TIBER-EU framework
TIBER-EU (Threat Intelligence-Based Ethical Red-Teaming) is a European framework for testing cybersecurity. It helps authorities, companies, and cybersecurity experts work together to improve a company's cyber resilience by conducting controlled cyberattacks.
Improving cyber resilience with test attacks
TIBER tests mimic the methods of real attackers and are specifically designed to test key functions of a company, such as its people, processes, and technologies. Companies cannot pass or fail a TIBER test. Instead, the test is intended to reveal the strengths and weaknesses of the cyber resilience measures put in place by the tested entity, with a focus on the learning effect of the test, and to enable the entity to reach a higher level of cyber maturity. Detailed information about TIBER-EU is available on the ECB's webpage.
TIBER-EU implementation by the AFM and its objectives
The AFM uses TIBER-EU for both voluntary tests and mandatory tests according to European legislation DORA. The AFM offers the TIBER-EU program to companies under its supervision.
AFM's goals with TIBER-EU:
- Strengthen the cyber resilience of the Dutch financial sector by conducting high-quality tests.
- Ensure a consistent approach to TIBER and TLPT (Threat Led Penetration Testing) by consistently applying the TIBER-EU framework.
- Promote collaboration between financial institutions and supervisory authorities.
- Create a resilience testing community to share knowledge and enhance the learning experience for financial institutions.
- DORA TLPT: For financial institutions under its supervision that meet the criteria of DORA. From 2025, this test is mandatory for certain institutions. These tests are conducted according to the TIBER-EU framework.
- Voluntary TIBER tests: For financial institutions under its supervision and, in special cases, for other relevant parties in the financial sector. These tests are also based on the TIBER-EU framework and can be part of an institution's digital resilience testing program, as required by DORA.
Key documents
- TIBER-EU Framework
- TIBER-EU Guidance for Service Provider Procurement
- TIBER-EU Control Team Guidance
- TIBER-EU Purple Teaming Guidance
- TIBER-EU Initiation Documents Guidance
- TIBER-EU Scope Specification Document Guidance
- TIBER-EU Targeted Threat Intelligence Report Guidance
- TIBER-EU Red Team Test Plan Guidance
- TIBER-EU Red Team Test Report Guidance
- TIBER-EU Blue Team Test Report Guidance
- TIBER-EU Test Summary Report Guidance
- TIBER-EU Remediation Plan Guidance
- TIBER-EU QA checklist format