Is Threat-Led Penetration Testing the New Penetration Testing?
Deloitte clarifies what TLPT is, how it differs from traditional penetration testing, and its role in EU DORA and other regulatory frameworks.

Introduction
Threat-Led Penetration Testing (TLPT) is one of the most demanding — and most misunderstood — requirements introduced by the European Union's Digital Operational Resilience Act (EU DORA). The name is the source of much of the confusion. It contains the words "penetration testing," yet in practice TLPT has very little in common with a conventional penetration test. It is broader in scope, longer in duration, run against live systems, and driven from start to finish by threat intelligence.
This article sets out to clear up that confusion. It explains what TLPT actually is, how it differs from traditional penetration testing, why the two are complementary rather than interchangeable, and how TLPT relates to the well-established Threat Intelligence-Based Ethical Red Teaming (TIBER) framework that underpins it.
What Is TLPT?
EU DORA defines TLPT as:
"a framework that mimics the tactics, techniques and procedures of real-life threat actors perceived as posing a genuine cyber threat, that delivers a controlled, bespoke, intelligence-led (red team) test of the financial entity's critical live production systems."
The operative phrase is "intelligence-led (red team) test." Everything else in the definition flows from it. TLPT is, first and foremost, a form of red teaming — a controlled simulation of a real-world attack designed to test how well an organisation can prevent, detect, and respond to a determined adversary. It is not a checklist exercise, and it is not about producing a long inventory of technical weaknesses. It is about answering a harder question: if a capable, motivated attacker came after us today, would we see them, could we stop them, and how badly could they hurt us?
The term did not originate with DORA. It was used as early as 2018 by the G-7 in their publication, G-7 Fundamental Elements for Threat-Led Penetration Testing. The G-7's stated aim was to "provide entities with a guide for the assessment of their resilience against malicious cyber incidents through simulation." Crucially, that same publication acknowledged that TLPT "may be referred to as Ethical Red Teaming." In other words, the industry has understood for years what the name obscures: TLPT is a threat-intelligence-driven flavour of red teaming, not a bigger penetration test.
How TLPT Differs From Regular Penetration Testing
The differences are not cosmetic. They touch almost every dimension of how the assessment is designed and run. The table below summarises the key distinctions.
Scope
A penetration test is deliberately narrow: you point it at a defined target and probe it deeply. TLPT is the opposite. It is an organisation-wide assessment that is not confined to a single system or even to the cyber dimension alone. The human dimension (can staff be socially engineered?) and the physical dimension (can an attacker walk into a building or plant a device?) are legitimate parts of the exercise, because real threat actors exploit whichever path is weakest.
Secrecy
In most penetration tests the defenders know a test is happening. In TLPT they do not. The blue team — the security operations centre and incident responders — is intentionally kept unaware. Only a very small, trusted control group inside the organisation knows the test is live. This secrecy is essential: it is the only way to measure how detection and response actually perform when the alarm is genuine rather than expected.
Duration
Real intrusions are patient. Attackers may spend weeks on reconnaissance, gaining a foothold, moving laterally, and escalating privileges. To simulate that faithfully, TLPT needs time. Under DORA the active testing phase must run for a minimum of twelve weeks, far longer than a typical penetration test measured in days.
Environment
Perhaps the most consequential difference is that TLPT is performed on live production systems, not on a sanitised test environment. This is what makes the results credible — and what demands rigorous risk control, close coordination with the control team, and carefully agreed rules of engagement so the business is never actually harmed.
Objective
A penetration test aims to be exhaustive: find every weakness in the target. TLPT is objective-oriented. The goal is to reach defined business-critical outcomes — the "flags," such as executing a fraudulent payment, accessing a crown-jewel database, or disrupting a critical service — using at least one realistic attack path. One credible path to the objective is worth more than a hundred low-severity findings, because it proves what an adversary could actually achieve.
Threat Intelligence
TLPT begins not with tools but with intelligence. A tailored threat intelligence report profiles the specific threat actors likely to target the entity, their motivations, and their tactics, techniques and procedures (TTPs). From that report, credible attack scenarios are derived. The red team then plays those scenarios out, emulating adversaries the organisation genuinely faces rather than a generic hacker.
Purple Teaming
Finally, TLPT does not end when the red team stops. A purple-teaming exercise is conducted afterwards, bringing the red team and blue team together to walk through the attack step by step. This is where the real learning happens: the defenders see exactly what was done, where they missed it, and how to close the gaps.
Complementary, Not Competing
Two tools, two jobs
Penetration testing and TLPT are distinct, complementary assessment types. Penetration testing gives you deep, technical assurance about specific systems — the right tool when you want to know whether a particular application or network is hardened. TLPT gives you a realistic, end-to-end simulation that challenges the whole organisation's preparedness: people, process, and technology together. You need both. One tells you if a door is locked; the other tells you whether an intruder could get from the street to the vault without anyone noticing.
Regulatory Context
TLPT is not a European invention in isolation. It builds on and aligns with the TIBER-EU framework, whose methodology — covering scoping, threat intelligence, red teaming, and remediation — is effectively made binding for designated entities under DORA. Similar national and regional frameworks exist around the world and follow the same philosophy:
CBEST — United Kingdom TIBER-EU — European Union AASE — Singapore iCAST — Hong Kong
Across all of them, threat-led testing has become the standard way to assess organisational resilience to cyber-attacks in a realistic yet risk-controlled manner. DORA simply makes it a legal obligation for a defined population of financial entities in the EU.
Conclusion
It would be a mistake to view TLPT purely as a compliance box to tick. Beyond satisfying the regulator, TLPT delivers outcomes that matter directly to executive management: an evidence-based view of real risk exposure, a clear picture of gaps in detection and prevention controls, and hard proof of whether processes are resilient and people are prepared when a genuine incident unfolds.
Done well, threat-led testing turns an abstract worry — "are we secure?" — into concrete, demonstrated answers. It combines threat intelligence expertise, deep regulatory knowledge, and proven red-teaming capability to help organisations understand, honestly and realistically, how ready they are for a serious cyber-attack. That readiness, not the certificate, is the real deliverable.