Financial sector resilienceAtlant Security
TLPT/DORABY ATLANT SECURITY

Planning

ICT third parties in a DORA TLPT

Why provider participation, shared services and testing permissions belong in the scope from the beginning.

A critical function rarely ends at the entity’s boundary

Financial entities rely on ICT third-party providers for functions that may be included in a TLPT. DORA addresses this involvement and requires arrangements for relevant participation. Outsourcing a dependency does not remove the financial entity’s responsibility.

Scoping needs to distinguish the function being tested, the systems supporting it and the legal permissions required to test those systems. A contract for using a service is not necessarily authorisation to conduct offensive testing against it.

Identify the dependency before selecting scenarios

Document what the provider supports, which systems or processes could be involved, and whether the service is shared with other customers. Establish the contractual and operational contact routes early.

A scenario may depend on identity services, hosting, communications or an outsourced operational process. If the engagement assumes participation that has not been agreed, its schedule and evidential value can both suffer.

Agree participation and operational safeguards

  • Identify the relevant provider and any material subcontracting dependency.
  • Obtain the permissions and contractual arrangements required for the proposed activity.
  • Clarify tenant boundaries, prohibited actions and effects on other customers.
  • Set escalation routes, stop conditions and incident coordination.
  • Agree evidence handling, access, confidentiality and report distribution.

Do not expose unrelated customers to the exercise or treat the provider’s entire platform as automatically in scope. The control team, provider and authority process need a shared understanding of boundaries.

When pooled testing may be relevant

DORA provides for pooled testing arrangements in the circumstances described in Article 26, including where participation in a test could affect service quality or security for other customers or confidentiality. Such arrangements need to follow the applicable conditions and oversight process.

A generic vendor penetration-test report is not automatically a pooled TLPT or a substitute for an entity’s obligations. Determine what functions, participants and risks the proposed arrangement actually covers, and how recognition will be handled.

Bring the issue into the first brief

Tell potential testing providers which ICT dependencies are likely to be material and which participation arrangements are already in place. Show unresolved approvals as dependencies, not as hidden exclusions.

The strongest next step is often a better map and an agreed contact route. Detailed scenarios can then be developed around a scope that is both meaningful and authorised.

Continue your preparation

Primary sources

General information, not legal advice. Confirm the applicable requirements and test arrangements with your relevant authority.

LET’S START A CONVERSATION

Define the scope.
Take the next step.

Your critical functions. Your authority’s requirements. A clear starting point for your TLPT engagement.

Discuss your TLPT