The classic trap
Annex VI lists what the blue team report must contain, but the real trap lies elsewhere: most financial entities discover, during the TLPT, that their blue team detected nothing. The CSSF (TLPT authority under Article 26 of DORA) and the BCL, within the TIBER-LU framework, do not penalise a low detection rate as such, but rather the inability to produce the log entries matching each attack step and the absence of root cause analysis. A blue report that merely states 'not detected' without correlating logs, evidence and lessons learned is deemed non-compliant and blocks the remediation phase required by CSSF circular 20/750.
The 6 blocks your blue team report must cover
- For each attack step in the red report: the list of detected offensive actions and the corresponding timestamped log entries.
- Assessment of the testers' findings and recommendations, validated by the white team.
- Evidence of the attack independently collected by the blue team (SIEM telemetry, EDR, network flows).
- Root cause analysis of each successful attack, not just the symptom.
- The list of lessons learned and prioritised improvement areas feeding TIC risk management.
- The list of topics to address in purple teaming.
Critical point: the test scope includes your TIC providers (outsourcing RTS 2025/532, CSSF circulars 22/806 and 25/882). If an attack step transits through a managed provider, your blue team must still produce the logs and cause analysis, which requires contractual access to the provider's telemetry.
How Luxgap automates this risk
Our Luxgap Blue Team Evidence Correlator turns the chore of writing the blue report into evidence enforceable before the CSSF, by automatically reconstructing, for each attack step in the red report, the chain of detected logs (or the absence of detection). The tool continuously ingests telemetry from Microsoft Defender, Azure Sentinel, CrowdStrike and Wazuh, then aligns each offensive action with its footprint in your logs through temporal correlation and the MITRE ATT&CK matrix.
- Automatically correlates each red report step with Sentinel, Defender and Wazuh log entries, and flags steps with no detected trace.
- Calculates a detection rate and mean time to detect per MITRE ATT&CK tactic, aligned with the TIBER-LU methodology revised on 20 June 2025.
- Generates pre-filled root cause analysis for each successful attack, distinguishing coverage gap, rule gap and response gap.
- Extracts telemetry from your in-scope TIC providers (CSSF circulars 22/806 and 25/882) via API connectors, covering the full outsourcing chain.
- Produces the prioritised list of lessons learned and purple teaming topics, ready to feed the remediation plan and TIC risk management (CSSF circular 20/750).
- Issues a timestamped, cryptographically sealed PDF report, structured exactly along the six points of Annex VI, enforceable during a CSSF or BCL inspection.
Available as an add-on to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real telemetry, with a free blank audit within 48h to measure your detection capability before any commitment.