TIBER-EU

Also known as:TIBER-EU

TIBER-EU (Threat Intelligence-Based Ethical Red Teaming) is a European framework developed by the European Central Bank (ECB) for conducting controlled, threat-led red teamRed TeamingA realistic, adversary-emulating attack simulation that tests how well an organization detects and responds to a real attacker. exercises against financial institutions. Published in 2018, the framework provides a standardized approach for testing the cyber resilience of critical financial entities by simulating the tactics, techniques, and procedures of real threat actors — based on bespoke threat intelligenceCyber Threat IntelligenceProcessed information regarding threat actors, tactics, indicators, and risks. — against live production systems.

Unlike conventional penetration testingPenetration TestingAuthorized, methodical testing of a system for exploitable weaknesses, to find them before real attackers do., TIBER-EU tests are intelligence-led, target production environments, and aim to assess not only technical vulnerabilities but also the detection and response capabilities of the institution under test. The framework has been adopted across the European Union and serves as the basis for national implementations such as TIBER-DETIBER-DEGermany's national implementation of the TIBER-EU framework for threat intelligence-based red teaming, overseen by Deutsche Bundesbank. (Germany), TIBER-NL (Netherlands), TIBER-BE (Belgium), and others.

Background and objectives

The ECB developed TIBER-EU in response to the growing sophistication of cyber threats targeting the European financial sector. Traditional compliance-driven security assessments were deemed insufficient to test actual resilience against advanced persistent threats. TIBER-EU aims to provide a consistent framework across the EU that allows authorities and institutions to assess and improve cyber resilience through realistic adversary simulation, fosters cross-border harmonization of threat-led testing practices, creates a controlled environment where real attack scenarios are executed against production systems without causing actual harm, and generates actionable insights that drive concrete security improvements.

The three phases

Preparation Phase — the target institution notifies its competent authority (national central bank or financial supervisor) of its intention to conduct a TIBER-EU test. The institution establishes a White Team — a small, strictly confidential group of senior staff who manage the test internally. The scope is defined in collaboration with the authority, identifying critical functions and systems. A Threat Intelligence (TI) provider and a Red Team (RT) provider are procured, each meeting the framework’s provider requirements. Strict confidentiality is maintained: the institution’s Blue Team (defensive security staff) must not be aware that a test is taking place.

Testing Phase — this phase has two sub-phases. First, the TI provider conducts a Targeted Threat Intelligence (TTI) report analyzing the specific threat landscape of the institution, identifying the most relevant threat actors, and developing realistic attack scenarios based on current intelligence. The RT provider then uses the TTI report to design and execute controlled attacks against the institution’s live production systems over a period typically spanning 10 to 12 weeks. The Red Team attempts to achieve predefined objectives (flags) that represent realistic attacker goals — such as accessing payment systems, exfiltrating customer data, or disrupting critical services. Throughout execution, the White Team maintains oversight and can intervene if operational risk thresholds are breached.

Closure Phase — the Red Team produces a detailed Red Team Test Report documenting the attacks executed, objectives achieved, and vulnerabilities exploited. The Blue Team is informed of the test and produces a Blue Team Report describing which activities they detected and how they responded. A joint replay workshop brings together Red Team, Blue Team, White Team, and the TI provider to review the full test timeline. The institution creates a remediation plan addressing identified weaknesses. The competent authority reviews the reports and remediation plan. A test summary is shared with relevant authorities to support sector-wide insights without disclosing sensitive details.

Key stakeholders

Competent authority — the national central bank or financial supervisor overseeing the test. They set expectations, review results, and may mandate tests for systemically important institutions.

Target institution — the financial entity being tested. It establishes the White Team, procures providers, and is responsible for remediation.

Threat Intelligence provider — an independent firm producing the Targeted Threat Intelligence report that drives the Red Team’s attack scenarios. Must have deep expertise in the financial sector’s threat landscape.

Red Team provider — an independent firm executing the controlled attacks. Must demonstrate advanced offensive capabilities, adhere to strict ethical standards, and operate under the legal framework defined in the Letter of Engagement.

White Team — a small group within the target institution (typically 2 to 4 people) managing the test. They serve as the single point of contact between the institution, providers, and authority. The White Team ensures operational safety without tipping off the Blue Team.

Blue Team — the institution’s defensive security staff. They are not informed of the test and respond to the Red Team’s activities as they would to a real intrusion. Their performance is a key outcome measure.

TIBER-EU and DORA

The Digital Operational Resilience Act (DORA), which entered into force in January 2025, mandates Threat-Led Penetration TestingThreat-Led Penetration TestingPenetration testing driven by threat intelligence, designed around real threat actors and their TTPs targeting a specific sector or organization. (TLPT) for significant financial entities across the EU. DORA explicitly references TIBER-EU as the framework for conducting TLPT. This regulatory mandate transforms TIBER-EU from a voluntary best practice into a compliance requirement for covered entities. Financial institutions designated by their competent authority must conduct TIBER-EU-aligned TLPT at least every three years, covering critical or important functions and using independent TI and RT providers that meet the framework’s qualification criteria.

  • TIBER-DETIBER-DEGermany's national implementation of the TIBER-EU framework for threat intelligence-based red teaming, overseen by Deutsche Bundesbank.: Germany’s national implementation of TIBER-EU, overseen by Deutsche Bundesbank.
  • Threat-Led Penetration Testing (TLPT)Threat-Led Penetration TestingPenetration testing driven by threat intelligence, designed around real threat actors and their TTPs targeting a specific sector or organization.: Intelligence-driven penetration testing mandated by DORA for critical financial entities.
  • Red TeamingRed TeamingA realistic, adversary-emulating attack simulation that tests how well an organization detects and responds to a real attacker.: Adversary simulation to test an organization’s detection and response capabilities.
  • Cyber Threat Intelligence (CTI)Cyber Threat IntelligenceProcessed information regarding threat actors, tactics, indicators, and risks.: The collection and analysis of information about current and emerging cyber threats.
  • Penetration TestingPenetration TestingAuthorized, methodical testing of a system for exploitable weaknesses, to find them before real attackers do.: Authorized security testing to identify exploitable vulnerabilities.
  • Threat-Informed DefenseThreat-Informed DefenseAlignment of controls and tests with specific threats and attack techniques.: A security approach that uses knowledge of real adversary behavior to prioritize defenses.