Threat-Led Penetration Testing
Also known as:TLPT · Threat-Led Pentest · Threat Intelligence-Led Penetration Test
Threat-Led Penetration Testing (TLPT) is a form of penetration testingPenetration TestingAuthorized, methodical testing of a system for exploitable weaknesses, to find them before real attackers do. in which the test scenarios are derived from real threat intelligenceCyber Threat IntelligenceProcessed information regarding threat actors, tactics, indicators, and risks. about the actors, campaigns, and TTPs that target a specific organization or sector. Instead of testing against a generic checklist, the red team replicates the exact tradecraft of adversaries with demonstrated intent and capability to attack the target. This approach is codified in regulatory frameworks such as TIBER-EU, TIBER-DE, CBEST, iCAST, FEER, and the DORA TLPT requirements.
TLPT follows a three-phase model: a Threat Intelligence phase produces targeted attack scenarios, a Red Team phase executes those scenarios against the live production environment, and a Blue Team assessment phase evaluates detection and response performance. The involvement of independent providers and regulatory oversight distinguishes TLPT from conventional red teamingRed TeamingA realistic, adversary-emulating attack simulation that tests how well an organization detects and responds to a real attacker..
Who commissions this test?
TLPT is primarily commissioned by systemically important financial institutions, payment service providers, and critical infrastructure operators. Under DORA (Digital Operational Resilience Act), the European Central Bank expects every significant institution to undergo TLPT at regular intervals. National competent authorities such as BaFin (Germany), DNB (Netherlands), or the Bank of England oversee and may mandate testing. Beyond finance, organizations subject to NIS2 critical infrastructure requirements increasingly adopt TLPT voluntarily.
Test objectives
The objective is to determine whether an organization can withstand attacks from the specific threat actors that target its sector. This goes beyond finding vulnerabilities: TLPT measures the organization’s ability to detect threat-actor-specific TTPs, assesses incident response maturity against realistic scenarios, validates whether threat intelligenceCyber Threat IntelligenceProcessed information regarding threat actors, tactics, indicators, and risks. is operationalized effectively, and provides regulators with evidence of operational resilience.
What is tested?
Testing covers the full kill chainCyber Kill ChainModel describing the successive phases of a cyberattack. as it would unfold from the identified threat actors. This includes initial access vectors favored by those actors (spear-phishing, supply chain compromise, watering holes), persistence and lateral movement techniques mapped to MITRE ATT&CKMITRE ATT&CKStructures known tactics and techniques of real-world cyberattacks., privilege escalation paths, data exfiltration methods, and the ability to reach critical functions. Critically, the Blue Team’s detection coverage, alerting thresholds, and response procedures are assessed against each phase.
Common findings
- Detection gaps for sector-specific TTPs that threat actors actively employ
- Threat intelligence not operationalized into detection rules or hunting hypotheses
- SOC alerting tuned to generic signatures, missing actor-specific indicators
- Incident response playbooks not aligned with the scenarios threat actors actually execute
- Lateral movement between business-critical segments went undetected
- Time-to-detect and time-to-contain exceeded organizational targets
- Insufficient logging at critical chokepoints identified by the threat intelligence phase
- Communication breakdowns between SOC, CSIRT, and business stakeholders during simulated incidents
Typical engagement workflow
A TLPT engagement follows a tightly structured, multi-party process with regulatory oversight:
Interest and initial inquiry – the organization initiates the process, often at the direction of its regulator or board. Initial scoping call – the organization, the TLPT authority (regulator or designated body), and prospective providers discuss objectives, regulatory requirements, and the overall framework (TIBER-EU, CBEST, etc.). Proposal and approval – separate proposals are sought from an independent Threat Intelligence (TI) provider and a Red Team provider. Independence between TI and Red Team is a regulatory requirement. Scope definition – the TLPT authority and the organization agree on critical functions to be tested, geographic scope, and any exclusions. The scope targets live production systems. Letter of Engagement – formal authorization is executed, including regulatory sign-off and the establishment of a control team (trusted agents) within the organization. Additional clearances – third-party provider notifications, cloud provider authorizations, and physical site permissions are arranged. Threat Intelligence phase – the TI provider conducts targeted research: identifying threat actors with intent and capability, their known TTPs, infrastructure, and campaigns. This produces a Targeted Threat Intelligence Report and specific attack scenarios. Kick-off call – the Red Team receives the TI-derived scenarios, and the control team aligns on rules of engagement, emergency procedures, and communication channels. Red Team execution – the Red Team executes the TI-derived scenarios against the live production environment over a period of weeks to months. The control team receives status updates; the broader organization, including the Blue Team, is unaware. Vulnerability collection and assessment – findings are documented with full evidence chains, mapped to the original TI scenarios and MITRE ATT&CKMITRE ATT&CKStructures known tactics and techniques of real-world cyberattacks. techniques. Blue Team assessment – the Blue Team is debriefed and asked to present its detection and response timeline. Gaps between actual detection and expected detection are analyzed. Final report – a comprehensive report is produced, combining the TI report, Red Team findings, Blue Team assessment, and a remediation plan with prioritized actions. Presentation – results are presented to the control team, senior management, and the TLPT authority. Project closure – the regulator receives a summary, remediation commitments are tracked, and a timeline for the next TLPT cycle is established.
Who should commission this test — and when?
TLPT is mandatory for systemically important financial institutions under DORA and TIBER frameworks. The ECB expects significant institutions to undergo TIBER testing on a regular cycle, typically every three years. National regulators may impose additional requirements. Beyond regulatory mandates, TLPT is valuable for any organization that faces advanced persistent threats: critical infrastructure operators under NIS2, large payment processors, central securities depositories, and organizations in sectors with known state-sponsored threat activity. The test is most meaningful when the organization has a functioning SOC, incident response capability, and a threat-informed defenseThreat-Informed DefenseAlignment of controls and tests with specific threats and attack techniques. strategy to validate.
Related concepts
- Penetration TestingPenetration TestingAuthorized, methodical testing of a system for exploitable weaknesses, to find them before real attackers do.: Authorized testing for exploitable weaknesses, typically breadth-oriented.
- Red TeamingRed TeamingA realistic, adversary-emulating attack simulation that tests how well an organization detects and responds to a real attacker.: Goal-oriented adversary simulation testing detection and response.
- Cyber Threat IntelligenceCyber Threat IntelligenceProcessed information regarding threat actors, tactics, indicators, and risks.: The collection and analysis of information about current and potential threats.
- Threat-Informed DefenseThreat-Informed DefenseAlignment of controls and tests with specific threats and attack techniques.: A strategic approach that uses threat intelligence to prioritize security investments.
- Threat EmulationThreat EmulationRealistic simulation of known attacker techniques to test defenses.: Replicating specific threat actor behavior to validate controls.
- MITRE ATT&CKMITRE ATT&CKStructures known tactics and techniques of real-world cyberattacks.: A knowledge base of adversary tactics, techniques, and procedures used to map findings.