Recital 5

Recital 5

Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190

(5)

To mirror the TIBER-EU framework, it is necessary that the testing methodology provides for the involvement of the following main participants: the financial entity, with a control team (mirroring the TIBER-EU ‘control team’) and a blue team (mirroring the TIBER-EU ‘blue team’), and the TLPT authority, in the form of a TLPT cyber team (mirroring the TIBER-EU ‘TIBER cyber teams’), a threat intelligence provider, and testers (whereby the testers mirror the TIBER-EU ‘red team provider’).

Luxembourg specificity
cadre TIBER-LU (BCL et CSSF), Implementation Document revise le 20 juin 2025

In Luxembourg, the TLPT authority within the meaning of Article 26 of DORA is the CSSF, operating jointly with the BCL under the national TIBER-LU framework. The five roles of recital 5 are operationalized through the TIBER-LU Implementation Document revised on 20 June 2025, aligned with TIBER-EU (ECB revision of 11 February 2025). The national cyber team validates the scope and closure, and remediation must feed ICT risk management under CSSF circular 20/750.

Luxgap practice: formalize the scope specification document and the team segregation log from the outset, because the CSSF and BCL require traceable proof of control team / blue team watertightness before validating the test.