The entry into force of the Digital Operational Resilience Act has transformed security testing from a recommended best practice into a strict regulatory obligation for the financial sector. Although part of the debate has focused on advanced Red Teaming tests, compliance primarily requires a solid DORA penetration testing program as part of the ordinary audits provided for in Article 25.
Ordinary penetration test vs. TLPT
DORA draws a clear distinction between conventional security tests and advanced tests.
- Ordinary Pentest (Art. 25): Focuses on a detailed assessment of technical and configuration vulnerabilities, often analyzing individual systems or environments in isolation. These tests are part of the general testing program that financial entities must conduct regularly.
- TLPT (Threat-Led Penetration Testing – Art. 26): This is an advanced, intelligence-led test (Red Teaming) that simulates real attack scenarios against the entire entity, involving people, processes, and technologies. TLPT must be performed mandatorily on real, operational production systems.
Use cases for penetration testing under DORA
- Validating security controls after significant infrastructure changes.
- Identifying weaknesses before deploying new systems or software packages.
- Meeting annual testing requirements for financial entities not subject to TLPT, while still ensuring the resilience of ICT systems.
Correct scope: Internet-facing, internal, cloud, app, IAM
The perimeter of a DORA penetration test must be risk-based and include:
- Internet-facing systems: To prevent external intrusions.
- Applications and software: Testing both source code and user interfaces.
- Cloud and third-party infrastructure: Since the DORA perimeter explicitly includes ICT services provided by third parties.
- Identity and Access Management (IAM): Verifying the robustness of authentication policies and privilege escalation risks.
Evidence and remediation
It is not enough to perform the test; DORA requires a rigorous documentation process. After the testing activity, the entity must produce a report that includes:
- A description of the identified shortcomings.
- A root cause analysis of successful attacks.
- A remediation plan indicating how vulnerabilities will be resolved, assigning priorities and clear timelines.
- Evidence of retests to confirm the effectiveness of corrective actions.
When it makes sense to use external testers
DORA allows the use of internal resources (under strict conditions of independence and competence), but the use of external testers is recommended and sometimes mandatory. External testers ensure:
- Total independence and absence of conflicts of interest.
- Specialized skills and market-recognized certifications.
- Compliance for systemic entities: significant credit institutions are required to use external testers for advanced tests and must, in any case, alternate between internal and external testers every three tests.
Typical mistakes in “compliance only” pentests
- Testing only in staging environments: for TLPT, DORA mandates tests on “live” systems, as test environments do not faithfully replicate operational risks.
- Excluding third parties: contracts with ICT providers must include the obligation to cooperate with the financial entity’s security tests.
- Considering the test a “pass/fail”: the ultimate goal must be to increase cyber maturity, not just to obtain a “stamp of approval.”
FAQ
- Are pentests and TLPT equivalent?
- No. A pentest is a technical vulnerability check, while a TLPT is an advanced and comprehensive attack simulation based on threat intelligence.
- Is a pentest always mandatory?
- Yes, for all entities within the scope of DORA, a periodic testing program that includes penetration testing is mandatory.
- Can it be done internally?
- Yes, but with strong limitations. It requires authority approval, the use of external threat intelligence, and, for significant banks, the mandatory use of external testers.
Don’t be caught unprepared: develop your risk-based annual penetration testing plan today to align your critical systems with DORA’s technical requirements.
Want to give your company the highest level of cyber security? ISGroup SRL is here to help with cyber security solutions tailored to your business.
Would you like us to take care of everything for you? Our Virtual CISO and vulnerability management services are a perfect fit for your organization.
Already know what you need? Explore our services:
- Vulnerability Assessment
- Network Penetration Testing
- Web Application Penetration Testing
- Mobile Application Security Testing
- Ethical Hacking
- Training
And much more. Protect your company with the best cybersecurity experts!
