- Specifies the criteria used to identify financial entities required to perform threat-led penetration testing.
References and citations
- ECB execution guidance for threat intelligence-based ethical red teaming, commonly used as a structured TLPT implementation handbook in EU financial sector contexts.
- Supervisory guidance for cyber stress testing approaches referenced as useful under NIS2/DORA/CER contexts.
- DORA Chapter IV testing programme requirements (Articles 24-25) and TLPT obligations and tester requirements (Articles 26-27).