The problem
A scan of the perimeter is not a network test.
External-only PDFs miss what a stolen credential can do inside. Internal-only tests miss the internet edge an adversary already sees. Scanners list possibilities; they do not prove the path.
Yearly external tests never walk the inside, so lateral movement stays theoretical.
Internal tests without the edge miss how an attacker actually gets in.
Severity-ranked scan output does not tell you which route works against this network.
Both sides
External
What the internet can see
Internal
What a foothold can reach
One plan. Both sides of the perimeter.



