Threat-Led
Penetration Testing
TLPT is the most advanced form of security testing required under DORA. Based on the TIBER-EU framework, it simulates real-world cyber attacks to test your organization's detection and response capabilities.
Mandatory for Significant Entities
Large financial institutions must conduct TLPT at least every 3 years
What is TLPT?
Threat-Led Penetration Testing (TLPT) is an advanced form of ethical hacking that mimics the tactics, techniques, and procedures of real threat actors targeting your specific organization.
TLPT vs Standard Pentesting
| Aspect | Standard | TLPT |
|---|---|---|
| Duration | 1-4 weeks | 16-26 weeks |
| Threat Intel | Limited | Comprehensive |
| Scope | Defined assets | Critical functions |
| Blue Team | Often aware | Unaware |
Key TLPT Characteristics
- Intelligence-led: Based on real threat actor analysis
- Realistic: Simulates actual attack scenarios
- Comprehensive: Tests people, processes, and technology
- Controlled: Managed by a control team
- Regulated: Overseen by competent authorities
TLPT Process
A typical TLPT engagement follows the TIBER-EU framework phases.
Preparation
- Scope definition and agreement
- Threat intelligence gathering
- Test team qualification verification
- Control team establishment
Testing
- Red team reconnaissance
- Initial compromise attempts
- Lateral movement and privilege escalation
- Objective achievement assessment
Closure
- Red team report delivery
- Remediation planning
- Replay testing (if required)
- Final attestation to supervisor
TLPT Tester Requirements
DORA and TIBER-EU specify strict requirements for TLPT providers.
Independence
TLPT testers must be independent from the entity being tested. Internal testing is only permitted in exceptional circumstances.
Certification
Testers should hold relevant certifications (CREST, OSCP, OSCE, etc.) and demonstrate threat-led testing experience.
Insurance
Professional indemnity insurance covering potential damages from testing activities.
Experience
Proven track record in TIBER-EU, CBEST, or equivalent threat-led testing frameworks.
Request TLPT Consultation
Our TIBER-EU qualified team is ready to discuss your TLPT requirements.