Financial sector resilienceAtlant Security
TLPT/DORABY ATLANT SECURITY

Delivery

The control team: governing a safe, useful TLPT

How a restricted control team keeps the exercise authorised, coordinated and focused on learning.

The control team connects realism with accountability

The control team is the restricted group inside the financial entity that knows about and manages the test. It coordinates the exercise while preserving the conditions needed to assess the defenders’ capabilities. Its lead is a central point of contact for providers and the authority’s test managers.

A control team should not be a name added to a project plan after procurement. Its membership, authority, confidentiality and escalation arrangements shape whether testing can proceed safely and produce useful evidence.

Before testing: make decisions executable

  • Confirm who can approve activity, change a boundary or stop the test.
  • Establish secure communication and a need-to-know approach.
  • Connect critical-function owners, operational constraints and provider dependencies.
  • Agree rules of engagement, incident handling and emergency contacts.
  • Plan which documents require review and how authority coordination works.

These decisions should be documented in a way that participants can actually use under time pressure. Ambiguous ownership becomes most costly when an unexpected production issue arises.

During testing: distinguish the exercise from a real incident

Controlled testing does not remove the possibility of a genuine attack or unrelated service disruption. The control team needs a process for distinguishing events, escalating uncertainty and pausing activity when warranted.

Keep records of material decisions, assumptions, restrictions and changes. The purpose is not to create paperwork for its own sake, but to preserve why an action was authorised and how risk was assessed. Avoid exposing the exercise unnecessarily to the broader defensive team.

At closure: turn observations into learning

The red team’s record and the blue team’s experience may tell different parts of the same story. The control team helps reconcile them through the applicable reporting, replay and purple-team process.

For example, an action may have generated telemetry without triggering an investigation, or a detection may have led to a response that did not contain the scenario. These are distinct outcomes and call for different improvements. A single vulnerability list would miss that distinction.

Keep ownership beyond the final meeting

Closure should produce agreed remediation actions, accountable owners and a process for tracking completion. The financial entity remains responsible for its regulatory obligations and follow-through even where a provider supports documentation.

Plan the handover from the restricted testing group to the teams that will implement improvements. Information should reach the people who need it while sensitive attack details remain appropriately controlled.

Continue your preparation

Primary sources

General information, not legal advice. Confirm the applicable requirements and test arrangements with your relevant authority.

LET’S START A CONVERSATION

Define the scope.
Take the next step.

Your critical functions. Your authority’s requirements. A clear starting point for your TLPT engagement.

Discuss your TLPT