The classic trap
Recital 16 looks harmless, but it sets a demanding requirement: the flow of information between the TLPT authority's test managers, the financial entity's control team (white team) and the TLPT providers. In practice, the CSSF, the TLPT authority under Article 46 of DORA, and the BCL police defective communication governance through the TIBER-LU framework: an unreachable white team, a threat intelligence provider not aligned on the validated scope, missing progress reports. A test whose information flow is not documented can be invalidated, forcing the entity to run it again, with a direct impact on the critical functions tested in live production.
What this recital concretely imposes on your white team
A recital is not binding, but it informs the interpretation of Article 26 of DORA and the RTS provisions on the conduct of the test. It turns communication into a documented obligation of means:
- Appoint a restricted white team, permanently reachable during the active phase, with a dedicated secure channel and a formalised escalation chain.
- Formalise the TLPT authority's expectations (scope, critical functions, ICT providers included under CSSF circulars 22/806 and 25/882) in a shared, versioned reference document.
- Trace every progress exchange between test managers, red team, threat intelligence and white team to prove control of the flow during a review.
- Align TLPT providers with the requirements of the subcontracting RTS 2025/532, in particular on confidentiality and information reporting.
- Ensure the remediation phase feeds ICT risk management under CSSF circular 20/750, with an evidence-grade report.
How Luxgap automates this risk
Our Luxgap TLPT Comms Orchestrator makes the information blackout that invalidates a TIBER-LU test impossible: it centralises and timestamps every exchange between test managers, white team and TLPT providers in a sealed log. The tool relies on M365, Teams, Azure Sentinel connectors and a dedicated encrypted channel to automatically capture the test's milestones without exposing sensitive content to unauthorised teams.
- Formalises the TLPT authority's expectations in a versioned reference document, with read-receipt tracking by the white team.
- Traces every red team / white team / threat intelligence interaction, timestamped and cryptographically sealed, ready for a CSSF or BCL review.
- Alerts in real time via Teams whenever a TIBER-LU communication milestone is missed or a white team contact becomes unreachable.
- Checks that TLPT providers comply with the confidentiality and reporting clauses required by RTS 2025/532.
- Generates an evidence-grade test conduct file linking remediation to ICT risk management under CSSF circular 20/750.
Available as an add-on to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real scope, with a free blind audit within 48h to measure your exposure before any commitment.