Local AI: Governance Before Hardware Purchase
Benedikt Langer
10 min readFour developments over two weeks show that locally operated AI goes far beyond the tech stack. ...
4 min. read
DORA requires systemically important financial institutions to conduct regular threat-led penetration tests on production systems. No test lab, no sandbox: real attacks on real infrastructure, without the Blue Team knowing. The first notifications from supervisory authorities will be issued in 2026. CIOs in the financial sector who are not prepared now have a problem on a short timeline.
Most companies are familiar with penetration tests: an external team checks defined systems for vulnerabilities, documents the results and provides recommendations. The test runs on test systems or within a defined scope, the internal security team is informed, and the results feed into the next audit report.
TLPT under DORA is something fundamentally different. Three dimensions distinguish TLPT from conventional pentests. First: secrecy. The Blue Team, meaning the internal IT security team, does not know that a test is taking place. Only a small circle in management is informed (the so-called White Team). Second: production systems. The test runs on the real infrastructure, not on copies or test environments. The risks are real, the results are meaningful, and a mistake by the Red Team can have actual consequences. Third: threat intelligence first. Before the Red Team attacks, a separate threat intelligence provider analyzes the institution’s specific threat landscape. The attack simulates real threat actors with real tactics, not a generic playbook.
The effort involved is considerable: a complete TLPT cycle takes 6 to 12 months. The red team phase alone has a minimum duration of 12 calendar weeks. Added to this are scoping, threat intelligence analysis, purple teaming (joint analysis with the Blue Team after the test ends) and the final report. For CIOs who have only dealt with standard pentests so far, TLPT is in a different league.
“Threat-led penetration testing enables financial institutions to identify vulnerabilities early and test the resilience of their ICT systems under realistic conditions.”
BaFin, “Simulating attacks to enhance security” (December 2024)
Not every financial company is subject to the TLPT obligation. DORA limits the requirement to institutions of systemic relevance. Specifically affected are: Global Systemically Important Institutions (G-SIIs) and Other Systemically Important Institutions (O-SIIs), institutions that processed more than 150 billion euros in payment transactions in each of the last two financial years, central securities depositories (CSDs) and central counterparties (CCPs).
In Germany, this includes the major institutions: Deutsche Bank, Commerzbank, DZ Bank, the Landesbanken and systemically relevant insurers. But specialized payment service providers that exceed the transaction threshold may also be affected. The supervisory authorities (BaFin and the Bundesbank in Germany) individually designate the institutions subject to the obligation. The first wave of notifications is underway in 2026.
For CIOs outside the financial sector, TLPT is still relevant: NIS2 contains similar requirements for regular security testing for essential entities. The TLPT methodology is likely to become the gold standard for resilience testing outside DORA as well.
TLPT under DORA is based on the TIBER-EU framework (Threat Intelligence-Based Ethical Red Teaming), which the European Central Bank introduced in 2018. In Germany, the Deutsche Bundesbank implements this framework as TIBER-DE, currently in version 4.0 (July 2025).
The TIBER-DE requirements are consistent with the DORA TLPT requirements, but impose slightly stricter preliminary requirements in some areas. The Bundesbank provides operational support for the tests; BaFin is the competent supervisory authority for supervisory tasks. Institutions that have already carried out a TIBER-DE test have a significant head start over institutions starting from scratch.
Important for CIOs: The threat intelligence provider must always be external. Every third test must be carried out with an external red team (the others may be internal, provided the internal red team meets the DORA requirements). Purple teaming is mandatory in the final phase. This means that the red team and the blue team jointly analyze what worked and what did not. This phase is the most valuable part of the test because it delivers concrete improvements.
Sources: DORA (EU 2022/2554), EBA Final RTS on TLPT, Bundesbank TIBER-DE v4.0
1. Clarify whether you are affected. Does your institution fall under the TLPT requirement? The criteria are clear (G-SII/O-SII, transaction volume above 150 billion euros, CSD/CCP). If in doubt, contact BaFin proactively. Anyone who only finds out they are affected when the official notification arrives will have too little lead time.
2. Form a White Team. The White Team manages the TLPT internally. It typically consists of the CIO/CISO, risk management and a representative of the management board. The White Team must commission the test, define the scope and ensure confidentiality vis-a-vis the Blue Team. Its composition should be defined in advance, not only once the notification arrives.
3. Evaluate external providers. Threat intelligence providers and red team service providers need to be selected early. The availability of qualified TLPT providers is limited, especially if the first notification wave activates many institutions at the same time. CIOs should prepare framework agreements with at least two providers. Qualification criteria: CREST certification, TIBER experience, references from comparable institutions.
4. Prepare the scope. The TLPT scope must cover critical business functions and their supporting IT systems. This requires up-to-date documentation of critical services, the underlying infrastructure and dependencies. Institutions that have not kept their cybersecurity architecture documentation current will run into difficulties when defining the scope.
5. Review internal resilience. TLPT reveals weaknesses that then need to be remediated. CIOs should close obvious gaps before the test: unpatched systems, missing network segmentation, outdated access rights. Not to pass the test, but because these gaps represent real risks. A TLPT that finds trivial vulnerabilities wastes the budget on the obvious instead of on the subtle risks that deliver the real added value.
The TLPT does not end with the final report. The results must feed into a concrete action plan, whose implementation is tracked by the supervisory authority. BaFin expects identified vulnerabilities to be remediated within defined deadlines. The board must approve the action plan and monitor its implementation.
For CIOs, TLPT therefore means not just a one-off effort, but a continuous improvement cycle. The personal liability of management under DORA makes this cycle a top-level issue. CIOs who treat TLPT as an annoying regulatory obligation miss its real value: a realistic stress test of their own defensive capabilities that no internal exercise can provide.
TLPT is performed on production systems (not test environments), the Blue Team knows nothing about it (confidentiality), and the attack is based on an individual threat intelligence analysis of the institution. A standard pentest runs on defined test systems with the knowledge of everyone involved.
Global and national systemically important institutions (G-SII/O-SII), institutions with more than 150 billion euros in payment transactions over the past 2 years, central securities depositories, and central counterparties. BaFin identifies the institutions subject to the requirement individually.
The full cycle takes 6 to 12 months. The Red Team phase alone has a minimum duration of 12 weeks. In addition, there is the threat intelligence analysis (4 to 8 weeks), scoping (2 to 4 weeks), Purple Teaming (2 to 4 weeks), and the final report.
Purple Teaming is the joint analysis by the Red Team (attackers) and Blue Team (defenders) after the test has ended. Only at this point does the Blue Team learn that a test took place. Together, they analyze detection gaps, response times, and escalation processes. Purple Teaming is mandatory under DORA.
Not under DORA. But NIS2 contains similar requirements for regular security testing for essential entities. The TLPT methodology is expected to become the gold standard for resilience testing outside the financial sector as well.
Title image source: Sora Shimazaki / Pexels