Financial sector resilienceAtlant Security
TLPT/DORABY ATLANT SECURITY

Delivery

From TLPT findings to accountable remediation

Make closure useful by connecting the attack narrative, defensive observations and practical improvement decisions.

Closure should explain outcomes, not just list weaknesses

A useful TLPT report connects the test’s objectives to the actions performed and the organisation’s response. It explains which controls prevented, detected or contained activity, where they did not, and what that means for the tested functions.

The RTS sets requirements for reporting and closure. Treat the reports as planned outputs from the start, with evidence collection and document ownership built into the engagement. Reconstructing events only after testing ends creates avoidable gaps.

Bring attack and defence accounts together

The red-team report records the tester’s perspective. The blue-team report describes what defenders observed and how they acted. Differences between those perspectives are often the most useful starting points for learning.

Replay and purple teaming can help explain why a detection was missed, why an alert was not escalated or why a response did not achieve its intended outcome. They can also reveal effective controls that deserve to be preserved or extended.

Turn a finding into an action

ElementA useful question
Affected functionWhich operational outcome could the issue undermine?
Root causeIs the gap in technology, process, ownership, knowledge or a combination?
ActionWhat specific change will reduce the risk?
Owner and timingWho is accountable, and what dependencies determine the target date?
ValidationWhat evidence will demonstrate that the improvement works?
Residual riskWhat remains unresolved, and who accepts or escalates it?

A plan that says only “improve monitoring” leaves important choices open. A more actionable plan identifies the missing visibility, the detection logic or operational step to change, and the team responsible for validating it.

Keep the regulatory timing visible

RTS Articles 12 and 13 cover closure and remediation requirements, including document timing. The red-team and blue-team reports, authority review, test summary and remediation documentation have distinct steps and triggers.

Assign someone to track these obligations and communications. Do not assume that submitting a technical report completes the entity’s responsibilities or that provider availability removes the need for internal ownership.

Control sensitive evidence

Reports can describe attack paths and security gaps that should not circulate broadly. Agree access, secure transfer, retention and redaction based on the audience and purpose. Management summaries can support decisions without reproducing every technical detail.

Do not put real findings into a public contact form or marketing case study. Any external case study needs a separate confidentiality and permission assessment.

Define what happens after closure

Remediation and any retesting should have explicit ownership and scope. Clarify whether follow-up validation is included in the contract, what evidence the entity will produce and how unresolved issues are escalated.

A completed TLPT is a basis for improvement. It does not guarantee that all weaknesses were found or discharge the entity’s wider DORA responsibilities.

Continue your preparation

Primary sources

General information, not legal advice. Confirm the applicable requirements and test arrangements with your relevant authority.

LET’S START A CONVERSATION

Define the scope.
Take the next step.

Your critical functions. Your authority’s requirements. A clear starting point for your TLPT engagement.

Discuss your TLPT