TIBER-Style / Threat-Led Testing (TLPT)
Overview
TIBER-EU and related frameworks (e.g. CBEST, DORA TLPT expectations) define intelligence-led red teaming against critical functions using realistic threat scenarios, with rigorous governance and learning-focused closure.
When to Use
- Financial-sector or critical-entity regulatory-style tests
- Designing critical-function-centric scenarios
- Separating threat intel and red-team roles appropriately
- Planning purple closure workshops after live tests
Core Practices
- Identify critical functions and underlying systems end-to-end
- Commission or produce targeted threat intelligence for scenario design
- Build scenarios that mimic relevant adversaries against those functions
- Govern the test with clear roles (entity, authority if any, TI provider, red team)
- Execute under strict RoE on agreed live scope
- Capture defensive performance along the attack path
- Close with structured purple teaming, remediation planning, and evidence of improvement
Principles
- Critical functions — not only “interesting servers” — define scope
- Intelligence quality drives scenario realism
- Independence/separation of TI and red team is often required or preferred
- The outcome is resilience improvement, not a pass/fail trophy
Verification
- Critical functions are defined and agreed
- Scenarios trace to threat intelligence
- Closure includes purple learning and remediation ownership