Threat-led penetration testing is a different exercise from the penetration testing most organisations buy. It targets live production systems, is driven by bespoke threat intelligence about who would actually attack you, and it tests your defenders at least as much as your controls.
What makes it different
- Live production. Not a staging copy. That is what makes the results meaningful and the risk management demanding.
- Intelligence-led. A threat intelligence provider builds a picture of plausible adversaries and their methods, and the red team emulates those specifically rather than running a generic methodology.
- Blue team is not told. Only a small white team knows the exercise is running. The point is to observe genuine detection and response.
- Regulator involvement. The exercise runs under a defined framework with supervisory oversight, not as a private engagement.
- Duration. Months, not weeks — reconnaissance and staged execution take time.
The phases
- Preparation — scope the critical functions to be tested, assemble the white team, procure providers, agree risk management and stop conditions.
- Testing — threat intelligence produces a targeted threat profile; the red team then executes scenarios against production over an extended window.
- Closure — red and blue teams reconstruct events together, findings are agreed, remediation is planned, and a report goes to the authority.
The purple-teaming replay in closure is where most of the value is. Comparing what the red team did against what the blue team saw exposes detection gaps far more precisely than a findings list — and it is the part organisations most often under-resource.
Connect test findings to the controls they affect
GRC Copilot records findings against the controls they touch and tracks remediation to closure, with the evidence supervisors expect.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
The white team is the critical role
A small group who know the test is live. They authorise scope, hold the stop conditions, and — most importantly — prevent a genuine incident response from escalating into regulatory notification, customer communication or law enforcement involvement over simulated activity.
They also have to distinguish the exercise from a real intrusion occurring concurrently, which is a scenario the framework expects them to plan for. That is why white team composition and availability matter more than any technical decision in the engagement.
Relationship to DORA
DORA requires advanced threat-led penetration testing for certain financial entities, and TIBER-EU is the established European framework for conducting it. Entities in scope should expect the requirement on a multi-year cycle rather than annually, given cost and duration.
Note the distinction from ordinary resilience testing: DORA requires a broad testing programme for everyone in scope, and TLPT only for a subset determined by their significance. Do not assume TLPT applies because DORA does.
Whether it is worth it if not required
Only if your defensive capability is mature enough for the answer to be informative. Running an intelligence-led red team against an estate that has never had a conventional penetration test produces an expensive report saying what a much cheaper engagement would have found. Sequence it after your detection capability exists.
Frequently asked questions
Is this the same as a red team engagement?
Closely related. TIBER-EU adds regulator oversight, prescribed phases, mandated threat intelligence and defined provider requirements.
How long does it take?
Months end to end. Procurement, intelligence and staged execution all take real time.
Does everyone under DORA need TLPT?
No — only entities identified as significant enough. Everyone in scope needs a testing programme; TLPT is a subset requirement.
What if a real incident happens during the test?
The white team must be able to distinguish and separate the two, and stop conditions must be defined in advance. Plan for it explicitly.
Key takeaways
- Live production, bespoke intelligence, and defenders kept unaware.
- The white team carries the risk management, not the red team.
- The purple-team replay is where the real learning sits.
- DORA scope does not automatically mean TLPT scope.