Threat-Led Penetration Testing (TLPT) Under DORA

6 min readLast updated By Oliver Stutz

Introduction

Threat-Led Penetration Testing (TLPT) is the most demanding testing mode DORA Pillar 3 establishes. Unlike classic penetration tests, TLPT simulates realistic, targeted attacks by so-called Advanced Persistent Threats (APT) against productive systems, over several months, with minimal advance notice to defenders, and with the explicit ambition of replicating real adversary tradecraft. The methodology derives from TIBER-EU (Threat Intelligence-Based Ethical Red Teaming), an ECB framework that has existed voluntarily since 2018 and now becomes mandatory for significant entities.

This article covers:

  • The TIBER-EU lineage and its translation into Art. 26-27 DORA.
  • Scope, frequency and target setting for a TLPT.
  • Roles: test team (red team), threat intelligence provider, white team.
  • Accreditation requirements for test teams per the RTS template.
  • Deliverables and the supervisor dialogue with the competent authority.

Legal anchors are Art. 26 and 27 of Regulation (EU) 2022/2554, the Commission Delegated Regulation on TLPT accreditation requirements (RTS under Art. 26(11) DORA), the ECB TIBER-EU framework (February 2018, repeatedly updated) and the national TIBER implementations (TIBER-DE at the Bundesbank, TIBER-FR at the Banque de France, TIBER-NL at DNB).

When TLPT becomes mandatory

Art. 26(1) DORA obliges significant entities to perform an advanced test in the form of a TLPT at least every three years. Designation as "significant" follows criteria such as systemic relevance, size, complexity, ICT maturity and cross-border activity. In practice these are typically:

  • Large credit institutions (LCBG; Less and More Significant Institutions in SSM Category 1-2).
  • Systemically relevant payment systems and central counterparties.
  • Large insurers with material cross-border business.
  • Material asset managers (especially AIFMs with substantial AuM).

Under Art. 26(8) DORA the competent authority can order TLPT for other financial entities where particular risk profiles warrant it. Member States are currently refining the designation criteria, with first productive TLPT exercises in H2 2025 in DE, FR, NL and LU. For Swiss actors this means: anyone with an EU subsidiary designated as "significant" typically plans a TLPT in 2026 with the national supervisor. FINMA Circular 23/01 paras 59-65 also requires regular advanced testing for Category 1 and partly Category 2 banks, with a methodology aligned to TIBER.

Anatomy of a TLPT

A full TLPT follows the TIBER-EU architecture in three phases that typically run six to nine months:

  1. Preparation (2-3 months): scoping, engagement letter, formation of the white team (CISO, risk, legal, test manager) as the only informed insiders; engagement of the threat intelligence provider and red team; generic threat landscape report; targeted threat intelligence (TTI) report; scenarios and flags definition.
  2. Testing (3-5 months): reconnaissance, weaponisation, delivery, exploitation, installation, command & control, actions on objectives, the classic cyber kill chain across several waves. The blue team (internal SOC) is not informed up front and must detect and respond as if it were a real attack.
  3. Closure (1-2 months): red team report, blue team report, joint workshop (purple teaming), remediation plan, supervisor reporting, lessons learned.

The test volume is substantial: typically 60-120 person-days red team, 40-80 person-days threat intelligence provider, plus internal time in the white team and downstream defence teams. Budget band: typically EUR 250,000 to EUR 700,000 per TLPT depending on scope, maturity and number of scenarios.

The three roles and their accreditation

The TIBER-EU methodology, carried over into DORA, has three independent roles whose clean separation is essential:

  • Threat Intelligence Provider (TIP): Delivers the targeted threat intelligence report identifying institution-specific TTPs (tactics, techniques, procedures) of plausible adversary groups. Sources: OSINT, commercial threat feeds, sometimes own research.
  • Red Team Provider (RTP): Carries out the actual attack based on the TTI report and agreed scenarios. Requires offensive tradecraft at APT level.
  • White team: Internal steering group of the tested entity, the sole informed insiders. Approves every action, is the sole communication channel with the RTP, and the only escalation point in emergencies.

The DORA RTS under Art. 26(11) establishes accreditation requirements for TIP and RTP. Key criteria: documented methodology (TIBER-EU or equivalent), demonstrable experience (at least five comparable engagements in the past three years per lead tester), certified testers (CREST CCSAS, OSCE3, GIAC GXPN or equivalent), professional indemnity insurance with adequate cover, ISO/IEC 27001 certification of the provider, and demonstrable segregation of TIP and RTP (either two different providers or organisationally clearly separated units).

Scope definition and flags

Under Art. 26(2) DORA, the scope of a TLPT covers the critical or important functions of the financial entity and the ICT systems supporting them, not everything, but specifically the crown jewels. Examples of typical scoping decisions:

  • Bank: core banking system, payment platform (Swift, SEPA, instant payments), trading platform, identity provider, ServiceNow / IT service management.
  • Insurer: policy administration, claims management, commission settlement, actuarial platform.
  • Asset manager: order management system, portfolio management, NAV calculation, custody interface, compliance monitoring.

During preparation, concrete flags are defined, "evidence of success" the red team must achieve. Examples: access to the domain admin console, execution of a test transaction over the payment platform, retrieval of a simulated customer list from the core banking database, persistence on a productive domain controller for 30 days. Flags must be measurable, harmless (no real data exfiltration, no productive impact) and meaningful to the supervisor.

Outsourcing components, ICT TPPs like cloud providers or SaaS vendors, can be included in scope under Art. 26(3) DORA, requiring provider cooperation via contractual amendments. In practice this is handled with notice clauses and defined testing windows.

Supervisor dialogue and deliverables

TLPT is not an internal project but a supervisory act with regulator involvement from day one. The competent authority is engaged at every phase:

  • Pre-engagement: notification of the planned TLPT, approval of scope and actors (TIP, RTP).
  • Engagement: regular status reports, emergency escalation if test activities threaten stability.
  • Post-engagement: submission of test reports, remediation plan and supervisor summary.

Key deliverables of a TLPT:

  • Targeted Threat Intelligence Report: 30-60 pages, identifies relevant adversary groups, their motivations, TTPs and plausible attack paths.
  • Red Team Report: 80-150 pages, detailed account of testing activities, flags achieved, vulnerabilities exploited, diary in character.
  • Blue Team Report: self-assessment of detection and response performance, produced by the internal SOC.
  • Remediation Plan: prioritised action catalogue with owners and deadlines, approved by the management body.
  • Supervisor Summary: 10-15 pages, key findings for the regulator.

After evaluation, the regulator can order further measures, including a retest if results are insufficient.

FINMA angle and Swiss practice

FINMA Circular 2023/1 (Operational Risks and Resilience – Banks) does not establish an explicit TIBER mandate but requires regular advanced security testing under paras 59-65 with a methodology aligned to international standards. In practice large Swiss banks, particularly the two systemically relevant institutions, have applied TIBER-style methodologies for several years, partly under the SNB / BACS TIBER-CH pilot, partly under in-house methodology.

For Swiss banks with EU subsidiaries, the question becomes acute: a TLPT of the EU entity often pulls in Swiss group systems because the parent provides ICT services to the EU entity. This requires:

  • Clear intra-group approval and communication paths.
  • Notice clauses in intra-group contracts that legitimise testing.
  • Notification of FINMA, even where the TLPT is driven primarily by EU supervision.
  • Coordination with all affected Swiss ICT providers.

Recommendation: when the EU subsidiary becomes TLPT-obliged, the group is well advised to design the TLPT as a group exercise rather than as an isolated EU project. This generates learning effects for the Swiss supervisor and can efficiently cover FINMA expectations on advanced testing. More in our penetration testing consulting.

How SIDD supports you

SIDD supports Swiss financial actors and their EU entities through TLPT preparation and execution. We act, on request, as white-team coach (steering the internal white team), as liaison to the Bundesbank / BaFin or other TIBER cyber teams, or as threat intelligence provider. If needed, we also deliver the red team via accredited partners.

Before a TLPT we recommend a pre-flight test, a classic penetration test in grey-box configuration, to fix obvious vulnerabilities before the "real" TLPT. In parallel we build out your vulnerability management and detection/response capabilities, because a TLPT that the SOC never detects always scores worse than one with an active blue team.

For ongoing DORA Pillar 3 governance we can place an external CISO or ISO who orchestrates the testing programme and reports to FINMA or the EU supervisor. Book a first conversation at /kontakt or request a TLPT preparation quote at /offerte. Our recommendation: start preparation 9-12 months before the planned TLPT, otherwise the test becomes pure compliance theatre rather than a genuine resilience stress test.

Need help putting this into practice? SIDD operates the matching service.
See service →

Threat-Led Penetration Testing (TLPT) Under DORA

INSIGHT

InfoSec
24 May 2026
Oliver Stutz
Threat-led penetration testing under DORA: when TLPT is mandatory, the TIBER-EU process, roles, scope, the supervisory dialogue and the Swiss angle.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.