Resilience testing and threat-led penetration testing
DORA requires financial entities to implement a comprehensive testing program to identify vulnerabilities and ensure the resilience of their ICT systems. While basic testing is required for all critical systems, certain significant entities must undergo advanced Threat-Led Penetration Testing (TLPT) every three years to simulate real-world cyberattacks on critical functions.
What it means
The intent is to shift from passive security checklists to active verification. Organizations must prove that their ICT tools and systems can withstand, respond to, and recover from operational disruptions. This ensures that resilience is a demonstrated capability rather than a theoretical design.
In practice, this creates two tiers of testing. Basic resilience testing involves routine checks—such as vulnerability scans and network assessments—across the ICT environment. TLPT is a more rigorous, scenario-based exercise designed to mimic the tactics, techniques, and procedures (TTPs) of actual threat actors targeting critical business functions.
The scope extends beyond internal infrastructure. Because financial entities rely heavily on third parties, resilience testing must account for the dependencies and interfaces between the entity and its ICT service providers.
How to meet it
- Establish a formal ICT Resilience Testing Framework that defines the types of tests, frequency, and the systems in scope.
- Conduct regular basic testing (e.g., vulnerability scanning, network security assessments) on all critical ICT systems.
- Identify "critical or important functions" to serve as the primary targets for advanced resilience exercises.
- For those required to perform TLPT, engage certified external testers to execute scenario-based attacks based on current threat intelligence.
- Develop and document a remediation plan for every vulnerability or weakness identified during testing.
- Ensure that tests are performed in environments that closely mirror production without compromising the stability of live services.
Evidence an auditor asks for
- The ICT Resilience Testing Policy/Framework documenting the strategy, schedule, and governance.
- Detailed reports from basic resilience tests (e.g., vulnerability scan results and penetration test summaries).
- For TLPT: Documentation of the threat intelligence used to build scenarios, the testing methodology, and the final report.
- A remediation tracker showing identified gaps, assigned owners, deadlines, and evidence of closure.
- Management sign-off on the test scopes and the subsequent remediation plans.
Common pitfalls
- Confusing standard penetration testing with TLPT; auditors look for specific threat-led scenarios and TTPs rather than generic vulnerability probes.
- Failing to include critical third-party ICT providers in the testing scope or failing to coordinate tests with them.
- Treating testing as a "point-in-time" compliance exercise instead of integrating results into a continuous risk management cycle.