The TIBER-EU guide outlines the implementation of the TIBER-EU framework for threat-led penetration testing (TLPT) required by DORA legislation for significant financial institutions. It aims to enhance the operational resilience of these institutions against sophisticated cyberattacks by providing an assessment and learning framework. This document serves as a reference to assist institutions in meeting the…
This document is a guide published in 2025 by the European Central Bank (ECB) - Banking Supervision (SSM). It concerns the implementation of the TIBER-EU framework for threat-led penetration tests (TLPT) mandatory under the Digital Operational Resilience Act (DORA) for significant financial institutions (SIs) supervised by the European Banking Supervision System (SSM). The scope covers the DORA regulatory requirements and associated regulatory technical standards (RTS), applicable to banks and financial institutions identified as significant, since DORA’s entry into force on 17 January 2025. The guide details processes, roles, responsibilities, test phases and best practices to ensure the digital operational resilience of the entities concerned (p. 1-20).
The guide addresses the implementation of the TIBER-EU framework by the ECB to conduct threat-led penetration tests (TLPT) imposed by DORA on significant financial institutions (SIs) under its supervision. These tests, mandatory at least every three years, aim to strengthen digital operational resilience against sophisticated cyberattacks. The ECB, as the competent and TLPT authority, identifies the SIs subject to these tests, organizes the testing teams and supervises the entire process. The TIBER-EU framework provides a harmonized, detailed and Europe-wide recognized methodology, preventing fragmentation of national approaches. The guide explains the preparation, testing (threat intelligence then red teaming) and closure phases, as well as key roles: ECB/TLPTA, TLPT cyber team, control team (CT), blue team (BT), threat intelligence providers (TIP) and red team testers (RTT). It emphasizes rigorous risk management, confidentiality, secure communication and contractualization of external providers. Finally, it specifies the compliance attestation modalities under DORA and interactions with supervisory authorities. This document is essential for SIs and stakeholders to understand and apply DORA TLPT requirements via TIBER-EU, thus ensuring better cyber resilience (p. 1-15).
The guide was developed to support significant financial institutions (SIs) in implementing threat-led penetration tests (TLPT) imposed by the Digital Operational Resilience Act (DORA), applicable since January 2025. Facing the need to harmonize digital operational resilience testing practices at the European level, the ECB adopted the TIBER-EU framework, initially published in 2018 and updated in 2025, as the standardized method. The objective is to ensure a uniform, high-quality and legally compliant approach with DORA requirements and regulatory technical standards (RTS). The guide aims to clarify roles, responsibilities, processes and best practices for conducting TLPT, while offering some flexibility to adapt to SIs’ specificities. It also specifies interactions between the ECB, national authorities and tested entities, as well as cooperation and mutual recognition modalities. The scope is limited to SIs identified by the ECB within the SSM framework, focusing on mandatory tests, without replacing legal requirements but detailing them operationally (p. 1-4).
1. Regulatory framework and TIBER-EU/DORA relationship:
- DORA mandates mandatory TLPT for SIs at least every three years, supervised by the ECB.
- The TIBER-EU framework, not legally binding, details the "how" of the tests, while DORA and RTS define the legal "what".
- The adoption of TIBER-EU aims to avoid regulatory fragmentation and ensure homogeneous test quality at the European level (p. 1-3).
2. Organization and stakeholders:
- The ECB acts as TLPT authority (TLPTA) and forms a dedicated cyber team (TCT-SSM).
- SIs must designate a single point of contact (SPOC) with authority and system knowledge.
- Key roles include: TLPTA (ECB), TLPT cyber team, SI management, control team (CT) and its leader (CTL), blue team (BT) uninformed of the test, external threat intelligence provider (TIP), external red team testers (RTT), and ICT providers (ISP) potentially included in scope.
- Close collaboration and confidentiality are essential (p. 5-9).
3. TIBER-EU SSM test process:
- Three mandatory phases: preparation, testing, closure.
- Preparation: notification, CT constitution, risk assessment, scope definition, TIP and RTT selection and validation.
- Testing: threat intelligence sub-phase (collection, analysis, TTIR report) then red teaming sub-phase (RTTP planning, execution).
- Closure: drafting RTTR and BTTR reports, replay and purple teaming exercises, final summary report and remediation plan, follow-up by JST and attestation by the ECB.
- Each phase includes milestones, meetings and precise deliverables (p. 9-12).
4. Risk management, confidentiality and communication:
- The CT is responsible for overall risk management and control related to the test.
- Confidentiality is crucial: only the CT and certain management members must be informed.
- Use of code names to protect SIs’ identity.
- Secure communication between stakeholders, with alert and escalation procedures in case of issues.
- Immediate sharing of critical vulnerabilities detected to enable rapid remediation (p. 13-15).
5. Contractual aspects and providers:
- The CT manages the selection and contractualization of external TIP and RTT, according to DORA requirements and TIBER-EU guides.
- Contracts must cover scope, confidentiality, prohibitions, availability, governance, risk management, absence of conflicts of interest, and language modalities.
- The TM validates provider compliance before contracting (p. 13-14).
6. Joint tests and cooperation:
- Possibility of joint or mutualized tests for entities within the same group or sharing critical infrastructures, under efficiency and compliance conditions.
- The ECB coordinates with national and European authorities to optimize efforts and reduce burdens (p. 15-16).
Findings:
- The ECB is the TLPT authority for SIs under the SSM, responsible for identification, supervision and issuance of compliance attestations for mandatory TLPT (p. 6).
- The TIBER-EU framework is adopted as the operational method to conduct TLPT in accordance with DORA and RTS requirements (p. 2-4).
- Tests must follow a structured three-phase process with precise deliverables and clear governance involving multiple stakeholders (p. 9-12).
- Tests must be conducted with qualified external providers (TIP and RTT) to ensure independence and quality (p. 13).
Assumptions and interpretations:
- Harmonization via TIBER-EU should reduce national disparities and improve overall test quality.
- Involvement of an uninformed blue team allows simulation of realistic defense, increasing result relevance.
Uncertainties:
- Test frequency may be adjusted by the ECB according to identified risks (p. 1).
- Possibility of joint or mutualized tests depends on efficiency criteria and stakeholder acceptance (p. 15).
- The concrete impact of tests on operational resilience will depend on implementation quality and remediation plan follow-up (p. 12).
The guide concludes that the adoption of the TIBER-EU framework by the ECB for implementing mandatory TLPT under DORA is essential to ensure a harmonized, rigorous and effective approach to digital operational resilience testing of significant financial institutions. It recommends that SIs strictly follow the preparation, testing and closure phases, ensuring clear governance through designation of a SPOC, a CT and a CTL, and respecting confidentiality and risk management requirements. The ECB, as TLPTA, must ensure test compliance, coordination with national authorities and issuance of attestations. The guide highlights the importance of close collaboration among all stakeholders, notably between TIP, RTT, CT and BT, to maximize learning and cyber resilience. Finally, it encourages considering joint or mutualized tests to optimize resources and reduce operational impacts. Compliance with contractual requirements, secure communication and proactive risk management are sine qua non conditions for TLPT success (p. 1-16).
Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.