DORA penetration testing and threat-led exercises explained
ID: 97ec0658-5b31-553a-82e1-1ec267811aad
STIX ID: report--97ec0658-5b31-553a-82e1-1ec267811aad
Feed Name: Security Boulevard
This document explains DORA’s risk-based, multi-layered ICT security testing expectations for EU financial entities, outlining routine penetration testing across infrastructure, applications, cloud, and APIs, and advanced Threat-Led Penetration Testing (TLPT) for critical functions at least every three years (aligned with frameworks such as TIBER-EU). It emphasizes qualified, independent testers; realistic, intelligence-led scenarios; robust scoping; clear, audit-ready reporting; and evidence-driven remediation tracking. Preparation guidance includes gap analysis, asset and service mapping, structured schedules, and third-party oversight, with advice on selecting experienced providers and a brief overview of how Sentrium can support DORA compliance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
