The TIBER framework provides a structured process to perform controlled cyber attacks on the live systems of vital infrastructure based on threat intelligence. The goal is to increase the cyber resilience of organisations and their sector as a whole.
TIBER stands for Threat Intelligence-Based Ethical Red-teaming. It is a threat intelligence led Red Teaming framework that is currently being used throughout Europe in 16 countries in multiple sectors. By using threat intelligence you test the most relevant threats against your organisation or sector and find the most relevant vulnerabilities. These findings are not limited to just technical findings. TIBER tests focus on people, processes and technology. TIBER tests therefore mimic the real tactics, techniques and procedures (TTPs) of actual threat actors. The goal is to learn and improve, it is not a pass or fail test.
What are the fundamental aspects of the TIBER-EU Framework?
- You test the complete attack, end to end, on your Crown Jewels
In order to properly simulate an actual attacker you start from the outside of your organisation and work towards your Crown Jewels. This on the contrary to assume compromise tests where you start inside the network by giving the Red Team an account or laptop. In TIBER the principle is that you follow the complete attack using the ‘In’, ‘Through’ and ‘Out’ phases of the attack. This means In: getting in the organisation, Through: moving through the network towards your goal and Out: executing you objective when you reach your goal. Your Crown Jewels, known in TIBER like critical functions, are the functions performed by the organisation that when impacted by a cyber attack this would have a huge impact on the organisation itself and the rest of the sector or even the society. - This includes people, processes and systems
TIBER is not only a technical test like many pentests. You want to see how your people react to a cyber attack, the proceses they follow and the systems that are used. By combing these you get a complete overview of where the organisation can improve when a real attack happens and not only a list of technical findings. - The test is done on live production systems
In order to see how resilient your systems are against an attack you need to focus on the same systems your attacker would target. The TIBER framework ensures that this is done in a controlled way by having strict guidelines on the providers that can do these tests, the organisation of a white team and experienced test managers from the TIBER Cyber Team next to other measures. - The defensive team is not informed about the test beforehand
You want your organisation to react like they would in an actual attack in order to improve the awareness, skills and processes. It is therefore important that nobody within the organisation has knowledge of the test except for the team in control of the test (the White Team). - For the test you use external TI and RT providers
Having an outside perspective by professionals that perform high end red teaming tests on many different organisations has a huge added value. This doesn’t mean that internal threat intelligence and red teaming tests of mature vital sector organisations do not provide value. They improve the resilience of their organisation on a daily basis, but once in a while you want a fresh outside perspective. - The test is accompanied by a TIBER Cyber Team
In order to ensure that the red team test constitutes a TIBER test the process is accompanied by a TIBER Cyber Team (TCT). This team ensures that the test is done according to the TIBER framework and that the test is performed in a controlled manner by the White Team and the providers. The TCT can also increase the learning experience of the organisation by sharing lessons from the other tests they have seen. - The learning of the test are shared
In order for organisations in a sector to not only learn from their own test, but also all other tests performed in the sector (anonymous) learnings from each test are shared amongst the testing pool of organisations. The tested organisation is the owner of the test results and therefore decides how much information and how this information is shared.

4 thoughts on “What is the TIBER framework?”