<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>TLPT DORA insights</title><link>https://tlptdora.com/blog/</link><description>Practical DORA TLPT guidance from Atlant Security.</description><language>en</language><item><title>TLPT vs penetration testing: what changes under DORA?</title><link>https://tlptdora.com/blog/dora-tlpt-vs-penetration-testing/</link><guid>https://tlptdora.com/blog/dora-tlpt-vs-penetration-testing/</guid><description>Why a conventional penetration test does not automatically meet the requirements of a DORA threat-led exercise.</description><pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate></item><item><title>How to scope a DORA TLPT around critical functions</title><link>https://tlptdora.com/blog/dora-tlpt-scope/</link><guid>https://tlptdora.com/blog/dora-tlpt-scope/</guid><description>Start with the function, trace the dependencies and make the boundary of the test explicit.</description><pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate></item><item><title>How long does a DORA TLPT take?</title><link>https://tlptdora.com/blog/tlpt-timeline/</link><guid>https://tlptdora.com/blog/tlpt-timeline/</guid><description>Understand the 12-week active-testing minimum and the preparation and closure work that sit around it.</description><pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Article 27: what to verify in a TLPT provider</title><link>https://tlptdora.com/blog/article-27-tester-requirements/</link><guid>https://tlptdora.com/blog/article-27-tester-requirements/</guid><description>Translate DORA’s tester requirements into evidence requests for your provider and the team that will actually deliver the test.</description><pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate></item><item><title>TIBER-EU and DORA: how the pieces fit</title><link>https://tlptdora.com/blog/tiber-eu-and-dora/</link><guid>https://tlptdora.com/blog/tiber-eu-and-dora/</guid><description>Separate legal requirements from operational guidance, and understand why both matter to a threat-led engagement.</description><pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate></item><item><title>The control team: governing a safe, useful TLPT</title><link>https://tlptdora.com/blog/tlpt-control-team/</link><guid>https://tlptdora.com/blog/tlpt-control-team/</guid><description>How a restricted control team keeps the exercise authorised, coordinated and focused on learning.</description><pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate></item><item><title>ICT third parties in a DORA TLPT</title><link>https://tlptdora.com/blog/tlpt-third-party-providers/</link><guid>https://tlptdora.com/blog/tlpt-third-party-providers/</guid><description>Why provider participation, shared services and testing permissions belong in the scope from the beginning.</description><pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate></item><item><title>From TLPT findings to accountable remediation</title><link>https://tlptdora.com/blog/tlpt-reporting-remediation/</link><guid>https://tlptdora.com/blog/tlpt-reporting-remediation/</guid><description>Make closure useful by connecting the attack narrative, defensive observations and practical improvement decisions.</description><pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate></item></channel></rss>