Cybersecurity Glossary

What is TIBER-EU?

TIBER-EU stands for Threat Intelligence-Based Ethical Red Teaming. The framework guides controlled tests in which threat intelligence and a red team emulate realistic attackers against the live environment of a financial entity. The focus is resilience of critical functions, not a simple vulnerability count.

Under DORA, designated financial entities may be required to perform threat-led penetration testing. The applicable regulatory technical standards and national implementation determine how a particular test is governed; TIBER-EU provides the established European framework and terminology.

What distinguishes a TIBER test?

  • - A threat-intelligence phase creates scenarios relevant to the entity.
  • - Independent providers and a control team manage a tightly protected test.
  • - The red team tests people, processes and technology in live critical functions.
  • - Purple teaming and remediation turn findings into verified improvements.

How does a TIBER-EU test proceed?

PhaseWorkOutcome
Preparation and scopeDefine the control team, critical functions, systems, providers, risk controls and secure communication.Approved project and scope framework.
Threat intelligenceAnalyse relevant actors, motives, attack paths and exposed information for the entity.Threat scenarios for red-team planning.
Red-team testExecute agreed scenarios against people, processes and live technology in a controlled manner.Attack narrative and objectives reached.
Purple teamingReview attacks and telemetry together and immediately verify improvements.Verified detection and response improvements.
ClosureComplete reports, remediation plan, test summary and any required attestation.Owned remediation and documented learning.

What changed through DORA?

The updated TIBER-EU framework published in 2025 is aligned with the technical standards for DORA TLPT. It incorporates regulatory deliverables and timelines, uses Control Team instead of White Team and makes purple teaming mandatory in the relevant process. It remains more than a compliance checklist and is designed to improve real protection, detection and response under controlled conditions.

Why is risk management central?

Testing touches live critical functions. Escalation, stop conditions, permitted techniques, data handling, providers and emergency contacts are agreed in advance. Only a small group knows about the test, while the Control Team must be able to intervene at any time. A conventional penetration test without threat intelligence and this governance framework is not automatically a TIBER-EU test.

Thank you for your feedback! We will review it and optimize this content.

Do you have feedback on TIBER-EU? Tell us!