Glossary · DORA
TLPT (Threat-Led Penetration Testing)
Advanced penetration testing based on real threat intelligence, required at least every three years for significant financial entities under DORA.
Explained in depth: DORA overview
TLPT simulates the tactics, techniques, and procedures of real threat actors against a financial entity's live production systems, covering its critical or important functions. Unlike a conventional penetration test, TLPT is intelligence-led: a threat intelligence provider profiles the realistic attackers first, and red team testers then emulate them, with only a small control group inside the entity aware the test is running. DORA Articles 26 and 27 require financial entities identified by their authorities (based on size, systemic importance, and risk profile) to conduct TLPT at least every three years. The EU framework builds on TIBER-EU, and results, remediation plans, and attestations are shared with the authority, with mutual recognition across member states.
Why it matters
TLPT is expensive, takes months, and touches production. Entities likely to be designated should build the prerequisite maturity (asset inventory, detection capability, incident response) well before their first mandated test, because a TLPT against an immature environment produces an uncomfortable report that the supervisor reads.
