Finance — DORA, CBEST, NYDFS, MAS TRM
Continuous testing and threat-led validation for DORA and TIBER-EU, CBEST, NYDFS Part 500, MAS TRM and APRA CPS 234 — with ICT-incident evidence mapped in the same appliance.
DORA (Regulation (EU) 2022/2554) entered application on 17 January 2025 across all EU financial entities. Article 25 mandates continuous testing of ICT systems supporting critical or important functions, with a risk-based approach updated annually. Article 26 + the RTS 2025 on TLPT require threat-led penetration testing for significant entities at least every 3 years using a documented methodology (TIBER-EU). The European Banking Authority and the Banca d'Italia have made it clear that "continuous" means continuous, not "more frequent than annual" — and that the testing program must incorporate the latest threat intelligence, not a fixed playbook.
What is on the DORA-regulated CISO's desk
DORA Art. 24–25 testing program
A risk-based program of tests for ICT systems, with those supporting critical or important functions tested at least yearly (Art. 24(6)) — and supervisors increasingly expect evidence between those points. A single yearly report shows the controls held on one day.
DORA Art. 26 / TLPT RTS 2025
Threat-led pentest with TIBER-EU methodology, signed evidence, full chain-of-custody from the threat intelligence input to the final report.
ICT incident reporting (Art. 17-22)
Initial notification at 4h for major incidents, intermediate at 72h, final at 1 month. Same time pressure as NIS2 but with stricter materiality thresholds.
Third-party risk (Art. 28-30)
You inherit the regulator's scrutiny on every ICT third-party provider — including security tooling vendors. SaaS pentest providers are increasingly hard to justify in DORA-scoped procurement.
How Zero Hunt addresses DORA
Threat-led testing between TLPT cycles
The 10-agent swarm runs threat-led campaigns informed by live intelligence (CISA KEV, EPSS, vendor advisories and the other intelligence sources), with a methodology that maps onto the TIBER-EU phases (threat intelligence, red-team test, purple team, closure). Every phase is signed, so the evidence traces back to the intelligence that drove it — input for your TLPT and for the testing DORA Art. 24 expects between TLPTs. The TLPT itself still runs under the RTS, with the testers and authority oversight it prescribes.
ICT incident evidence for DORA Art. 17-19 reporting
Detected events come with the timeline, affected assets and signed evidence your team needs to classify them against the DORA criteria and meet the 4h/72h/1-month reporting cadence. Findings and evidence are mapped to DORA controls and exported from the Trust Center as a signed bundle for auditors and supervisors.
Wire-speed detection on the payments and trading boundary
AI traffic analysis on the appliance GPU catches the in-progress patterns: market-data exfiltration, payment-system C2, dwell-and-pivot attacks targeting clearing infrastructure. Real-time, not batch.
Capability emphasis for finance
- ▸Continuous validation of critical ICT systems (Art. 25 baseline)
- ▸TIBER-EU-aligned TLPT campaign workflow with signed evidence
- ▸Signed incident evidence and timelines for DORA reporting
- ▸4h / 72h / 1-month notification timeline as queryable workflow
- ▸Third-party-risk story: 100% on-prem, no SaaS vendor in scope
Who buys this in finance
CISO sponsoring; Head of ICT Risk co-signing on DORA scope; Compliance / Internal Audit validating against the EBA technical standards; CFO authorizing on the basis that continuous validation between TLPT cycles replaces separate continuous-testing tooling and shortens TLPT preparation — the TLPT itself is still run by the testers the regulation requires (external, or internal ones with the approval of the authority and an external team every third test).
Frameworks mapped for this sector, worldwide
The same on-premise appliance serves regulated organizations in every region. For this sector, findings and evidence are mapped out of the box to:
- Global / cross-industry
- SWIFT Customer Security Programme
- PCI DSS
- ISO/IEC 27001:2022
- European Union
- DORA
- TIBER-EU
- United States
- NYDFS Part 500
- GLBA / FTC Safeguards Rule
- SEC cybersecurity disclosure rules
- SOX IT controls
- United Kingdom
- CBEST / STAR-FS
- Canada
- OSFI Guideline B-13
- Asia-Pacific
- APRA CPS 234
- MAS Technology Risk Management
- RBI Cybersecurity Framework
- FISC Security Guidelines
- Middle East
- Saudi NCA ECC / SAMA CSF
- Bank of Israel Directive 361
Why this sector runs its AI red team on-premise, on private AI →
Go deeper on the regulations
- Playbook · 11 minDORA penetration testing requirements beyond TLPT — the Article 24–25 testing programme
A practical guide to the digital operational resilience testing programme that DORA Articles 24 and 25 require of almost every financial entity, how it differs from TLPT under Articles 26 and 27, and how to prepare for a TLPT with continuous internal testing.
- Definition · 6 minWhat is TLPT (Threat-Led Penetration Testing)?
TLPT is a regulator-mandated form of penetration testing where the attack scenarios are explicitly driven by threat intelligence about adversaries currently targeting the tested entity, executed by an independent red team under a documented methodology with verifiable evidence chain.
- Playbook · 11 minUK penetration testing requirements — CBEST for financial firms and the NCSC Cyber Assessment Framework
How the Bank of England's CBEST intelligence-led testing and the NCSC Cyber Assessment Framework v4.0 treat penetration testing and vulnerability management: who they apply to, who may test, and what evidence counts.
- Playbook · 10 minMAS TRM penetration testing requirements — what section 13 of the Technology Risk Management Guidelines expects
A paragraph-by-paragraph guide to vulnerability assessment, penetration testing and red teaming in the MAS Technology Risk Management Guidelines, how binding they are, and the evidence that shows you follow them.
- Playbook · 10 minAPRA CPS 234 security testing requirements — control testing, tester independence and what CPG 234 says about penetration testing
A guide to the testing paragraphs of APRA Prudential Standard CPS 234, APRA's guidance on penetration testing in CPG 234, who is in scope, and the records that show the testing program works.
- Playbook · 10 minNYDFS Part 500 penetration testing and vulnerability management — the §500.5 playbook
An operational guide to 23 NYCRR 500.5 as amended in November 2023: the penetration testing, scanning and remediation duties, who they cover, and the evidence behind the annual filing.
- Playbook · 10 minDORA TLPT engagement playbook — from the authority notification to the attestation
Step-by-step operational reference for running a DORA Art. 26 threat-led penetration test: the binding RTS deadlines, the team roles, the scenario rules, and the evidence each gate consumes.
Want to see this against your environment?
A 30-minute technical demo runs Zero Hunt against a recorded slice of your stack, scoped to the regulatory regime you operate under.