Recital 10

Recital 10

Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190

(10)

As evidenced through the experience gathered in the TIBER-EU framework with respect to the ‘control team’, the selection of an adequate control team lead is indispensable for the safe conduct of TLPT. The control team lead should have the necessary mandate within the financial entity to guide all the aspects of the testing, without compromising its confidentiality. For the same reason, members of the control team should have a deep knowledge of the financial entity, of the control team lead’s job role and strategic positioning, should have the required seniority and should have access to the management board. To reduce the risk of compromising the TLPT, the control team should be as small as possible.

Luxembourg specificity
TIBER-LU Implementation Document (BCL / CSSF), version révisée du 20 juin 2025

In Luxembourg, the TLPT authority designated under Article 26 of DORA is the CSSF, operating jointly with the BCL within the TIBER-LU framework. The TIBER-LU Implementation Document, revised on 20 June 2025, sets out the white team governance expectations and its articulation with the white team lead, consistent with RTS 2025/1190 and TIBER-EU revised by the ECB on 11 February 2025.

Luxgap practice: validate the composition and mandate of your control team with the BCL TIBER Cyber Team before any kick-off, and document each member against the "as small as possible" principle.