Back to Publications
Regulatory Brief · DORA

DORA TLPT (TIBER-EU): How to Select a Red Team Provider for Financial Entities

30 May 2026By NexCyber Editorial DORA

Financial entities in the EU face a hard deadline: by 17 January 2025, Digital Operational Resilience Act (DORA) Article 26(8) requires them to have completed at least one threat-led penetration test (TLPT) if they are identified as “significant” by their competent authority. Even non-significant entities must still run TLPTs on a risk-based cycle. The only EU-harmonised framework for these tests is TIBER-EU, developed by the European Central Bank and now embedded in DORA Article 27. Selecting t

Financial entities in the EU face a hard deadline: by 17 January 2025, Digital Operational Resilience Act (DORA) Article 26(8) requires them to have completed at least one threat-led penetration test (TLPT) if they are identified as “significant” by their competent authority. Even non-significant entities must still run TLPTs on a risk-based cycle. The only EU-harmonised framework for these tests is TIBER-EU, developed by the European Central Bank and now embedded in DORA Article 27. Selecting the wrong red-team provider can mean wasted budget, regulatory push-back, or—worse—undetected critical vulnerabilities. This guide sets out practical selection criteria, a comparison matrix of European providers, and budget benchmarks.

---

1. DORA TLPT Mandate: Who Must Run Threat-Led Penetration Testing

DORA Article 26(1) defines the scope: credit institutions, payment institutions, e-money institutions, investment firms, crypto-asset service providers, central securities depositories, central counterparties, trading venues, trade repositories, managers of alternative investment funds, and insurance undertakings. Competent authorities will publish lists of “significant” entities by 17 July 2024; these must complete their first TLPT by 17 January 2026. Non-significant entities must still conduct TLPTs “at least every three years or more frequently if required by the risk profile of the financial entity” (DORA Article 26(9)).

Crucially, DORA Article 26(2) states that the test must be “threat-led”, meaning it must simulate the tactics, techniques and procedures (TTPs) of real threat actors relevant to the entity. This requirement elevates the test from a generic penetration test to a full-spectrum adversary emulation. Only providers accredited under the TIBER-EU framework or an equivalent national scheme (e.g., CBEST in the UK, iCAST in the Netherlands) can deliver such tests.

---

2. TIBER-EU Framework Structure: Preparation, Testing, Closure Phases

TIBER-EU is a three-phase process governed by the ECB’s TIBER-EU Framework v2.0 (March 2022).

2.1 Preparation Phase (4–8 weeks)

  • Scoping & threat intelligence (TI) briefing: The entity, its internal blue team, and the red-team provider agree on the critical functions to be tested (e.g., payment processing, trading systems). A threat-intelligence provider (often a separate firm) delivers a bespoke threat landscape report.
  • Rules of engagement (RoE): Legal, risk, and IT teams sign off on the scope, out-of-scope systems, and acceptable impact levels. DORA Article 26(5) requires that the test “does not endanger the financial stability of the financial entity or the financial system”.
  • White team formation: The entity’s internal team (white team) is established; it includes senior management, risk, compliance, and IT security leads. The white team must be available 24/7 during the live test phase.

2.2 Testing Phase (8–12 weeks)

  • Red-team execution: The provider emulates the TTPs of the threat actors identified in the TI briefing. Testing is conducted in “black box” mode: the red team has no prior knowledge of the internal network beyond what is publicly available or can be discovered through reconnaissance.
  • Blue-team detection & response: The entity’s internal security operations centre (SOC) and incident response team attempt to detect and respond to the red-team activities. The provider logs all actions in a detailed timeline that will later feed into the closure report.
  • Purple-team debriefs (optional): Daily or weekly syncs between red and blue teams to share indicators of compromise (IoCs) and detection gaps. These are not mandated by TIBER-EU but are increasingly adopted to accelerate learning.

2.3 Closure Phase (4–6 weeks)

  • Reporting: The provider delivers a classified report (TLP:AMBER) that includes: - Executive summary for the board (DORA Article 26(7) requires board-level reporting). - Technical findings, mapped to MITRE ATT&CK. - Detection and response metrics (e.g., mean time to detect, mean time to respond). - Remediation roadmap with risk-ranked actions.
  • Remediation & retesting: The entity must remediate critical findings within 6 months (DORA Article 26(6)). A retest is optional but recommended; some competent authorities require it.
  • Lessons-learned workshop: The white team, red team, and threat-intelligence provider review the test and update the entity’s threat model.

---

3. Provider Selection Matrix: Accreditation, Methodology, Threat Intel

Not all red-team providers are TIBER-EU accredited. The ECB maintains a list of accredited providers on its TIBER-EU portal; as of April 2024, 18 firms are listed, spanning global consultancies, boutique European firms, and national cybersecurity agencies. Below is a comparison matrix of key selection criteria.

CriterionMinimum RequirementAdvanced Capability
AccreditationTIBER-EU accredited (or national equivalent).Additional accreditations: CREST STAR, CBEST, iCAST, or NCSC CHECK (UK).
MethodologyFollows TIBER-EU phases; uses MITRE ATT&CK; provides TLP:AMBER report.Custom TTPs for financial sector (e.g., SWIFT, SEPA, blockchain); purple-team debriefs.
Threat IntelligencePartners with a recognised TI provider (e.g., Recorded Future, CrowdStrike, Anomali).In-house TI team; bespoke reports for financial crime (e.g., APT29, FIN7, Lazarus).
Team CompositionAt least 50% of team holds OSCP, OSCE, or SANS GPEN.Former financial-sector CISOs or SOC leads; ex-law-enforcement (e.g., Europol, NCSC).
ToolingCommercial tools (Cobalt Strike, Metasploit, Burp Suite).Custom tooling for financial protocols (e.g., ISO 20022, FIX); hardware implants.
Post-Test Support30-day retest window; executive debrief.6-month remediation advisory; detection-as-code (Sigma rules, YARA signatures).
Data ResidencyEU-based SOC; data stored in EU (GDPR Article 44).On-premise data processing; no cloud storage.
InsuranceProfessional indemnity cover (€5M minimum).Cyber liability cover (€10M+); financial crime rider.

3.1 Accreditation: Non-Negotiable

DORA Article 27(2) states that TLPTs must be “conducted by independent providers that meet the requirements set out in the regulatory technical standards”. The RTS (expected Q4 2024) will likely reference TIBER-EU accreditation as the baseline. Selecting a non-accredited provider risks non-compliance and invalidates the test.

3.2 Methodology: Beyond Check-the-Box

A TIBER-EU test is not a vulnerability scan. The provider must demonstrate:

  • Adversary emulation: Ability to replicate the kill chain of a specific threat actor (e.g., a state-sponsored group targeting SWIFT).
  • Realistic impact: The test must simulate real-world consequences (e.g., unauthorised payment initiation, data exfiltration) without causing actual harm.
  • Detection metrics: The provider must measure and report on the blue team’s detection and response times, not just the red team’s success.

3.3 Threat Intelligence: The Differentiator

The TI briefing is the foundation of the test. Providers that partner with or employ former financial-crime analysts (e.g., from Europol’s EC3 or the UK’s NCA) can deliver more targeted TTPs. For example, a provider with experience in ransomware-as-a-service (RaaS) groups like LockBit or Black Basta will design tests that include double extortion tactics, which are increasingly used against financial entities.

---

4. Cost Benchmarks per Scope: €80k–€450k per Engagement

Costs vary widely based on scope, complexity, and provider tier. Below are benchmarks for a single TIBER-EU engagement, excluding retesting and remediation advisory.

ScopeComplexityDurationTeam SizeEstimated Cost (EUR)Notes
Single critical function (e.g., retail payments)Low8 weeks4–6€80k–€120kSuitable for non-significant entities or subsidiaries.
Multiple critical functions (e.g., payments + trading)Medium12 weeks6–8€150k–€250kMost common for significant entities.
Full enterprise (all critical functions + third parties)High16 weeks8–12€300k–€450kRequired for systemically important financial institutions (SIFIs).

4.1 Cost Drivers

  • **Threat intelligence