Financial institutions invest heavily in cybersecurity. They perform vulnerability assessments and penetration tests, implement security controls, and regularly demonstrate compliance with industry regulations. Yet despite these efforts, sophisticated cyberattacks continue to compromise even well-protected organizations.
The reason is simple: real attackers don’t think like auditors.
Rather than exploiting a single vulnerability, they combine reconnaissance, phishing, stolen credentials, supply chain weaknesses, and misconfigurations into coordinated campaigns that often unfold over weeks or even months. Their objective isn’t simply to compromise a system – it is to disrupt critical business operations while avoiding detection for as long as possible.
Recognizing this shift in the threat landscape, the European Union introduced the Digital Operational Resilience Act (DORA) to strengthen the cyber resilience of financial entities operating across the EU. The regulation establishes a comprehensive framework covering ICT risk management, incident reporting, third-party risk management, and digital operational resilience testing.
Among its most demanding requirements is Threat-Led Penetration Testing (TLPT).
Unlike traditional penetration testing, TLPT doesn’t simply ask whether a vulnerability exists. It evaluates whether your organization could withstand the tactics, techniques, and procedures (TTPs) of the threat actors most likely to target it.
For organizations that fall within its scope, TLPT represents far more than another compliance exercise. It provides a realistic assessment of how people, processes, and technology perform under the pressure of a sophisticated cyberattack, helping organizations identify weaknesses before real adversaries can exploit them.
This guide is based on the expertise of Peter Djalaliev, Red Team Lead at AMATAS. Peter specializes in adversary simulation, intelligence-driven security assessments, and offensive security, helping organizations better understand how sophisticated attackers could target their critical business services.
In this guide, we combine Peter’s expertise with the DORA framework to explain what TLPT is, how it works, and how organizations can prepare for it.
What Is a Threat-Led Penetration Test (TLPT)?
Despite its name, a Threat-Led Penetration Test (TLPT) is much closer to a red team engagement than a conventional penetration test.
Traditional penetration testing focuses on identifying exploitable vulnerabilities within a defined technical scope. TLPT takes a broader approach.
Rather than asking, “Can this system be compromised?”, it asks a broader and more strategic question: “Could a realistic threat actor achieve its objectives against our most critical business services?”
To answer that question, every TLPT begins with extensive threat intelligence. Instead of simulating generic attacks, the engagement is designed around the adversaries most likely to target the organization. Their known tactics, techniques, and procedures (TTPs) are used to build realistic attack scenarios that reflect how these groups operate in the real world.
The testing itself is performed as a controlled red team exercise against carefully selected critical business functions. Throughout the engagement, the red team adapts its approach in the same way a real attacker would – looking for alternative attack paths whenever existing security controls prevent the original scenario from succeeding.
This intelligence-driven methodology allows organizations to assess far more than technical vulnerabilities. It validates whether security controls, detection capabilities, incident response procedures, and internal communication processes work together effectively during a realistic cyberattack.
The methodology behind DORA TLPT is defined by the TIBER-EU (Threat Intelligence-Based Ethical Red Teaming) framework, ensuring a consistent approach across European financial institutions while allowing each engagement to reflect the organization’s unique threat landscape.
“One of the biggest misconceptions I encounter is that organizations see TLPT as simply a more advanced penetration test. In reality, the objective is entirely different. We’re not trying to identify every possible vulnerability – we’re validating whether a realistic threat actor could achieve a meaningful business objective using the same tactics they would employ in the real world.”
Peter Djalaliev
Red Team Service Lead, AMATAS
Why DORA Introduced TLPT?
Financial organizations have become increasingly interconnected.
Banks, insurers, payment providers, investment firms, and other financial entities rely on complex digital ecosystems that include cloud providers, payment processors, software vendors, managed service providers, and numerous third-party partners. While this interconnectedness enables innovation and efficiency, it also creates new opportunities for attackers to compromise multiple organizations through a single weakness.

Recent years have shown that sophisticated threat actors rarely rely on direct attacks alone. Instead, they exploit trusted relationships, compromised suppliers, stolen credentials, or weaknesses across the broader supply chain to reach their intended targets.
Traditional security testing remains an essential part of any cybersecurity program, but it typically focuses on identifying individual technical vulnerabilities. On its own, it cannot always demonstrate how multiple weaknesses might be combined into a coordinated attack against an organization’s most critical services.
This is where Threat-Led Penetration Testing delivers unique value.
By combining targeted threat intelligence with realistic adversary simulation, TLPT allows financial organizations to validate whether their security controls, monitoring capabilities, and response procedures can withstand the threats they are genuinely most likely to face.
Rather than measuring security through isolated technical findings, TLPT evaluates how people, processes, and technology perform together under the pressure of a realistic attack. It reveals whether an organization can detect, respond to, and recover from sophisticated threats before they have the opportunity to disrupt critical operations.
The objective isn’t simply to produce another technical report. It’s to answer one of the most important questions any financial organization can ask:
If a sophisticated attacker targeted our critical business functions tomorrow, how well would we actually perform?
Defining the Scope: Critical and Important Functions
Every DORA TLPT begins by answering a fundamental question: What are the organization’s most critical services?
Unlike traditional penetration tests, which often assess applications, networks, or infrastructure components individually, a TLPT focuses on the business functions that are essential to the organization’s operations.
Under DORA, these are referred to as Critical and Important Functions (CIFs). The regulation defines them as services whose disruption would significantly impact the organization’s financial performance, operational continuity, or ability to meet regulatory obligations.
Rather than attempting to test every system across the organization, the assessment focuses on the ICT assets that support these critical functions. This ensures the engagement concentrates on the areas where a successful attack would have the greatest business impact.
The scope is defined collaboratively between the financial entity, the testing providers, and the competent authority. While the organization identifies the functions it considers critical, regulators may require additional services to be included to ensure the assessment reflects the organization’s operational risk.
By narrowing the scope in this way, TLPT remains realistic and business-focused. Instead of producing a long list of technical findings across unrelated systems, it evaluates whether an attacker could disrupt the services that matter most.
“One of the first questions we ask isn’t ‘Which systems should we test?’ – it’s ‘Which business services would cause the greatest impact if they became unavailable or were compromised?’ That shift in perspective changes the entire engagement.”
Peter Djalaliev
Red Team Service Lead, AMATAS
Threat Intelligence: Understanding Your Most Likely Adversaries
Threat intelligence is what makes every TLPT unique.
Without it, security testing often relies on generic attack techniques that could apply to almost any organization. With it, the engagement is tailored to the threats your organization is genuinely most likely to face.
To achieve this, the financial entity appoints an independent Threat Intelligence Provider (TIP) responsible for researching both the organization and the wider threat landscape.
Their objective isn’t simply to collect technical indicators or vulnerability data. Instead, they build a detailed picture of the adversaries that have the capability, opportunity, and motivation to target the organization.
This includes analyzing:
- threat actor groups active in the financial sector
- their tactics, techniques, and procedures (TTPs)
- recent campaigns targeting similar organizations
- publicly available information about the organization
- exposed internet-facing assets
- leaked credentials, domains, and other indicators that could support an attack
The result is a threat profile that reflects the organization’s actual exposure rather than theoretical risk.
From Intelligence to Realistic Attack Scenarios
Using the collected intelligence, the Threat Intelligence Provider develops several high-level threat scenarios based on realistic attacker behaviour.
These scenarios are then reviewed collaboratively by the financial organization, the threat intelligence provider, and the red team.
Together, they select the attack paths that will be simulated during the engagement.
This collaboration is important because it bridges the gap between strategic intelligence and operational testing. The threat intelligence explains who the likely attackers are and why they pose a risk, while the red team translates that intelligence into realistic attack scenarios that can be executed safely during the engagement.
The result is a testing plan based on credible threats rather than assumptions.
“Threat intelligence is what separates TLPT from a standard red team engagement. Instead of asking ‘How can we compromise this organization?’, we’re asking ‘How would these attackers compromise this organization?’ That context makes all the difference.”
Peter Djalaliev
Red Team Service Lead, AMATAS
Simulating a Real-World Attack
Once the testing scenarios have been agreed, the engagement moves into the red team phase.
Rather than following a rigid checklist, the red team operates much like a genuine attacker. They follow the approved scenarios but continuously adapt their approach as new information becomes available or obstacles arise.
If an attack path is blocked, they don’t simply stop. Instead, they look for alternative routes that could still achieve the objectives defined during planning, just as a real adversary would.
Throughout the engagement, every action is carefully documented – from reconnaissance and initial access to privilege escalation, lateral movement, and attempts to reach the agreed objectives. This detailed record becomes essential during the reporting and knowledge-sharing stages of the engagement.
Unlike criminal attackers, however, the red team operates within clearly defined rules of engagement approved by the organization and the relevant authorities. The objective is never to cause disruption but to safely demonstrate how realistic attacks could unfold against critical business functions.
Example: How a TLPT Might Unfold
Imagine a payment provider selected for a TLPT.
Threat intelligence reveals that a financially motivated threat group has recently targeted similar organizations by compromising employee credentials through phishing before moving laterally towards payment processing systems.
Instead of simply testing whether phishing is possible, the red team follows the same sequence of actions used by the real threat actor. They attempt to gain initial access, escalate privileges, move across the environment, evade detection, and ultimately reach the agreed business objective – all while the organization’s security teams respond as they would during a real incident.
The goal isn’t to “win” the exercise.
It’s to understand whether existing controls, monitoring capabilities, and response procedures can interrupt the attack before it succeeds.
Turning the Findings into Stronger Defenses
The red team engagement doesn’t mark the end of a TLPT. In many ways, it’s the beginning of the most valuable phase.
Unlike traditional penetration tests, where organizations often receive a report and begin remediation independently, DORA TLPT emphasizes collaboration between the offensive and defensive teams. The objective isn’t simply to identify weaknesses – it’s to understand why they existed, how they were exploited, and what improvements will have the greatest impact on the organization’s resilience.
This collaborative phase, often referred to as Replay and Purple Teaming within the TIBER-EU framework, transforms technical findings into practical improvements across people, processes, and technology.
Replay: Reconstructing the Attack
During the replay exercise, the red team walks the organization through each stage of the engagement.
Rather than presenting only the final findings, they demonstrate how the attack unfolded – from the initial access vector to the techniques used for privilege escalation, lateral movement, persistence, and attempts to reach the agreed business objectives.
This allows the organization’s blue team to compare the attack timeline with its own monitoring and response activities.
Questions such as these become central to the discussion:
- Which activities were detected?
- Which indicators were missed?
- Were alerts investigated quickly enough?
- Where did attackers remain undetected?
- Which security controls successfully interrupted the attack?
By replaying the engagement step by step, both teams gain a much clearer understanding of how the organisation performed under realistic attack conditions.
Purple Teaming: Turning Insights into Action
Replay explains what happened. Purple teaming focuses on what happens next.
During these collaborative sessions, the red and blue teams work together to analyze the findings, validate defensive improvements, and discuss alternative attack paths that could be explored in future exercises.
Rather than assigning blame, the goal is continuous improvement.
The discussions often extend beyond technical controls to include incident response procedures, communication processes, security monitoring, and operational decision-making.
By the end of the exercise, organizations have a much deeper understanding of how attackers think, where defensive gaps exist, and which improvements will provide the greatest reduction in risk.
“Many organizations expect the greatest value to come from the attack itself. In reality, some of the most important conversations happen afterwards. Replay and purple teaming allow both sides to understand not just what happened, but why it happened – and how to prevent it from happening again.”
Peter Djalaliev
Red Team Service Lead, AMATAS
What Does a DORA TLPT Deliver?
A successful TLPT provides much more than evidence for regulatory compliance.
It gives organizations a detailed understanding of how realistic attacks could affect their most critical services and identifies the improvements needed to strengthen their resilience against future threats.
Throughout the engagement, several reports are produced to document the assessment and support remediation efforts.
Targeted Threat Intelligence Report (TTIR)
Developed by the Threat Intelligence Provider, this report summarizes the organization’s threat landscape, identifies the adversaries most relevant to its operations, and documents the intelligence used to build the testing scenarios.
Red Team Test Plan (RTTP)
The testing plan defines how the engagement will be conducted, including the agreed scenarios, communication procedures, reporting requirements, and the tactics, techniques, and procedures that will be used throughout the exercise.
Red Team Test Report (RTTR)
This report documents the engagement itself, describing each attack scenario, the techniques used, the objectives achieved, and the security weaknesses that enabled the attack. It also includes recommendations to help the organisation reduce future risks.
Blue Team Test Report (BTTR)
Prepared by the organization’s defensive team, this report evaluates how effectively existing security controls detected and responded to the simulated attack. It captures observations, lessons learned, and planned improvements resulting from the exercise.
Together, these deliverables provide far more than a record of the engagement. They create a roadmap for strengthening cyber resilience while demonstrating compliance with DORA’s Threat-Led Penetration Testing requirements.
The Value of TLPT Goes Beyond Compliance
It’s easy to view DORA TLPT as another regulatory requirement. It actually represents a shift in how financial organizations evaluate cybersecurity.
Traditional security assessments remain essential for identifying vulnerabilities and validating individual controls. Threat-Led Penetration Testing builds on that foundation.
By combining targeted threat intelligence, realistic adversary simulation, and collaborative knowledge sharing, TLPT provides insights that are difficult to obtain through conventional security testing alone.
Perhaps more importantly, it helps organizations understand not only where weaknesses exist, but how those weaknesses could be exploited to disrupt critical business operations.
For financial institutions operating in an increasingly interconnected threat landscape, that knowledge is invaluable.
Organizations that approach TLPT as an opportunity to strengthen resilience – not simply satisfy a regulatory requirement – will gain far more than compliance. They will develop a clearer understanding of their exposure, improve their ability to detect and respond to sophisticated attacks, and build greater confidence in the security of their critical services.
Learn more about our Red Team Testing services or get in touch to discuss your requirements with our experts.
Frequently Asked Questions
Is DORA TLPT the same as a Red Team engagement?
Not exactly. A DORA TLPT uses red team testing as its core methodology, but it also includes mandatory elements such as threat intelligence, regulatory oversight, defined governance, and collaborative replay and purple team exercises under the TIBER-EU framework. In other words, every TLPT includes a red team engagement, but not every red team engagement qualifies as a DORA TLPT.
How often must a DORA TLPT be performed?
Organizations selected by the competent authorities are generally expected to perform a TLPT at least once every three years, unless a different frequency is required based on their risk profile or supervisory decisions. Additional testing may also be required following significant changes to critical systems or business operations.
Does TLPT replace traditional penetration testing?
No. Traditional penetration testing remains an essential part of a mature cybersecurity programme. It identifies vulnerabilities within systems and applications, while TLPT validates whether a realistic attacker could compromise critical business functions by combining multiple techniques and attack paths.
The two approaches complement each other rather than compete.
What is the role of threat intelligence in a TLPT?
Threat intelligence ensures that the engagement reflects the organization’s real-world threat landscape. Rather than relying on generic attack techniques, the testing scenarios are built around the tactics, techniques, and procedures of adversaries that are most likely to target the organization. This makes the assessment significantly more realistic and relevant than conventional security testing.
What is the difference between TIBER-EU and DORA TLPT?
TIBER-EU is the European framework that defines how intelligence-led red team exercises should be planned and executed. DORA is the regulation that requires certain financial organizations to perform Threat-Led Penetration Testing and references TIBER-EU as the methodology for conducting those exercises. Simply put, DORA establishes the requirement, while TIBER-EU provides the methodology.
