The classic trap
Article 5 requires the control team to assess and manage the risks of the test before and during the exercise, on live production systems. What the CSSF and the BCL sanction under the TIBER-LU framework is not the test itself but the absence of a formalised, documented risk management trail. An entity that launches a red team active phase without a documented risk register, without a crisis escalation plan and without provable rollback measures risks an invalid TLPT, meaning the lack of the attestation referred to in Article 26(7) of DORA, plus real operational exposure if the red team corrupts production data with no tested restoration plan.
The 6 risk families your control team must track
Article 5(2) requires at least six categories to be taken into account. Each must be documented, assessed and reviewed throughout the test:
- Access granted to threat intelligence providers and external testers to sensitive information on the entity: confidentiality scope, need to know, enforceable NDAs.
- Non-compliance of the TLPT itself with DORA and the RTS, including confidentiality breaches or unethical conduct by providers, which invalidates the attestation.
- Crisis and incident escalation: who alerts whom, within what deadline, when to switch to real crisis management.
- Red team active phase: interruption of critical activities, data corruption, impacts on third parties (clients, counterparties, ICT providers).
- Blue team activity: it too can interrupt critical services or corrupt data while responding, unaware it is a test.
- Incomplete restoration of affected systems: proof that each impacted system returns to nominal state, verified and timestamped.
Luxembourg point of attention: ICT providers included in the test scope also fall under CSSF circulars 22/806 and 25/882 and the subcontracting RTS 2025/532. The remediation that closes the TLPT must feed your ICT risk management under circular 20/750.
How Luxgap automates this risk
Our Luxgap TLPT Risk Sentinel turns the risk management required by Article 5 into a living, enforceable register rather than a Word document frozen at kickoff. The tool connects to your Microsoft Defender, Azure Sentinel, CrowdStrike and your CMDB to map in real time the critical functions affected by the red team phase, correlates each tester action to an Article 5(2) risk and triggers automatic escalation the moment a real danger threshold is crossed.
- Automatically maps critical or important functions in production from your CMDB and your Defender or Sentinel feeds, and links them to the six risk families of Article 5(2).
- Detects in real time any interruption of a critical service or data corruption caused by the red or blue team, and alerts the control team on Teams before the incident becomes a real crisis.
- Generates the prefilled crisis and incident escalation plan, with a named escalation matrix covering white team, blue team, management and CSSF or BCL under TIBER-LU.
- Tracks every access granted to threat intelligence providers and external testers, logs the sensitive information exposed and alerts on any breach of the confidentiality scope.
- Verifies full restoration of each affected system through a before and after state comparison, and blocks closure as long as a system remains degraded.
- Produces a timestamped, sealed PDF report, enforceable before the CSSF and the BCL, demonstrating that risk management was maintained throughout the test in line with Article 5.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a personalised quote and our teams prepare a demonstration on your real perimeter, with a free blank audit within 48h to measure your exposure before any engagement.