Best Threat-Led Penetration Testing (TLPT) Companies (2026)

Threat-led penetration testing (TLPT) is regulator-grade red teaming: a controlled, intelligence-led attack against your live production systems, mandated under DORA in the EU and CBEST in the UK for significant financial entities. The providers below have documented TLPT capability through CBEST, TIBER-EU, or equivalent threat-led engagements.

Related: Pen testing for banking and fintech · CBEST-accredited companies · TIBER-EU red teaming companies · Adversary simulation providers

What is threat-led penetration testing (TLPT)?

TLPT is a higher tier of offensive security testing than a conventional red team. It is goal-oriented and driven throughout by bespoke threat intelligence about the specific real-world actors most likely to target your sector, and it is performed against live production systems rather than a test environment. Engagements are deliberately slow-paced to test detection and response over time, and are mapped to frameworks like MITRE ATT&CK.

The demand is overwhelmingly regulatory. Under the EU Digital Operational Resilience Act (DORA), significant financial entities must undergo TLPT, with the methodology based on TIBER-EU (Threat Intelligence-Based Ethical Red Teaming) and its national variants such as TIBER-DE and TIBER-NL. In the UK, CBEST under the Bank of England plays the equivalent role. These schemes pre-vet a small number of qualified threat-intelligence and red-team providers, and engagements are coordinated with the relevant supervisory authority.

A full TLPT programme typically runs 6 to 9 months end to end: a threat-intelligence and scoping phase, 4 to 12 weeks of active red teaming, and a purple-team replay and reporting phase afterwards. When choosing a provider, look for CBEST or TIBER-EU eligibility, evidence of custom offensive tooling and EDR-evasion experience, clean operational tradecraft and attribution restraint, and a methodology rigorous enough to satisfy a regulator's threat-led test plan.

11 providers
London, United Kingdom · Checked Sept 2026

Global Big Four professional services firm delivering CREST, CHECK, and CBEST-accredited penetration testing and red teaming services from London, serving the UK's largest enterprises and regulated organisations.

Accreditations: CREST, CHECK, CBEST, STAR, ISO 27001 +1
Services: Web Application, Network, IoT, Cloud +8
Chester, United Kingdom · Checked Sept 2026

CREST and CHECK-accredited UK penetration testing and managed security provider formed in 2026 from Pentest People, Bulletproof, and Target Defense, with CREST STAR/TLPT-FS capability and the GuardNest vulnerability management platform.

Accreditations: CREST, CHECK, STAR, NCSC Assured, ISO 27001 +1
Services: Web Application, Network, Mobile App, API +8
Southam, United Kingdom · Checked Sept 2026

Elite UK offensive security consultancy specialising in CBEST/STAR/TIBER red teaming, advanced adversary simulation, and CREST-accredited penetration testing for FTSE 100 clients.

Accreditations: CREST, CHECK, CBEST, STAR, ISO 27001 +2
Services: Web Application, Network, Cloud, Red Teaming +6
Worcester, United Kingdom · Checked Apr 2026

CREST and CHECK-accredited UK penetration testing consultancy with CBEST approval, specialising in infrastructure, application, and simulated attack assessments across the public and private sectors.

Accreditations: CREST, CHECK, CBEST, STAR, ISO 27001 +3
Services: Web Application, Network, Mobile App, Cloud +4
Reston, Virginia, United States · Checked Apr 2026

World-renowned cybersecurity firm now part of Google Cloud, delivering threat intelligence-led penetration testing and red teaming informed by front-line incident response experience.

Accreditations: SOC 2, ISO 27001, FedRAMP 3PAO
Services: Red Teaming, Purple Teaming, Network, Web Application +5
Paris, France · Checked Sept 2026

Cybersecurity division of the Thales Group, with ANSSI, CREST, FedRAMP 3PAO, and NATO-cleared personnel. Defence, government, and critical infrastructure penetration testing worldwide.

Accreditations: CREST, FedRAMP 3PAO, ISO 27001, ISO 9001
Services: Web Application, Network, Cloud, IoT +8
Helsinki, Finland · Checked Sept 2026

Helsinki-headquartered Finnish cybersecurity firm with roots dating to 1988, offering CREST-accredited penetration testing and deep expertise in EU regulatory compliance including GDPR, NIS 2, and TIBER-EU.

Accreditations: CREST, ISO 27001
Services: Web Application, Network, Cloud, API +6
London, United Kingdom · Checked Sept 2026

Subscription-based offensive cybersecurity firm delivering continuous cyber attack services with CREST STAR and CBEST accreditations from its London headquarters.

Accreditations: CREST, CBEST, STAR
Services: Web Application, Network, Cloud, API +4
New York, United States · Checked Sept 2026

Global risk advisory firm with a 400+ person cyber practice. IR-led penetration testing that feeds active breach intelligence straight into test scoping.

Accreditations: PCI QSA, ISO 27001, SOC 2
Services: Web Application, Network, Cloud, API +8
Paris, France · Checked May 2026

Airbus group cybersecurity consultancy with ANSSI PASSI qualification. Aerospace, defence, and critical infrastructure penetration testing across Europe.

Accreditations: ANSSI PASSI, ISO 27001, Cyber Essentials
Services: Web Application, Network, Cloud, IoT +7

Best Threat-Led Penetration Testing (TLPT) Companies (2026), FAQs

What is threat-led penetration testing (TLPT)?+

TLPT is intelligence-led red teaming performed against an organisation's live production systems to test detection and response against the specific threat actors most likely to target it. It is goal-oriented, slow-paced by design, and mapped to frameworks like MITRE ATT&CK. Under DORA it is a legal requirement for significant EU financial entities.

How is TLPT different from a standard penetration test or red team?+

A standard pen test finds vulnerabilities within a defined scope. A conventional red team is an objective-driven attack simulation. TLPT is the regulated tier: driven by bespoke threat intelligence about a named actor, run against live systems, coordinated with a supervisory authority, and required (not chosen) for in-scope financial entities. It is longer and more rigorous than a commercial red team.

Which regulations require TLPT?+

In the EU, DORA mandates TLPT for significant financial entities, using the TIBER-EU framework (and national variants like TIBER-DE and TIBER-NL). In the UK, CBEST under the Bank of England and PRA is the equivalent. Both pre-vet the threat-intelligence and red-team providers that may deliver the engagement.

How often is TLPT required, and how long does it take?+

Under DORA, in-scope entities must run TLPT at least every three years. A full programme typically spans 6 to 9 months end to end: threat intelligence and scoping, 4 to 12 weeks of active red teaming, then purple-team replay and reporting.