Recital 25

Recital 25

Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190

(25)

To further facilitate the learning experience of all parties involved in the TLPT, for the benefit of future tests, and to further the digital operational resilience of financial entities, the parties concerned should provide feedback to each other on the overall process, and in particular identify which activities progressed well or could have been improved, and which aspects of the TLPT process worked well or could be improved.

Luxembourg specificity
cadre TIBER-LU (BCL et CSSF), Implementation Document revise le 20 juin 2025

In Luxembourg, the TLPT authority within the meaning of Article 26 of DORA is the CSSF, which jointly operates with the BCL the national TIBER-LU framework, whose Implementation Document was revised on 20 June 2025. The cross feedback referred to in recital 25 concretely materialises in the 360 feedback meeting facilitated by the TIBER-LU Cyber Team, and the lessons must feed the ICT risk management framework described in CSSF circular 20/750.

Luxgap practice: formalise the 360 feedback meeting minutes as part of the test file submitted to the CSSF, and trace the reinjection of each improvement axis into your ICT risk register before the next triennial cycle.