Closure should explain outcomes, not just list weaknesses
A useful TLPT report connects the test’s objectives to the actions performed and the organisation’s response. It explains which controls prevented, detected or contained activity, where they did not, and what that means for the tested functions.
The RTS sets requirements for reporting and closure. Treat the reports as planned outputs from the start, with evidence collection and document ownership built into the engagement. Reconstructing events only after testing ends creates avoidable gaps.
Bring attack and defence accounts together
The red-team report records the tester’s perspective. The blue-team report describes what defenders observed and how they acted. Differences between those perspectives are often the most useful starting points for learning.
Replay and purple teaming can help explain why a detection was missed, why an alert was not escalated or why a response did not achieve its intended outcome. They can also reveal effective controls that deserve to be preserved or extended.
Turn a finding into an action
| Element | A useful question |
|---|---|
| Affected function | Which operational outcome could the issue undermine? |
| Root cause | Is the gap in technology, process, ownership, knowledge or a combination? |
| Action | What specific change will reduce the risk? |
| Owner and timing | Who is accountable, and what dependencies determine the target date? |
| Validation | What evidence will demonstrate that the improvement works? |
| Residual risk | What remains unresolved, and who accepts or escalates it? |
A plan that says only “improve monitoring” leaves important choices open. A more actionable plan identifies the missing visibility, the detection logic or operational step to change, and the team responsible for validating it.
Keep the regulatory timing visible
RTS Articles 12 and 13 cover closure and remediation requirements, including document timing. The red-team and blue-team reports, authority review, test summary and remediation documentation have distinct steps and triggers.
Assign someone to track these obligations and communications. Do not assume that submitting a technical report completes the entity’s responsibilities or that provider availability removes the need for internal ownership.
Control sensitive evidence
Reports can describe attack paths and security gaps that should not circulate broadly. Agree access, secure transfer, retention and redaction based on the audience and purpose. Management summaries can support decisions without reproducing every technical detail.
Do not put real findings into a public contact form or marketing case study. Any external case study needs a separate confidentiality and permission assessment.
Define what happens after closure
Remediation and any retesting should have explicit ownership and scope. Clarify whether follow-up validation is included in the contract, what evidence the entity will produce and how unresolved issues are escalated.
A completed TLPT is a basis for improvement. It does not guarantee that all weaknesses were found or discharge the entity’s wider DORA responsibilities.
Continue your preparation
Primary sources
General information, not legal advice. Confirm the applicable requirements and test arrangements with your relevant authority.
