A penetration test searches a clearly scoped target system for as many exploitable vulnerabilities as possible within a fixed timeframe; breadth takes precedence over stealth, and the defenders are usually informed. Red teaming is objective- and scenario-driven: it emulates a specific threat actor, operates covertly and primarily measures detection and response capability – the defending blue team is typically not informed in advance. Purple teaming deliberately brings both sides together: testers and defenders work collaboratively to improve detection and response in a targeted way. The three approaches do not compete with each other; they address different maturity levels and different questions.
Red Teaming: TTP-Based Attack Simulation
How targeted simulations modelled on real-world adversaries let you verify whether your organisation actually detects, contains and responds to an attack – not just whether a single vulnerability exists.
3approaches – penetration testing, red and purple teaming address different maturity levels
15tactics in the Enterprise matrix since ATT&CK v19 (April 2026)
3years – TLPT cycle under DORA Art. 26(1), at least every three years
12weeks – minimum duration of the active red team testing phase (Delegated Regulation (EU) 2025/1190)
A penetration test answers the question of which vulnerabilities a defined system contains. Red teaming answers a different one: does your organisation detect and stop a real, targeted attack – across people, processes and technology? Rather than collecting as many individual findings as possible, a red team emulates the tactics, techniques and procedures (TTPs) of real adversaries and works towards predefined objectives. For financial entities, this approach has evolved from a voluntary exercise into a regulatory obligation with the DORA regulation and the updated TIBER-EU framework.
From Voluntary Exercise to Obligation
From TIBER-EU to ATT&CK v19 – tap a milestone for details.
11 Feb 2025
TIBER-EU Aligned with DORA
The ECB's TIBER-EU framework is aligned with DORA and forms the operational foundation for TLPT.
13 Feb 2025
Delegated Regulation (EU) 2025/1190
Specifies scope, methodology and phases of TLPT; the active red team testing phase must last at least twelve weeks.
July 2025
TIBER-DE Version 4.0
Deutsche Bundesbank implements the TIBER-EU framework as TIBER-DE, while BaFin carries out the supervisory tasks.
April 2026
MITRE ATT&CK v19
The former “Defense Evasion” tactic is split into “Stealth” (TA0005) and “Defense Impairment” (TA0112); the Enterprise matrix now comprises 15 tactics.
The Essentials at a Glance
Six topic blocks — tap to expand.
Three Approaches Compared
Penetration testing, red teaming and purple teaming do not compete – they address different maturity levels and different questions. Pick an approach.
- Searches a clearly scoped target system for as many exploitable vulnerabilities as possible within a fixed timeframe.
scoped target systemfixed timeframeexploitable vulnerabilities
- Emulates a specific threat actor and operates covertly.
- Primarily measures detection and response capability.
threat actorcovertblue teamdetection & response
- Deliberately brings both sides together: testers and defenders improve detection and response in a targeted way.
testersdefendersdetectionresponse
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
Verordnung (EU) 2022/2554 (DORA), Art. 26 und 27
Obligation to conduct TLPT at least every three years (Art. 26(1)) on live production systems supporting critical/important functions (Art. 26(2)), plus requirements for testers (Art. 27); applicable since 17 January 2025.
Delegierte Verordnung (EU) 2025/1190 (RTS zu TLPT)
Regulatory technical standard of 13 February 2025 on the scope, methodology and phases of TLPT; among other things, it sets the minimum duration of the active red team testing phase at twelve weeks (Art. 11) and mandates purple teaming in the closure phase (Art. 12).
TIBER-EU Framework (an DORA angeglichene Fassung)
Operational framework for threat intelligence-based ethical red-teaming; aligned with the DORA RTS on 11 February 2025, including the renaming of the White Team to Control Team and mandatory purple teaming.
Implementierung von TIBER-DE, Version 4.0
National implementation of the TIBER-EU framework (July 2025); governs operational support by the Bundesbank's TIBER Cyber Team and the supervisory involvement of BaFin in mandatory TLPT.
MITRE ATT&CK, Version v19 (Enterprise)
Public knowledge base of real-world adversary TTPs; release v19 of 28 April 2026 split the “Defense Evasion” tactic into Stealth (TA0005) and Defense Impairment (TA0112), bringing the Enterprise matrix to 15 tactics.
Related Services
Want to Determine Where Red Teaming Fits Your Organisation?
Whether a classic penetration test, threat-led red teaming under TIBER/DORA or a purple teaming follow-up makes the most sense depends on your maturity level and your regulatory obligations. In an initial consultation, we assess this together.