The classic trap
Annex III sets the minimum content of the Targeted Threat Intelligence Report, the cornerstone of the intelligence phase of a TLPT. In practice, the CSSF (TLPT authority under Article 46 of DORA) and the BCL reject reports that stay theoretical: a generic threat landscape, without concrete actionable intelligence about the tested entity, fails point 2. The most common trap is delivering three threat scenarios that do not cover the availability / integrity / confidentiality triad required by point 5, or whose attack path is not truly end-to-end. Without a compliant TTI report, the BCL/CSSF Test Manager refuses to greenlight the red teaming phase and the whole test slips.
The 6 blocks your TTI report must cover without gaps
- Scope (point 1): critical or important functions in scope, geographical location, official EU language, relevant ICT third-party providers (to be aligned with the outsourcing RTS 2025/532 and CSSF circulars 22/806 and 25/882) and the collection time window.
- Actionable intelligence (point 2): leaked employee usernames and passwords, look-alike domains, technical reconnaissance of vulnerable systems, OSINT posted by employees, data for sale on the dark web and, where relevant, physical targeting of premises.
- Contextual analysis (point 3): geopolitical and economic environment and technological trends in the financial sector.
- Attacker profiles (point 4): specific or generic actors, systems most likely to be compromised, motivation, intent and modus operandi.
- Threat scenarios (point 5): at least three end-to-end scenarios with the highest severity scores, covering availability, integrity and confidentiality.
- Non-threat-led scenario (point 6): optional description of the scenario referred to in Article 10(4).
The TIBER-LU framework (BCL + CSSF), whose Implementation Document was revised on 20 June 2025 and aligned with TIBER-EU (revised by the ECB on 11 February 2025), expects this level of granularity. The remediation resulting from the test then feeds ICT risk management under CSSF circular 20/750 and Articles 26-27 of DORA.
How Luxgap automates this risk
Our Luxgap TTI Report Composer turns the OSINT and dark web collection chore into a structured report, mapped point by point to Annex III, ready to submit to the BCL/CSSF Test Manager. The tool continuously aggregates leaked credentials (cross-referencing HIBP, dark web sources and credential brokers), scans your external exposure and look-alike domains, then a specialised LLM agent drafts each normative section without the white team having to gather evidence by hand.
- Automatically detects exposed employee usernames and passwords by cross-referencing HIBP, dark web forums and credential databases, mapping them to the critical functions in scope.
- Scans external technical reconnaissance (vulnerable or exploitable software, systems and technologies) through Microsoft Defender, Azure Sentinel, CrowdStrike and Wazuh connectors, prioritising by real exploitability.
- Monitors in real time the registration of look-alike domains that could impersonate your official domains and alerts on Teams at each new detection.
- Generates the three end-to-end threat scenarios covering availability, integrity and confidentiality, mapped to MITRE ATT&CK and to the attacker profiles relevant to the Luxembourg financial sector.
- Includes the in-scope ICT third-party providers by relying on RTS 2025/532 and CSSF circulars 22/806 and 25/882, so the outsourcing chain is part of the targeting.
- Produces a timestamped, sealed PDF report structured along the six points of Annex III, opposable and directly submittable to the CSSF and the BCL within the TIBER-LU framework.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real perimeter, with a free 48h scan to measure your exposure before any engagement.