customer can read another customer's data. That needs web application testing, and it is a separate line on the quote.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
What an internal network test covers
Internal testing is usually framed as assumed breach. The alternative is spending half the engagement getting in, which you can grant instead. The tester is given either a virtual machine on your network, a laptop, or VPN access with the same rights a new employee would have.
| Finding class | Why it is still everywhere in 2026 |
|---|---|
| Directory privilege escalation paths | Group nesting and delegation accumulate for years and nobody audits the graph |
| Credentials in file shares and scripts | A deployment script written in 2019 is still doing its job, and still has the password in it |
| Name resolution poisoning | Legacy broadcast protocols stay enabled because turning them off once broke a printer |
| Flat segmentation | The network was built before anyone assumed a workstation could be hostile |
| Service accounts with weak or old passwords | Rotating them requires knowing what would break, and nobody does |
| Unpatched internal hosts | Patching is scheduled around uptime for internal systems, so it slips |
If your company has no office network and everything runs in a cloud account, the equivalent engagement is not an internal network test. It is an identity and privilege path review of that account, described on cloud penetration testing. Buying a traditional internal test for an environment with no directory service wastes most of the budget.
Counting scope so the quote is comparable
Network testing is priced on live hosts and on the number of distinct environments, not on the size of the IP range you own. A /16 with eleven live addresses in it is an eleven-host engagement. Firms that quote on range size are quoting on the wrong number. Push back before you compare their price with anyone else's.
| Engagement | Tester days | Typical range |
|---|---|---|
| External, under 15 live hosts | 3 to 5 | $6,000 to $14,000 |
| External, 15 to 100 live hosts | 5 to 8 | $10,000 to $22,000 |
| Internal, single site, one directory | 5 to 10 | $12,000 to $28,000 |
| Internal, multi-site or multi-domain | 8 to 15 | $20,000 to $35,000 |
| Wireless testing added to an internal test | 1 to 2 | $3,000 to $6,000 |
| PCI DSS segmentation testing | 2 to 4 | $5,000 to $12,000 |
Those ranges come from tester days at Canadian rates of roughly $1,500 to $2,800 CAD a day, which is the arithmetic explained on penetration testing cost in Canada. The cost calculator applies the same day counts to a scope you describe.
What to hand over before the test starts
Every hour the tester spends working out your network is an hour not spent testing it, so the answer is almost everything. A list of in-scope ranges with the live hosts marked. A note of anything fragile, which is not a request to avoid testing it but a request to be told before it is touched. Contact details for someone reachable during the test window. For internal work, credentials for a standard user account and a description of what a normal employee can reach.
Two things belong in writing rather than in a conversation: whether denial-of-service conditions are permitted, which is almost always no, and whether the tester may use captured credentials against systems outside the agreed range, which is also no. Both exclusions belong in the rules of engagement on penetration testing services.
How often to retest a network
Annually is the compliance default and it is a poor engineering trigger. Networks change through events rather than through time. Retest after a merger, after a site opens or closes, after a firewall migration, after a VPN or remote access product is replaced, and after any change that alters what is reachable from where. If none of those happened this year, an annual external retest mostly buys you a current dated report for the auditor. That is a real reason, and it should be priced as the small engagement it is.
When continuous external scanning beats an annual test
For an external perimeter that changes often, an annual test is a snapshot of one Tuesday. A continuous external scanning service at $2,000 to $5,000 CAD a year will notice the certificate that expired in March and the management interface somebody exposed in July, neither of which an annual engagement catches. The honest arrangement for many Canadian companies is continuous scanning on the perimeter plus one manual internal test a year. Internal assumed-breach testing is the half automation cannot do, and the half most buyers skip. The cadence argument is on how often you should test.
Get a network test scoped properly
Tell us what the footprint looks like and who asked for the test, and we will put one scope in front of Canadian firms.
Get matchedCommon questions
Do we need internal network testing if all our staff work remotely?
If there is no office network, no directory service and no shared file storage, then a traditional internal test has nothing to test and you should not buy one. What replaces it is a review of the identity provider and the cloud accounts, because that is now where lateral movement happens. If you still run a directory service for laptop management, that directory is in scope even with nobody in an office.
Is a network penetration test the same as a vulnerability scan?
No. A scan enumerates known vulnerabilities against a signature database and stops there. A network penetration test uses scanning as one input and then chains what it finds: using one machine's credentials to reach another, escalating within a directory, moving between segments. The difference is explained at length on vulnerability assessment versus penetration test.
Will testing take our systems down?
It should not, and the risk is managed through the rules of engagement rather than through hope. Denial-of-service testing is excluded by default. The genuine risk is old and fragile equipment, industrial controllers, building systems and unsupported appliances, which can fail on ordinary scanning. Tell the tester which those are before the test rather than afterwards, and agree a stop condition and a contact who is reachable during the window.
Can one engagement cover external and internal together?
Yes, and it is normally better value than buying them separately, because the tester carries context across both and the reporting overhead is paid once. Expect the combined quote to be close to the sum of the tester days rather than a discount on them. What should not happen is the day count for each half shrinking to fit a combined price.
Does an auditor accept an external test on its own?
It depends on what your scope statement says. If your SOC 2 or ISO 27001 scope covers a product hosted in a cloud account and no corporate network, external plus application testing is a coherent answer. If your scope includes an office network where staff handle in-scope data, an auditor can reasonably ask why that network was never tested. Match the test scope to the scope statement, not to the budget.