Financial sector resilienceAtlant Security
TLPT/DORABY ATLANT SECURITY

OUR APPROACH

A controlled test. A complete learning cycle.

How scope, threat intelligence, red teaming, closure and remediation planning fit together in a DORA TLPT engagement.

Discuss your requirements

01 — Prepare and define the scope

Establish the control team, engage with the relevant authority and confirm the basis for testing. Map critical or important functions to people, processes, production systems and ICT providers. Record scope boundaries and dependencies in a form that can be reviewed and validated.

Procurement, confidentiality, authority coordination, risk assessment and rules of engagement are prerequisites for safe execution. Identify who can approve a change, stop activity and resolve a genuine incident during testing.

02 — Develop targeted threat intelligence

Use the organisation’s exposure and threat landscape to identify relevant adversaries and plausible attack scenarios. The intelligence phase should connect the reasons for choosing a scenario to the functions being tested.

Separate established facts, analytical judgments and uncertainty. Agree the intelligence and scenario outputs with the appropriate participants before red-team planning is finalised.

03 — Execute controlled red-team testing

Translate scenarios into a test plan, agreed objectives and controlled actions. The control team maintains oversight while the defenders’ prevention, detection and response capabilities are tested under the applicable methodology.

The active red-team testing phase has a minimum duration of 12 weeks under RTS Article 11(5). Operational circumstances, approved changes and any limited purple teaming must be managed in accordance with the RTS and authority process. This is not permission to shorten or redefine the test unilaterally.

04 — Reconstruct the test and learn

After active testing, disclose the exercise to the blue team through the agreed process. Bring the red-team attack narrative together with the defenders’ account. Replay, collaborative analysis and purple teaming help explain where controls worked, where visibility was missing and what should change.

The RTS sets report content and timing requirements. Plan the red-team report, blue-team report and test summary early rather than assembling them from incomplete notes at the end.

05 — Plan remediation and complete the evidence

Assign remediation ownership and priorities, distinguish immediate fixes from structural improvements, and agree how completion will be evidenced. Submit the required documentation through the financial entity’s authority process.

Closure documentation and any authority attestation concern the test. The entity continues to own its broader DORA obligations and remediation programme. Read more about the outputs and responsibilities.

How TIBER-EU fits

The ECB’s TIBER-EU framework provides operational guidance, participant roles and templates. Use it consistently with DORA, the TLPT RTS and the applicable authority’s implementation. A provider should explain how its approach maps to these requirements, rather than treating the TIBER name as an accreditation.

Primary sources

General information, not legal advice. Confirm the applicable requirements and test arrangements with your relevant authority.

LET’S START A CONVERSATION

Define the scope.
Take the next step.

Your critical functions. Your authority’s requirements. A clear starting point for your TLPT engagement.

Discuss your TLPT