What Threat-Led Penetration Testing Is
Threat-Led Penetration Testing (TLPT) is the most advanced form of resilience testing in DORA — a controlled simulation of a real adversary against an entity’s live production systems.
TLPT vs an ordinary penetration test
| Ordinary pen test | TLPT | |
|---|---|---|
| Goal | Find technical vulnerabilities | Simulate a realistic, named adversary end to end |
| Target | Often a test environment | Live production systems supporting critical functions |
| Scope | Technology | Technology, people and processes — including the defenders |
| Intelligence | Generic | Driven by tailored threat intelligence |
The legal basis
TLPT sits in DORA Art. 26–27, with the detail filled in by a dedicated RTS on TLPT developed by the ESAs in cooperation with the ECB. It is required of financial entities identified by their competent authority on the basis of size, risk profile and systemic importance — and must be conducted at least every three years, though an authority may set a different frequency on a risk basis.
TLPT is the apex of DORA’s testing pyramid. The base — vulnerability scans, network assessments, source-code reviews — applies to every entity annually under Art. 24–25. TLPT is the demanding extra layer for the systemically important few. The two are complementary: ordinary testing keeps the hygiene baseline; TLPT validates whether the whole organisation — technology, people and process — would survive a determined, intelligent adversary.
That was your free preview
Enrol to unlock all 23 lessons, every knowledge check, the dedicated certification exam, the downloadable toolkit and your verifiable certificate — lifetime access.
Secure payment via Stripe · 30-day money-back guarantee.