Source: OJ L, 2025/1190, 18.6.2025

Current language: EN

Article 10 Testing phase: threat intelligence


Summary What does Article 10 of the RTS on threat-led penetration testing say?

Article 10 governs the threat intelligence phase of a TLPT, which kicks off once the scope specification document has been approved under Article 9.

It places the threat intelligence provider at the centre of this phase, requiring them to research and analyse the threat landscape relevant to the financial entity, identify cyber threats and vulnerabilities, and translate this into concrete, realistic attack scenarios.

Those scenarios are then presented to the control team, testers, and test managers, before the control team lead selects at least three to form the basis of the actual test.

The article closes with the completed threat intelligence report being submitted by the control team for TLPT authority approval, which acts as the gateway into the next testing phase.

Important points:

  • The threat intelligence provider is required to analyse both generic and entity-specific threats, identify vulnerabilities, and propose distinct scenarios targeting each critical or important function in scope.
  • Select at least three scenarios to conduct the TLPT, with no more than one permitted to be non-threat-led.
  • In pooled or joint TLPTs involving ICT third-party or intra-group service providers, at least one scenario must cover the service provider's underlying ICT systems supporting the financial entities' critical or important functions.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. Following the approval of the scope specification document by the TLPT authority, the threat intelligence provider shall analyse generic and sector-specific threat intelligence relevant for the financial entity. Where a generic threat landscape has been provided by the TLPT authority for the financial sector of a Member State, the threat intelligence provider may use that landscape as a baseline for the national threat landscape. The threat intelligence provider shall identify cyber threats and existing or potential vulnerabilities concerning the financial entity. Furthermore, the threat intelligence provider shall gather information on, and analyse concrete, actionable, and contextualised target and threat intelligence concerning the financial entity, including through consulting the control team and the test managers.

    1. The threat intelligence provider shall present the relevant threats and targeted threat intelligence, and propose requisite scenarios to the control team, testers and test managers. The proposed scenarios shall differ with reference to the identified threat actors and associated tactics, techniques and procedures and shall target each critical or important function in the scope of the TLPT.

    1. The control team lead shall select at least three scenarios to conduct the TLPT on the basis of all of the following elements:

      1. the recommendation by the threat intelligence provider and the threat-led nature of each scenario;

      2. the input provided by the test managers;

      3. the feasibility of the proposed scenarios for execution, based on the expert judgement of the testers;

      4. the size, complexity and overall risk profile of the financial entity and the nature, scale, and complexity of its services, activities, and operations.

    1. No more than one of the selected scenarios may be non-threat-led and may be based on a forward-looking and potentially fictive threat with high predictive, anticipative, opportunistic, or prospective value given the anticipated developments of the threat landscape concerning the financial entity.

    2. For pooled TLPTs, without prejudice to the scenarios targeting directly the critical or important functions of the financial entities involved in the testing, at least one scenario shall include the ICT third-party services provider’s relevant underlying ICT systems, processes, and technologies supporting the critical or important functions of the financial entities in scope.

    3. Where the test is a joint TLPT involving an ICT intra-group service provider, without prejudice to the scenarios targeting directly the critical or important functions of the financial entities involved in the test, at least one scenario shall include the ICT intragroup services provider’s relevant underlying ICT systems, processes and technologies supporting the critical or important functions of the financial entities in scope.

    1. The threat intelligence provider shall provide the targeted threat intelligence report to the control team, including the scenarios selected in accordance with paragraphs 3 and 4. The threat intelligence report shall contain the information set out in Annex III.

    1. The control team shall submit the targeted threat intelligence report to the test manager for approval. Where the targeted threat intelligence report is complete and ensures the performance of an effective TLPT, the TLPT authority shall approve the targeted threat intelligence report and inform the control team lead thereof.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod