TLPT testing: the red team exercise DORA requires from financial entities

TLPT is not a penetration test under another name. It is a threat intelligence-led red team exercise, run against production systems with the defensive team unaware. DORA requires it from financial entities designated by their competent authority, and the provider must demonstrate independence and technical capability.

A conventional penetration test does not meet the TLPT requirement

Many entities find out late that the security testing they already run does not satisfy the advanced testing DORA regulates in articles 26 and 27. TLPT has requirements a standard penetration test does not meet: it starts from a threat intelligence phase specific to the entity, runs against critical or important functions in production rather than staging, keeps the defensive team unaware except for a small control team, and requires providers who can evidence independence and technical capability. Submitting a standard penetration test report to the supervisor does not close the requirement, and the remediation window afterwards eats whatever margin was left.

What a TLPT exercise covers

  • Threat intelligence phase: threat actors relevant to your entity and sector, observed TTPs and prioritised attack scenarios.
  • Scope definition over critical or important functions, agreed with the control team and, where applicable, the competent authority.
  • Red team exercise against production systems, using technical, human and physical vectors within the agreed scope.
  • Work carried out without notice to the defensive team, measuring real detection and response capability.
  • MTTD and MTTR measured per scenario, not just a list of vulnerabilities.
  • Purple team closing phase: joint review with the defensive team of what was detected, what was not and why.
  • Documentation aligned with TIBER-EU for submission to the supervisor.

How we run a TLPT

  1. Preparation and scoping: Control team set-up, identification of critical or important functions and scope agreement with the entity and, where applicable, the competent authority.
  2. Threat intelligence: Entity-specific threat report: actors with real motivation against your organisation, documented TTPs and attack scenarios prioritised by business impact.
  3. Red team execution: Scenarios executed against production with the defensive team unaware. Aligned with MITRE ATT&CK and with continuous action logging for traceability.
  4. Closing and purple team: Joint session with the defensive team: which actions were detected, which went unnoticed and which controls failed.
  5. Reporting and remediation: Technical and executive documentation following TIBER-EU, with a prioritised remediation plan and retest of the fixes applied.

Deliverables

  • Entity-specific threat intelligence report.
  • Technical report with the full attack chain, evidence and traceability of every action.
  • Executive report aimed at the board and the compliance function.
  • Detection and response metrics (MTTD/MTTR) per scenario executed.
  • Remediation plan prioritised by risk and effort.
  • Documented retest of the fixes applied.

Which entities TLPT applies to

  • Credit institutions and banks designated by their competent authority for advanced testing.
  • Insurers and reinsurers within the scope of DORA.
  • Investment firms and fund managers.
  • Crypto-asset service providers and electronic money institutions.
  • Market infrastructures: payment systems, central securities depositories and central counterparties.
  • Critical ICT providers to financial entities, reached through the supply chain.

Frequently asked questions about TLPT

What is the difference between TLPT and a penetration test

A penetration test looks for vulnerabilities within a defined scope, usually with the defensive team informed. TLPT starts from real threat intelligence about your entity, runs in production against critical functions and keeps the defensive team unaware, because what it measures is detection and response capability, not just the presence of flaws.

Do all financial entities have to run TLPT

No. DORA requires a resilience testing programme from every entity in scope, but advanced testing such as TLPT applies to those designated by their competent authority based on criteria including size, risk profile and relevance. If your entity is not designated, the rest of the testing programme still applies.

How often must a TLPT be repeated

DORA sets a minimum frequency of three years for entities in scope, without prejudice to what the competent authority determines. It is worth planning ahead: the full cycle, including prior intelligence and subsequent remediation, runs over several months.

How does TLPT relate to TIBER-EU

TIBER-EU is the European Central Bank framework for threat intelligence-led testing and is the methodological reference underpinning DORA TLPT. Documenting the exercise in line with TIBER-EU eases its submission to the supervisor.

Can the team that runs our regular audits also run the TLPT

DORA requires providers of advanced testing to evidence independence, reputation and technical capability. It is worth reviewing potential conflicts with whoever already delivers recurring services to the entity before awarding the exercise.

How long does a full TLPT take

It depends on scope, but a TLPT covering intelligence, execution, closing and remediation rarely takes less than three months. Entities that start with the deadline already close end up cutting scope, which is precisely what the supervisor examines.

Related resources

Discuss my TLPT scope