Threat-led penetration testing under DORA

A threat-led penetration test is a controlled attack on live production systems, planned from intelligence about the groups that actually target the firm. DORA in Germany states that the duty exists and that TIBER-DE runs it; the subject here is the procedure, from how the scope is set to the attestation the authority issues at the end.

A red-team tester connects a test cable to network equipment during a controlled security exercise.

The duty, the three-year cycle and the two kinds of testing

DORA separates two testing obligations. Article 25 of Regulation (EU) 2022/2554 requires a general testing program, with vulnerability assessments, scans and penetration tests, run at least yearly on ICT systems supporting critical or important functions. Article 26 adds threat-led penetration testing for the entities the supervisor designates, at least every three years.

The three-year figure is a floor. The authority may require a different rhythm for an individual firm, and the cycle runs on the completion of the last test, so a firm that finishes a test late moves its own next deadline. The scope has to cover several critical or important functions and be carried out on live production systems, which is the line that separates a TLPT from everything in the Article 25 program.

Who is in scope, and why the firm does not decide

The entity does not opt in. Under Article 26(8) of DORA the competent authority identifies the financial entities required to perform a TLPT, on the basis of their size, their risk profile and their importance for the financial sector, with criteria set out in the regulatory technical standards. In Germany BaFin decides which firms must test and tells each one its rhythm.

Being out of scope changes nothing about Article 25, so a firm not designated for TLPT still runs penetration tests on its critical systems every year. Firms sometimes read a TLPT designation as a judgment about their security; it is a judgment about their systemic weight.

TIBER-EU and TIBER-DE as the method behind the rule

The method predates DORA. TIBER-EU, the European framework for threat intelligence-based ethical red teaming, was published by the European Central Bank in 2018 and run on a voluntary basis, and the Deutsche Bundesbank implemented it nationally as TIBER-DE. DORA made the test mandatory for designated entities and the framework was revised to match the regulation.

In Germany the Bundesbank's TIBER Cyber Team accompanies the test, and BaFin remains the competent authority for the obligation. For the firm this means two authorities in the room, with different roles: one supervises the duty, the other supports and quality-assures the exercise.

The four phases and who sits in the control team

A TLPT runs in preparation, threat intelligence, red teaming and closure. Preparation fixes the scope, the rules of engagement and the risk management measures for testing in production. The threat intelligence phase produces a targeted threat intelligence report naming the actors relevant to this firm and mapping their tactics, techniques and procedures into scenarios with defined objectives, often described as flags.

The red team phase executes those scenarios against the live estate, deliberately slowly, because moving at the pace of an ordinary penetration test would be detected immediately and would test nothing about detection. Closure includes a replay with the defenders, a purple teaming session where red and blue walk the attack path together. The control team is the small group inside the firm that knows the test is running and carries the authority to stop it; the security operations team does not know, which is the point.

What the testers have to be, and when internal testers are allowed

The testers are assessed, not just hired. The regulatory technical standards on threat-led penetration testing set requirements on the reputation, the capacity, the technical skills and the professional indemnity insurance of the testers and of the threat intelligence provider, and require them to be independent of the entity being tested.

Internal testers are possible under conditions. DORA Article 26(8) allows them for entities other than credit institutions classified as significant, subject to the authority's approval, a documented absence of conflicts of interest, and the use of an external threat intelligence provider. Even then an external red team has to be used at least every third test, so a firm cannot test itself indefinitely.

How a TLPT differs from a penetration test and from red teaming

Three differences matter. Scope: a penetration test examines a defined system for vulnerabilities, while a TLPT pursues an objective across the firm, including the people and the physical access that lead to it. Intelligence: a TLPT's scenarios come from a report about the actors that target this firm, so the test is specific to it and not generic. Environment: a TLPT runs in production, with the operational risk that creates and the risk management measures the preparation phase puts in place.

Against ordinary red teaming the difference is formal and not technical. A TLPT follows a prescribed process under supervisory oversight, with required documentation, an assessed tester, a control team and an authority reading the result. A red team exercise a firm buys for its own purposes answers to nobody but the firm.

The attestation at the end and its recognition elsewhere

When the test closes, the authorities provide the entity with an attestation confirming that the test was performed in accordance with the requirements, under Article 26(7) of DORA. The attestation records that the process was followed; it is not a certificate that the firm passed, because a TLPT has no pass mark.

The same article provides for mutual recognition: the attestation is recognized by competent authorities in other member states, so a group tested once under TIBER-DE does not repeat the exercise for each jurisdiction it operates in. For a cross-border group this is the part that decides whether the test is one project or several.

What is threat-led penetration testing?

Threat-led penetration testing is a controlled attack on a firm's live production systems, built from intelligence about the threat actors that target it and executed by an independent red team while the firm's own defenders are unaware. Under Article 26 of DORA it is mandatory at least every three years for the financial entities a supervisor designates, and in Germany it runs within the TIBER-DE framework with the Deutsche Bundesbank.

How long does a TLPT take?

Months, not weeks. The red team phase alone runs over a sustained period, commonly cited as at least twelve weeks of active testing, because the team moves slowly to avoid detection. Preparation and the threat intelligence phase come before it and the closure phase after, so firms plan a full exercise across two to three quarters and treat the control team's time as a committed resource.

Who knows that a TLPT is running?

Only the control team and the named people it discloses to. The security operations center, the incident response team and the business stay unaware, because the test measures whether they detect and respond to a real attack pattern. The control team holds the escalation route, the agreed stop conditions and the record that the activity is authorized, which is what prevents the firm's own responders from treating the test as a genuine breach and from escalating it outside.

What happens to the findings?

They go into a remediation plan with owners and dates, and the firm reports to the authority on the test and on the measures taken. What the firm gets out of it is usually the detection timeline and not a list of vulnerabilities: at which step the attack became visible, how long the alert took to reach a decision, and which part of the path produced no signal at all. DORA incident reporting covers the route a real incident takes through the same organization.

Threat-led penetration testing and Finance Loop

Finance Loop is the meeting place for the red teams, control teams and ICT risk officers who run these tests in German finance. Finance Loop events bring them together with the Bundesbank and BaFin staff who accompany and supervise the same exercises.

Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, tokenization, stablecoins, and DeFi. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.

Let's stay in touch

4,000+ members in finance and tech. Become a Network Member for free.

Get updates for free!

Exclusive event invitations, member perks and news from the network. Unsubscribe at any time.

By submitting you agree to the terms.