The classic trap
Recital 25 anchors a requirement too often overlooked: TLPT does not end with the remediation report. Financial entities treat the cross feedback as an end of mission formality, whereas the CSSF and the BCL, within the TIBER-LU framework, review the quality of the 360 feedback meeting as evidence that the test genuinely fed collective learning (red team, blue team, white team, threat intelligence). Without a structured trace of this feedback, the entity fails to demonstrate the continuous improvement expected under Article 26 of DORA and poorly feeds its ICT risk management within the meaning of CSSF circular 20/750.
What recital 25 requires in practice
This recital is not normative, but it clarifies the legislator's intent: TLPT is a learning cycle, not a one off exam. Concretely, you must structure and retain:
- Cross feedback between all parties (external red team, internal blue team, white team, control team, ICT providers within scope under circulars 22/806 and 25/882).
- Explicit identification of activities that worked well and those that could have been improved, on both the defence and attack sides.
- Assessment of the TLPT process itself: scoping, threat intelligence quality, white team coordination, scenario compliance.
- Transmission of these lessons to the ICT risk management framework (circular 20/750) and their reinjection into preparation of the next triennial cycle.
- Documentation of the loop with critical ICT providers, consistent with subcontracting RTS 2025/532.
Without formal capitalisation, each test starts from scratch and the entity loses the resilience benefit the legislator precisely seeks to build.
How Luxgap automates this risk
Our Luxgap TLPT Learning Loop turns end of test feedback, often lost in emails and slides, into an opposable learning register usable for the next cycle. The tool aggregates structured feedback from the four teams via connectors to your collaboration tools (M365, Teams, Jira, ServiceNow) and cross references findings with your ICT risk repositories to materialise what worked and what must improve, without imposing a manual form on the white team.
- Automatically collects cross feedback from red, blue, white and threat intelligence teams from Teams, Jira and ServiceNow, structured according to the TIBER-LU methodology revised on 20 June 2025.
- Classifies each lesson by process phase (scoping, threat intelligence, execution, closure) and by actor type, including in scope ICT providers.
- Generates the 360 feedback meeting minutes aligned with CSSF and BCL expectations, ready to add to the test file.
- Links each improvement axis to a risk in the ICT register within the meaning of CSSF circular 20/750 and tracks its reinjection into the next triennial cycle.
- Produces a timestamped PDF report demonstrating that the entity closed the learning loop required by Article 26 of DORA, opposable during a CSSF inspection.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a personalised quote and our teams will prepare a demonstration on your real perimeter, with a free blind audit within 48h to measure your TLPT maturity before any engagement.