Two vantage points, one service

External and internal scanning: what each covers

An external vulnerability scan examines your internet-facing assets from outside your network, seeing exactly what an attacker on the internet can reach and probe. An internal vulnerability scan runs from inside, via an agent or appliance, showing what an attacker or malicious insider could reach after gaining a foothold.

The short version

Internal vs external vulnerability scanning, side by side

The two scan types answer different questions. External scanning answers "what can anyone on the internet see and exploit right now?". Internal scanning answers "if something got in, or someone plugged in, how far could they get?". Most compliance regimes eventually ask for both, so the comparison below is worth five minutes before you commit to anything.

  External vulnerability scanning Internal vulnerability scanning
Vantage point From the internet, outside your perimeter: the view an attacker gets of anything with a public IP address or hostname. From inside your network, via an installed agent or a small virtual appliance: the view an attacker gets after a foothold.
What it finds Exposed services and open ports, expired or weak certificates, unpatched internet-facing software, misconfigured public systems. Missing patches on servers and endpoints, insecure default settings, legacy protocols left enabled, weaknesses reachable between internal systems.
Typical cadence Monthly as standard on our Essential band; quarterly is the minimum PCI DSS accepts for merchants. Monthly or weekly, usually aligned to your patch cycle so each report shows whether last month's fixes landed.
Compliance drivers PCI DSS Req 11.3.2 quarterly external scans by an Approved Scanning Vendor; Cyber Essentials Plus assessors scan internet-facing in-scope systems; ISO 27001 control A.8.8. PCI DSS Req 11.3.1 quarterly internal scans; Cyber Essentials Plus assessors also examine in-scope internal devices; ISO 27001 control A.8.8 evidence across the estate.
Deployment effort Minimal. Your scanner needs your external IP ranges and hostnames in scope; we configure and schedule the scans on it for you, or ingest the results of the scans you run. An agent on in-scope machines or an appliance on the network, deployed on your scanner with our guidance during onboarding.

Compliance requirements stated above reviewed July 2026. Quarterly external PCI scans must be performed by a PCI-SSC Approved Scanning Vendor; we arrange these through our ASV partner and manage the process end to end. Details on the PCI ASV scanning page.

The outside view

What an external vulnerability scan actually surfaces

Everything with a public IP address or hostname gets examined from the same position an attacker occupies. In practice, four categories account for most of what we report:

  • Exposed services. Databases, remote access services and admin panels answering on public addresses that nobody intended to publish. These are the findings that most often turn out to be urgent.
  • Certificate problems. Expired certificates, certificates about to lapse, and public endpoints still accepting outdated protocols and weak ciphers.
  • Unpatched internet-facing software. Web servers, VPN gateways, firewalls and mail systems running versions with publicly known vulnerabilities, which is where most opportunistic compromises begin.
  • Misconfiguration. Default pages left live, directory listings, overly chatty error responses and storage shared more widely than anyone realised.

Raw scan output is noisy, so a consultant triages every finding before it reaches you: false positives removed, duplicates merged, and the remainder put through our proprietary risk analysis and ranked by actual exposure rather than raw severity score. The how it works page walks through that cycle.

The inside view

What internal scanning adds

External scanning tells you nothing about the ninety-odd percent of your estate that does not face the internet. Internal scanning, run from an agent or appliance inside the network, covers the rest:

  • Lateral exposure. What a single compromised laptop or phished account could reach next: the file servers, management interfaces and shared systems an attacker would move towards.
  • Missing patches on servers and endpoints. The operating system and application updates that never landed, invisible from outside but exactly what malware looks for once inside.
  • Insecure defaults. Services switched on out of the box that nobody uses, weak local configurations, and legacy protocols still enabled years after they should have been retired.

Internal findings feed the same triage and the same monthly report as external ones, so you get one prioritised fix list for the whole estate rather than two documents that disagree.

Decision guidance

Which do you need, and when?

Every organisation needs external scanning. Your internet-facing systems are being probed by strangers whether you scan them or not; the only question is whether you find the weaknesses before someone else does. It also requires nothing deployed on your side, which makes it the natural starting point.

If you take card payments, PCI DSS settles the question for you: Req 11.3.2 requires quarterly external scans by an Approved Scanning Vendor and Req 11.3.1 requires quarterly internal scans, so merchants need both. We fold the ASV cycle into the service through our ASV partner; see quarterly PCI ASV scanning.

If Cyber Essentials Plus is on your calendar, your assessor will scan in-scope systems, internal devices included, on assessment day. Regular scanning of the same scope beforehand means the assessment confirms what you already know instead of surprising you.

If you hold or are pursuing ISO 27001, control A.8.8 expects vulnerabilities to be identified and managed across the estate, not just at the perimeter, and auditors ask for cadence and treatment evidence. Monthly reports covering both views are precisely that evidence.

If neither applies yet, start with the internal estate your scanner already covers, fix what the first cycle finds, and fold external coverage into the same view whenever you are ready. The first assessment cycle establishes the full baseline before the monthly rhythm takes over.

Compliance positions stated above reviewed July 2026.

The managed service

How the managed service delivers both

Our managed vulnerability scanning service is built around the scanner you already licence, whether that is Nessus, Tenable, Qualys or another. On the Essential band, from £1,890 per month, it covers the external view: we configure and run monthly scans of your internet-facing assets on your tooling, or ingest the exports from the scans you run, with every finding put through our proprietary risk analysis and a prioritised report with remediation guidance.

The Managed band, at £2,870 per month, rolls up to five scanners into one view, covers the internal estate through your scanner's agents or an appliance, and includes remediation guidance calls, so the inside and outside views land in one report with one fix list.

All three bands, Essential, Managed and Complex, are published in full with no quotation round trip: see the pricing page for the whole ladder.

Asked most often

Questions about external and internal scanning

Internal vs external vulnerability scanning: which do we need first?

Start external. Your internet-facing systems are the ones every attacker on the planet can already probe, so weaknesses there carry the most immediate risk and external scanning needs nothing installed on your side.

Add internal scanning once the outside view is under control, or straight away if a compliance regime asks for it: PCI DSS requires both, and Cyber Essentials Plus assessors examine in-scope internal devices as well as what faces the internet.

See what each band includes

Will vulnerability scanning disrupt our systems?

A vulnerability scan identifies weaknesses; it does not attempt to exploit them. Scans are rate-limited so they behave like modest background traffic, and internal scans can be scheduled into quiet windows if you prefer.

The rare exceptions are fragile legacy devices, which we identify during onboarding and handle with exclusions or gentler scan profiles rather than surprises.

How long does a vulnerability scan take?

An external scan of a typical SME footprint completes within hours. Internal scans vary with the number of devices in scope, from a few hours to a day or so for larger estates.

As a managed customer you never babysit a scan. We schedule and run them on your own scanning tool, or ingest the exports where you prefer to run them yourself; a consultant triages what comes back, and you receive a prioritised report each month.

How the service runs month to month

Does internal scanning need an agent on every machine?

No. Whichever scanner you run, Nessus, Tenable, Qualys or another, internal scanning comes either from lightweight agents on in-scope machines or from a small virtual appliance that scans across the network from one place. Appliances suit office and server estates; agents suit remote-heavy fleets where laptops rarely touch the office network.

Most organisations end up with a mix. We recommend the split during onboarding and configure the deployment on your tooling, or guide your team through it.

Rocket above the Managed Vulnerability Scanning call to action

Outside view first

Find out what your estate shows the internet

In one free 45 minute session a consultant walks your external footprint, works out whether internal scanning belongs in scope, and lands on a monthly figure before you commit to anything.