The classic trap
Recital 21 describes the full kill chain the red team must execute against live production systems: reconnaissance, weaponization, delivery, exploitation, control and movement, actions on target. The trap that the CSSF and the BCL sanction in practice under the TIBER-LU framework is the cosmetic test: a red team that stops at reconnaissance or that tests an isolated pre-production environment, never reaching real compromise of critical functions. A TLPT that fails to demonstrate lateral movement and agreed actions on target proves nothing and will be deemed non-compliant with Article 26 of DORA. The second trap: failing to trace every TTP deployed, which makes remediation and the feed into ICT risk management (CSSF circular 20/750) impossible.
The 6 kill chain stages to cover and document
- Reconnaissance: OSINT collection on the entity, its staff, its exposed infrastructure and its in-scope ICT providers (subcontracting RTS 2025/532, CSSF circulars 22/806 and 25/882).
- Weaponization: analysis of gathered information and preparation of target-specific operations (payloads, tailored social engineering scenarios).
- Delivery: active launch of the full operation on the target in live production, not in a sandbox.
- Exploitation: compromise of servers and networks, exploitation of staff through social engineering.
- Control and movement: pivoting from compromised systems to further vulnerable or high value ones (lateral movement).
- Actions on target: broader access and acquisition of the previously agreed target information and data set out in the red team test plan.
Each TTP must be timestamped, mapped (ideally on MITRE ATT&CK) and tied back to the initial threat scenario provided by threat intelligence, so that the white team, the CSSF and the BCL can verify the real coverage of the test.
How Luxgap automates this risk
Our Luxgap Red Team Killchain Tracker turns the red team narrative report into structured evidence that is enforceable before the CSSF and the BCL, guaranteeing that all six phases of Recital 21 are covered and mapped. The tool ingests red team logs, your SOC alerts (Microsoft Defender, Azure Sentinel, CrowdStrike, Wazuh) and the white team validated test plan, then reconstructs the full kill chain timeline without asking the white team to re-enter anything.
- Automatically maps every tactic, technique and procedure deployed onto the MITRE ATT&CK matrix and onto the six phases of Recital 21, and flags any uncovered phase.
- Correlates red team actions with blue team detections to measure the real detection rate, critical function by critical function in production.
- Detects lateral movement toward your in-scope ICT providers (RTS 2025/532, CSSF circulars 22/806 and 25/882) and maps the full compromise chain.
- Generates prioritised remediation records and feeds them directly into your ICT risk management aligned with CSSF circular 20/750.
- Produces a timestamped, cryptographically sealed PDF report aligned with the TIBER-LU methodology (Implementation Document of 20 June 2025), enforceable during a CSSF or BCL review.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams prepare a demonstration on your real scope, with a free blind audit within 48h to measure the coverage of your next TLPT before any commitment.