TIBER-DE

Also known as:TIBER-DE

TIBER-DE is Germany’s national implementation of the TIBER-EUTIBER-EUEuropean framework for threat intelligence-based ethical red teaming of financial institutions. framework for threat intelligence-based ethical red teamingRed TeamingA realistic, adversary-emulating attack simulation that tests how well an organization detects and responds to a real attacker. of financial institutions. Overseen by the Deutsche Bundesbank in collaboration with the Federal Financial Supervisory Authority (BaFin), TIBER-DE provides the operational and regulatory framework for conducting controlled, intelligence-led adversary simulations against German financial entities on their live production systems.

TIBER-DE follows the three-phase structure of TIBER-EU — Preparation, Testing, and Closure — while introducing Germany-specific requirements for provider qualification, regulatory coordination, and reporting that reflect the German regulatory landscape and the particular structure of its financial sector.

Background

Germany adopted TIBER-EU in 2019 with the Deutsche Bundesbank as the national TIBER Cyber Team (TCT), responsible for overseeing all TIBER-DE tests. The adoption was motivated by the need to stress-test the cyber resilience of systemically important German financial institutions — including major banks, payment service providers, central counterparties, and financial market infrastructure operators — using realistic, intelligence-driven attack scenarios rather than compliance-driven checklists.

The Deutsche Bundesbank published the TIBER-DE Implementation Guide, which supplements the TIBER-EU framework with national specifics. BaFin acts as the competent supervisory authority and coordinates with the Bundesbank on test initiation, scoping, and results assessment.

How TIBER-DE differs from TIBER-EU

While TIBER-DE adheres to the core TIBER-EU methodology, several aspects are specific to the German implementation. The Deutsche Bundesbank acts as both the TCT and the primary point of contact for institutions, creating a dual-role structure not present in all national implementations. Provider requirements are more prescriptive: Threat Intelligence and Red Team providers must demonstrate specific qualifications, experience, and independence, and the Bundesbank maintains oversight of provider suitability. Reporting language is German, with final reports and remediation plans expected in German unless otherwise agreed. The scoping process involves close coordination with both the Bundesbank and BaFin, particularly for systemically important institutions where the scope must cover critical functions that could impact financial stability. TIBER-DE tests have increasingly been conducted for institutions that are also subject to ECB direct supervision, requiring coordination between national and European supervisory authorities.

Test process

A TIBER-DE test follows the three TIBER-EU phases with German-specific procedural requirements at each stage.

Preparation — the institution initiates the process by contacting the Deutsche Bundesbank TCT. A preliminary scoping discussion identifies critical functions and systems. The institution procures a TI provider and an RT provider, each meeting the Bundesbank’s qualification criteria. The White Team is established within the institution, typically comprising 2 to 4 senior staff with direct access to executive management. The scope and test parameters are formally agreed with the Bundesbank. The Blue Team — the institution’s security operations — is not informed of the test. A Letter of Engagement provides the legal authorization.

Testing — the TI provider produces a Targeted Threat Intelligence report analyzing the institution’s specific threat landscape, identifying relevant threat actors (state-sponsored groups, financially motivated attackers, hacktivists), and developing attack scenarios grounded in current threat intelligenceCyber Threat IntelligenceProcessed information regarding threat actors, tactics, indicators, and risks.. The RT provider then designs and executes controlled attacks against production systems over approximately 10 to 12 weeks. The Red Team operates covertly, attempting to achieve predefined flags — such as accessing core banking systems, manipulating transaction data, or exfiltrating sensitive information. The White Team maintains oversight, managing operational risk and serving as the communication channel to the Bundesbank. Critical findings or situations that threaten operational stability trigger predefined escalation procedures.

Closure — the Red Team delivers a comprehensive test report. The Blue Team is debriefed and produces its own report on detected activities and response actions. A replay session brings all parties together to walk through the test timeline. The institution develops a remediation plan with specific measures, owners, and timelines. The Bundesbank reviews the reports and remediation plan, and may require specific actions. A summary is shared with BaFin and, where applicable, the ECB.

Regulatory context

TIBER-DE operates within a regulatory framework shaped by multiple authorities. BaFin, as the supervisory authority for banks, insurance companies, and securities firms in Germany, may recommend or require TIBER-DE tests for institutions under its supervision. The Deutsche Bundesbank provides the operational framework and oversight. For institutions under direct ECB supervision, TIBER-DE tests are coordinated with the ECB’s supervisory activities.

The Digital Operational Resilience Act (DORA), effective since January 2025, mandates Threat-Led Penetration TestingThreat-Led Penetration TestingPenetration testing driven by threat intelligence, designed around real threat actors and their TTPs targeting a specific sector or organization. (TLPT) for significant financial entities. DORA references TIBER-EU as the baseline framework, making TIBER-DE the vehicle through which German institutions fulfill their TLPT obligations. This elevates TIBER-DE from a supervisory recommendation to a regulatory requirement for covered entities, with tests mandated at least every three years.

  • TIBER-EUTIBER-EUEuropean framework for threat intelligence-based ethical red teaming of financial institutions.: The European Central Bank’s framework for threat intelligence-based ethical red teaming, on which TIBER-DE is based.
  • Threat-Led Penetration Testing (TLPT)Threat-Led Penetration TestingPenetration testing driven by threat intelligence, designed around real threat actors and their TTPs targeting a specific sector or organization.: Intelligence-driven penetration testing mandated by DORA for critical financial entities.
  • Red TeamingRed TeamingA realistic, adversary-emulating attack simulation that tests how well an organization detects and responds to a real attacker.: Adversary simulation to test an organization’s detection and response capabilities.
  • Cyber Threat Intelligence (CTI)Cyber Threat IntelligenceProcessed information regarding threat actors, tactics, indicators, and risks.: The collection and analysis of information about current and emerging cyber threats.
  • Penetration TestingPenetration TestingAuthorized, methodical testing of a system for exploitable weaknesses, to find them before real attackers do.: Authorized security testing to identify exploitable vulnerabilities.