The Cyber Academy take
TLPT is the regulator-supervised red-team exercise required by DORA for significant financial entities. Built on the TIBER-EU framework (Threat Intelligence-Based Ethical Red Teaming). Multi-month, intelligence-driven, supervised by the national authority. The most rigorous test a CISO will face, and the one that exposes the SOC for what it really is.
What threat-led penetration testing actually is
Threat-led penetration testing is a controlled red-team exercise against an organisation in full production, driven by real threat intelligence and supervised by a financial authority. The Digital Operational Resilience Act, DORA, makes it a periodic obligation for the financial entities a regulator judges significant enough to warrant it, and the exercise is built on TIBER-EU, the framework the European Central Bank published for Threat Intelligence-Based Ethical Red Teaming.
The defining word is led: the test is not a generic checklist of vulnerabilities but a campaign shaped by who would realistically attack this firm and how. A threat intelligence provider profiles the entity, identifies plausible adversaries and their methods, and hands the red team a set of scenarios. The red team then attempts to compromise live critical functions using those scenarios, the same way an actual attacker would.
Two properties separate TLPT from ordinary penetration testing. First, it targets the live production estate and the people and processes around it, not a copy or a scoped slice, which is why it is run under tight rules and a small, trusted control team. Second, it is supervised. The national competent authority and, where relevant, a dedicated TIBER team are involved in the engagement, validating scope, accrediting the testers and overseeing how the exercise is conducted. That oversight is what makes the result credible to a regulator rather than just to the firm that commissioned it.
How a TLPT engagement runs
A TLPT is a multi-month programme, not a one-week assessment, and it unfolds in defined phases that the TIBER-EU framework lays out. In the preparation phase the entity, the control team and the authority agree the scope, confirm which critical functions are in play and engage accredited threat intelligence and red-team providers. In the testing phase the intelligence provider produces a targeting report on the entity, and the red team uses it to run realistic attack scenarios against the live functions, often over many weeks, attempting to reach defined objectives without being stopped. In the closure phase the red team, the blue team and the control team meet to reconstruct what happened, agree the findings and build a remediation plan.
The critical detail is that almost nobody inside the organisation knows the test is happening. The defenders, the security operations centre and the incident responders are not told, because the whole point is to see how they perform against a real intrusion rather than a scheduled drill. Only a tiny control team is aware. This is what makes a TLPT the most honest measure of operational resilience a CISO will commission, and the one that most reliably exposes the gap between what the SOC is believed to do and what it actually detects under pressure.
TLPT, TIBER-EU and ordinary penetration testing
| Dimension | Standard penetration test | Threat-led penetration test (TLPT) |
|---|---|---|
| Driver | Predefined scope and a tester checklist | Tailored threat intelligence on the specific entity |
| Target | Often a staging copy or a scoped application | Live production critical functions and the people around them |
| Defenders awareness | Usually informed, sometimes assisting | Not informed, only a small control team knows |
| Duration | Days to a few weeks | Multiple months across defined phases |
| Oversight | Internal, commissioned by the firm | Supervised by the national authority under TIBER-EU |
| Trigger | Discretionary or contractual | A DORA obligation for designated significant entities |
It helps to keep the relationship between the terms clear. TIBER-EU is the framework, the methodology and the phases. TLPT is the regulatory obligation under DORA that adopts and references that framework for in-scope financial entities. A standard penetration test remains a valuable and far more frequent activity, but it answers a narrower question: are there exploitable weaknesses in this system. A TLPT answers a harder one: if a realistic adversary came for our most important functions today, would we even notice, and could we respond. The two are complementary, and an organisation expecting a TLPT does not stop running ordinary tests, it uses them to close the obvious gaps so the threat-led exercise can probe the subtle ones.
What practitioners actually do to prepare is rarely about buying one more tool. They build an accurate inventory of critical functions and the systems that support them, so scope can be agreed honestly. They make sure detection use cases are tuned and that the SOC has rehearsed escalation against realistic scenarios rather than tabletop ones. They confirm the control team structure and the legal and risk sign-offs needed to run an intrusion against production safely. And they treat the findings as input to operational resilience and continuity planning, because under DORA the remediation is not a private report, it is evidence the regulator expects to see acted upon.
Frequently asked questions
01What is the difference between TLPT and a normal penetration test?
A standard penetration test works to a predefined scope, often against a staging system, with defenders usually aware. A TLPT is driven by tailored threat intelligence, runs against live production critical functions over months, keeps the defenders in the dark and is supervised by a financial authority. It tests detection and response, not just vulnerabilities.
02Who has to perform TLPT under DORA?
DORA requires it of the financial entities that a national authority designates as significant enough to warrant advanced testing, based on their risk profile and systemic importance. Smaller entities still face proportionate digital operational resilience testing, but the full threat-led exercise is reserved for those the regulator identifies.
03What is the relationship between TLPT and TIBER-EU?
TIBER-EU is the European Central Bank framework that defines the methodology, phases and roles for intelligence-based red teaming. TLPT is the DORA obligation that adopts that framework. In practice a DORA TLPT is run according to TIBER-EU principles and overseen by the relevant authority.
04Why are the defenders not told a TLPT is happening?
The objective is to measure real detection and response, not a scheduled drill. If the SOC knew, it would watch for the test and the result would be meaningless. Only a small trusted control team is aware, so the exercise reflects how the organisation truly performs under a live intrusion.
05How long does a TLPT take?
It is a multi-month programme rather than a short assessment, spanning the preparation, testing and closure phases of TIBER-EU. The threat intelligence work, the red-team campaign against live functions and the joint reconstruction with the blue team each take real time, often adding up to several months end to end.