DORA requires designated EU financial entities to conduct Threat-Led Penetration Testing (TLPT) at least every three years, a fundamentally different exercise from standard penetration testing with its own governance structure, accredited providers, and regulatory reporting obligations. This post explains which organisations fall within scope, how a compliant engagement is structured, and what TLPT consistently reveals that conventional testing cannot.
Fintech and payment platforms are among the most targeted systems in the world, combining high-value financial data with rapidly evolving API ecosystems and cloud-native infrastructure. This guide covers everything you need to know about penetration testing — from PCI DSS and DORA compliance requirements to API security methodology, tooling, and cost benchmarks. Developed by Kyte Global, Europe's specialist fintech security advisory firm headquartered in Malta, it is the definitive practitioner resource for CISOs, compliance officers, and fintech founders.
Achieving PCI DSS certification is a structured journey that spans seven distinct phases—from initial scoping and gap analysis through to your signed Attestation of Compliance. This guide maps out a realistic 20–24 week timeline for Level 1 merchants and service providers, highlighting the technical controls, policy requirements, and assessment milestones that matter most. Whether you are starting from scratch or transitioning to PCI DSS v4.0, Kyte Global's compliance advisors walk you through every step.
At Kyte Global we attempt to add value in everything we do. Our services have evolved as a result of the growing needs of our clients. Regulations keep getting stricter, compliance requirements keep getting more onerous and clients find themselves spending more time addressing these issues rather than focusing on their business. At the same time, resources with the right knowledge and experience are hard to come by. Kyte Global tries to tackle these issues by providing a one stop shop to all the client’s needs. Kyte Global understands that Compliance is an effective way of ensuring that controls are implemented.
Internally, Kyte Global is organised in teams, each dedicated to a specific service, usually revolving around a specific standard or regulation. Some of these are PCI DSS, ISO 27001, GDPR, Internal Audit, AML, Gaming, Penetration Testing, Training to name a few. Each team is made up of trained professionals, all experts in their own field.
Over the years, Kyte Global has established partnerships with suppliers that develop and implement industry leading solutions so that it can make recommendations to clients who require such services or products. Kyte is proud to have a network of partners that can assist its clients, big or small, in virtually all of the industries it operates in.