Book an Appointment

Red Teaming: TTP-Based Attack Simulation

How targeted simulations modelled on real-world adversaries let you verify whether your organisation actually detects, contains and responds to an attack – not just whether a single vulnerability exists.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

3approaches – penetration testing, red and purple teaming address different maturity levels
15tactics in the Enterprise matrix since ATT&CK v19 (April 2026)
3years – TLPT cycle under DORA Art. 26(1), at least every three years
12weeks – minimum duration of the active red team testing phase (Delegated Regulation (EU) 2025/1190)

A penetration test answers the question of which vulnerabilities a defined system contains. Red teaming answers a different one: does your organisation detect and stop a real, targeted attack – across people, processes and technology? Rather than collecting as many individual findings as possible, a red team emulates the tactics, techniques and procedures (TTPs) of real adversaries and works towards predefined objectives. For financial entities, this approach has evolved from a voluntary exercise into a regulatory obligation with the DORA regulation and the updated TIBER-EU framework.

From Voluntary Exercise to Obligation

From TIBER-EU to ATT&CK v19 – tap a milestone for details.

The Essentials at a Glance

Six topic blocks — tap to expand.

Three Approaches Compared

Penetration testing, red teaming and purple teaming do not compete – they address different maturity levels and different questions. Pick an approach.

breadth over stealth
  • Searches a clearly scoped target system for as many exploitable vulnerabilities as possible within a fixed timeframe.
scoped target systemfixed timeframeexploitable vulnerabilities

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Amtsblatt der EU / EUR-Lex · 2022

Verordnung (EU) 2022/2554 (DORA), Art. 26 und 27

Obligation to conduct TLPT at least every three years (Art. 26(1)) on live production systems supporting critical/important functions (Art. 26(2)), plus requirements for testers (Art. 27); applicable since 17 January 2025.

Amtsblatt der EU / EUR-Lex · 2025

Delegierte Verordnung (EU) 2025/1190 (RTS zu TLPT)

Regulatory technical standard of 13 February 2025 on the scope, methodology and phases of TLPT; among other things, it sets the minimum duration of the active red team testing phase at twelve weeks (Art. 11) and mandates purple teaming in the closure phase (Art. 12).

Europäische Zentralbank (EZB) · 2025

TIBER-EU Framework (an DORA angeglichene Fassung)

Operational framework for threat intelligence-based ethical red-teaming; aligned with the DORA RTS on 11 February 2025, including the renaming of the White Team to Control Team and mandatory purple teaming.

Deutsche Bundesbank · 2025

Implementierung von TIBER-DE, Version 4.0

National implementation of the TIBER-EU framework (July 2025); governs operational support by the Bundesbank's TIBER Cyber Team and the supervisory involvement of BaFin in mandatory TLPT.

The MITRE Corporation · 2026

MITRE ATT&CK, Version v19 (Enterprise)

Public knowledge base of real-world adversary TTPs; release v19 of 28 April 2026 split the “Defense Evasion” tactic into Stealth (TA0005) and Defense Impairment (TA0112), bringing the Enterprise matrix to 15 tactics.

Want to Determine Where Red Teaming Fits Your Organisation?

Whether a classic penetration test, threat-led red teaming under TIBER/DORA or a purple teaming follow-up makes the most sense depends on your maturity level and your regulatory obligations. In an initial consultation, we assess this together.