window.dataLayer = window.dataLayer || []; function gtag(){dataLayer.push(arguments);} gtag('js', new Date()); gtag('config', 'G-MFCXEZZS5T');
Threat-Led Penetration Testing (TLPT)

DORA_[ready]?

Threat-Led Penetration Testing for financial entities under the EU Digital Operational Resilience Act.

Threat-Led Penetration Testing

Test your defenses the way real attackers would test them.

Built for DORA, TIBER-EU, and any financial entity serious about operational resilience.

Our insight.

Loading...

Frequently asked, always answered.

Do you provide both threat intelligence and red teaming?

Yes. Our team includes both the threat intelligence providers and the red team operators required to deliver an end-to-end TLPT. For organisations that prefer to separate the two functions, we are happy to work alongside a third-party intelligence provider.

Who is required to undertake TLPT under DORA?

DORA introduces advanced testing for a defined group of financial entities, designated by competent authorities based on size, risk profile, and systemic importance. This includes significant banks, central counterparties, central securities depositories, and certain insurers and investment firms. If you are unsure whether your organisation is in scope, we can help you make that determination as part of an initial consultation.

How is TLPT different from a red team exercise?

A standard red team exercise can be scoped however the client wants. TLPT is bound by a specific methodology (TIBER-EU or equivalent under DORA), uses threat intelligence to drive scenario design, must be conducted against live production systems, and is observed by your competent authority. The bar is intentionally higher.

How long does a TLPT engagement take?

End-to-end, expect 6 to 9 months from scoping to closure report. The active red teaming phase alone typically runs for 10-12 weeks. We work with your team to build a realistic timeline that fits your release cycles and regulatory deadlines.

Will the test disrupt production?

The engagement is carefully designed to minimise operational impact. Risk management is a formal part of the methodology, and the white team has clear escalation paths to pause the exercise if necessary. In practice, well-run TLPT engagements complete without service disruption.

Go to Top