Threat-Led
Penetration Testing

TLPT is the most advanced form of security testing required under DORA. Based on the TIBER-EU framework, it simulates real-world cyber attacks to test your organization's detection and response capabilities.

Every 3 Years
TIBER-EU Aligned
Supervisor Oversight
Request TLPT Consultation

Mandatory for Significant Entities

Large financial institutions must conduct TLPT at least every 3 years

Testing FrequencyEvery 3 years minimum
Typical Duration16-26 weeks
FrameworkTIBER-EU
OversightCompetent Authority

What is TLPT?

Threat-Led Penetration Testing (TLPT) is an advanced form of ethical hacking that mimics the tactics, techniques, and procedures of real threat actors targeting your specific organization.

TLPT vs Standard Pentesting

AspectStandardTLPT
Duration1-4 weeks16-26 weeks
Threat IntelLimitedComprehensive
ScopeDefined assetsCritical functions
Blue TeamOften awareUnaware

Key TLPT Characteristics

  • Intelligence-led: Based on real threat actor analysis
  • Realistic: Simulates actual attack scenarios
  • Comprehensive: Tests people, processes, and technology
  • Controlled: Managed by a control team
  • Regulated: Overseen by competent authorities

TLPT Process

A typical TLPT engagement follows the TIBER-EU framework phases.

1

Preparation

4-8 weeks
  • Scope definition and agreement
  • Threat intelligence gathering
  • Test team qualification verification
  • Control team establishment
2

Testing

8-12 weeks
  • Red team reconnaissance
  • Initial compromise attempts
  • Lateral movement and privilege escalation
  • Objective achievement assessment
3

Closure

4-6 weeks
  • Red team report delivery
  • Remediation planning
  • Replay testing (if required)
  • Final attestation to supervisor

TLPT Tester Requirements

DORA and TIBER-EU specify strict requirements for TLPT providers.

🎯

Independence

TLPT testers must be independent from the entity being tested. Internal testing is only permitted in exceptional circumstances.

📜

Certification

Testers should hold relevant certifications (CREST, OSCP, OSCE, etc.) and demonstrate threat-led testing experience.

🛡️

Insurance

Professional indemnity insurance covering potential damages from testing activities.

Experience

Proven track record in TIBER-EU, CBEST, or equivalent threat-led testing frameworks.

Request TLPT Consultation

Our TIBER-EU qualified team is ready to discuss your TLPT requirements.

By submitting, you agree to our Privacy Policy