Home › Academy › Library › Joint Regulatory Technical Standards…
Synthesis note · Standard

Joint Regulatory Technical Standards specifying elements related to threat led penetration tests

European Banking Authority (EBA) · 2024 · Standard · 184 pages · Intermediate

This document outlines the regulatory technical standards related to threat-led penetration tests (TLPT) in the financial sector, in accordance with the DORA regulation. It details the criteria for identifying affected financial entities, the requirements for internal and external testers, and the testing methodologies. Feedback from stakeholders led to changes aimed at improving the clarity and flexibility of the…

General Information

This document is the final report of the Joint Regulatory Technical Standards (RTS) specifying elements related to threat-led penetration tests (TLPT) according to Article 26(11) of Regulation (EU) 2022/2554 (DORA). It was prepared by the European Supervisory Authorities (ESAs) in agreement with the European Central Bank (ECB) and published in July 2024. The scope covers the technical requirements for conducting TLPT in the European financial sector, including criteria for identifying concerned financial entities, requirements for internal and external testers, test methodology, results management, closure and remediation, as well as cooperation between supervisory authorities. The document relies on the TIBER-EU framework and concerns financial institutions subject to DORA, with application planned from January 17, 2025 (p. 1-4, 5-20, 21-39).

Executive Summary

The document concerns the specification of regulatory technical standards related to threat-led penetration tests (TLPT) under the DORA regulation, aiming to strengthen the digital operational resilience of financial entities. This topic is crucial as TLPT simulate realistic cyberattacks to identify vulnerabilities in critical systems, essential for financial stability and data protection. The main findings are: (i) the need for a harmonized framework to identify financial entities required to perform TLPT, based on impact, financial stability, and ICT maturity criteria; (ii) the integration of the TIBER-EU framework into regulation, with adaptations to make requirements legally binding; (iii) recognition of constraints in the TLPT provider market, leading to relaxation of some tester requirements while maintaining strict risk management measures; (iv) clarification of processes for tests involving multiple financial entities or ICT providers, notably through the concepts of pooled and joint tests; (v) the controlled introduction of internal testers, with strict conditions to ensure test quality and security; (vi) the importance of enhanced cooperation between national and European authorities for supervision and mutual recognition of tests. Conclusions emphasize the balance between requirement rigor and operational flexibility, the need for robust risk management, and promotion of a homogeneous and proportionate sectoral approach. Recommendations concern the rapid adoption of RTS by the European Commission, implementation from January 2025, and continued cooperation between authorities and sector actors to ensure TLPT effectiveness and digital resilience of the European financial sector (p. 2-4).

Context and Objectives

The document was drafted under Article 26(11) of DORA, which requires the ESAs, in agreement with the ECB, to develop regulatory technical standards specifying TLPT modalities for the financial sector. These tests, based on the TIBER-EU framework, aim to simulate realistic cyberattacks to assess the resilience of financial entities against digital threats. The challenge is to ensure homogeneous and enhanced digital operational resilience across the European Union, considering specificities of different financial subsectors and local markets. The document addresses the mandatory implementation of TLPT by defining criteria for identifying concerned entities, requirements for internal and external testers, test methodology, risk management, and cooperation between authorities. The scope is limited to provisions foreseen by DORA, transposing the "mandatory" requirements of the TIBER-EU framework without reproducing it entirely. The document takes into account feedback from a public consultation and stakeholder groups, addressing regulatory harmonization needs while ensuring some application flexibility (p. 5-20).

Summary of Key Points by Theme

- Regulatory framework and mandate: DORA imposes uniform digital resilience requirements for financial entities and their critical ICT providers. Article 26(11) mandates the ESAs to define RTS in accordance with the TIBER-EU framework, specifying identification criteria, methodology, results management, and cooperation (p. 5-7).

- TIBER-EU framework and adaptation: TIBER-EU is a voluntary red teaming framework based on threat intelligence. The RTS transpose its "mandatory" requirements into binding standards, with adaptations notably on the responsible authority, use of internal testers, and the now mandatory purple teaming phase at closure (p. 6-8).

- Identification of entities subject to TLPT: two-level approach based on impact, financial stability, ICT profile and maturity criteria. Certain entities (G-SIIs, O-SIIs, CCP, CSD, trading venues, payment and insurance institutions) are subject by default, with opt-out or opt-in possibilities based on qualitative assessment. Precise quantitative criteria are defined (e.g., euro thresholds for payment institutions, gross premiums for insurers) (p. 9-11, 31-36).

- Test methodology: three-phase process (preparation, test, closure) modeled on TIBER-EU. Preparation includes control team formation, scope, tester and intelligence provider selection. The active test phase lasts at least 12 weeks to simulate stealthy attacks. Closure includes reports, replay exercises and purple teaming, and remediation planning. Flexibility introduced for deadlines, notably at closure (p. 11-16).

- Participants and roles: five main actors – TLPT authority (TLPT cyber team), control team (internal control), blue team (uninformed defense), threat intelligence provider (external intelligence provider), and testers (internal or external). Risk control is paramount, with main responsibility on the tested entity. Rigorous provider selection, with experience and insurance requirements, but possible relaxations under risk management conditions (p. 12-14, 36-39).

- Pooled and joint tests: clear distinction between pooled testing (multiple entities with third-party ICT, test commissioned by this third party) and joint testing (multiple entities of the same group or sharing an intra-group provider). Test scenarios must cover critical functions of entities and ICT provider systems. Enhanced cooperation between involved TLPT authorities (p. 15-20).

- Use of internal testers: novelty compared to TIBER-EU. Strict conditions to guarantee competence, absence of conflicts of interest, prior approval, mandatory use of external testers every three tests. Requirements on composition, seniority (reduced to one year), resources and training of internal teams. Mandatory mention in test documentation (p. 16-19).

- Cooperation between authorities: coordination necessary for entities operating in multiple Member States, notably for joint or pooled tests. The TLPT authority of the home Member State organizes the test and consults host State authorities, with different possible levels of involvement. Multi-entity test management relies on an agreement between authorities to designate the leader (p. 19-20).

- Organizational and risk management requirements: strict confidentiality, limited access to information, key role of control team lead, continuous risk management, restoration and securing procedures post-test, prohibition of destructive or unauthorized activities by testers (p. 36-39).

- Detailed criteria for testers and intelligence providers: minimum experience, technical and sectoral skills, function separation to avoid conflicts of interest, insurance requirements, professional references, prohibition of conflicting function cumulation (p. 37-39).

Main Findings and Lessons Learned

- Established facts:

- The DORA regulatory framework mandates mandatory TLPT execution for certain financial entities identified by precise impact, stability, and ICT maturity criteria (p. 9-11, 31-36).

- The TLPT process follows the TIBER-EU methodology adapted into a binding standard, with preparation, test (minimum 12 weeks), and closure phases including mandatory purple teaming (p. 11-16).

- Participation of several specialized actors is required, with strict requirements on testers' and intelligence providers' skills and insurance (p. 12-14, 36-39).

- Use of internal testers is allowed under strict conditions, with obligation to use external testers every three tests (p. 16-19).

- Cooperation between national and European authorities is necessary for tests involving multiple Member States, with leader designation and responsibility sharing (p. 19-20).

- Assumptions:

- The TLPT provider market is young and limited, justifying some flexibility in requirements while maintaining risk management (p. 13-14).

- Uniform RTS application will strengthen the digital resilience of the European financial sector and facilitate mutual recognition of tests (p. 3-4).

- Interpretations:

- Integrating the TIBER-EU framework into a binding standard ensures a high security level while adapting requirements to operational realities and legal framework (p. 6-8).

- Distinguishing pooled and joint tests clarifies risk management and coordination between entities and authorities (p. 15-20).

- Uncertainties:

- The evolution of the TLPT provider market and entities' capacity to recruit fully compliant testers remain uncertain (p. 13-14).

- The effectiveness of cross-border cooperation will depend on practical implementation by national authorities (p. 19-20).

Conclusions and Recommendations

The ESAs conclude that the developed RTS meet the DORA mandate by specifying a harmonized, clear, and legally binding framework for conducting TLPT in the European financial sector. They recommend the rapid adoption of these RTS by the European Commission, followed by their implementation from January 17, 2025. The document emphasizes the importance of rigorous risk management, strict selection of testers and intelligence providers, and enhanced cooperation between national and European authorities, especially for tests involving multiple entities or Member States. The RTS set precise criteria for identifying concerned entities, test methodology, controlled use of internal testers, and cooperation modalities. They stress the need to preserve test confidentiality and promote learning through closure phases, notably purple teaming. Finally, they encourage authorities to adapt implementation to local specificities while respecting defined minimum requirements, and to continue dialogue with stakeholders to support the evolution of the TLPT framework (p. 3-4, 20-28).

Key takeaways

References

Year
2024
Type
Standard
Level
Intermediate
Licence
Attribution required
Original document
https://www.eba.europa.eu/sites/default/files/2024-07/427a52cf-5772-4…
Read the original document ← Back to the library

Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.