Financial sector resilienceAtlant Security
TLPT/DORABY ATLANT SECURITY

Requirements

TIBER-EU and DORA: how the pieces fit

Separate legal requirements from operational guidance, and understand why both matter to a threat-led engagement.

Law and operational guidance play different roles

DORA and its TLPT RTS establish the legal requirements for advanced threat-led testing. TIBER-EU provides a practical framework for organising and conducting intelligence-led red-team exercises. They are connected, but the names are not interchangeable.

For a DORA engagement, the framework must be applied consistently with the legislation, technical standards and applicable authority process. A voluntary exercise inspired by TIBER is not automatically a recognised DORA TLPT.

Understand the participants

A threat-led test involves more than the testers and a customer contact. The financial entity needs a restricted control team and a control-team lead. Threat intelligence providers develop the threat basis; red-team testers execute agreed scenarios; the blue team supplies the defensive perspective during closure.

The relevant authority’s test managers have their own oversight role. Procurement and planning should make these responsibilities explicit, including communication routes and which participants receive sensitive information at each stage.

Use templates to expose unanswered questions

TIBER-EU publishes guidance and templates that can structure scoping, threat intelligence, testing, reporting and remediation. Their value lies in the decisions and evidence they organise, rather than in the mere use of a familiar document title.

Map each output to the applicable RTS content requirements and authority directions. A completed template that omits a material dependency or unresolved authorisation question does not solve the underlying issue.

Check the implementation that applies to you

Authorities may have national or sector-specific operational arrangements. Cross-border testing introduces questions about oversight, coordination and recognition. Resolve these at initiation so the exercise is not planned around incompatible assumptions.

For significant institutions under ECB supervision, the ECB’s implementation guide is a useful official reference. Other financial entities should identify the relevant authority and guidance rather than assuming the same operating model applies in every case.

Ask for the mapping

A useful provider proposal explains how scope, scenarios, risk controls, execution and closure map to DORA, the RTS and the applicable framework. It also shows which responsibilities remain with the financial entity and the authority.

Ask the provider to identify any assumptions or departures that need approval. “TIBER aligned” is a description that should be supported by an understandable delivery model; it is not a regulatory endorsement.

Continue your preparation

Primary sources

General information, not legal advice. Confirm the applicable requirements and test arrangements with your relevant authority.

LET’S START A CONVERSATION

Define the scope.
Take the next step.

Your critical functions. Your authority’s requirements. A clear starting point for your TLPT engagement.

Discuss your TLPT