What is TLPT (Threat-Led Penetration Testing)?
Published by Zero Hunt, an autonomous AI red team on an on-premise appliance running private AI: automated penetration testing for networks and infrastructure, black-box or gray-box, with a human approving every step that matters.
Short definition
TLPT is a regulator-mandated form of penetration testing where the attack scenarios are explicitly driven by threat intelligence about adversaries currently targeting the tested entity, executed by an independent red team under a documented methodology with verifiable evidence chain.
Why this matters now
Since DORA applied in January 2025, TLPT is mandatory for the financial entities their competent authority identifies under Art. 26. The RTS on TLPT (Commission Delegated Regulation (EU) 2025/1190), drafted in accordance with the TIBER-EU framework, fixes the phases from threat intelligence through red team test to closure, and the authority attests each completed test. Entities that are not in TLPT scope still owe the yearly testing programme of Arts. 24-25.
Key points
- ▸Mandated by DORA Art. 26 for significant financial entities; recommended for any regulated operator under NIS2.
- ▸Reference methodology: TIBER-EU (Threat Intelligence-based Ethical Red Teaming).
- ▸Phases: TI Provision → Red Team Test → Purple Team → Closure, each with mandatory artifacts.
- ▸The threat intelligence provider must always be external; internal testers need the approval of the authority, and external testers are required every third test (DORA Arts. 26(8), 27(2)).
- ▸Each phase has defined deliverables; the authority issues an attestation after the summary of findings and remediation plans (DORA Art. 26(6)-(7)).
- ▸Cadence baseline: at least every 3 years for the formal exercise; in between, yearly tests of systems supporting critical or important functions (Art. 24(6)) and weekly automated vulnerability scans (RTS 2024/1774).
How TLPT differs from a standard pentest
A standard pentest starts from a scope document. TLPT starts from threat intelligence about who is targeting your sector — Brain Cipher, Akira, FIN12, Scattered Spider, state-aligned actors — and reproduces their actual tactics, techniques and procedures (TTPs) in your environment.
The practical implications: scope is informed by adversary capability rather than client convenience, testers must meet DORA Art. 27 (external testers, or internal ones only with the approval of the authority and external testers every third test; significant credit institutions use external testers only), and the methodology is documented and reproducible. Each phase produces deliverables the competent authority reviews before it attests the test.
TIBER-EU phases in plain terms
- TI Provision — a threat-intelligence provider produces a tailored report on who would attack you, how, and which crown-jewel assets they would target. Signed, dated, attributable.
- Red Team Test — an independent red team executes the scenarios from the TI report against the production environment, observing rules of engagement signed by both parties. Real systems, real users, no announcement to the SOC.
- Purple Team — red and blue teams reconstruct the attack chain together. Findings, detection gaps, and process failures are cataloged.
- Closure — remediation plan, retest, formal closure report signed by the entity and the competent authority observer.
Evidence and deliverables (RTS 2025/1190)
The RTS on TLPT fixes the phases and their minimum durations: for example, an active red team phase of at least 12 weeks, followed by a replay and a purple teaming exercise with the blue team (RTS Arts. 11(5) and 12(5)). At the end the entity submits a summary of findings and remediation plans, and the authority issues an attestation (DORA Art. 26(6) and (7)).
Neither DORA nor the RTS prescribes cryptographic signing of TLPT deliverables. Signed, time-stamped evidence from continuous internal testing is still useful: it shows what was tested between TLPTs and what was fixed, which makes scoping and remediation tracking easier. It does not turn internal testing into a TLPT.
How often must TLPT be run?
The DORA baseline is once every three years for the formal TLPT exercise on critical ICT systems. However, it does not replace the Arts. 24-25 testing programme: systems supporting critical or important functions must be tested at least yearly (Art. 24(6)), and the ICT risk management RTS requires automated vulnerability scanning at least weekly on those assets (Commission Delegated Regulation (EU) 2024/1774, Art. 10(2)).
In practice, mature entities run the formal TLPT every 24-36 months and run continuous internal validation in between (automated, informed by the same threat intelligence, with signed evidence). The benefit is that the formal exercise becomes a confirmation, not a discovery.
Goes deeper
Want this against your environment?
Book a 30-minute scoping call — we will map this directly to your current compliance scope and threat profile.