The classic trap
Recital 22 frames leg-ups, the occasional assistance given to the red team when it stalls on an attack step. The trap the CSSF (TLPT authority under Article 46 of DORA) and the BCL observe within the TIBER-LU framework: financial entities that let the white team grant assistance informally, untracked, and without the prior agreement of the TLPT authority. A poorly documented leg-up distorts the value of the test and can invalidate the threat scenario: the entity will never know whether its critical function would have held without the artificial help given to the tester. The consequence is not an immediate fine, but a TLPT report deemed inconclusive, hence to be redone, with the budget impact that implies.
How to document a leg-up defensibly
A leg-up is only acceptable if it is properly governed. Recital 22 implicitly imposes a governance discipline on every assistance granted:
- Document the nature of the leg-up: information (intelligence on architecture, a credential, a path) or access (opening an ICT system or internal network).
- Obtain the prior agreement of the TLPT authority (CSSF, coordinated with the BCL under TIBER-LU) before any assistance, never after the fact.
- Timestamp each leg-up and attribute it by name to the control team member who granted it.
- Justify the constraint that made the leg-up necessary: available time, resources, ethical or legal boundary reached.
- Isolate, in the final report, the steps reached thanks to a leg-up from those achieved by the red team alone, to avoid overestimating your resilience.
- Verify that the ICT providers within scope (CSSF circulars 22/806 and 25/882, subcontracting RTS 2025/532) fall under the same traceability regime.
Post-test remediation then feeds your ICT risk management (circular 20/750): a poorly isolated leg-up injects false certainty about a critical function.
How Luxgap automates this risk
Our Luxgap LegUp Ledger turns leg-ups, today managed through scattered emails and Teams messages, into a timestamped, cryptographically sealed register, opposable to the CSSF and the BCL during the TIBER-LU review. The tool sits within the control team channel via connectors to Microsoft 365, Teams, Azure Sentinel and your access bastions (jump servers, CyberArk PAM or equivalent) to capture every grant of information or access in real time, without relying on the white team's goodwill to declare it.
- Automatically detects each network or system access granted to the red team through your bastion and PAM logs, and classifies it as an information or access leg-up.
- Blocks the validation of a leg-up until the TLPT authority's agreement has been recorded, materialising the requirement of recital 22.
- Timestamps and attributes each assistance by name, with the justifying constraint (time, resources, ethical or legal boundary).
- Generates a test timeline that visually isolates steps crossed with assistance from those reached by the red team alone.
- Produces a sealed PDF report, integrable into the TLPT file and your remediation under circular 20/750.
- Tracks leg-ups involving your in-scope ICT providers (circulars 22/806 and 25/882) to ensure full traceability of the chain.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a personalised quote and our teams will prepare a demonstration on your real environment, with a free blind audit within 48h to measure your exposure before any commitment.