The classic trap
Recital 23 is frequently misused at the first hitch in a test. When the red team is stuck, the temptation is to open a purple teaming collaboration immediately to protect the schedule. Yet this recital requires that red team / blue team collaboration remain a last resort, in exceptional circumstances and only once all alternative options have been exhausted. The CSSF, the TLPT authority under Article 46 of DORA, and the BCL, within the TIBER-LU framework (Implementation Document revised on 20 June 2025), expect a documented justification for every switch to purple teaming. A test that slides too early into collaboration loses its realistic threat value and may be found non-compliant with the TLPT under Article 26 of DORA.
The 3 framed methods and their guardrails
The recital names three techniques, but each can only be activated once you have proven the pure adversarial path is exhausted. The white team must record the decision.
- Catch-and-release: testers continue a scenario, get detected on purpose, then resume. Use only to unblock an otherwise impossible attack chain, never to save time.
- War gaming: complex scenarios to test the blue team's strategic decision-making. Useful when the organisational, not technical, response is the blind spot.
- Collaborative proof-of-concept: joint validation of a measure, tool or technique in a controlled and cooperative environment.
- Mandatory traceability: every switch must be timestamped, motivated, validated by the white team and filed in the dossier submitted to the CSSF and the BCL.
- ICT provider scope: if critical providers are in scope (subcontracting RTS 2025/532, CSSF circulars 22/806 and 25/882), their involvement in the collaborative exercise must be covered contractually.
Remediation from these phases then feeds ICT risk management under CSSF circular 20/750, in line with Articles 26 and 27 of DORA.
How Luxgap automates this risk
Our Luxgap Purple Escalation Tracker makes unjustified switches to purple teaming impossible: every move from pure adversarial mode to collaborative mode requires proof that alternatives were exhausted, timestamped and signed, and admissible before the CSSF and the BCL. The tool integrates with your testing platform (Microsoft Defender, Azure Sentinel, CrowdStrike, Wazuh) and the white team coordination channel (Teams, Slack) to capture the context of each escalation decision in real time.
- Detects automatically when the red team is blocked and triggers a checklist of alternatives to exhaust before any catch-and-release.
- Classifies each switch by the method invoked (catch-and-release, war gaming, collaborative proof-of-concept) and requires the exceptional justification of recital 23.
- Generates a cryptographically sealed decision log linking each escalation to its timestamp, white team validator and specific TLPT scenario.
- Alerts the white team instantly via Teams whenever purple teaming is initiated without a recorded prior validation.
- Produces a timestamped PDF report, admissible before the CSSF and the BCL, demonstrating that purple teaming remained a compliant last resort under the TIBER-LU framework.
- Automatically feeds remediation findings into your ICT risk register aligned with CSSF circular 20/750.
Available as an add-on to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real scope, with a free blind audit within 48h to measure your exposure before any commitment.