TIBER Red Team-Test for DORA

Threat-Led Penetration Testing (TLPT)

The DORA (Digital Operational Resilience Act, Regulation (EU) 2022/2554) has, since January 2025, required EU financial institutions to carry out, among other things, Threat-Led Penetration Testing (TLPT) – a penetration test based on threat intelligence that emulates advanced adversaries. In Germany, the national framework standard TIBER-DE has been established for this purpose: binsec GmbH's TIBER Red Team Test conducts TLPT in TIBER-DE format – tailored to the ICT environments of banks, insurers, and other DORA-relevant institutions.

The requirements are set out in Article 26 DORA in conjunction with the Regulatory Technical Standards (RTS) on Threat-Led Penetration Testing adopted by the EBA and the TIBER-DE framework standard of the German supervisory authorities (Deutsche Bundesbank / BaFin). Under these, institutions must perform TLPT at least every three years – more frequently where the risk profile justifies it – and submit the TLPT report to the supervisory authority. At its core is the overall assessment of the effectiveness of the implemented security measures and of the institution's ICT resilience.

The TIBER-DE process provides for official accompaniment by the TIBER Cyber Team (TCT) of the Deutsche Bundesbank and BaFin: institutions register their test with the TCT, which steers the execution on an administrative level and ensures compliance with the supervisory requirements. As an external red team provider, binsec GmbH supports you through the entire process – from preparing the test registration through the attack emulation to the report-ready documentation.

Roles and Flow of a TIBER-DE-Compliant TLPT

The TIBER-DE methodology clearly distinguishes the roles – binsec GmbH takes on the red team:

  • White Team (internal): The institution's internal test steering defines mission objectives, scope, and rules of engagement, coordinates the test with the supervisor, and evaluates the results – without being part of the defence.
  • Threat Intelligence (TI): The TI team – internal to the institution or as an external TI provider – is responsible for the threat landscape: selection of the realistic threat profile and the TTPs (e.g., per MITRE ATT&CK) based on current threat intelligence for the financial sector. On request, binsec supports in shaping the threat profile.
  • Red Team (binsec): We simulate the advanced adversary per red team methodology across the entire ICT environment – infrastructure, applications, cloud, remote access, and, on request, social engineering – aiming to reach the agreed mission objectives while remaining undetected as much as possible.
  • Blue Team (internal): Your defence is not informed in advance – detection, investigation, and incident response are tested exactly as a real attack would require.

The TIBER-DE approach focuses the test on the agreed objectives: only paths that lead to the mission objective are pursued; additional vulnerabilities are not systematically collected. The TLPT report meets the minimum requirements of the DORA RTS: documented attack path with timeline and TTP mapping, overall assessment of the effectiveness of the security measures and of ICT resilience, and remediation recommendations – in a format that stands up to submission to the supervisory authority and to the execution process via the TCT. As an external service provider, we additionally meet the DORA requirements for ICT third-party providers (Article 30): contractual provisions, evidence, and governance included.

Request your DORA TLPT offer in TIBER-DE format today – threat profile, mission objectives, and rules of engagement are agreed in a kickoff with your internal test steering; we prepare the test registration with the TCT for you.

EU financial institutions in scope of the DORA – e.g., credit institutions, insurers, investment fund managers, payment service providers, and other DORA-relevant entities. Smaller institutions with limited ICT risk may be exempt from the obligation under specific conditions (Article 26 DORA); the exact classification is clarified with the competent authority.
Article 26 DORA in conjunction with the Regulatory Technical Standards (RTS) on Threat-Led Penetration Testing adopted by the EBA, and the TIBER-DE framework standard of the German supervisory authorities (Deutsche Bundesbank / BaFin). The RTS specify, among other things, the scope, the methodology, the types of threats, and the minimum requirements for the TLPT report.
At least every three years – more frequently where your risk profile justifies it, e.g., after significant changes to the ICT environment, new threats, or a security incident.
The TIBER Cyber Team of the Deutsche Bundesbank and BaFin officially accompanies TIBER-DE tests: institutions register their test with the TCT, which steers the execution on an administrative level and ensures compliance with the supervisory requirements. The TLPT report is submitted to the supervisor in this process.
The white team is the institution's internal test steering: mission objectives, scope, and rules of engagement. The threat intelligence team – internal or as an external TI provider – is responsible for the threat landscape and the threat profile. The red team (binsec) emulates the advanced adversary. The blue team, your defence, is not informed in advance and reacts under realistic conditions.
Your ICT environment: infrastructure, applications, cloud connectivity, remote access – as well as your defence's reaction. The exact scope and the mission objectives (e.g., access to sensitive data) are defined with the white team and documented in the rules of engagement.
The report is submitted within the TIBER-DE process to the competent supervisory authority (in Germany: BaFin, additionally the ECB for systemically relevant institutions) and covers, in accordance with the DORA RTS, the overall assessment of the effectiveness of your security measures and of your ICT resilience. We prepare it so that the supervisory minimum requirements are directly covered.
A named white team for the internal test steering, an overview of your ICT environment (including cloud connectivity and third-party access), the clarification of the threat profile with your TI team or TI provider, a realistic time window – TIBER tests typically take several weeks – and the agreed rules of engagement. We prepare the test registration with the TCT together with you.
Critical findings are reported immediately to the white team – usually by phone – and documented in the report. The attack path is not ended prematurely but continued in a controlled manner, in order to preserve the mission objective and thus the meaningful overall assessment of ICT resilience.

Your advantages with
binsec GmbH

As an owner-managed pentest boutique – staffed by a high-performing team of around 10 experienced senior experts – binsec GmbH has specialized in sophisticated penetration testing for over a decade. We demonstrate our deep roots in the community every day through our own platforms like binsec.tools, binsec.wiki, and binsec.academy. Relevant academic degrees, high-caliber industry certifications, and years of hands-on project experience are what truly matter to us – and how we guarantee a precise, manual analysis for every assessment.

Contact us

More than 10 years of practical experience in penetration testing

No subcontractors or external freelancers

Direct communication with the responsible senior penetration tester

Structured, documented, and reproducible testing methodology based on PTDoc®

Fully controlled in-house pentesting infrastructure, no cloud services used

Local LLMs on own hardware in German data centers

Professional offensive security certifications: OSCP, OSCE, CRTO, BACPP

Identification of technical and business-relevant security risks

Risk-weighted vulnerability assessment or CVSS based scoring

Report including executive summary and detailed technical section

Retesting of identified vulnerabilities included

Your advantages with
binsec GmbH

As an owner-managed pentest boutique – staffed by a high-performing team of around 10 experienced senior experts – binsec GmbH has specialized in sophisticated penetration testing for over a decade. We demonstrate our deep roots in the community every day through our own platforms like binsec.tools, binsec.wiki, and binsec.academy. Relevant academic degrees, high-caliber industry certifications, and years of hands-on project experience are what truly matter to us – and how we guarantee a precise, manual analysis for every assessment.

More than 10 years of practical experience in penetration testing

No subcontractors or external freelancers

Direct communication with the responsible senior penetration tester

Structured, documented, and reproducible testing methodology based on PTDoc®

Fully controlled in-house pentesting infrastructure, no cloud services used

Local LLMs on own hardware in German data centers

Professional offensive security certifications: OSCP, OSCE, CRTO, BACPP

Identification of technical and business-relevant security risks

Risk-weighted vulnerability assessment or CVSS based scoring

Report including executive summary and detailed technical section

Retesting of identified vulnerabilities included

Approach: Standard-Compliant & Reproducible

A penetration test is a structured attack on IT systems or applications to identify potential vulnerabilities. It uses the same tools and techniques that real attackers would use to break into a system. Thus, a penetration test is not an automated vulnerability scan. On the contrary, a penetration test as a service is always a combination of using security tools and conducting manual tests to uncover vulnerabilities. While a real attacker only needs to find and exploit a single vulnerability, a penetration tester checks all relevant attack vectors.

Having a structured approach is one of the most important factors. For this purpose, we use our own platform PTDoc®, a specialized pentest documentation tool that logs all manual testing steps in full compliance with all relevant security standards and translates them into a clear, reproducible report for you. Since this tool significantly reduces the overhead of report generation, it allows us to focus entirely on our core mission as pentesters: identifying and analyzing critical security flaws. Our approach is based on all relevant standards and publications.

How We Work
From Planning to Re-Testing

 
 
 
 

Preparations

We coordinate the technical and organisational framework for the penetration test, communication channels, points of contact and testing windows. Depending on the project, this is done through a kick-off meeting or a brief exchange via e-mail. Where required, the client provides relevant technical documentation and access to the systems within scope.

 
 
 
 

Conducting

The penetration test is performed using a structured and risk-oriented assessment approach that combines automated analysis techniques with extensive manual testing. The specific test cases and assessment procedures depend on the actual conditions, technologies and attack surface encountered within the target environment.

 
 
 
 

Reporting

After the assessment, we prepare a detailed report including an executive summary, risk ratings, technical details and remediation recommendations. Findings are documented in a clear and reproducible manner and critical issues are communicated immediately during the engagement if required.

 
 
 
 

Debriefing

We are happy to review the findings and recommendations together with your team. During the debriefing, we explain technical details, potential impacts and remediation priorities, while answering questions and discussing next steps.

 
 
 
 

Re-Testing

After remediation, we verify whether the identified findings have been successfully resolved and update the report accordingly. Re-testing is generally included for remote assessments and provides assurance that the implemented measures are effective.

Pentest Offer for DORA/TIBER TLPT

Planning a penetration test always requires a careful balance between the time invested in testing and the financial framework to achieve a reasonable price-performance ratio. Successful pentests are characterized by a precise balance between these factors, as this is the only way to guarantee a reliable review of all relevant attack vectors. The time required depends on the size and complexity of the scope. While analyzing a small web application without complex permission structures often takes just a few days, auditing extensive corporate networks can take several weeks.

To provide a tailored pentest offer, we require initial information regarding the systems and applications to be examined, allowing us to accurately assess the target environment. For web applications, providing test credentials is highly beneficial. Any additional technical details, such as the frameworks and technologies utilized, help us design the ideal testing scenario for you. If you require an infrastructure penetration test, we will need the relevant network addresses in advance. In this case, we will first perform a non-invasive network scan to conduct an initial scoping analysis, which forms the basis for your detailed quote.

binsec GmbH is a German pentest company for professional penetration testing. Get in touch with us for your "DORA/TIBER TLPT" pentest offer - Get your pentest today!

Contact us
Pentest Offer

binsec GmbH: Professional Penetration Testing
according DORA/TIBER TLPT

binsec GmbH conducts technical penetration testing based on established standards, specializing in your DORA/TIBER TLPT security assessment.

Talk directly to the executing experts instead of sales consultants. Better pentesting. No nonsense. As a dedicated penetration testing firm, we do things differently: We do not sell automated vulnerability scans as a true pentest, focusing instead on manual analysis of complex business logic flaws. Looking for a professionally conducted penetration test? Let's discuss your project.

Contact us

Frequently Asked Questions

Of course. Please contact us for a pentest example report.

It is difficult to give an generalized answer to this question, since the toolset used basically depends on the respective test object. Of course, we use tools such as nmap to check IT infrastructures or the Burp Suite Professional in the case of web applications.

However, we believe that publishing a tool list is mere window dressing, as each target system should be tested individually. However, you are welcome to ask us about the tools we used after the pentest.

If you fix the vulnerabilities within a reasonable amount of time, we would be glad to retest at no additional cost.

Hosting critical business applications on a cloud provider such as Amazon AWS, Microsoft Azure, Google Cloud Hetzner Cloud or STACKIT Cloud is becoming increasingly common.

Of course we perform penetration tests for applications hosted in the cloud. This also applies to penetration testing of cloud-based IT infrastructures, provided that the virtual machines are not managed directly by the cloud provider.

There are three approaches based on the information a penetration tester gets before starting: Black-Box-Pentest, Grey-Box-Pentest and White-Box-Pentest. We always recommend going for grey box pentesting. It has the best cost-benefit ratio if you like to get your complete attack surface tested.
Of course, we also offer Red Teaming. Basically Red Teaming is a subcategory of pentesting with a very strong focus on unstructured Ethical Hacking.

We perform penetration tests for almost any IT environment, system, application or network – right down to protocol fuzzing. Only the analysis of hardware chips under a microscope is something we leave to others.

Typical targets of our penetration tests include:

Web Applications and APIs

Mobile Applications

Servers, Platforms and Infrastructure

Containers and DevOps

Identity and Authentication

Pentest Knowledge and Tools

Free pentest tools for your security analysis.

Pentest Tools

Take a look at our wiki page about pentesting.

Pentest WIKI

Straight answers to common pentesting questions.

Pentest FAQ

News about pentesting and the binsec universe.

Pentest News

Company

binsec GmbH
Clemensstraße 6-8
60487 Frankfurt am Main
Germany

Legal notice

Director: Patrick Sauer
Authorised Officer: Florian Zavatzki, Dominik Sauer
Registration: Frankfurt am Main, HRB97277
Turnover Tax Identification No.: DE290966808

© 2026 binsec GmbH. The operative core enterprise of the binsec group. Your specialized penetration testing service provider.

© 2026 All rights reserved by binsec GmbH.