tlpt

What is TLPT? Threat-led penetration testing explained

Updated 2026-07-06 2 min read

TLPT is the most advanced testing DORA requires. It goes far beyond scanning a system for flaws — it tests whether your whole organisation can withstand a realistic, intelligence-led attack.

Definition

Threat-led penetration testing (TLPT) is a form of advanced security testing in which skilled testers emulate the tactics, techniques and procedures of real threat actors against an organisation’s live production systems. The goal is to measure real resilience: can attackers get in, and can the organisation detect and respond before damage is done?

Under the EU DORA regulation, TLPT is built on TIBER-EU — the ECB’s Threat Intelligence-Based Ethical Red Teaming framework, published in 2018 and already run by several EU jurisdictions.

What makes it "threat-led"

The "threat-led" part is crucial. Instead of a generic checklist, a threat-intelligence provider first researches the specific adversaries most likely to attack the entity, and those findings shape realistic attack scenarios. The red team then tries to achieve those scenario objectives.

Who must do it

TLPT applies to significant financial entities identified by their competent authorities. In-scope entities must complete a TLPT at least every three years. Other entities run DORA’s baseline testing programme but are not required to perform full TLPT.

What it is not

  • Not a vulnerability scan — it is a full, intelligence-led attack simulation.
  • Not a standard penetration test of one system — it targets critical functions across the organisation.
  • Not a pass/fail exam — the point is to find and close gaps.

FAQ

Related questions

Is TLPT the same as a red-team engagement?

TLPT is a formalised, regulated form of red teaming. It follows a defined framework (TIBER-EU), uses real threat intelligence, and has strict requirements on scope, governance and tester independence.

Does TLPT replace normal penetration testing?

No. It sits on top of DORA’s baseline testing programme. Routine testing finds and fixes known issues; TLPT then tests overall resilience against a realistic attack.

What is measured in a TLPT?

Whether attackers can achieve the scenario objectives, and how well the defenders detect and respond — the full prevent, detect and respond chain, not just the presence of a flaw.