Recital 5
Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190
| (5) | To mirror the TIBER-EU framework, it is necessary that the testing methodology provides for the involvement of the following main participants: the financial entity, with a control team (mirroring the TIBER-EU ‘control team’) and a blue team (mirroring the TIBER-EU ‘blue team’), and the TLPT authority, in the form of a TLPT cyber team (mirroring the TIBER-EU ‘TIBER cyber teams’), a threat intelligence provider, and testers (whereby the testers mirror the TIBER-EU ‘red team provider’). |
In Luxembourg, the TLPT authority within the meaning of Article 26 of DORA is the CSSF, operating jointly with the BCL under the national TIBER-LU framework. The five roles of recital 5 are operationalized through the TIBER-LU Implementation Document revised on 20 June 2025, aligned with TIBER-EU (ECB revision of 11 February 2025). The national cyber team validates the scope and closure, and remediation must feed ICT risk management under CSSF circular 20/750.
Luxgap practice: formalize the scope specification document and the team segregation log from the outset, because the CSSF and BCL require traceable proof of control team / blue team watertightness before validating the test.