Today the Advanced Red Teaming Framework (ART) was launched. A framework based on TIBER-EU, but because of its modular setup it allows an entity to structure their TLPT/red teaming test to match their goals while still following a structured framework.
ART has been developed by De Nederlandsche Bank together with the Government of the Netherlands and Z-CERT (Healthcare CERT). It has been based on the principles of the TIBER-EU framework but making it modular and thereby removing potentially unnecessary elements.
The main differences are more freedom in the way threat intelligence is acquired, the number of scenarios, adding assumed compromise and adding Gold Teaming
What is different in ART compared to TIBER-EU?

ART follows the same process as the TLPT framework TIBER-EU. But there are some differences that we will highlight phase by phase. There are mandatory elements that are the minimum requirements (above the black line) and these can be upgraded using the optional elements (below the black line).
Threat Intelligence
While ART is still a Threat Intelligence based framework it is more flexibele in the way the entity acquires its threat intelligence. The entity has the following options:
- Use the internal TI team + Generic Threat Landscape (GTL)
This is the minimum requirement where the GTL is used as a basis and the internal TI team of the entity can create their own basic TI report. - Use the internal TI team + an old TI report
The entity is allowed to use an old TI report (maximum 24 months) by having their internal TI team use it as input for their own basic TI report. - Use a RT provider to create a limited TI report
There is also the option to ask the RT provider to create a limited TI report. The team that creates the TI report should be separate from the team that executes the RT test. - Use a TI provider to create a full TI report
The last option is the same as the default in TIBER-EU where a TI provider is procured to create a full TI report for the entity.
In TIBER only the last option is a possibility often combined with the GTL.
Red Teaming
For the Red Teaming phase there a lot of options for the entity.
- 1 Scenario, assumed compromise
The default option for red teaming in ART is assumed compromise and just testing 1 scenario. - 2 scenarios
The number of scenarios can upgraded to two. - End to end simulation
The scenario or scenarios can also be upgraded to be end to end instead of assumed compromise. - Scenario X
Scenario X is an option to add where the scenario is more forward looking; this scenario focusses on new tooling or new threats for the entity.
In TIBER-EU the default is 2 end to end scenarios that have to be based on threat intelligence and some countries add a Scenario X.
Purple Teaming
Purple teaming in pulled into the testing phase and separated into:
- PT fundamentals
- PT Full
The only difference is the amount of time that is spend on Purple Teaming. PT fundamentals is a minimum of 1 day where PT full is more than 1 day.
Other changes
In order to be more inclusive the ART framework speaks about the Control Team instead of the White Team. This is the team consisting of the people leading the test and they are the only ones who know that a test is ongoing.
Current implementations of ART
At the time of launch today three sectors are using ART and only in the Netherlands.
- ART for the financial sector: provided by DNB
- ART for the Government: provided by the Ministry of Ministry of the Interior and Kingdom Relations (ART framework not yet online)
- ZORRO for the Healthcare sector: provided by Z-CERT
The last one is a bit different. The healthcare ART variant is called ZORRO which stands for “ZOrg Redteaming Resilience Exercises”. In this framework, based on ART, Z-CERT not only provides test management, but also the threat intelligence report.
The supporting documentation like the service procurement guidelines, the ART Threat Intelligence guide, the ART Red Team/Purple Team/Gold Team and different templates are not yet online. This blog will be updated as soon as they are available.
For who is ART useful?
Whether you are an authority that is looking for a more modular red teaming framework or an entity that wants to use a framework for their own red teaming tests ART can be of use. It is a lighter framework, but if you want to perform a Threat Led Penetration Test you might end up asking a RT or TI provider to perform the Threat Intelligence assessment. This unless you have a very capable internal TI team. If you then go up to two scenarios you are already approaching the level of a TIBER test.
ART is therefore interesting for:
- Entities that want to do their first TLPT/red team test and want a light test
- Entities that have a limited threat landscape (for example no nation state threat actors)
- Entities that want to plan a lighter test in between TIBER tests
Cyberdefense B.V. has experience with Advanced Red Teaming (ART) since it has assisted two of the current three implementations. We are working with the Dutch Government on TIBER & ART and with Z-CERT on ZORRO for the healthcare sector.
