Financial Services · DORA & TLPT (TIBER-DE)

Resilience that holds up
under regulatory scrutiny

Since January 17, 2025, DORA has applied directly across the EU financial sector and replaced the German BaFin circulars BAIT, VAIT, ZAIT, and KAIT. Every entity in scope must run regular security tests under Art. 24/25, and institutions the supervisor designates as significant must additionally undergo a Threat-Led Penetration Test (TLPT) under Art. 26/27, at least every three years and exclusively on live production systems. We cover both: the structured basic test most firms need, and the groundwork that keeps a later TLPT from turning into a scramble.

Art. 24-27 DORA covered TIBER-DE-aligned approach Free initial consultation
The distinction DORA draws

Basic security testing or TLPT: which one applies to you?

DORA doesn't apply one standard to everyone. Most financial entities only need a structured security test under Art. 24/25. Only institutions the supervisor designates as systemically important also need the far more demanding Threat-Led Penetration Test under Art. 26/27. Here's where the two actually differ.

Criterion
Basic security testing (Art. 24/25 DORA)
TLPT (Art. 26/27 DORA)
Who it applies to
Every entity in scope of DORA, no exceptions
Only institutions the supervisor designates as significant, including entities processing over EUR 150 billion in payment transactions per year
Frequency
At least yearly
At least every three years
Test environment
Test or production systems, depending on scope
Live production systems only, no exceptions
Project duration
Typically a few weeks
At least 12 weeks under the TIBER-DE process
Who is allowed to test
An experienced pentest team is sufficient
Only specifically accredited TLPT testers, under the Bundesbank's TIBER-DE framework
What we deliver
Fully covered as a standalone engagement
A TLPT-readiness assessment to prepare you; we don't run the accredited test itself
TIBER-DE is Germany's framework for TLPT, run operationally by the Bundesbank and supervised by BaFin. If you're not sure whether your institution's size is heading toward TLPT territory, a short initial call is the fastest way to find out.
Two paths, one goal

Path A or Path B: how it runs at your institution

Depending on your institution's designation, we scope the engagement either as an Art. 24/25 basic test or as a TLPT-readiness assessment. Both paths follow a clear sequence, but they differ in depth, lead time, and outcome.

Path A · Art. 24/25 DORA

The structured basic test

For the vast majority of financial entities, this is the relevant evidence. We deliver it as a clearly scoped, repeatable engagement.

What happens
  1. 01

    Scoping & designation check

    We work out together whether a basic test covers you, and define which core systems, online banking components, branches, and third-party connections belong in scope.

  2. 02

    Reconnaissance & test execution

    Open-source information gathering, network reconnaissance, and then manual testing within the agreed scope, on test or production systems as agreed.

  3. 03

    Risk assessment & DORA-mapped report

    Every finding is rated by severity and exploitability and mapped to the relevant DORA article. The audit-ready report with a management summary is usable directly for BaFin reviews.

Outcome: documented evidence under Art. 24/25 DORA, repeatable every year.
Path B · Art. 26/27 DORA

TLPT readiness, not a scramble later

If your institution is likely to be designated as significant, we prepare your systems and processes for a future TLPT, without running the accredited test ourselves.

What happens
  1. 01

    Threat-intel-informed scoping

    We derive realistic attack scenarios from open-source information and your institution's threat picture, including possible vishing pretexts, the same way the threat-intelligence phase of a TLPT will later demand.

  2. 02

    Production-safe rehearsal of the TIBER-DE phases

    We walk through the phases of a TLPT in a controlled way, with clear abort criteria and no risk to live operations, and check whether your processes, contacts, and detection hold up.

  3. 03

    Gap list before the accredited test

    You get a prioritized list of the gaps an accredited tester team would find, plus a remediation plan, so the later, considerably more expensive TLPT doesn't stumble over avoidable basics.

Outcome: a readiness report and gap list as groundwork for your next TLPT cycle, at least every three years.
We don't run the accredited TLPT itself. Under TIBER-DE that is reserved for specifically accredited tester teams, run operationally by the Bundesbank and supervised by BaFin.
Art. 13(6) DORA

A well-run vishing campaign is a test and a compliance artifact at once

DORA explicitly lists phishing simulations, vishing included, among the recognized test types under Art. 13(6). In practice, that means a controlled call posing as IT support, a branch manager, or an outside vendor checks whether staff hand over credentials or approve a transfer, and produces exactly the documented test artifact you need for your DORA evidence at the same time. We plan every campaign with agreed scenarios and clear escalation limits, and hand over a debrief that drops straight into your compliance file.

Alongside classic email phishing, vishing specifically mirrors the attack path regulators have recently flagged, with more malware campaigns targeting German financial institutions this way. More on that below.
The financial-sector attack surface

Where attackers actually get in at banks and insurers

01

Core banking & payment processing

Core banking platforms and payment interfaces that grew over decades, often on protocols that rarely get a fresh look.

Art. 25 DORA
02

Online banking

Customer portals and banking APIs: a direct target, and the system with the most damage potential if access succeeds.

Art. 25 DORA
03

Branch networks

Foot traffic, teller areas, and meeting rooms with network access, a physical attack surface a pure IT review usually misses.

Art. 25 DORA
04

ICT third parties & supply chain

Outsourcing partners, cloud providers, and payment processors, which DORA treats as its own risk category under Art. 28.

Art. 28 DORA
Path A in practice

What a basic-test report looks like

An excerpt of what stands at the end of Path A: every finding with its severity, remediation, and the DORA article it relates to.

Financial Services Pentest Report · Sample excerptSample
Vishing simulation: customer service discloses credentials under an authority pretext (sample value)
Art. 13(6) DORA
Online banking API: weak authorization check between customer accounts (BOLA)
Art. 25 DORA
Third-party VPN: access without multi-factor authentication
Art. 28 DORA
Core banking system: outdated interface protocol without encryption
Art. 25 DORA
Branch: network jack in the customer area reachable without port security
Art. 25 DORA
Active Directory: missing network segmentation between branch and headquarters
Art. 25 DORA
6 findings · remediation plan includedDORA mapping Art. 24-28
Illustrative example, no real customer data.
Self-check

Which path are you on?

Three questions that point the way. The binding designation is made by the supervisor, not by you.

  1. Has the supervisor designated your institution as significant under Art. 26/27 DORA?

    Yesmore likely Path B: TLPT is mandatory, at least every three years, on production systems
    NoPath A is enough: basic testing under Art. 24/25, at least yearly
  2. Do you process more than EUR 150 billion in payment transactions per year?

    Yesmore likely Path B: that is one of the criteria for a significant designation
    NoPath A is enough, provided no other designation criterion applies
  3. Is a TLPT date under TIBER-DE already in sight?

    Yesmore likely Path B: the test itself takes at least 12 weeks, and preparing for it needs lead time
    NoPath A is enough, repeated yearly

The self-check doesn't replace a look at your actual figures. If you're unsure whether your size is heading toward TLPT territory, we work through it in a free initial call.

Sort it out in a first call
Relevant modules

These tests cover your DORA evidence

Art. 24 through 28 DORA call for different kinds of evidence. Here's how we put them together for financial institutions.

For the full regulatory picture

Every DORA and TLPT detail lives on our DORA page

This page focuses on the sector view: attack surface, vishing, and the difference between basic testing and TLPT. For the complete regulatory picture, including fines, reporting duties, and the DORA timeline, see our dedicated DORA page.

Visit the DORA page

DORA & TLPT for financial services: your questions

Basic testing under Art. 24/25 DORA applies to every financial entity and runs at least yearly, usually on test or production systems. The Threat-Led Penetration Test (TLPT) under Art. 26/27 is far more demanding: it runs exclusively on live production systems, takes at least 12 weeks, and is only mandatory for institutions the supervisor designates as significant.
Because lawmakers deliberately set it up that way: under Section 28(5) of the German BSIG, DORA acts as a specialized regime (lex specialis) for financial entities, taking precedence over NIS2. If you're subject to DORA, you don't need to implement NIS2 separately: its testing requirements already provide at least equivalent coverage.
We agree the target group, pretexts, and escalation limits with you up front, for example whether a call is allowed to go as far as requesting a wire transfer or should be stopped earlier. The calls themselves run in a controlled, logged manner. Afterward you get a breakdown of response behavior and, where useful, targeted awareness recommendations for specific teams.
No, we deliberately don't run the full, accredited TLPT under TIBER-DE ourselves: that requires specialized, officially accredited tester teams. What we offer is the preparation for it: a TLPT-readiness assessment that surfaces gaps beforehand, so the later, considerably more expensive TLPT doesn't stumble over avoidable basics.
The supervisor makes that designation, not you, based on criteria like systemic relevance or transaction volume, including a rough threshold of EUR 150 billion in processed payment transactions per year. If you're unsure whether your size is heading that direction, we can work through your actual figures in a free initial call.
It depends on scope: number of systems and branches, whether vishing and physical testing are included, and whether you need a basic test or a TLPT-readiness engagement. After a free initial call we know your scope and you get a transparent fixed-price quote.
A basic test under Art. 24/25 typically takes a few weeks from kickoff to final report, depending on scope. A TLPT-readiness assessment usually needs more lead time, since more systems and stakeholders are involved. Under TIBER-DE, a full TLPT itself takes at least 12 weeks.
Indirectly, yes: Art. 28 DORA requires you, as the bank, to maintain a register of all ICT third parties and assess their risk. Critical providers can even fall under direct oversight from the European supervisory authorities. As part of our pentest, we also check how your third-party access paths and interfaces are secured.