Back to glossary

Threat-led penetration testing (TLPT)

2 min read

In offensive security, threat-led penetration testing (TLPT) is an intelligence-driven red team exercise against live production systems, run to a supervised framework. It is the form of testing DORA requires of certain financial entities, and it is built on the TIBER-EU methodology used by European central banks.

July 29, 2026
Compartir:

How it works

TLPT separates three roles. A threat intelligence provider produces a targeted profile: who would attack this entity, and how. A red team then executes against real production systems using those techniques, while a small control group (the Control Team) is the only party inside the organisation that knows the test is happening. The blue team is not told, so their detection and response are measured under realistic conditions. TIBER-EU sets the process for scoping, intelligence, testing and closure; DORA makes a version of it mandatory for significant financial entities and specifies how often it recurs. Because it hits live systems, deconfliction and a tested abort procedure are part of the design, not an afterthought.

What goes wrong

The failure a TLPT exposes is almost never a single vulnerability. It is the gap between what a firm believes its response looks like and what actually happens when nobody has been warned. Under a real intrusion the escalation path stalls, the on-call analyst treats a genuine alert as noise, or the containment step depends on a person who is on leave. An attacker counts on exactly this: the technical foothold is the easy part, and the value is in the hours between the first detectable action and any coordinated response. Running the exercise without warning the defenders is the only way to measure that honestly.

Where this shows up in an audit

The output is a regulator-facing narrative: the intelligence used, the scenarios executed against production, what was detected, and how the blue team responded, with timelines. Findings are framed as resilience gaps tied to DORA obligations, and a replay session with the defenders (a purple team step) turns each miss into a concrete detection improvement. This is how we run a threat-led engagement end to end under strict rules of engagement.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.