What is TLPT? Threat-led penetration testing explained
TLPT is the most advanced testing DORA requires. It goes far beyond scanning a system for flaws — it tests whether your whole organisation can withstand a realistic, intelligence-led attack.
Definition
Threat-led penetration testing (TLPT) is a form of advanced security testing in which skilled testers emulate the tactics, techniques and procedures of real threat actors against an organisation’s live production systems. The goal is to measure real resilience: can attackers get in, and can the organisation detect and respond before damage is done?
Under the EU DORA regulation, TLPT is built on TIBER-EU — the ECB’s Threat Intelligence-Based Ethical Red Teaming framework, published in 2018 and already run by several EU jurisdictions.
What makes it "threat-led"
The "threat-led" part is crucial. Instead of a generic checklist, a threat-intelligence provider first researches the specific adversaries most likely to attack the entity, and those findings shape realistic attack scenarios. The red team then tries to achieve those scenario objectives.
Who must do it
TLPT applies to significant financial entities identified by their competent authorities. In-scope entities must complete a TLPT at least every three years. Other entities run DORA’s baseline testing programme but are not required to perform full TLPT.
What it is not
- Not a vulnerability scan — it is a full, intelligence-led attack simulation.
- Not a standard penetration test of one system — it targets critical functions across the organisation.
- Not a pass/fail exam — the point is to find and close gaps.
FAQ
Related questions
Is TLPT the same as a red-team engagement?
TLPT is a formalised, regulated form of red teaming. It follows a defined framework (TIBER-EU), uses real threat intelligence, and has strict requirements on scope, governance and tester independence.
Does TLPT replace normal penetration testing?
No. It sits on top of DORA’s baseline testing programme. Routine testing finds and fixes known issues; TLPT then tests overall resilience against a realistic attack.
What is measured in a TLPT?
Whether attackers can achieve the scenario objectives, and how well the defenders detect and respond — the full prevent, detect and respond chain, not just the presence of a flaw.
Keep reading
More guides
-
TLPT vs penetration testing: what is the difference?
A standard pen test checks a system for flaws. TLPT tests the whole organisation against a realistic, intelligence-led attack. Here is how they compare.
Read guide -
How to prepare for a TLPT engagement
TLPT touches live systems and a defending team that must stay unaware. Good preparation is what makes it safe and valuable.
Read guide