TIBER-EU updated – What are the changes and how does it relate to DORA TLPT?

The European Central Bank has published the updated version of the TIBER-EU framework. This is now completely aligned to DORA Threat Led Penetration Testing (TLPT) and it has also been revised to be more structured. In this blogpost I will highlight the main differences with the former version and see how it relates to DORA TLPT.

Of course the new version reflects the changes necessary to align to the DORA TLPT regulations. These include:

  • The document explicitly states that following the TIBER framework fulfils the Threat Led Penetration Testing requirements under DORA;
  • The use of internal red team testers is allowed (under conditions) as I described in my previous blog post1;
  • In order to comply with DORA TLPT there is a more strict role for the Test Manager of the Test Cyber Team;
  • Deadlines for meeting and deliverables have been adapted according to DORA TLPT;
  • Frequency of testing is set to once every three years, but this can been changed by the respective TLPT authority;
  • Purple teaming is mandatory, although in practice every TIBER implementation already required it;
  • Some terminology like White team to Control team and Red Team to Red Team Testers have been changed.

But there are bigger changes in the framework that I will highlight below.

Scope change to Critical Important Functions

One bigger change related to DORA TLPT is that the term Critical Function (CF) has been replaced by Critical and Important Function (CIFs). Therefore the definition of it also had to be changed. CIFs is now defined as:

“a function, the disruption of which would materially impair the financial performance
of a financial entity, or the soundness or continuity of its services and activities, or
the discontinued, defective or failed performance of that function would materially
impair the continuing compliance of a financial entity with the conditions and
obligations of its authorisation, or with its other obligations under applicable financial
services law”

This can cause a larger scope and therefore the framework now indicates that a maximum of 10 CIFs per tested entity is adequate.

Multi party testing

In the original TIBER framework TCTs could already cooperate if an entity was present in multiple jurisdictions, but it generally focussed on one entity per test. The updated framework gives the option for multi party testing as introduced with DORA TLPT. These multi party tests reduce redundancy and ensure more worthwhile tests if done correctly. If entities for example rely on the same IT provider, cloud service of payment network they can conduct joint tests to including (part of) their supply chain.

The framework does not give a lot of guidance which is logical as the different options mentioned in DORA TLPT have not all been tested in practice yet. I will dedicate a specific blogpost to multi party testing as it is quite complicated.

Threat Intelligence

Threat Intelligence is a critical component in a threat led red team test. In the original TIBER version the scenarios had to be threat intelligence based. DORA on the other hand had one major point that I disagreed with as mentioned in a previous post. DORA TLPT under article 9.2 requires scenarios to target every CIF:

The proposed scenarios shall differ with reference to the identified threat actors and associated tactics, techniques and procedures and shall target each and every critical or important functions in the scope of the TLPT.

This contradicts the threat led approach and would make TLPT more of a generic pentest than a threat led red teaming test. As TIBER-EU wants to align with DORA TLPT to ensure compatibility this is also addressed in the updated TIBER framework. This is however done in an elegant way by requiring a longlist and shortlist.

Regarding the longlist the TIBER-EU framework phrases it in 7.1 as:

Based on this information the TIP will develop a broad set of high-level scenarios, which are tailored to the tested entity and from which test scenarios will be selected during the scenario selection meeting. The draft high-level scenarios should vary regarding the included threat actors and TTPs – and together cover all CIFs in scope.

If we look at the specific threat intelligence guidance of TIBER-EU (Targeted Threat Intelligence Report Guidance) it says that not all CIFs in scope need to be targeted in the shortlist:

Although not all CIFs in the scope need to be targeted in the scenarios shortlist, there should be breadth and depth in the CIFs targeted. 

In my opinion this is a smart way to align with DORA TLPT without losing the threat intelligence approach in TIBER-EU.

In the updated TIBER-EU framework the scenarios are also required to hit the different parts of the CIA-triad (Confidentiality, Integrity and Availability) as required by DORA TLPT:

Threat scenarios: at least three end-to-end threat scenarios for the threat profiles identified in accordance with point 4, who exhibit the highest threat severity scores. The threat scenarios shall describe the end-to-end attack path and shall include, at least:

a. one scenario that includes, but is not limited to, compromised service availability;

b. one scenario that includes, but is not limited to, compromised data integrity;

c. one scenario that includes, but is not limited to, compromised information confidentiality;

d. Optionally: a scenario-X.

Next to threat intelligence based scenarios a Scenario X scenario can be added. Threat intelligence led scenarios look back at evidence based threat actor behaviour. Scenario X is a more forward looking scenario. Scenario X was not in the original TIBER-EU framework, but was first added by De Nederlandsche Bank in the TIBER-NL framework. It can have new techniques that are not yet seen to be used by specific threat actors or it could be a scenario that currently doesn’t align with the current geopolitics status quo for example.

Conclusion

Since the original publication of TIBER-EU in 2018 little had been changed about the framework. This major revision does not only align it with DORA TLPT, but also improves the framework as a whole. Because it completely aligns with DORA TLPT, but also gives much more context around the process it allows for more controlled Threat Led Penetration Testing.

If you have questions about TLPT or TIBER as an entity or authority please feel free to reach out!

  1. Internal testers can only be used in 2/3 tests but this is not possible for significant credit institutions ↩︎

Leave a Reply

Your email address will not be published. Required fields are marked *