DORA-Art26-P1

Article
26 (1)
Pillar
Digital Operational Resilience Testing
Regulation Ref
Regulation (EU) 2022/2554, Article 26(1)
Last Reviewed
2026-01-15

Financial entities identified in accordance with Article 6(1) of this Regulation shall carry out at least every 3 years advanced testing by means of threat-led penetration testing (TLPT).

Evidence Profiles

TLPT Scope and Planning Document RARE

Document defining the scope, objectives, and planning for threat-led penetration testing (TLPT) as required by DORA Article 26, including threat intelligence phase, red team scope, and critical function coverage.

Formats
DOCX PDF
Evidence Class
tlpt-scope-document
Availability
RARE
Update Frequency
every 3 years
Typical Author
CISO
Approval Chain
CISO → CRO → Board Risk Committee

Content Sections

Expected Fields

Common Quality Issues

View Example

Generated example artifact using the default institution profile (COMMON availability, synthetic data only).

PLAIN_TEXT — Inline Preview
THREAT-LED PENETRATION TESTING (TLPT) SCOPE AND PLANNING DOCUMENT
Nordvik Bank AG
TLPT ID: TLPT-2025-001
Planning Date: 10 January 2025
Document Owner: Chief Information Security Officer (CISO)
Classification: Strictly Confidential

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

1. TLPT OBJECTIVES

This document defines the scope, objectives, and planning for Nordvik Bank AG's
first threat-led penetration test (TLPT) conducted in accordance with DORA
Article 26. The TLPT is designed to:

  (a) Assess the Bank's resilience against realistic, intelligence-led attack
      scenarios targeting critical and important business functions.
  (b) Evaluate the effectiveness of the Bank's detection and response capabilities
      against sophisticated threat actors.
  (c) Identify vulnerabilities and weaknesses that conventional penetration testing
      may not uncover.
  (d) Satisfy the DORA Article 26 requirement for financial entities designated
      by competent authorities to carry out TLPT at least every three years.
  (e) Provide the competent authority with assurance of the Bank's operational
      resilience posture.

The TLPT will follow the TIBER-EU framework as referenced by DORA Article 26(2),
adapted to the Bank's specific threat landscape and critical function profile.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

2. THREAT INTELLIGENCE SCOPE

The threat intelligence phase will be conducted by an independent threat
intelligence provider to develop a targeted threat assessment specific to
Nordvik Bank AG.

  Threat Intelligence Provider:  ThreatScape Europe AG
  Engagement Period:             February – March 2025
  Deliverable:                   Targeted Threat Intelligence Report

  Scope of Threat Intelligence:
    — Threat actors targeting mid-size European banking institutions
    — Attack vectors relevant to the Bank's technology stack and geography
    — Sector-specific threat trends (financial services, Switzerland/EU)
    — Supply chain threats relevant to the Bank's critical ICT providers
    — Geopolitical threat factors affecting the European financial sector

  Intelligence Sources:
    — Open-source intelligence (OSINT)
    — Commercial threat intelligence feeds
    — Financial sector ISACs (Information Sharing and Analysis Centres)
    — Competent authority threat briefings (where available)
    — Dark web monitoring for institution-specific indicators

  The threat intelligence report will inform the red team's attack scenarios,
  ensuring they reflect realistic and current threats to the Bank.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

3. RED TEAM SCOPE

The red team phase will be conducted by an independent external provider with
no prior engagement history with the Bank, ensuring objectivity.

  Red Team Provider:  RedForce Security BV (Netherlands)
  Engagement Period:  April – June 2025 (12 weeks)
  Expected Duration:  10 weeks active testing + 2 weeks reporting

  Red Team Objectives:
    — Simulate realistic attack scenarios based on the threat intelligence report
    — Attempt to compromise critical business functions through multi-stage attacks
    — Test the Bank's ability to detect, respond to, and contain sophisticated
      intrusions
    — Assess the effectiveness of security controls across all layers

  Red Team Constraints:
    — No denial-of-service attacks against production systems
    — No destruction or modification of production data
    — No testing of physical security (separate assessment)
    — Immediate halt if unintended production impact detected
    — All activities logged and attributable

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

4. CRITICAL FUNCTIONS COVERED

The TLPT scope covers the following critical and important business functions
as identified in the Bank's business impact analysis:

  Function                          Criticality   Systems in Scope
  ─────────────────────────────────────────────────────────────────────────────
  Retail Payment Processing          Critical      Payment Gateway, SWIFT/SEPA
                                                   interface, core banking ledger
  Customer Account Management        Critical      Core Banking Platform (T24),
                                                   Digital Banking Portal, Mobile
                                                   Banking API
  Regulatory Reporting               Important     ABACUS reporting platform,
                                                   data warehouse, regulatory
                                                   submission interfaces
  Treasury Operations                Critical      Treasury Management System,
                                                   market data feeds, trading
                                                   interfaces
  Customer Authentication            Critical      Active Directory, MFA platform,
                                                   identity provider

  Total critical functions in scope: 5
  Coverage of designated critical functions: 100%

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

5. RULES OF ENGAGEMENT

  Rule                              Specification
  ─────────────────────────────────────────────────────────────────────────────
  Testing environment               Live production systems
  Testing hours                     24/7 (realistic threat simulation)
  Data access                       No exfiltration of real customer data;
                                    proof of access sufficient
  Emergency stop                    CISO can invoke immediate halt at any time
  Communication channel             Encrypted channel between CISO and red
                                    team lead; daily status updates
  Knowledge boundary                Blue team (SOC, incident response) must
                                    NOT be informed of the TLPT in advance
  Insider knowledge                 White team (CISO, CRO, TLPT coordinator)
                                    only

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

6. TIMELINE AND MILESTONES

  Phase                    Period              Milestone
  ─────────────────────────────────────────────────────────────────────────────
  Planning and Scoping     Jan 2025            Scope document approved by BRC
  Threat Intelligence      Feb – Mar 2025      Targeted threat report delivered
  Red Team Preparation     Mar 2025            Attack scenarios defined and
                                               approved by white team
  Red Team Execution       Apr – Jun 2025      Active testing (10 weeks)
  Reporting                Jun 2025            Red team report delivered
  Purple Team Exercise     Jul 2025            Joint red/blue team review
  Remediation Planning     Jul – Aug 2025      Remediation plan approved
  Competent Authority      Aug 2025            Summary report submitted to
  Notification                                 competent authority

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

7. GOVERNANCE AND OVERSIGHT

  Role                    Person                  Responsibility
  ─────────────────────────────────────────────────────────────────────────────
  TLPT Sponsor            Erik Lindqvist, CRO     Executive oversight; BRC
                                                  reporting
  TLPT Coordinator        Katrin Halvorsen, CISO  Day-to-day management; white
                                                  team lead; emergency stop
                                                  authority
  White Team Member       Lars Eriksson, CIO      Infrastructure coordination;
                                                  access provisioning
  Competent Authority     FINMA                   Notified of TLPT scope and
  Liaison                                         timeline; receives summary
                                                  report

  Oversight Authority Notified: Yes
  Notification Date: 15 January 2025
  Notification Reference: FINMA-TLPT-2025-NVK-001

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Document History:
  v1.0  10 Jan 2025  Initial TLPT scope and planning document

Approved by: Board Risk Committee
Signature:   [Board Risk Committee Chair]
Date:        20 January 2025

Expected Structured Facts

Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).

tlpt_execution_status — fs-tlpt-execution-status
{
  "factId": "c1d2e3f4-a5b6-7890-abcd-300000000006",
  "evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000006",
  "evidenceClassId": "tlpt-execution-report",
  "factType": "tlpt_execution_status",
  "data": {
    "tlpt_date": "2025-06-10",
    "tlpt_performed": true,
    "covers_critical_functions": true,
    "threat_intelligence_used": true,
    "findings_count": 14,
    "critical_findings": 2,
    "defence_detection_rate_percent": 67.0,
    "competent_authority_notified": true,
    "next_tlpt_due_date": "2028-06-10"
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-06-20T09:00:00Z",
  "supersededBy": null
}
tlpt_findings — fs-tlpt-findings
{
  "factId": "c1d2e3f4-a5b6-7890-abcd-300000000007",
  "evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000006",
  "evidenceClassId": "tlpt-execution-report",
  "factType": "tlpt_findings",
  "data": {
    "tlpt_id": "TLPT-2025-001",
    "total_findings": 14,
    "critical_findings": 2,
    "high_findings": 4,
    "remediation_plan_exists": true,
    "remediation_actions_count": 14,
    "remediation_completed_count": 0,
    "target_completion_date": "2025-12-31"
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-07-05T09:00:00Z",
  "supersededBy": null
}

TLPT Execution Report RARE

Report documenting the execution and results of threat-led penetration testing, including attack scenarios executed, findings, impact assessment, and remediation requirements as required by DORA Articles 26-27.

Formats
PDF
Evidence Class
tlpt-execution-report
Availability
RARE
Update Frequency
every 3 years
Typical Author
External TLPT Provider
Approval Chain
CISO → CRO → Board Risk Committee → Competent Authority

Content Sections

Expected Fields

Common Quality Issues

View Example

Generated example artifact using the default institution profile (COMMON availability, synthetic data only).

PLAIN_TEXT — Inline Preview
THREAT-LED PENETRATION TESTING (TLPT) EXECUTION REPORT
Nordvik Bank AG
TLPT ID: TLPT-2025-001
Execution Date: 1 April – 10 June 2025
Prepared by: RedForce Security BV
Reviewed by: Katrin Halvorsen, CISO, Nordvik Bank AG
Classification: Strictly Confidential

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

EXECUTIVE SUMMARY

RedForce Security BV conducted a threat-led penetration test (TLPT) of Nordvik
Bank AG between 1 April and 10 June 2025, targeting five critical business
functions across the Bank's production ICT environment. The TLPT was conducted
in accordance with DORA Article 26 and followed the TIBER-EU framework.

Key Results:
  — Attack scenarios executed: 6
  — Total findings: 14
  — Critical findings: 2
  — High findings: 4
  — Medium findings: 5
  — Low findings: 3
  — Defence team detection rate: 67% (4 of 6 scenarios detected)
  — Mean time to detect (for detected scenarios): 18.5 hours
  — Mean time to contain (for detected scenarios): 6.2 hours

The TLPT revealed that while the Bank's perimeter defences and endpoint protection
are effective against commodity threats, sophisticated multi-stage attacks exploiting
trust relationships between internal systems can bypass detection for extended
periods. Two critical findings relate to the ability to move laterally from a
compromised treasury workstation to the payment processing infrastructure, and
the ability to extract authentication tokens from a misconfigured API gateway cache.

The Bank's SOC detected 4 of 6 attack scenarios, demonstrating adequate but
improvable detection capabilities. The two undetected scenarios exploited
legitimate administrative tools and encrypted channels that blended with normal
traffic patterns.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

THREAT INTELLIGENCE SUMMARY

ThreatScape Europe AG delivered the targeted threat intelligence report on
15 March 2025. The report identified the following primary threat actors and
attack vectors relevant to Nordvik Bank AG:

  Threat Actor Profile 1: State-Sponsored Financial Espionage
    Motivation: Intelligence gathering on financial flows and sanctions compliance
    Capability: Advanced persistent threat (APT) with custom tooling
    Relevance: Medium — Bank processes cross-border payments subject to sanctions

  Threat Actor Profile 2: Organised Cybercrime (Ransomware)
    Motivation: Financial gain through ransomware and data extortion
    Capability: Sophisticated initial access via phishing and supply chain
    Relevance: High — primary threat to mid-size European banks

  Threat Actor Profile 3: Insider Threat (Privileged User)
    Motivation: Financial gain or coercion
    Capability: Legitimate access to critical systems
    Relevance: Medium — Bank has 47 privileged users across IT and operations

The red team developed attack scenarios based on these threat profiles, simulating
realistic attack chains that a motivated adversary would employ against the Bank.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

RED TEAM ACTIVITIES

  Scenario    Threat Profile    Target Function              Detected?
  ─────────────────────────────────────────────────────────────────────────────
  SC-01       Ransomware        Customer Account Mgmt         Yes (12h)
  SC-02       APT               Treasury Operations           No
  SC-03       Ransomware        Retail Payment Processing     Yes (8h)
  SC-04       Insider           Regulatory Reporting          Yes (32h)
  SC-05       APT               Customer Authentication       No
  SC-06       Ransomware        Customer Account Mgmt         Yes (22h)

  Detection Rate: 67% (4/6)
  Average Detection Time (detected): 18.5 hours

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

ATTACK SCENARIOS EXECUTED

Scenario SC-01: Ransomware — Customer Account Management
  Initial Access:    Spear-phishing email with malicious macro document
  Execution:         Macro executed PowerShell downloader; CrowdStrike EDR
                     detected the payload but a modified variant evaded detection
  Lateral Movement:  Moved from compromised workstation to file server using
                     stolen credentials from memory
  Objective:         Encrypt customer account database
  Result:            Detected by SOC after 12 hours via anomalous file access
                     patterns. Contained within 4 hours of detection.
  Impact Assessment: Moderate — attacker gained access to file server but was
                     contained before reaching database tier.

Scenario SC-02: APT — Treasury Operations
  Initial Access:    Compromised third-party market data feed update mechanism
  Execution:         Injected backdoor into legitimate software update package
  Lateral Movement:  Used legitimate administrative tools (PsExec, WMI) to
                     move from market data server to treasury workstation
  Objective:         Access payment initiation capability
  Result:            NOT DETECTED — red team maintained persistent access for
                     3 weeks. Lateral movement via legitimate tools blended
                     with normal administrative traffic.
  Impact Assessment: Critical — demonstrates that supply chain compromise
                     combined with living-off-the-land techniques can bypass
                     current detection capabilities.

Scenario SC-03: Ransomware — Retail Payment Processing
  Initial Access:    Exploitation of vulnerable web application (staging instance
                     accessible from internet)
  Execution:         Web shell deployed on staging server; pivoted to production
                     network via shared service account
  Lateral Movement:  Service account had access to payment gateway configuration
  Objective:         Disrupt payment processing
  Result:            Detected by SOC after 8 hours via IDS alert on unusual
                     traffic from staging to production zone. Contained within
                     2 hours.
  Impact Assessment: High — staging-to-production pivot path should not exist.

[Scenarios SC-04 through SC-06 detailed in Appendix A]

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

FINDINGS AND IMPACT

  ID         Severity    Title
  ─────────────────────────────────────────────────────────────────────────────
  TLPT-F01   Critical    Lateral movement from treasury to payment systems
                         via trust relationship exploitation
  TLPT-F02   Critical    Authentication token extraction from API gateway
                         cache enabling session hijacking
  TLPT-F03   High        Supply chain attack vector via market data feed
                         update mechanism
  TLPT-F04   High        Staging-to-production network path via shared
                         service account
  TLPT-F05   High        Living-off-the-land techniques evade SIEM detection
                         rules (PsExec, WMI, PowerShell remoting)
  TLPT-F06   High        Insufficient monitoring of encrypted east-west
                         traffic in production zone
  TLPT-F07   Medium      Weak service account password policy (no rotation)
  TLPT-F08   Medium      Excessive file share permissions for IT staff
  TLPT-F09   Medium      Missing network segmentation between staging and
                         production environments
  TLPT-F10   Medium      Incomplete logging of administrative tool usage
  TLPT-F11   Medium      SOC playbooks lack procedures for supply chain
                         compromise scenarios
  TLPT-F12   Low         Outdated threat intelligence feeds in SIEM
  TLPT-F13   Low         Inconsistent endpoint hardening across server fleet
  TLPT-F14   Low         Missing alerting for dormant privileged accounts

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

DEFENCE TEAM RESPONSE ASSESSMENT

The Bank's Security Operations Centre (SOC) demonstrated competent detection and
response capabilities for known attack patterns. Key observations:

  Strengths:
    — Rapid containment once threats were detected (average 6.2 hours)
    — Effective use of EDR for endpoint-level threat detection
    — Good coordination between SOC and incident response team
    — Appropriate escalation to CISO for critical detections

  Areas for Improvement:
    — Detection of living-off-the-land techniques requires enhanced behavioural
      analytics and UEBA capabilities
    — Supply chain compromise scenarios not covered in current SOC playbooks
    — East-west encrypted traffic monitoring gap limits visibility
    — Administrative tool usage monitoring insufficient for detecting
      lateral movement via legitimate tools

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

REMEDIATION REQUIREMENTS

  Priority     Finding     Recommended Action                  Deadline
  ─────────────────────────────────────────────────────────────────────────────
  Immediate    TLPT-F01    Segment treasury and payment         31 Jul 2025
                           systems; remove trust relationships
  Immediate    TLPT-F02    Secure API gateway cache; implement  31 Jul 2025
                           token binding and short-lived tokens
  High         TLPT-F03    Implement software supply chain      30 Sep 2025
                           integrity verification
  High         TLPT-F04    Isolate staging from production;     31 Aug 2025
                           eliminate shared service accounts
  High         TLPT-F05    Deploy UEBA and enhance SIEM rules   31 Oct 2025
                           for administrative tool monitoring
  High         TLPT-F06    Implement east-west TLS inspection    30 Sep 2025
  Medium       TLPT-F07    Implement service account password    30 Nov 2025
               to F11      rotation; address remaining findings
  Low          TLPT-F12    Update threat intelligence feeds;     31 Dec 2025
               to F14      address remaining low findings

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

COMPETENT AUTHORITY SUMMARY

A summary of this TLPT execution report will be submitted to FINMA in accordance
with DORA Article 26(6). The summary will include: scope of testing, threat
intelligence basis, key findings (anonymised where appropriate), defence team
performance metrics, and the remediation plan timeline.

Submission Reference: FINMA-TLPT-2025-NVK-001-REPORT
Planned Submission Date: August 2025

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Prepared by: RedForce Security BV
Lead Red Team Operator: [Red Team Lead]
Reviewed by: Katrin Halvorsen, CISO, Nordvik Bank AG
Date:        15 June 2025

Expected Structured Facts

Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).

tlpt_execution_status — fs-tlpt-execution-status
{
  "factId": "c1d2e3f4-a5b6-7890-abcd-300000000006",
  "evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000006",
  "evidenceClassId": "tlpt-execution-report",
  "factType": "tlpt_execution_status",
  "data": {
    "tlpt_date": "2025-06-10",
    "tlpt_performed": true,
    "covers_critical_functions": true,
    "threat_intelligence_used": true,
    "findings_count": 14,
    "critical_findings": 2,
    "defence_detection_rate_percent": 67.0,
    "competent_authority_notified": true,
    "next_tlpt_due_date": "2028-06-10"
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-06-20T09:00:00Z",
  "supersededBy": null
}
tlpt_findings — fs-tlpt-findings
{
  "factId": "c1d2e3f4-a5b6-7890-abcd-300000000007",
  "evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000006",
  "evidenceClassId": "tlpt-execution-report",
  "factType": "tlpt_findings",
  "data": {
    "tlpt_id": "TLPT-2025-001",
    "total_findings": 14,
    "critical_findings": 2,
    "high_findings": 4,
    "remediation_plan_exists": true,
    "remediation_actions_count": 14,
    "remediation_completed_count": 0,
    "target_completion_date": "2025-12-31"
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-07-05T09:00:00Z",
  "supersededBy": null
}

TLPT Remediation Plan RARE

XML-structured remediation plan addressing findings from threat-led penetration testing, including prioritised actions, responsible owners, timelines, and validation criteria.

Formats
XML
Evidence Class
tlpt-remediation-plan
Availability
RARE
Update Frequency
event-driven
Typical Author
CISO
Approval Chain
CISO → CRO

Content Sections

Expected Fields

Common Quality Issues

View Example

Generated example artifact using the default institution profile (COMMON availability, synthetic data only).

XML — Inline Preview
<?xml version="1.0" encoding="UTF-8"?>
<TLPTRemediationPlan
    planId="TLPT-REM-2025-001"
    tlptId="TLPT-2025-001"
    creationDate="2025-07-01"
    institution="Nordvik Bank AG"
    totalActions="14"
    criticalActions="2"
    targetCompletionDate="2025-12-31"
    validationMethod="Targeted retesting by independent provider"
    approvedBy="Katrin Halvorsen, CISO"
    approvalDate="2025-07-05">

  <!-- ═══════════════════════════════════════════════════════════════════════
       REMEDIATION ACTIONS — CRITICAL PRIORITY
       ═══════════════════════════════════════════════════════════════════════ -->
  <RemediationActions priority="Critical">

    <Action actionId="REM-001" findingRef="TLPT-F01" status="In Progress">
      <Title>Segment Treasury and Payment Systems</Title>
      <Description>Implement strict network segmentation between treasury
        workstations and payment processing infrastructure. Remove all trust
        relationships that allow lateral movement between these zones. Deploy
        micro-segmentation using Illumio or equivalent for granular control.</Description>
      <ResponsibleOwner>Network Operations Team Lead</ResponsibleOwner>
      <TargetDate>2025-07-31</TargetDate>
      <EstimatedEffort unit="person-days">25</EstimatedEffort>
      <ValidationCriteria>
        <Criterion>No direct network path from treasury zone to payment zone</Criterion>
        <Criterion>All cross-zone traffic routed through application proxy</Criterion>
        <Criterion>Penetration test confirms segmentation effectiveness</Criterion>
      </ValidationCriteria>
      <Dependencies>
        <Dependency>Firewall change request approved (CR-2025-0891)</Dependency>
        <Dependency>Application proxy deployment complete</Dependency>
      </Dependencies>
    </Action>

    <Action actionId="REM-002" findingRef="TLPT-F02" status="In Progress">
      <Title>Secure API Gateway Cache and Token Management</Title>
      <Description>Reconfigure API gateway to prevent caching of authentication
        tokens. Implement token binding to client IP and device fingerprint.
        Reduce JWT token lifetime from 4 hours to 15 minutes with refresh
        token rotation.</Description>
      <ResponsibleOwner>Application Security Team Lead</ResponsibleOwner>
      <TargetDate>2025-07-31</TargetDate>
      <EstimatedEffort unit="person-days">15</EstimatedEffort>
      <ValidationCriteria>
        <Criterion>API gateway cache does not store authentication tokens</Criterion>
        <Criterion>Token binding prevents token reuse from different client</Criterion>
        <Criterion>JWT lifetime reduced to 15 minutes</Criterion>
        <Criterion>Refresh token rotation implemented and tested</Criterion>
      </ValidationCriteria>
      <Dependencies>
        <Dependency>API gateway vendor support engagement (case SR-44521)</Dependency>
      </Dependencies>
    </Action>

  </RemediationActions>

  <!-- ═══════════════════════════════════════════════════════════════════════
       REMEDIATION ACTIONS — HIGH PRIORITY
       ═══════════════════════════════════════════════════════════════════════ -->
  <RemediationActions priority="High">

    <Action actionId="REM-003" findingRef="TLPT-F03" status="Planned">
      <Title>Implement Software Supply Chain Integrity Verification</Title>
      <Description>Deploy software supply chain security controls for all
        third-party software updates, including cryptographic signature
        verification, hash validation, and sandboxed testing before
        production deployment. Prioritise market data feed and core
        banking update channels.</Description>
      <ResponsibleOwner>IT Operations Team Lead</ResponsibleOwner>
      <TargetDate>2025-09-30</TargetDate>
      <EstimatedEffort unit="person-days">30</EstimatedEffort>
      <ValidationCriteria>
        <Criterion>All critical software updates verified via cryptographic signature</Criterion>
        <Criterion>Sandboxed testing environment operational for update validation</Criterion>
        <Criterion>Automated alerting for unsigned or modified update packages</Criterion>
      </ValidationCriteria>
      <Dependencies>
        <Dependency>Vendor cooperation for signature verification keys</Dependency>
        <Dependency>Sandbox environment provisioning (AWS)</Dependency>
      </Dependencies>
    </Action>

    <Action actionId="REM-004" findingRef="TLPT-F04" status="Planned">
      <Title>Isolate Staging from Production Environment</Title>
      <Description>Implement complete network isolation between staging and
        production environments. Eliminate all shared service accounts.
        Deploy separate identity stores for staging and production.</Description>
      <ResponsibleOwner>Infrastructure Team Lead</ResponsibleOwner>
      <TargetDate>2025-08-31</TargetDate>
      <EstimatedEffort unit="person-days">20</EstimatedEffort>
      <ValidationCriteria>
        <Criterion>No network connectivity between staging and production zones</Criterion>
        <Criterion>No shared service accounts across environments</Criterion>
        <Criterion>Separate Active Directory OUs for staging and production</Criterion>
      </ValidationCriteria>
      <Dependencies>
        <Dependency>Service account audit complete (REM-007)</Dependency>
      </Dependencies>
    </Action>

    <Action actionId="REM-005" findingRef="TLPT-F05" status="Planned">
      <Title>Deploy UEBA and Enhance Administrative Tool Monitoring</Title>
      <Description>Deploy User and Entity Behaviour Analytics (UEBA) solution
        to detect anomalous use of legitimate administrative tools (PsExec,
        WMI, PowerShell remoting). Create SIEM correlation rules for
        living-off-the-land attack patterns.</Description>
      <ResponsibleOwner>SOC Manager</ResponsibleOwner>
      <TargetDate>2025-10-31</TargetDate>
      <EstimatedEffort unit="person-days">40</EstimatedEffort>
      <ValidationCriteria>
        <Criterion>UEBA solution deployed and baselined for all privileged users</Criterion>
        <Criterion>SIEM rules detect PsExec, WMI, and PowerShell remoting anomalies</Criterion>
        <Criterion>Purple team exercise validates detection of LOTL techniques</Criterion>
      </ValidationCriteria>
      <Dependencies>
        <Dependency>UEBA vendor selection and procurement (Q3 2025 budget)</Dependency>
      </Dependencies>
    </Action>

    <Action actionId="REM-006" findingRef="TLPT-F06" status="Planned">
      <Title>Implement East-West TLS Inspection</Title>
      <Description>Deploy TLS inspection capability for encrypted traffic
        within the production zone to enable detection of malicious
        activity in encrypted channels between application servers.</Description>
      <ResponsibleOwner>Network Security Engineer</ResponsibleOwner>
      <TargetDate>2025-09-30</TargetDate>
      <EstimatedEffort unit="person-days">20</EstimatedEffort>
      <ValidationCriteria>
        <Criterion>TLS inspection active for production zone east-west traffic</Criterion>
        <Criterion>Decrypted traffic fed to SIEM and IDS for analysis</Criterion>
        <Criterion>No performance degradation exceeding 5% on inspected paths</Criterion>
      </ValidationCriteria>
      <Dependencies>
        <Dependency>Internal CA certificate deployment to all production servers</Dependency>
      </Dependencies>
    </Action>

  </RemediationActions>

  <!-- ═══════════════════════════════════════════════════════════════════════
       REMEDIATION ACTIONS — MEDIUM PRIORITY
       ═══════════════════════════════════════════════════════════════════════ -->
  <RemediationActions priority="Medium">

    <Action actionId="REM-007" findingRef="TLPT-F07" status="Planned">
      <Title>Implement Service Account Password Rotation</Title>
      <Description>Deploy automated service account password rotation using
        CyberArk for all service accounts. Implement 90-day rotation policy
        with automated credential distribution.</Description>
      <ResponsibleOwner>IAM Team Lead</ResponsibleOwner>
      <TargetDate>2025-11-30</TargetDate>
      <EstimatedEffort unit="person-days">15</EstimatedEffort>
      <ValidationCriteria>
        <Criterion>All service accounts enrolled in CyberArk rotation</Criterion>
        <Criterion>90-day rotation policy enforced</Criterion>
      </ValidationCriteria>
    </Action>

    <Action actionId="REM-008" findingRef="TLPT-F08" status="Planned">
      <Title>Review and Restrict File Share Permissions</Title>
      <ResponsibleOwner>IT Operations Team Lead</ResponsibleOwner>
      <TargetDate>2025-11-30</TargetDate>
      <EstimatedEffort unit="person-days">10</EstimatedEffort>
      <ValidationCriteria>
        <Criterion>Least-privilege access enforced on all file shares</Criterion>
      </ValidationCriteria>
    </Action>

    <Action actionId="REM-009" findingRef="TLPT-F09" status="Planned">
      <Title>Complete Staging-Production Network Isolation</Title>
      <ResponsibleOwner>Network Operations Team Lead</ResponsibleOwner>
      <TargetDate>2025-08-31</TargetDate>
      <EstimatedEffort unit="person-days">10</EstimatedEffort>
      <ValidationCriteria>
        <Criterion>Firewall rules block all staging-to-production traffic</Criterion>
      </ValidationCriteria>
    </Action>

    <Action actionId="REM-010" findingRef="TLPT-F10" status="Planned">
      <Title>Enhance Administrative Tool Logging</Title>
      <ResponsibleOwner>SOC Manager</ResponsibleOwner>
      <TargetDate>2025-10-31</TargetDate>
      <EstimatedEffort unit="person-days">8</EstimatedEffort>
      <ValidationCriteria>
        <Criterion>All administrative tool usage logged and forwarded to SIEM</Criterion>
      </ValidationCriteria>
    </Action>

    <Action actionId="REM-011" findingRef="TLPT-F11" status="Planned">
      <Title>Develop Supply Chain Compromise SOC Playbooks</Title>
      <ResponsibleOwner>SOC Manager</ResponsibleOwner>
      <TargetDate>2025-09-30</TargetDate>
      <EstimatedEffort unit="person-days">5</EstimatedEffort>
      <ValidationCriteria>
        <Criterion>Supply chain compromise playbook documented and tested</Criterion>
        <Criterion>SOC analysts trained on new playbook</Criterion>
      </ValidationCriteria>
    </Action>

  </RemediationActions>

  <!-- ═══════════════════════════════════════════════════════════════════════
       REMEDIATION ACTIONS — LOW PRIORITY
       ═══════════════════════════════════════════════════════════════════════ -->
  <RemediationActions priority="Low">

    <Action actionId="REM-012" findingRef="TLPT-F12" status="Planned">
      <Title>Update Threat Intelligence Feeds in SIEM</Title>
      <ResponsibleOwner>SOC Manager</ResponsibleOwner>
      <TargetDate>2025-12-31</TargetDate>
      <EstimatedEffort unit="person-days">3</EstimatedEffort>
    </Action>

    <Action actionId="REM-013" findingRef="TLPT-F13" status="Planned">
      <Title>Standardise Server Hardening Across Fleet</Title>
      <ResponsibleOwner>Infrastructure Team Lead</ResponsibleOwner>
      <TargetDate>2025-12-31</TargetDate>
      <EstimatedEffort unit="person-days">15</EstimatedEffort>
    </Action>

    <Action actionId="REM-014" findingRef="TLPT-F14" status="Planned">
      <Title>Implement Dormant Privileged Account Alerting</Title>
      <ResponsibleOwner>IAM Team Lead</ResponsibleOwner>
      <TargetDate>2025-12-31</TargetDate>
      <EstimatedEffort unit="person-days">5</EstimatedEffort>
    </Action>

  </RemediationActions>

  <!-- ═══════════════════════════════════════════════════════════════════════
       TRACKING AND VALIDATION
       ═══════════════════════════════════════════════════════════════════════ -->
  <TrackingAndValidation>
    <ReviewFrequency>Monthly review by ICT Risk Committee</ReviewFrequency>
    <EscalationThreshold>Any critical action overdue by more than 2 weeks</EscalationThreshold>
    <ValidationApproach>Independent retesting of critical and high findings by
      RedForce Security BV upon remediation completion</ValidationApproach>
    <CompetentAuthorityReporting>Remediation progress included in FINMA
      TLPT summary report (August 2025)</CompetentAuthorityReporting>
  </TrackingAndValidation>

</TLPTRemediationPlan>

Expected Structured Facts

Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).

tlpt_execution_status — fs-tlpt-execution-status
{
  "factId": "c1d2e3f4-a5b6-7890-abcd-300000000006",
  "evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000006",
  "evidenceClassId": "tlpt-execution-report",
  "factType": "tlpt_execution_status",
  "data": {
    "tlpt_date": "2025-06-10",
    "tlpt_performed": true,
    "covers_critical_functions": true,
    "threat_intelligence_used": true,
    "findings_count": 14,
    "critical_findings": 2,
    "defence_detection_rate_percent": 67.0,
    "competent_authority_notified": true,
    "next_tlpt_due_date": "2028-06-10"
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-06-20T09:00:00Z",
  "supersededBy": null
}
tlpt_findings — fs-tlpt-findings
{
  "factId": "c1d2e3f4-a5b6-7890-abcd-300000000007",
  "evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000006",
  "evidenceClassId": "tlpt-execution-report",
  "factType": "tlpt_findings",
  "data": {
    "tlpt_id": "TLPT-2025-001",
    "total_findings": 14,
    "critical_findings": 2,
    "high_findings": 4,
    "remediation_plan_exists": true,
    "remediation_actions_count": 14,
    "remediation_completed_count": 0,
    "target_completion_date": "2025-12-31"
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-07-05T09:00:00Z",
  "supersededBy": null
}

Fact Schemas

tlpt_execution_status

Schema ID
fs-tlpt-execution-status
Control
DORA-Art26-P1

Valid Ranges

tlpt_date
within last 3 years
next_tlpt_due_date
within 3 years of last TLPT

Related Schemas

JSON Schema

{
  "properties": {
    "competent_authority_notified": {
      "type": "boolean"
    },
    "covers_critical_functions": {
      "type": "boolean"
    },
    "critical_findings": {
      "minimum": 0,
      "type": "integer"
    },
    "defence_detection_rate_percent": {
      "maximum": 100,
      "minimum": 0,
      "type": "number"
    },
    "findings_count": {
      "minimum": 0,
      "type": "integer"
    },
    "next_tlpt_due_date": {
      "format": "date",
      "type": "string"
    },
    "threat_intelligence_used": {
      "type": "boolean"
    },
    "tlpt_date": {
      "format": "date",
      "type": "string"
    },
    "tlpt_performed": {
      "type": "boolean"
    }
  },
  "required": [
    "tlpt_date",
    "tlpt_performed",
    "covers_critical_functions",
    "findings_count"
  ],
  "type": "object"
}

tlpt_findings

Schema ID
fs-tlpt-findings
Control
DORA-Art26-P1

Valid Ranges

remediation_completed_count
should equal remediation_actions_count for full remediation
target_completion_date
within 12 months of TLPT completion

Related Schemas

JSON Schema

{
  "properties": {
    "critical_findings": {
      "minimum": 0,
      "type": "integer"
    },
    "high_findings": {
      "minimum": 0,
      "type": "integer"
    },
    "remediation_actions_count": {
      "minimum": 0,
      "type": "integer"
    },
    "remediation_completed_count": {
      "minimum": 0,
      "type": "integer"
    },
    "remediation_plan_exists": {
      "type": "boolean"
    },
    "target_completion_date": {
      "format": "date",
      "type": "string"
    },
    "tlpt_id": {
      "minLength": 1,
      "type": "string"
    },
    "total_findings": {
      "minimum": 0,
      "type": "integer"
    }
  },
  "required": [
    "tlpt_id",
    "total_findings",
    "critical_findings",
    "remediation_plan_exists"
  ],
  "type": "object"
}