
TLPT vs penetration testing: what changes under DORA?
Why a conventional penetration test does not automatically meet the requirements of a DORA threat-led exercise.
Read the perspectiveINSIGHTS & GUIDES
Practical reading for the people who scope, procure and govern a DORA TLPT.

8 guides

Why a conventional penetration test does not automatically meet the requirements of a DORA threat-led exercise.
Read the perspective
Start with the function, trace the dependencies and make the boundary of the test explicit.
Read the perspective
Understand the 12-week active-testing minimum and the preparation and closure work that sit around it.
Read the perspective
Translate DORA’s tester requirements into evidence requests for your provider and the team that will actually deliver the test.
Read the perspective
Separate legal requirements from operational guidance, and understand why both matter to a threat-led engagement.
Read the perspective
How a restricted control team keeps the exercise authorised, coordinated and focused on learning.
Read the perspective
Why provider participation, shared services and testing permissions belong in the scope from the beginning.
Read the perspective
Make closure useful by connecting the attack narrative, defensive observations and practical improvement decisions.
Read the perspectiveNo guides match this search. Try “scope”, “testing” or choose All topics.

LET’S START A CONVERSATION
Your critical functions. Your authority’s requirements. A clear starting point for your TLPT engagement.
Discuss your TLPT