Financial sector · DORA Pillar 3 · resilience testing & TLPT

Digital resilience testing and TLPT for financial institutions

DORA requires financial institutions to run a regular programme for testing digital operational resilience, from vulnerability assessments to scenario-based testing. For significant institutions, threat-led penetration testing based on TIBER-EU is added. We build a risk-based testing programme, run vulnerability scans and pentests ourselves and prepare TLPT in an audit-ready way. Whether DORA and TLPT apply to you directly we verify case by case.

DORA Pillar 3 · TIBER-EU pentests in-house · TLPT coordinated DE · FR · EN
Digital resilience testing and TLPT for financial institutions

For banks, insurers, securities firms, FinTechs, asset managers and their critical IT providers

Pentest & vulnerability scan in-house, OWASP · PTES
TLPT / TIBER-EU readiness & coordination
DORA & FINMA scope case by case
Audit-ready evidence in the Priverion Platform
CH · EU multilingual DE/FR/EN
Philipp Staiger

Responsible for this mandate

Philipp Staiger

M.Sc., MIT Sloan Fellow · Lead Auditor ISO 27001 (BSI)

Leads ISO 27001 and ISMS projects in healthcare from the scope workshop to stage-2 audit support, the interface to management, IT, data protection and the external certification body.

LinkedIn

What DORA Pillar 3 and FINMA require for testing

Resilience cannot be asserted, it has to be tested. DORA turns the testing of digital operational resilience into a recurring duty, and FINMA expects institutions to verify their measures effectively. What applies concretely depends on your institution, which we verify case by case.

DORA, the EU Digital Operational Resilience Act, applies since 17 January 2025. Pillar 3 requires a risk-based programme for testing digital operational resilience. This includes regular vulnerability assessments, open-source analyses, network security tests, scenario-based testing and business-continuity testing. Scope and frequency depend on the size, risk profile and criticality of the institution.

For institutions identified as significant under the criteria, threat-led penetration testing is added, TLPT for short. It follows the European TIBER-EU framework and simulates a realistic attack on the institution's critical functions in the production environment, typically about every three years. Whether TLPT applies to your institution is a case-by-case question that we clarify up front.

For Swiss institutions DORA usually applies only indirectly, via EU branches or subsidiaries or via contracts with EU-regulated financial entities. Direct versus indirect application must be checked per institution. Regardless, in Circular 2023/01 on operational risks and resilience FINMA expects banks to test their controls and their response capability, the circular is in force and applies to FINMA-supervised institutions.

  • A documented, risk-based testing programme with scope, frequency and methodology according to criticality
  • Regular vulnerability assessments and network security tests across the relevant systems
  • Penetration tests for web, API, network and infrastructure by qualified testers
  • Scenario-based testing and business-continuity testing for the critical functions
  • For significant institutions, TLPT under TIBER-EU, typically about every three years, applicability case by case
  • Remediation of the findings with traceable measures and audit-ready documentation

How we build your resilience testing programme

We turn DORA Pillar 3 into a repeatable programme rather than a one-off exercise. Vulnerability scans and penetration tests we run with our in-house technical team. For full red-team TLPT we prepare, scope and coordinate, and engage a specialised red-team partner where required.

We start with a risk-based test plan. We map your critical or important functions and the systems supporting them to the right test types and set scope and frequency. The result is a transparent plan that shows what is tested when and with which methodology, aligned with your risk profile and the expectations from DORA and FINMA Circular 2023/01.

Vulnerability scans and penetration tests are existing SIDD services that we deliver with our in-house technical team under an ISO 27001 Lead Auditor. We test web applications, APIs, networks and infrastructure to recognised methodologies such as OWASP and PTES. You receive reports with prioritised findings, a clear risk classification and concrete remediation recommendations, written so that internal audit and examiners can follow them.

For TLPT under TIBER-EU we take on preparation and orchestration. We first check whether TLPT is relevant for your institution at all, define the scope of critical functions with you, build the threat-intelligence basis and the test design and set up the governance with the white team. The actual red-team exercise against the production environment is carried out by a specialised red-team partner whom we engage and steer. SIDD does not run an in-house red team and does not claim to, and exactly this clear line keeps our role as an independent coordinator clean.

A test is only valuable once the findings are remediated. We track the remediation of the vulnerabilities, agree deadlines and, where sensible, perform a retest. The testing programme, the reports, the measures and the remediation status are maintained in the Priverion Platform. So the evidence on testing and resilience is ready, maintained and exportable when internal audit, an examiner or the supervisor asks for it.

Why SIDD for your resilience testing

Resilience testing under DORA combines supervisory expectations with real technical depth. We cover exactly that combination from one partner, with a clear line between what we do ourselves and what we coordinate.

Pentest and vulnerability scan in-house

Vulnerability scans and penetration tests for web, API, network and infrastructure are run by our in-house technical team under an ISO 27001 Lead Auditor, to OWASP and PTES. You receive audit-ready reports that convince internal audit and the supervisor.

TLPT clearly delineated

For full TLPT under TIBER-EU we prepare, scope and coordinate, and engage a specialised red-team partner. We do not run an in-house red team and do not claim to. This honesty protects the validity of the test and your position towards the supervisor.

Supervisory law and technology from one partner

Our doctorate-level lawyers classify the expectations from DORA Pillar 3 and FINMA Circular 2023/01, the technical team tests. So the testing programme fits together legally and technically, without friction between two providers.

Audit-ready evidence in tooling

We maintain the test plan, the reports, the findings, the measures and the remediation status in the Priverion Platform. If internal audit, an examiner or FINMA asks about the resilience testing, the evidence is ready, maintained and exportable.

Multilingual and independent

We test and report in German, French and English, fitting institutions in Switzerland and the EU. Because we do not sell an in-house SOC, our recommendations on findings and measures stay independent and focused on your resilience.

Scope clarified up front

We first clarify whether and how DORA and TLPT apply to your institution, directly or indirectly via EU exposure, before we test. So you invest in what is actually required, and not in an effort your risk profile does not call for.

Two routes to tested digital resilience

TLPT readiness & coordination

on request fixed price by scope

The preparation and orchestration of a TLPT under TIBER-EU. We check applicability, set the scope and coordinate, the red team is provided by a specialised partner.

  • Assessment of whether TLPT applies to your institution, applicability clarified case by case
  • Scope definition of the critical functions and threat-intelligence basis
  • Governance with the white team and alignment with the supervisor under TIBER-EU
  • Selection, engagement and steering of a specialised red-team partner
  • Closing report, lessons learned and a traceable remediation plan in the Priverion Platform

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For your resilience testing programme, concretely: LexCommand backs each test finding with the specific duty it touches under DORA and FINMA, with a source reference, and frames the requirements for vulnerability testing and threat-led penetration testing (TIBER-EU), so your testing evidence holds up to supervision.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions

Does DORA Pillar 3 apply to our Swiss institution?

DORA applies in the EU since 17 January 2025. For Swiss institutions it usually applies only indirectly, for example via EU branches or subsidiaries or via contracts with EU-regulated financial entities. Whether application is direct or indirect must be checked per institution. Regardless, FINMA in Circular 2023/01, which is in force, expects supervised banks to test their controls and their response capability. We clarify your situation up front and case by case.

Do we really need a TLPT?

Not every institution. TLPT under TIBER-EU is intended for institutions identified as significant under the criteria, typically about every three years. Whether your institution falls under it is a case-by-case question that we clarify up front. If TLPT is not relevant, vulnerability scans, scenario-based testing and penetration tests cover the required testing programme. So you only invest in what your risk profile actually requires.

Does SIDD run an in-house red team?

No. Vulnerability scans and penetration tests we run with our in-house technical team, which is an existing part of our services. For a full red-team TLPT under TIBER-EU we prepare, scope and coordinate, and engage a specialised red-team partner. We do not claim an in-house red team, and exactly this clear line keeps the validity of the test and our independent coordinator role clean.

How often do we have to test?

It depends on your risk profile and the criticality of the systems. DORA requires a regular, risk-based programme, and many institutions combine ongoing vulnerability scans with annual penetration tests of the most important applications. TLPT, where applicable, typically takes place about every three years. We set scope and frequency in the test plan, aligned with your risk profile and the supervisor's expectations. We verify the concrete requirements case by case.

What happens with the vulnerabilities you find?

A test is only valuable once the findings are remediated. You receive a report with prioritised vulnerabilities, a risk classification and concrete recommendations. We track the remediation, agree deadlines and, where sensible, perform a retest. We maintain findings, measures and remediation status in the Priverion Platform so progress is auditable at any time. The operational fixing is implemented by your IT or your providers, we support and verify.

Can you test and report in French and English?

Yes. We test and report throughout in German, French and English, relevant for institutions in German-speaking Switzerland, French-speaking Switzerland and the EU. We write the reports so that internal audit, management and examiners can follow them in their language.

Matching next steps

Resilience testing ties directly into pentests and the ICT risk management under DORA Pillar 1:

Ready to test your digital resilience audit-ready?

We build your risk-based testing programme under DORA Pillar 3, run vulnerability scans and penetration tests ourselves and prepare and coordinate TLPT under TIBER-EU. Scope verified case by case.