Back to glossaryLaw & regulation

Threat-led penetration testing

Simulated attack exercise run against a financial entity's live production systems, driven by threat intelligence, and required by DORA of the most significant entities.

Definition

A classical penetration test targets an announced perimeter, in an agreed window, against staging systems. Threat-led testing differs on three points that change its evidential value. It starts from threat intelligence reconstructing the tradecraft of groups likely to actually target the entity, and replays that tradecraft rather than a generic vulnerability checklist. It runs against production systems, hence the environment holding the data and the customers. And it is conducted without the defense teams' knowledge, so that what is measured is not attack surface but real detection and response capability. DORA makes it mandatory for entities designated as significant, at a frequency of at least one exercise every three years, with requirements on tester independence and mutual recognition of results between European supervisors. The framework builds on the TIBER-EU methodology published by the European Central Bank in 2018, which it makes binding.

Example

The European Central Bank published the TIBER-EU framework in May 2018 on a voluntary basis, and several national central banks adopted it in the following years. The DORA regulation, applicable since January 17, 2025, makes it mandatory for significant entities: a full exercise commonly mobilizes a threat intelligence provider, an independent red team and a supervisory lead, over six to nine months.

Related terms
Also known as

TLPT, TIBER-EU, test d'intrusion avancé, red team réglementaire