Audit · TLPT

TLPT Testing (Threat-Led Penetration Testing) Under DORA: An Implementation Guide for Financial Institutions

Remote Admin Audit Team·March 25, 2026·5 min read

The deadline for implementing the EU’s DORA regulation passed in January 2025. Now, in 2026, supervisory authorities are no longer asking for declarations or plans. They demand hard technological proof. For key financial institutions, TLPT (Threat-Led Penetration Testing) has become the most important and most rigorous test of digital resilience. How does it differ from classic pentests, exactly who is required to run it, and how do you get through it unscathed while avoiding financial penalties? Here’s an engineering-grade guide based on current ESA guidelines and the TIBER-EU standard.

What is TLPT, and why are classic pentests no longer enough in 2026?

Regulatory requirements have evolved radically. For years, financial institutions relied on automated scanners and standard pentests targeting selected applications. Today, DORA (the Digital Operational Resilience Act) verifies the resilience of an institution’s entire infrastructure under combat conditions.

While traditional penetration testing focuses on identifying vulnerabilities in a specific application or network segment, TLPT is an advanced simulation of a targeted cyberattack at the level of an entire organization. These tests are grounded in threat intelligence analysis and assess not only technical flaws, but also human behavior (social engineering) and incident response procedures.

Before diving into the details of TLPT implementation, make sure you understand the basic differences between vulnerability scanning and penetration testing, since TLPT represents an even higher level of complexity (closer to a Red Teaming operation).

TLPT vs. standard pentest: key differences under DORA

Feature Standard penetration test TLPT (threat-led) test under DORA
Attack vector Known software vulnerabilities (e.g., OWASP Top 10, CVE) Complex attacks (APT) targeting business processes and the supply chain
Scope Narrow: a selected application, web service, or network segment Broad: critical business functions across the entire institution (including CTPPs)
Approach and knowledge White box / gray box (clear rules, announced actions) Always black box (often kept secret from the institution’s own IT/SOC team)
Overarching goal Finding and patching specific bugs in code and configuration Assessing the organization’s real-world ability to defend against, detect, and contain an attack in production

Who in the financial sector must undergo TLPT testing?

Under the EU’s regulatory technical standards (RTS) for DORA, not every financial institution has to run such costly simulations. The obligation to conduct TLPT testing applies primarily to entities deemed significant and essential to the stability of the financial market, including:

  • Large credit institutions (banks).

  • Central securities depositories and central counterparties.

  • Payment institutions and large e-money providers.

  • Significant crypto-asset trading entities (at the intersection of DORA and MiCA).

  • Critical third-party ICT service providers (CTPPs) that serve the financial sector.

Even if you’re “just” an IT subcontractor for the banking sector, an auditor will require you to prove that you manage high availability and operational resilience to a degree that doesn’t create an opening for a supply chain attack.

3 phases of TLPT implementation: what does the process look like step by step?

Implementing Threat-Led Penetration Testing isn’t a few-day project that boils down to running an automated script. It’s based on the European TIBER-EU framework and consists of three rigorously controlled phases.

1. Preparation and threat intelligence phase (reconnaissance)

Before any technical “shot” is fired, a specialized team builds a risk profile for the institution. The threat intelligence phase analyzes who (which ransomware/APT groups), why, and how might attack your processes. This produces so-called threat scenarios that precisely mirror the tactics, techniques, and procedures (TTPs) used by cybercriminals targeting the finance sector in 2026.

2. Red Teaming phase (active attack on production)

This is the real core of the TLPT test. The strike team (Red Team) executes the predefined scenarios on live production systems. This can include phishing campaigns targeting the board (spear-phishing), attempts to compromise Active Directory, injecting malicious code through a third-party provider’s CI/CD tools, or attempts to delete WORM backups. The goal is to reach predetermined “flags” (e.g., a transaction authorization server) without causing service outages for customers.

3. Reporting and remediation phase (evidence for supervisory authorities)

Simply completing the test isn’t enough for auditing bodies such as the KNF (Polish Financial Supervision Authority) or the ESAs. DORA requires a so-called Evidence Pack. The Red Team analyzes how the operation unfolded together with the Blue Team (the defenders). The result is a final report that covers not just architectural gaps, but above all an assessment of detection time and a precise remediation plan with a timeline for patching the vulnerabilities found.

Your roadmap ahead of the upcoming inspection

The lack of properly documented, up-to-date resilience tests is the surest path to painful fines from regulators. To make sure IT security is aligned with your business processes and contract terms, check your company’s readiness using our DORA-in-practice checklist.

Today’s auditors are looking for operational continuity. They check backup retention, access management (Zero Trust), incident response procedures within the first 24 hours, and whether the conclusions from TLPT testing have actually been implemented in the IT environment.

Protect your business and avoid regulatory penalties

Treating DORA requirements as nothing more than tedious paperwork is a dead end for financial institutions. Advanced testing based on real-world threat scenarios is currently the best available tool for hardening a company against multimillion-euro financial and reputational losses caused by a collapse in digital services.

Want to check whether your procedures are ready to face financial supervisors?

  • Cover yourself procedurally and commission a comprehensive DORA audit that will pinpoint areas needing immediate improvement.
  • Don’t wait for a summons from the KNF — order professional TLPT testing to prove your infrastructure’s resilience with hard engineering facts.