Home/Audit/TLPT testing (Threat-Led Penetration Testing)

02 · Audit

TLPT testing (Threat-Led Penetration Testing)

TLPT is advanced, threat intelligence-led penetration testing required under DORA Articles 26–27 for designated financial entities — at least once every three years, following the TIBER-EU framework. We run it end to end, from the intelligence phase to the report for the regulator.

Who it's for

Who uses this service

  • Financial entities designated by the supervisory authority as required to perform TLPT
  • Institutions that want to run a TIBER-EU test voluntarily — ahead of a regulator's decision
  • ICT providers within the scope of a financial institution's test

When it makes sense

Signs that the time is right

  • The supervisory authority has set a deadline for TLPT
  • Traditional pentests don't answer the question “would we detect a real attack?”
  • The management board wants to test the security team (blue team) under near-real conditions

Scope

What the service includes

Preparation phase

Scope, critical systems, control team, test safety rules.

Threat Intelligence

Threat report for the institution: actors, techniques, scenarios (TTPs).

Red Team

Attack simulation against production systems based on scenarios from the TI phase — without the blue team's knowledge.

Purple Teaming

Joint review with the defense team: what was detected, when, and what was missed.

Report and remediation plan

Test report, TI report, summary for the management board and regulator, remediation plan.

Attestation

Documents confirming the test was conducted in line with DORA requirements.

Process

How we work — four steps

STEP 1

Preparation (4–6 weeks)

Scope, contract, escalation rules, client-side control team.

STEP 2

Threat Intelligence (4 weeks)

Threat intelligence, attacker profile, test scenarios.

STEP 3

Red Team (10–12 weeks)

Scenario execution in the production environment under full oversight.

STEP 4

Closure (4 weeks)

Purple teaming, reports, remediation plan, documents for the supervisor.

Outcome

What you get

  1. Threat Intelligence report
  2. Red Team report with attack timeline and evidence
  3. Purple teaming report — assessment of detection and response capabilities
  4. Management board summary and attestation documents for the regulator
  5. Prioritized remediation plan
Art. 26–27DORA
every 3 yearsrequired frequency
TIBER-EUframework
See how it worked for a client

Anonymized Audit engagements — scope, process, outcome.

Case studies

Questions

Frequently asked questions

How does TLPT differ from a regular pentest?

A pentest checks a specific system for vulnerabilities within an agreed scope. TLPT tests the entire organization: whether a real attacker — using real-world techniques — can achieve their objective, and whether the defense team notices. It is conducted in production, without the blue team's knowledge.

Who is required to perform TLPT?

Financial entities designated by the supervisory authority based on the criteria in the RTS — typically the largest and systemically important ones. Others may run the test voluntarily.

Is TLPT safe for production?

The test is run with a control team, escalation rules and a stop procedure. Risk is managed at every stage — it is part of the TIBER-EU methodology.

Related services

Often combined with this service

First step

Let's talk about TLPT testing (Threat-Led Penetration Testing).

30 minutes, no slide deck. We'll tell you straight whether this service solves your problem, what scope makes sense and how much it costs.

Book a consultation

A proposal with scope and pricing within 48 hours of the call.

Go to contact