Threat-led penetration testing
Threat-led penetration testing under DORA Article 26
Threat-led penetration testing (TLPT) is not a bigger penetration test. It is a controlled exercise in which a red team attacks the live production systems that support your critical or important functions, using the tactics of threat actors that realistically target your institution, while your defenders continue operating normally, unaware of the exercise.
For financial entities identified by their competent authority under Article 26 of DORA, this testing is a supervisory obligation, to be performed at least every three years. The TIBER-EU framework, developed jointly by the European Central Bank and the national central banks of the EU, is the established model behind it. Since July 2025 the binding requirements come directly from Commission Delegated Regulation (EU) 2025/1190, the regulatory technical standards on TLPT.
How is TLPT different from a normal penetration test?
A penetration test targets selected systems, often outside production. It is driven by a scope agreed with you, your defenders usually know it is happening, oversight sits with you alone, and you choose the frequency.
A threat-led penetration test targets live production systems supporting critical or important functions. It is driven by threat intelligence on the actors that target your institution, the defenders are deliberately not informed, oversight includes your White Team (the internal control team) and the authority, and entities in scope must test at least every three years.
The consequence of that first difference is what makes institutions nervous: testing happens against production. This is why the control team, the rules of engagement and the risk management around the exercise matter as much as the offensive work itself.
What are the phases of a TIBER-EU style engagement?
Preparation
The White Team is established, scope is defined around critical or important functions, and the authority is engaged. Providers are appointed. This phase is longer than people expect and it determines whether the rest works.
Testing: threat intelligence
A targeted threat intelligence provider produces a report on the actors realistically targeting your institution and the scenarios they would use. This is what makes the test threat-led rather than imagination-led.
Testing: red teaming
The red team executes the agreed scenarios against production, pursuing the defined objectives, under the rules of engagement, with the control team able to stop the exercise at any moment.
Closure
Replay of the attack path with the blue team, a remediation plan, and the reporting the authority expects.
Where we fit
We deliver the red teaming component, and we support the preparation and closure phases: scoping critical or important functions, drafting rules of engagement, running the purple team replay, and building the remediation plan and evidence pack.
Whether we can act as your TLPT provider for a regulated exercise depends on the requirements set by your competent authority and on your national implementation of the framework. That is a question we answer honestly at the scoping stage, before anyone signs anything, including telling you when we are not the right provider for a specific regulated test.
For institutions not yet in scope of Article 26, the same discipline is available as a red team assessment, without the regulatory overhead.
What you should have in place before starting
TLPT tests detection and response under realistic pressure. Running it before you have those functions produces an expensive confirmation of something you already suspected.
Before commissioning a threat-led test, you want monitoring that covers your critical or important functions, an incident process that people actually follow, and prior offensive testing that has already removed the obvious findings. If any of those is missing, the honest sequence is to fix it first, and we will say so.
Is TIBER-EU mandatory?
TIBER-EU itself is a framework, not a law. The obligation comes from DORA Article 26 for entities identified by their competent authority, with the binding requirements set out in Commission Delegated Regulation (EU) 2025/1190. TIBER-EU remains the established model that supervisory practice is built on. Entities not identified still need a proportionate testing programme, but not TLPT.
How often must threat-led testing be performed?
At least every three years for entities in scope, unless your authority sets a different frequency.
Does testing really run against production?
Yes, and that is the point: it is what distinguishes TLPT. The exercise is governed by rules of engagement, a control team with a stop condition, and risk management agreed in advance.
How long does an engagement take?
Months rather than weeks when the full framework applies, because preparation and threat intelligence precede the red teaming. Non-regulated red team assessments are considerably shorter.