The reason it carries this much weight ties directly to DORA. Under Articles 26 and 27, financial entities the ECB designates as significant, generally banks holding total assets above €30 billion under the ECB/SSM threshold, must run Threat-Led Penetration Testing at least once every three years. TIBER EU is the methodology the ECB built to make that testing consistent, defensible, and mutually recognized across borders. This guide breaks down what TIBER EU actually involves, who’s on the hook for it, how a test runs from start to finish, and how it connects to TIBER-DE, Germany’s national implementation of the framework.
What TIBER EU Actually Is?
TIBER EU stands for Threat Intelligence-Based Ethical Red Teaming, and TIBER Threat Intelligence sits at the center of the whole approach: every test is built around bespoke intelligence on adversaries who would realistically target that specific entity, not a generic threat list. It’s a framework, not a product or a single test type, developed jointly by the ECB and national central banks, approved by the ECB’s Governing Council, and published back in May 2018. It got a significant update in 2024 to bring it fully in line with DORA’s Regulatory Technical Standards on Threat-Led Penetration Testing.
Here’s the part that trips people up: a TIBER EU test doesn’t end with a score. There’s no pass or fail. The whole exercise is designed to surface how an organization’s people, processes, and technology actually hold up against a simulated version of a real attacker, using real threat intelligence about who would plausibly target that specific entity. What comes out the other end is a picture of where the resilience gaps are, not a certificate.
Source: https://qualysec.com/tiber- ...