CyberFinance

Resilience Testing & TLPT Advisory

Prepare for, scope and survive threat-led penetration testing.

The situation

DORA requires all in-scope entities to run a digital operational resilience testing programme, and requires significant entities to undergo threat-led penetration testing on the TIBER-EU model at least every three years.

TLPT is expensive, disruptive and unforgiving of unprepared organisations. We work on the institution's side of the table: readiness assessment, scoping and critical-function selection, control-team support throughout the engagement, and remediation of what the testing finds.

What the client receives

Schedule of deliverables

  1. 01Resilience testing programme design across the DORA test taxonomy
  2. 02TLPT readiness assessment and maturity gate
  3. 03Critical function scoping and threat intelligence input review
  4. 04Control team advisory throughout the test lifecycle
  5. 05Purple-team and detection-improvement support
  6. 06Remediation plan and attestation support

Frameworks and standards

Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.

  • DORA Art. 24–27
  • TIBER-EU framework
  • RTS on TLPT
  • MITRE ATT&CK

Discuss this engagement

Tell us about where you are in the testing cycle and which functions are critical and we will set out the scope, the method and the reporting format.

Contact us