← All cheat sheets

TIBER-EU

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

TIBER-EU (Threat Intelligence-Based Ethical Red-teaming) is the ECB
framework for intelligence-led red team tests of financial entities'
critical live production systems. Published May 2018, updated 2024 to
align with the DORA TLPT RTS. This sheet covers the roles, phases,
and deliverables - the execution detail behind DORA Article 26.

KEY FACTS#

# Origin:    ECB + EU national central banks, published May 2018
# Update:    2024, aligned to DORA TLPT RTS (EU) 2025/1190
# Adoption:  20+ EU/EEA jurisdictions; Switzerland as TIBER-CH
# Target:    critical/important functions (CIFs) on LIVE production
# Outcome:   NOT pass/fail - it measures detect/respond capability
# Relation:  TLPT (DORA-mandated) uses TIBER-EU as its framework

ROLES / TEAMS#

# WT  White Team   - small internal group that knows about the test,
#                    manages it from inside the entity
# CT  Control Team - manages the end-to-end test (subset of/with WT)
# BT  Blue Team    - the entity's defenders; must NOT know (tests
#                    real detection & response)
# RT  Red Team     - external testers executing the attack (RTT)
# TI  TI Provider  - external threat intelligence provider (TIP)
# TCT TIBER Cyber Team - the authority's team overseeing the test
# Strict separation between TI provider and Red Team provider
# (some jurisdictions allow one firm with internal separation)

THREE PHASES#

# 1. PREPARATION
#    - engagement/scoping, launch meeting, procurement of TI + RT
#    - risk management (test is on live systems)
#    - define critical functions and target flags
# 2. TESTING
#    - Targeted Threat Intelligence (TTI) report by the TI provider
#    - Red Team develops the Red Team Test Plan (RTTP)
#    - active red teaming: recon -> intrusion -> lateral -> objectives
# 3. CLOSURE
#    - red team report + blue team report
#    - replay / purple teaming (walk through TTPs with BT)
#    - remediation plan + attestation to the authority

KEY DELIVERABLES#

# - Scope Specification Document
# - Targeted Threat Intelligence (TTI) Report
# - Red Team Test Plan (RTTP)
# - Red Team Test Report
# - Blue Team Report
# - Remediation Plan
# - Test Summary Report / Attestation to the competent authority

THREAT INTELLIGENCE INPUT#

# TI provider builds bespoke, entity-specific threat scenarios from
# generic + sector + targeted intelligence, mapping real adversary
# TTPs (aligned to ATT&CK). The RT turns TTI scenarios into concrete
# end-to-end attack paths against the scoped CIFs.

DORA / TLPT ALIGNMENT#

# TLPT (DORA Art.26, RTS (EU) 2025/1190):
#   - mandatory for entities identified by competent authorities
#   - at least every 3 years
#   - on live production systems supporting CIFs
#   - tester qualification + independence requirements
#   - regulator involvement + reporting
# TIBER-EU is the recognised framework to satisfy these

TYPICAL TIMELINE & COST#

# Duration: ~ 9-14 months end-to-end (prep-heavy)
# Testing (active red team) window: often 10-12 weeks
# Indicative budget: EUR ~150k-500k depending on scope/entity
# (figures are industry estimates, not regulatory values)

RISK MANAGEMENT (LIVE TESTING)#

# - conduct a risk assessment before the test
# - agree "leg-ups" to keep the test on-track without full compromise
# - define stop/greenlight procedures and legal authorisation
# - a backup Test Team Manager (TTM) is strongly advised

EXAMPLES#

# Identify the entity's critical/important functions to scope flags
# Confirm TI provider and RT provider independence arrangements
# Verify the Blue Team is NOT informed (genuine detection test)
# Plan the purple-team replay + remediation tracking in Closure

NOTES#

- TIBER is deliberately NOT a prescriptive method - it is an
  overarching framework complemented by guidance docs (procurement,
  control team, purple teaming, white team)
- "Not pass/fail": the value is measured detection/response uplift,
  not a vulnerability count
- Separation of TI and RT roles is a core control - watch for it in
  procurement
- Distinct from standard pen testing/red teaming: intelligence-led,
  scoped to CIFs, authority-overseen
- For LU FS clients this pairs with DORA-RTS-ITS.txt (Art.26) and the
  CSSF supervisory context (CSSF-CIRCULARS.txt)
- Practitioner reference, not legal advice