Increase your Cyber Resilience with TIBER
The threat intelligence led red teaming framework implemented in over 20 countries.
THREAT INTELLIGENCE BASED TEST
Test what is most likely to be attacked using threat intelligence.
END TO END TEST
Test the complete attack chain: From outside until your crown jewels.
LIVE SYSTEMS TEST
Test the systems that your attacker would also target, your live systems.
learn more
What is the TIBER framework?
The TIBER framework provides a structured process to perform controlled cyber attacks on the live systems of vital infrastructure based on threat intelligence. The goal is to increase the cyber resilience of organisations and their sector as a whole.


learn more
Why should you implement TIBER-EU?
Implementing TIBER-EU as an authority or supervisor has numerous advantages for your sector. The Digital Operational Resilience Act (DORA) should not be the only reason to adopt this framework to perform Threat Led Penetration Testing (TLPT).
The latest articles
Bringing ART to Dutch education & research — a practical, sector-tailored take on TIBER-style red teaming
Over the past year I was asked by SURF to help set up a red-teaming framework specifically for the Dutch education and […]
The DORA Threat-led Penetration Testing RTS has been published
Today on 18 June 2025, the European Commission officially published the long-awaited Regulatory Technical Standards (RTS) for Threat-Led Penetration Testing (TLPT) under the Digital Operational Resilience Act […]
TIBER-EU updated – What are the changes and how does it relate to DORA TLPT?
The European Central Bank has published the updated version of the TIBER-EU framework. This is now completely aligned to DORA Threat Led […]
A Maturity Model for training TLPT/TIBER test managers
A key distinction between TLPT in DORA and TIBER-EU frameworks and traditional red teaming lies in the role of test managers from […]