ECB hardwires DORA’s threat-led pentesting via TIBER-EU network

The European Central Bank is tightening the link between cyber realism and regulatory oversight with the formalisation of its TIBER-EU network as the supervisory backbone for threat-led penetration testing under Europe’s digital resilience regime.

In November of last year, the ECB’s Governing Council raised no objection to a proposal from the Supervisory Board to publish the TIBER-EU SSM Implementation Guide, a move that embeds the Threat Intelligence-Based Ethical Red Teaming framework into the mandatory testing regime for significant institutions.

The guide adopts TIBER-EU as the operational model for threat-led penetration testing required under the Digital Operational Resilience Act (DORA), marking a decisive step in how cyber resilience is assessed across Europe’s banking system.

Now 2026 has started, banks and financial services firms across the European Union are urged to adopt the guidelines and align their strategies with the ECB’s approach as .

For QA leaders and software testing teams inside the finance space, the development underscores a shift away from isolated penetration tests and technical checklists towards intelligence-driven, end-to-end resilience testing that spans applications, infrastructure, people and response processes.

Operational weaknesses

TIBER-EU does not aim to deliver a pass or fail outcome. Instead, it is designed to expose how systems and teams behave under conditions that closely resemble real attacks, providing regulators and institutions with a detailed picture of operational weaknesses and recovery capability.

At the heart of the framework is a structured but realistic testing model. Each exercise is built on bespoke threat intelligence and tailored to the critical functions of the institution being tested.

Simulated attacks mirror the tactics, techniques and procedures used by real adversaries, targeting not just technology but also decision-making, escalation paths and coordination between teams.

From a QA and testing perspective, this elevates security testing from a periodic activity into a board-relevant assessment of whether systems are genuinely resilient in production.

The framework relies on a defined network of participants, coordinated through national and European supervisory authorities.

Blue teams inside the institution continue their normal operations without knowing a test is under way, allowing supervisors to observe genuine detection and response behaviour.

External threat intelligence providers and red-team testers conduct reconnaissance and execute controlled attacks, while a small internal control team manages the exercise in cooperation with the relevant TIBER cyber team at supervisory level.

Relevance under DORA

The ECB’s role is to ensure that tests meet the framework’s requirements and can be mutually recognised across jurisdictions.

This emphasis on harmonisation is central to TIBER-EU’s relevance under DORA. The regulation requires certain financial entities to undergo advanced threat-led penetration testing, particularly those deemed systemically important. B

By aligning TIBER-EU with the Regulatory Technical Standards on threat-led penetration testing, the ECB has positioned the framework as a practical route to meeting those obligations while reducing duplication for cross-border firms subject to multiple supervisors.

For software testing teams, this has concrete implications. TIBER-EU tests cut across traditional boundaries between application testing, infrastructure resilience, incident response and recovery validation.

Findings are formalised through reports, remediation plans and attestations, creating a direct feedback loop into development pipelines, test strategies and operational controls.

In effect, QA functions are increasingly drawn into regulatory-grade resilience testing, where evidence of testing depth, coverage and remediation progress matters as much as vulnerability discovery.

Pan-European network

Since its original publication in 2018, TIBER-EU has evolved into a pan-European network. Developed jointly by the ECB and national central banks, it was updated in 2024 to align fully with DORA.

So far, the framework has been adopted across much of the EU and beyond, including major financial centres such as Germany, France, Italy, the Netherlands and Spain. It is also applied directly by ECB Banking Supervision, with other jurisdictions in the process of adoption.

National TIBER-EU cyber teams conduct tests within their own markets, while internationally active banks may participate in coordinated exercises involving multiple authorities.

Supporting this structure is the TIBER-EU Knowledge Centre, hosted by the ECB, where supervisory teams share experiences and coordinate implementation to maintain consistency across Europe.

As cyber risk continues to move higher on supervisory agendas, the formalisation of the TIBER-EU network signals that advanced testing is no longer a niche security exercise.

For QA and software testing teams in regulated financial institutions, threat intelligence-led testing is increasingly becoming a core component of compliance, resilience and credibility in the eyes of supervisors.


COMING IN 2026



Why not become a QA Financial subscriber?

It’s entirely FREE

* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *

REGISTER HERE TODAY


REGULATION & COMPLIANCE

Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.


READ MORE


WATCH NOW


QA FINANCIAL PODCASTS

CLICK HERE TO LISTEN TO OUR EXCLUSIVE CONVERSATIONS