
UK offensive security consultancy delivering CREST-accredited penetration testing, adversary simulation and CBEST, TIBER-EU and TBEST threat-led testing, mainly for financial services and other large organisations.
Digital Operational Resilience Act · Europe
DORA is the EU regulation establishing a comprehensive framework for digital operational resilience in the financial sector. Effective from January 2025, DORA requires financial entities to implement advanced testing of ICT tools, systems, and processes. Article 26 specifically mandates threat-led penetration testing (TLPT) for significant financial entities, to be conducted at least every three years using frameworks like TIBER-EU.
DORA goes beyond traditional penetration testing requirements by mandating that testing be conducted by qualified, independent testers using threat intelligence to simulate real adversary tactics, techniques, and procedures. The regulation covers banks, insurance companies, investment firms, payment institutions, and ICT third-party service providers to the financial sector.
DORA's TLPT requirements are among the most rigorous in any regulatory framework, requiring testers to demonstrate advanced capabilities in adversary simulation, threat intelligence, and financial sector expertise. Non-compliance can result in significant penalties and regulatory action from financial supervisory authorities.
Particularly relevant for Financial services pen testing providers.
DORA mandates threat-led penetration testing for significant entities. See threat-led penetration testing (TLPT) providers.

UK offensive security consultancy delivering CREST-accredited penetration testing, adversary simulation and CBEST, TIBER-EU and TBEST threat-led testing, mainly for financial services and other large organisations.

Global enterprise cybersecurity consultancy founded in 1999 in Oxford, holding rare CREST STAR-FS accreditation and delivering penetration testing, red and purple teaming, and PCI QSA services across five international offices.

Global Big Four professional services firm delivering CREST, CHECK, and CBEST-accredited penetration testing and red teaming services from London, serving the UK's largest enterprises and regulated organisations.
CREST and CHECK-accredited UK penetration testing and managed security provider formed in 2026 from Pentest People, Bulletproof, and Target Defense, with CREST STAR/TLPT-FS capability and the GuardNest vulnerability management platform.

Elite UK offensive security consultancy specialising in CBEST/STAR/TIBER red teaming, advanced adversary simulation, and CREST-accredited penetration testing for FTSE 100 clients.

Cybersecurity division of the Thales Group, with ANSSI, CREST, FedRAMP 3PAO, and NATO-cleared personnel. Defence, government, and critical infrastructure penetration testing worldwide.

Helsinki-headquartered Finnish cybersecurity firm with roots dating to 1988, offering CREST-accredited penetration testing and deep expertise in EU regulatory compliance including GDPR, NIS 2, and TIBER-EU.

Cardiff-based CREST and CHECK-accredited cyber security company delivering penetration testing, red teaming, and OT security assessments as part of the Chess Group.

Subscription-based offensive cybersecurity firm delivering continuous cyber attack services with CREST STAR and CBEST accreditations from its London headquarters.
Frankfurt-based European payment security specialist holding the full set of PCI credentials (QSA, PFI, ASV, P2PE). Manual-first penetration testing for fintechs, acquirers, and regulated enterprises.

Global risk advisory firm with a 400+ person cyber practice. IR-led penetration testing that feeds active breach intelligence straight into test scoping.

Vienna-headquartered Austrian cybersecurity consultancy with a prolific Vulnerability Lab research program and deep expertise in IoT and embedded systems security across the DACH region.
TLPT under DORA requires realistic adversary simulation based on threat intelligence, targeting live production systems of financial entities. It follows frameworks like TIBER-EU and must be performed by qualified external testers.
Significant financial entities as identified by supervisory authorities, including major banks, insurance companies, investment firms, and central counterparties.
DORA requires TLPT at least every three years for entities that meet the significance threshold, with the scope and timing coordinated with financial supervisory authorities.