Recital 18
Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190
| (18) | To provide the testers with the information needed to simulate a real-life and realistic attack on the financial entity’s live systems underpinning its critical or important functions, the threat intelligence provider should collect intelligence or information that cover at least two key areas of interest: the targets, by identifying potential attack surfaces across the financial entity, and the threats, by identifying relevant threat actors and probable threat scenarios. To ensure that the threat intelligence provider considers the relevant threats for the financial entity, the testers, the control team, and the test managers should provide feedback the draft threat intelligence report. If it is available, the threat intelligence provider may use a generic threat landscape provided by the TLPT authority for the financial sector of a Member State as a baseline for the national threat landscape. Based on the TIBER-EU framework application, the threat intelligence gathering process typically lasts approximately 4 weeks. |
In Luxembourg, TLPT is run through the TIBER-LU framework jointly steered by the BCL and the CSSF, whose Implementation Document was revised on 20 June 2025. The national threat landscape referenced in recital 18 corresponds in practice to the generic threat landscape made available under this framework, which the intelligence provider must use as a baseline before contextualising it to the entity's critical functions.
Luxgap practice: check that your threat intelligence provider incorporates the latest 20 June 2025 TIBER-LU Implementation Document and the BCL/CSSF landscape into the draft report submitted for validation.