Threat-Led Penetration Testing Under DORA
What Financial Entities Need to Get Right

DORA requires designated EU financial entities to conduct Threat-Led Penetration Testing (TLPT) at least every three years, a fundamentally different exercise from standard penetration testing with its own governance structure, accredited providers, and regulatory reporting obligations. This post explains which organisations fall within scope, how a compliant engagement is structured, and what TLPT consistently reveals that conventional testing cannot.

Posted on: Monday, July 27th, 2026

DORA entered into force across the European Union on 17 January 2025. Among its most significant requirements for the financial  services sector is the obligation for certain entities to conduct Threat-Led Penetration Testing, commonly referred to as TLPT, at least every three years under the supervision of their competent authority. 

TLPT is not an enhancement of the penetration testing most organisations already conduct. It is a fundamentally different category of security exercise, one that requires specialist threat intelligence providers, accredited red team operators, coordinated governance across multiple parties, and formal regulatory reporting. Many financial entities, even those that have invested heavily in cybersecurity, are not yet prepared for what DORA-compliant TLPT actually demands. 

This post draws on a presentation delivered by Kyte’s Francis Kyereh at a recent financial services conference, setting out what TLPT is, which organisations it applies to, how the TIBER-EU framework structures the engagement, and what the most common mistakes are that derail programmes before they produce value.

What Is Threat-Led Penetration Testing?

The term penetration testing is used loosely across the industry. TLPT has a precise definition that distinguishes it from both standard penetration testing and traditional red team exercises. 

TLPT is a threat intelligence-based, custom-made, entity-specific, controlled red team test. It simulates the tactics, techniques, and procedures of real threat actors who are likely to target your organisation, based on intelligence gathered specifically about your sector, your geography, your technology environment, and your operational profile. The test is conducted covertly on live production systems. Your security operations team is not told it is happening. 

The purpose is to evaluate end-to-end operational resilience: not whether vulnerabilities exist in your systems, but whether your organisation can prevent, detect, respond to, and recover from a sophisticated, intelligence-driven attack against its most critical functions. 


Who Must Conduct TLPT Under DORA?

DORA applies a proportionality principle to advanced testing obligations. Not every entity subject to DORA is required to conduct TLPT. Competent authorities determine which organisations fall within the scope of the advanced testing requirement based on their systemic importance, size, and ICT risk profile. 

The following categories of entity should treat their TLPT obligations as a priority matter: 

  • Credit institutions and banks operating within the EU 
  • Payment institutions and e-money institutions 
  • Investment firms and alternative investment fund managers 
  • Insurance and reinsurance undertakings 
  • Crypto-asset service providers (CASPs) authorised under MiCA 
  • Central counterparties and trading venues 

Note: Critical ICT Third-Party Service Providers (CTPPs) do not have a standalone legal obligation to initiate a regulatory DORA TLPT on themselves. The statutory mandate to conduct TLPT applies directly to designated Financial Entities (FEs). Under DORA Articles 26 and 27, the formal obligation to undergo TLPT is placed on financial entities identified by their respective Competent Authorities. However, they may be required to participate in scope as part of a financial entity’s TLPT engagement where they support critical or important functions. Financial entities must account for this when defining scope. 

Entities not immediately identified as subject to advanced testing are still required to conduct vulnerability assessments and standard penetration testing under DORA’s basic testing pillar. The advanced testing obligation, TLPT, sits above that baseline and carries additional governance, intelligence, and reporting requirements. 


The Five Phases of a DORA-Compliant TLPT Engagement

A TLPT engagement under DORA follows the TIBER-EU framework, which structures the exercise across five distinct phases. Understanding each phase is essential for any CISO or risk officer planning or overseeing a TLPT programme. Timelines will vary depending on organisational complexity, and the scope agreed with the competent authority. 

Phase 1: Stakeholders and Governance 

Before any testing begins, the governance structure for the engagement must be established. This involves defining the roles of the Financial Entity, the TLPT Authority, the TIBER Cyber Team, the Threat Intelligence Provider, the Red Team, and the White Team — the internal control function that manages the engagement on behalf of the organisation. The competent authority must be notified, and legal authority for the testing activities must be formally documented. 

Phase 2: Scoping and Target Definition 

The scope of the engagement is defined around the organisation’s critical and important functions, not around specific systems or applications. A Generic Threat Landscape report is produced for the relevant sector, and the boundaries of the test — including stop conditions and risk limits — are agreed with the competent authority. Third-party ICT providers that support critical functions must also be considered for inclusion in scope. 

Phase 3: Threat Intelligence 

This is the phase that distinguishes TLPT from every other form of penetration testing. An accredited Threat Intelligence Provider produces a Targeted Threat Intelligence report specific to your organisation. This report identifies the threat actors most likely to target your business, their known tactics and techniques, and the specific attack scenarios that the red team will execute. The quality of this intelligence determines the quality of the entire engagement. 

Phase 4: Red Team Testing 

The Red Team executes the attack scenarios defined by the threat intelligence. This phase is conducted covertly over an extended period on live production systems. The blue team — your security operations function — is deliberately not informed. This is the only way to generate a realistic measurement of detection and response capability. Testing covers technical intrusion, social engineering, and in some cases physical security, depending on the agreed scope. 

Phase 5: Closure 

The closure phase produces the documentation and learning that give the engagement lasting value. A comprehensive Red Team Test Report documents all activities and findings. A Blue Team Replay reveals the full attack timeline to the security operations team for the first time. A Purple Team exercise brings red and blue together to close the detection and response gaps identified during the covert phase. A remediation plan is produced, and a formal attestation is submitted to the competent authority.


What TLPT Consistently Reveals 

The following observations are drawn from Kyte Global’s experience conducting red team engagements with financial services organisations, and from wider industry practice. TLPT surfaces four categories of weakness that standard penetration testing does not identify and that most organisations are genuinely surprised to encounter. 

Detection performance is lower than monitoring coverage implies 

Organisations with sophisticated SIEM deployments, SOC operations, and EDR coverage frequently find that attackers using legitimate credentials or authorised communication channels can move through their environments for extended periods without triggering alerts. The gap between theoretical monitoring coverage and actual detection performance is almost always larger than expected. 

Incident response processes break down under realistic conditions 

Alert fatigue, unclear escalation paths, and the difficulty of distinguishing sophisticated attacker behaviour from normal operational noise all cause response processes to fail in ways that tabletop exercises and planned simulations never reveal. TLPT is the only exercise that tests the full response chain under conditions that replicate what a real incident would look like. 

Third-party access is systematically under-monitored 

Financial entities operate with extensive third-party ICT relationships. TLPT consistently finds that access granted to third-party providers is inadequately monitored and that a compromise of a supplier can propagate into the financial entity’s environment without detection. This is precisely why DORA requires third-party ICT providers to be considered in scope for TLPT. 

Human factors undermine technical controls 

Social engineering components of TLPT engagements regularly demonstrate that staff can be manipulated into actions that bypass technical controls entirely. These findings cannot be addressed by technical investment alone and require targeted security awareness programmes informed by the specific techniques that succeeded during the test.


Common Mistakes That Derail TLPT Programmes

Across TLPT engagements with financial entities, the same mistakes appear repeatedly. Being aware of them in advance significantly reduces the risk of a costly and time-consuming programme failure. 

  • Treating TLPT as an enhanced penetration test.  The engagement model, governance requirements, timeline, and regulatory obligations of TLPT are categorically different from standard penetration testing. Appointing a standard penetration testing firm without TIBER-EU experience will not produce a DORA-compliant result. 
  • Under-investing in threat intelligence.  The Targeted Threat Intelligence report is the foundation of the entire engagement. Weak intelligence produces generic scenarios that do not reflect the actual threat landscape facing your organisation and significantly reduce the value of the exercise. 
  • Assuming TLPT applies to every entity.  DORA’s advanced testing obligation is reserved for entities designated by their competent authority based on systemic importance and risk profile. Treating TLPT as a universal requirement misallocates resources and misrepresents the regulatory obligation. 
  • Insufficient safeguards for live system testing.  TLPT is conducted on live production systems. Rigorous business continuity protocols, clearly defined stop conditions, and formal escalation paths must be in place before any testing begins. 
  • Late notification of the competent authority.  Regulators expect to be informed of planned TLPT engagements well in advance. Late or inadequate engagement with the authority creates delays, affects mutual recognition outcomes, and can undermine the credibility of the attestation. 
  • Treating the remediation plan as a compliance formality.  Regulators assess the quality of the remediation response as carefully as they assess the findings themselves. A credible, prioritised, and time-bound remediation plan is not optional — it is the evidence that the organisation has taken the findings seriously. 

Conclusion 

TLPT under DORA represents a genuine step change in the security testing obligations facing EU financial entities. It is more demanding, more structured, and more consequential than anything most organisations have previously been required to undertake. But approached correctly, with the right threat intelligence provider, an experienced red team, disciplined governance, and a commitment to acting on findings, it is also the most accurate measure available of whether your security programme is fit for purpose against the threats that actually exist. 

Kyte Global supports financial entities across Europe through every phase of a DORA-compliant TLPT engagement, from initial scoping and authority notification through to regulatory attestation and remediation validation.

News & Insights

Stay informed with our dynamic News and Insights section, where we share timely updates, industry trends, and expert perspectives to keep you ahead of the curve and informed about the latest developments in the field. Explore a wealth of valuable resources that empower you with knowledge and actionable insights for informed decision-making.

Penetration Testing for Fintech & Payment Platforms
Friday, 5th June 2026

Fintech and payment platforms are among the most targeted systems in the world, combining high-value financial data with rapidly evolving API ecosystems and cloud-native infrastructure. This guide covers everything you need to know about penetration testing — from PCI DSS and DORA compliance requirements to API security methodology, tooling, and cost benchmarks. Developed by Kyte Global, Europe's specialist fintech security advisory firm headquartered in Malta, it is the definitive practitioner resource for CISOs, compliance officers, and fintech founders.

Continue reading
From Audit to Certification: A Real-World Timeline for Achieving PCI DSS Compliance
Thursday, 15th January 2026

Achieving PCI DSS certification is a structured journey that spans seven distinct phases—from initial scoping and gap analysis through to your signed Attestation of Compliance. This guide maps out a realistic 20–24 week timeline for Level 1 merchants and service providers, highlighting the technical controls, policy requirements, and assessment milestones that matter most. Whether you are starting from scratch or transitioning to PCI DSS v4.0, Kyte Global's compliance advisors walk you through every step.

Continue reading
PCI DSS Compliance for Fintech: 5 Critical Requirements Your Payment Platform Can't Ignore in 2026
Thursday, 8th January 2026

Fintech companies handling cardholder data must meet the stringent requirements of the Payment Card Industry Data Security Standard (PCI DSS) to protect sensitive payment information and maintain trust with customers and partners. This guide breaks down the five most critical PCI DSS requirements for fintech platforms in 2026, offering practical implementation strategies and common pitfalls to help turn compliance from a burden into a competitive advantage.

Continue reading