Financial entities identified in accordance with Article 6(1) of this Regulation shall carry out at least every 3 years advanced testing by means of threat-led penetration testing (TLPT).
Document defining the scope, objectives, and planning for threat-led penetration testing (TLPT) as required by DORA Article 26, including threat intelligence phase, red team scope, and critical function coverage.
tlpt-scope-documentGenerated example artifact using the default institution profile (COMMON availability, synthetic data only).
THREAT-LED PENETRATION TESTING (TLPT) SCOPE AND PLANNING DOCUMENT
Nordvik Bank AG
TLPT ID: TLPT-2025-001
Planning Date: 10 January 2025
Document Owner: Chief Information Security Officer (CISO)
Classification: Strictly Confidential
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
1. TLPT OBJECTIVES
This document defines the scope, objectives, and planning for Nordvik Bank AG's
first threat-led penetration test (TLPT) conducted in accordance with DORA
Article 26. The TLPT is designed to:
(a) Assess the Bank's resilience against realistic, intelligence-led attack
scenarios targeting critical and important business functions.
(b) Evaluate the effectiveness of the Bank's detection and response capabilities
against sophisticated threat actors.
(c) Identify vulnerabilities and weaknesses that conventional penetration testing
may not uncover.
(d) Satisfy the DORA Article 26 requirement for financial entities designated
by competent authorities to carry out TLPT at least every three years.
(e) Provide the competent authority with assurance of the Bank's operational
resilience posture.
The TLPT will follow the TIBER-EU framework as referenced by DORA Article 26(2),
adapted to the Bank's specific threat landscape and critical function profile.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
2. THREAT INTELLIGENCE SCOPE
The threat intelligence phase will be conducted by an independent threat
intelligence provider to develop a targeted threat assessment specific to
Nordvik Bank AG.
Threat Intelligence Provider: ThreatScape Europe AG
Engagement Period: February – March 2025
Deliverable: Targeted Threat Intelligence Report
Scope of Threat Intelligence:
— Threat actors targeting mid-size European banking institutions
— Attack vectors relevant to the Bank's technology stack and geography
— Sector-specific threat trends (financial services, Switzerland/EU)
— Supply chain threats relevant to the Bank's critical ICT providers
— Geopolitical threat factors affecting the European financial sector
Intelligence Sources:
— Open-source intelligence (OSINT)
— Commercial threat intelligence feeds
— Financial sector ISACs (Information Sharing and Analysis Centres)
— Competent authority threat briefings (where available)
— Dark web monitoring for institution-specific indicators
The threat intelligence report will inform the red team's attack scenarios,
ensuring they reflect realistic and current threats to the Bank.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
3. RED TEAM SCOPE
The red team phase will be conducted by an independent external provider with
no prior engagement history with the Bank, ensuring objectivity.
Red Team Provider: RedForce Security BV (Netherlands)
Engagement Period: April – June 2025 (12 weeks)
Expected Duration: 10 weeks active testing + 2 weeks reporting
Red Team Objectives:
— Simulate realistic attack scenarios based on the threat intelligence report
— Attempt to compromise critical business functions through multi-stage attacks
— Test the Bank's ability to detect, respond to, and contain sophisticated
intrusions
— Assess the effectiveness of security controls across all layers
Red Team Constraints:
— No denial-of-service attacks against production systems
— No destruction or modification of production data
— No testing of physical security (separate assessment)
— Immediate halt if unintended production impact detected
— All activities logged and attributable
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
4. CRITICAL FUNCTIONS COVERED
The TLPT scope covers the following critical and important business functions
as identified in the Bank's business impact analysis:
Function Criticality Systems in Scope
─────────────────────────────────────────────────────────────────────────────
Retail Payment Processing Critical Payment Gateway, SWIFT/SEPA
interface, core banking ledger
Customer Account Management Critical Core Banking Platform (T24),
Digital Banking Portal, Mobile
Banking API
Regulatory Reporting Important ABACUS reporting platform,
data warehouse, regulatory
submission interfaces
Treasury Operations Critical Treasury Management System,
market data feeds, trading
interfaces
Customer Authentication Critical Active Directory, MFA platform,
identity provider
Total critical functions in scope: 5
Coverage of designated critical functions: 100%
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
5. RULES OF ENGAGEMENT
Rule Specification
─────────────────────────────────────────────────────────────────────────────
Testing environment Live production systems
Testing hours 24/7 (realistic threat simulation)
Data access No exfiltration of real customer data;
proof of access sufficient
Emergency stop CISO can invoke immediate halt at any time
Communication channel Encrypted channel between CISO and red
team lead; daily status updates
Knowledge boundary Blue team (SOC, incident response) must
NOT be informed of the TLPT in advance
Insider knowledge White team (CISO, CRO, TLPT coordinator)
only
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
6. TIMELINE AND MILESTONES
Phase Period Milestone
─────────────────────────────────────────────────────────────────────────────
Planning and Scoping Jan 2025 Scope document approved by BRC
Threat Intelligence Feb – Mar 2025 Targeted threat report delivered
Red Team Preparation Mar 2025 Attack scenarios defined and
approved by white team
Red Team Execution Apr – Jun 2025 Active testing (10 weeks)
Reporting Jun 2025 Red team report delivered
Purple Team Exercise Jul 2025 Joint red/blue team review
Remediation Planning Jul – Aug 2025 Remediation plan approved
Competent Authority Aug 2025 Summary report submitted to
Notification competent authority
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
7. GOVERNANCE AND OVERSIGHT
Role Person Responsibility
─────────────────────────────────────────────────────────────────────────────
TLPT Sponsor Erik Lindqvist, CRO Executive oversight; BRC
reporting
TLPT Coordinator Katrin Halvorsen, CISO Day-to-day management; white
team lead; emergency stop
authority
White Team Member Lars Eriksson, CIO Infrastructure coordination;
access provisioning
Competent Authority FINMA Notified of TLPT scope and
Liaison timeline; receives summary
report
Oversight Authority Notified: Yes
Notification Date: 15 January 2025
Notification Reference: FINMA-TLPT-2025-NVK-001
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Document History:
v1.0 10 Jan 2025 Initial TLPT scope and planning document
Approved by: Board Risk Committee
Signature: [Board Risk Committee Chair]
Date: 20 January 2025
Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).
tlpt_execution_status — fs-tlpt-execution-status
{
"factId": "c1d2e3f4-a5b6-7890-abcd-300000000006",
"evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000006",
"evidenceClassId": "tlpt-execution-report",
"factType": "tlpt_execution_status",
"data": {
"tlpt_date": "2025-06-10",
"tlpt_performed": true,
"covers_critical_functions": true,
"threat_intelligence_used": true,
"findings_count": 14,
"critical_findings": 2,
"defence_detection_rate_percent": 67.0,
"competent_authority_notified": true,
"next_tlpt_due_date": "2028-06-10"
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-06-20T09:00:00Z",
"supersededBy": null
}
tlpt_findings — fs-tlpt-findings
{
"factId": "c1d2e3f4-a5b6-7890-abcd-300000000007",
"evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000006",
"evidenceClassId": "tlpt-execution-report",
"factType": "tlpt_findings",
"data": {
"tlpt_id": "TLPT-2025-001",
"total_findings": 14,
"critical_findings": 2,
"high_findings": 4,
"remediation_plan_exists": true,
"remediation_actions_count": 14,
"remediation_completed_count": 0,
"target_completion_date": "2025-12-31"
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-07-05T09:00:00Z",
"supersededBy": null
}
Report documenting the execution and results of threat-led penetration testing, including attack scenarios executed, findings, impact assessment, and remediation requirements as required by DORA Articles 26-27.
tlpt-execution-reportGenerated example artifact using the default institution profile (COMMON availability, synthetic data only).
THREAT-LED PENETRATION TESTING (TLPT) EXECUTION REPORT
Nordvik Bank AG
TLPT ID: TLPT-2025-001
Execution Date: 1 April – 10 June 2025
Prepared by: RedForce Security BV
Reviewed by: Katrin Halvorsen, CISO, Nordvik Bank AG
Classification: Strictly Confidential
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
EXECUTIVE SUMMARY
RedForce Security BV conducted a threat-led penetration test (TLPT) of Nordvik
Bank AG between 1 April and 10 June 2025, targeting five critical business
functions across the Bank's production ICT environment. The TLPT was conducted
in accordance with DORA Article 26 and followed the TIBER-EU framework.
Key Results:
— Attack scenarios executed: 6
— Total findings: 14
— Critical findings: 2
— High findings: 4
— Medium findings: 5
— Low findings: 3
— Defence team detection rate: 67% (4 of 6 scenarios detected)
— Mean time to detect (for detected scenarios): 18.5 hours
— Mean time to contain (for detected scenarios): 6.2 hours
The TLPT revealed that while the Bank's perimeter defences and endpoint protection
are effective against commodity threats, sophisticated multi-stage attacks exploiting
trust relationships between internal systems can bypass detection for extended
periods. Two critical findings relate to the ability to move laterally from a
compromised treasury workstation to the payment processing infrastructure, and
the ability to extract authentication tokens from a misconfigured API gateway cache.
The Bank's SOC detected 4 of 6 attack scenarios, demonstrating adequate but
improvable detection capabilities. The two undetected scenarios exploited
legitimate administrative tools and encrypted channels that blended with normal
traffic patterns.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
THREAT INTELLIGENCE SUMMARY
ThreatScape Europe AG delivered the targeted threat intelligence report on
15 March 2025. The report identified the following primary threat actors and
attack vectors relevant to Nordvik Bank AG:
Threat Actor Profile 1: State-Sponsored Financial Espionage
Motivation: Intelligence gathering on financial flows and sanctions compliance
Capability: Advanced persistent threat (APT) with custom tooling
Relevance: Medium — Bank processes cross-border payments subject to sanctions
Threat Actor Profile 2: Organised Cybercrime (Ransomware)
Motivation: Financial gain through ransomware and data extortion
Capability: Sophisticated initial access via phishing and supply chain
Relevance: High — primary threat to mid-size European banks
Threat Actor Profile 3: Insider Threat (Privileged User)
Motivation: Financial gain or coercion
Capability: Legitimate access to critical systems
Relevance: Medium — Bank has 47 privileged users across IT and operations
The red team developed attack scenarios based on these threat profiles, simulating
realistic attack chains that a motivated adversary would employ against the Bank.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
RED TEAM ACTIVITIES
Scenario Threat Profile Target Function Detected?
─────────────────────────────────────────────────────────────────────────────
SC-01 Ransomware Customer Account Mgmt Yes (12h)
SC-02 APT Treasury Operations No
SC-03 Ransomware Retail Payment Processing Yes (8h)
SC-04 Insider Regulatory Reporting Yes (32h)
SC-05 APT Customer Authentication No
SC-06 Ransomware Customer Account Mgmt Yes (22h)
Detection Rate: 67% (4/6)
Average Detection Time (detected): 18.5 hours
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
ATTACK SCENARIOS EXECUTED
Scenario SC-01: Ransomware — Customer Account Management
Initial Access: Spear-phishing email with malicious macro document
Execution: Macro executed PowerShell downloader; CrowdStrike EDR
detected the payload but a modified variant evaded detection
Lateral Movement: Moved from compromised workstation to file server using
stolen credentials from memory
Objective: Encrypt customer account database
Result: Detected by SOC after 12 hours via anomalous file access
patterns. Contained within 4 hours of detection.
Impact Assessment: Moderate — attacker gained access to file server but was
contained before reaching database tier.
Scenario SC-02: APT — Treasury Operations
Initial Access: Compromised third-party market data feed update mechanism
Execution: Injected backdoor into legitimate software update package
Lateral Movement: Used legitimate administrative tools (PsExec, WMI) to
move from market data server to treasury workstation
Objective: Access payment initiation capability
Result: NOT DETECTED — red team maintained persistent access for
3 weeks. Lateral movement via legitimate tools blended
with normal administrative traffic.
Impact Assessment: Critical — demonstrates that supply chain compromise
combined with living-off-the-land techniques can bypass
current detection capabilities.
Scenario SC-03: Ransomware — Retail Payment Processing
Initial Access: Exploitation of vulnerable web application (staging instance
accessible from internet)
Execution: Web shell deployed on staging server; pivoted to production
network via shared service account
Lateral Movement: Service account had access to payment gateway configuration
Objective: Disrupt payment processing
Result: Detected by SOC after 8 hours via IDS alert on unusual
traffic from staging to production zone. Contained within
2 hours.
Impact Assessment: High — staging-to-production pivot path should not exist.
[Scenarios SC-04 through SC-06 detailed in Appendix A]
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
FINDINGS AND IMPACT
ID Severity Title
─────────────────────────────────────────────────────────────────────────────
TLPT-F01 Critical Lateral movement from treasury to payment systems
via trust relationship exploitation
TLPT-F02 Critical Authentication token extraction from API gateway
cache enabling session hijacking
TLPT-F03 High Supply chain attack vector via market data feed
update mechanism
TLPT-F04 High Staging-to-production network path via shared
service account
TLPT-F05 High Living-off-the-land techniques evade SIEM detection
rules (PsExec, WMI, PowerShell remoting)
TLPT-F06 High Insufficient monitoring of encrypted east-west
traffic in production zone
TLPT-F07 Medium Weak service account password policy (no rotation)
TLPT-F08 Medium Excessive file share permissions for IT staff
TLPT-F09 Medium Missing network segmentation between staging and
production environments
TLPT-F10 Medium Incomplete logging of administrative tool usage
TLPT-F11 Medium SOC playbooks lack procedures for supply chain
compromise scenarios
TLPT-F12 Low Outdated threat intelligence feeds in SIEM
TLPT-F13 Low Inconsistent endpoint hardening across server fleet
TLPT-F14 Low Missing alerting for dormant privileged accounts
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
DEFENCE TEAM RESPONSE ASSESSMENT
The Bank's Security Operations Centre (SOC) demonstrated competent detection and
response capabilities for known attack patterns. Key observations:
Strengths:
— Rapid containment once threats were detected (average 6.2 hours)
— Effective use of EDR for endpoint-level threat detection
— Good coordination between SOC and incident response team
— Appropriate escalation to CISO for critical detections
Areas for Improvement:
— Detection of living-off-the-land techniques requires enhanced behavioural
analytics and UEBA capabilities
— Supply chain compromise scenarios not covered in current SOC playbooks
— East-west encrypted traffic monitoring gap limits visibility
— Administrative tool usage monitoring insufficient for detecting
lateral movement via legitimate tools
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
REMEDIATION REQUIREMENTS
Priority Finding Recommended Action Deadline
─────────────────────────────────────────────────────────────────────────────
Immediate TLPT-F01 Segment treasury and payment 31 Jul 2025
systems; remove trust relationships
Immediate TLPT-F02 Secure API gateway cache; implement 31 Jul 2025
token binding and short-lived tokens
High TLPT-F03 Implement software supply chain 30 Sep 2025
integrity verification
High TLPT-F04 Isolate staging from production; 31 Aug 2025
eliminate shared service accounts
High TLPT-F05 Deploy UEBA and enhance SIEM rules 31 Oct 2025
for administrative tool monitoring
High TLPT-F06 Implement east-west TLS inspection 30 Sep 2025
Medium TLPT-F07 Implement service account password 30 Nov 2025
to F11 rotation; address remaining findings
Low TLPT-F12 Update threat intelligence feeds; 31 Dec 2025
to F14 address remaining low findings
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
COMPETENT AUTHORITY SUMMARY
A summary of this TLPT execution report will be submitted to FINMA in accordance
with DORA Article 26(6). The summary will include: scope of testing, threat
intelligence basis, key findings (anonymised where appropriate), defence team
performance metrics, and the remediation plan timeline.
Submission Reference: FINMA-TLPT-2025-NVK-001-REPORT
Planned Submission Date: August 2025
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Prepared by: RedForce Security BV
Lead Red Team Operator: [Red Team Lead]
Reviewed by: Katrin Halvorsen, CISO, Nordvik Bank AG
Date: 15 June 2025
Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).
tlpt_execution_status — fs-tlpt-execution-status
{
"factId": "c1d2e3f4-a5b6-7890-abcd-300000000006",
"evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000006",
"evidenceClassId": "tlpt-execution-report",
"factType": "tlpt_execution_status",
"data": {
"tlpt_date": "2025-06-10",
"tlpt_performed": true,
"covers_critical_functions": true,
"threat_intelligence_used": true,
"findings_count": 14,
"critical_findings": 2,
"defence_detection_rate_percent": 67.0,
"competent_authority_notified": true,
"next_tlpt_due_date": "2028-06-10"
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-06-20T09:00:00Z",
"supersededBy": null
}
tlpt_findings — fs-tlpt-findings
{
"factId": "c1d2e3f4-a5b6-7890-abcd-300000000007",
"evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000006",
"evidenceClassId": "tlpt-execution-report",
"factType": "tlpt_findings",
"data": {
"tlpt_id": "TLPT-2025-001",
"total_findings": 14,
"critical_findings": 2,
"high_findings": 4,
"remediation_plan_exists": true,
"remediation_actions_count": 14,
"remediation_completed_count": 0,
"target_completion_date": "2025-12-31"
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-07-05T09:00:00Z",
"supersededBy": null
}
XML-structured remediation plan addressing findings from threat-led penetration testing, including prioritised actions, responsible owners, timelines, and validation criteria.
tlpt-remediation-planGenerated example artifact using the default institution profile (COMMON availability, synthetic data only).
<?xml version="1.0" encoding="UTF-8"?>
<TLPTRemediationPlan
planId="TLPT-REM-2025-001"
tlptId="TLPT-2025-001"
creationDate="2025-07-01"
institution="Nordvik Bank AG"
totalActions="14"
criticalActions="2"
targetCompletionDate="2025-12-31"
validationMethod="Targeted retesting by independent provider"
approvedBy="Katrin Halvorsen, CISO"
approvalDate="2025-07-05">
<!-- ═══════════════════════════════════════════════════════════════════════
REMEDIATION ACTIONS — CRITICAL PRIORITY
═══════════════════════════════════════════════════════════════════════ -->
<RemediationActions priority="Critical">
<Action actionId="REM-001" findingRef="TLPT-F01" status="In Progress">
<Title>Segment Treasury and Payment Systems</Title>
<Description>Implement strict network segmentation between treasury
workstations and payment processing infrastructure. Remove all trust
relationships that allow lateral movement between these zones. Deploy
micro-segmentation using Illumio or equivalent for granular control.</Description>
<ResponsibleOwner>Network Operations Team Lead</ResponsibleOwner>
<TargetDate>2025-07-31</TargetDate>
<EstimatedEffort unit="person-days">25</EstimatedEffort>
<ValidationCriteria>
<Criterion>No direct network path from treasury zone to payment zone</Criterion>
<Criterion>All cross-zone traffic routed through application proxy</Criterion>
<Criterion>Penetration test confirms segmentation effectiveness</Criterion>
</ValidationCriteria>
<Dependencies>
<Dependency>Firewall change request approved (CR-2025-0891)</Dependency>
<Dependency>Application proxy deployment complete</Dependency>
</Dependencies>
</Action>
<Action actionId="REM-002" findingRef="TLPT-F02" status="In Progress">
<Title>Secure API Gateway Cache and Token Management</Title>
<Description>Reconfigure API gateway to prevent caching of authentication
tokens. Implement token binding to client IP and device fingerprint.
Reduce JWT token lifetime from 4 hours to 15 minutes with refresh
token rotation.</Description>
<ResponsibleOwner>Application Security Team Lead</ResponsibleOwner>
<TargetDate>2025-07-31</TargetDate>
<EstimatedEffort unit="person-days">15</EstimatedEffort>
<ValidationCriteria>
<Criterion>API gateway cache does not store authentication tokens</Criterion>
<Criterion>Token binding prevents token reuse from different client</Criterion>
<Criterion>JWT lifetime reduced to 15 minutes</Criterion>
<Criterion>Refresh token rotation implemented and tested</Criterion>
</ValidationCriteria>
<Dependencies>
<Dependency>API gateway vendor support engagement (case SR-44521)</Dependency>
</Dependencies>
</Action>
</RemediationActions>
<!-- ═══════════════════════════════════════════════════════════════════════
REMEDIATION ACTIONS — HIGH PRIORITY
═══════════════════════════════════════════════════════════════════════ -->
<RemediationActions priority="High">
<Action actionId="REM-003" findingRef="TLPT-F03" status="Planned">
<Title>Implement Software Supply Chain Integrity Verification</Title>
<Description>Deploy software supply chain security controls for all
third-party software updates, including cryptographic signature
verification, hash validation, and sandboxed testing before
production deployment. Prioritise market data feed and core
banking update channels.</Description>
<ResponsibleOwner>IT Operations Team Lead</ResponsibleOwner>
<TargetDate>2025-09-30</TargetDate>
<EstimatedEffort unit="person-days">30</EstimatedEffort>
<ValidationCriteria>
<Criterion>All critical software updates verified via cryptographic signature</Criterion>
<Criterion>Sandboxed testing environment operational for update validation</Criterion>
<Criterion>Automated alerting for unsigned or modified update packages</Criterion>
</ValidationCriteria>
<Dependencies>
<Dependency>Vendor cooperation for signature verification keys</Dependency>
<Dependency>Sandbox environment provisioning (AWS)</Dependency>
</Dependencies>
</Action>
<Action actionId="REM-004" findingRef="TLPT-F04" status="Planned">
<Title>Isolate Staging from Production Environment</Title>
<Description>Implement complete network isolation between staging and
production environments. Eliminate all shared service accounts.
Deploy separate identity stores for staging and production.</Description>
<ResponsibleOwner>Infrastructure Team Lead</ResponsibleOwner>
<TargetDate>2025-08-31</TargetDate>
<EstimatedEffort unit="person-days">20</EstimatedEffort>
<ValidationCriteria>
<Criterion>No network connectivity between staging and production zones</Criterion>
<Criterion>No shared service accounts across environments</Criterion>
<Criterion>Separate Active Directory OUs for staging and production</Criterion>
</ValidationCriteria>
<Dependencies>
<Dependency>Service account audit complete (REM-007)</Dependency>
</Dependencies>
</Action>
<Action actionId="REM-005" findingRef="TLPT-F05" status="Planned">
<Title>Deploy UEBA and Enhance Administrative Tool Monitoring</Title>
<Description>Deploy User and Entity Behaviour Analytics (UEBA) solution
to detect anomalous use of legitimate administrative tools (PsExec,
WMI, PowerShell remoting). Create SIEM correlation rules for
living-off-the-land attack patterns.</Description>
<ResponsibleOwner>SOC Manager</ResponsibleOwner>
<TargetDate>2025-10-31</TargetDate>
<EstimatedEffort unit="person-days">40</EstimatedEffort>
<ValidationCriteria>
<Criterion>UEBA solution deployed and baselined for all privileged users</Criterion>
<Criterion>SIEM rules detect PsExec, WMI, and PowerShell remoting anomalies</Criterion>
<Criterion>Purple team exercise validates detection of LOTL techniques</Criterion>
</ValidationCriteria>
<Dependencies>
<Dependency>UEBA vendor selection and procurement (Q3 2025 budget)</Dependency>
</Dependencies>
</Action>
<Action actionId="REM-006" findingRef="TLPT-F06" status="Planned">
<Title>Implement East-West TLS Inspection</Title>
<Description>Deploy TLS inspection capability for encrypted traffic
within the production zone to enable detection of malicious
activity in encrypted channels between application servers.</Description>
<ResponsibleOwner>Network Security Engineer</ResponsibleOwner>
<TargetDate>2025-09-30</TargetDate>
<EstimatedEffort unit="person-days">20</EstimatedEffort>
<ValidationCriteria>
<Criterion>TLS inspection active for production zone east-west traffic</Criterion>
<Criterion>Decrypted traffic fed to SIEM and IDS for analysis</Criterion>
<Criterion>No performance degradation exceeding 5% on inspected paths</Criterion>
</ValidationCriteria>
<Dependencies>
<Dependency>Internal CA certificate deployment to all production servers</Dependency>
</Dependencies>
</Action>
</RemediationActions>
<!-- ═══════════════════════════════════════════════════════════════════════
REMEDIATION ACTIONS — MEDIUM PRIORITY
═══════════════════════════════════════════════════════════════════════ -->
<RemediationActions priority="Medium">
<Action actionId="REM-007" findingRef="TLPT-F07" status="Planned">
<Title>Implement Service Account Password Rotation</Title>
<Description>Deploy automated service account password rotation using
CyberArk for all service accounts. Implement 90-day rotation policy
with automated credential distribution.</Description>
<ResponsibleOwner>IAM Team Lead</ResponsibleOwner>
<TargetDate>2025-11-30</TargetDate>
<EstimatedEffort unit="person-days">15</EstimatedEffort>
<ValidationCriteria>
<Criterion>All service accounts enrolled in CyberArk rotation</Criterion>
<Criterion>90-day rotation policy enforced</Criterion>
</ValidationCriteria>
</Action>
<Action actionId="REM-008" findingRef="TLPT-F08" status="Planned">
<Title>Review and Restrict File Share Permissions</Title>
<ResponsibleOwner>IT Operations Team Lead</ResponsibleOwner>
<TargetDate>2025-11-30</TargetDate>
<EstimatedEffort unit="person-days">10</EstimatedEffort>
<ValidationCriteria>
<Criterion>Least-privilege access enforced on all file shares</Criterion>
</ValidationCriteria>
</Action>
<Action actionId="REM-009" findingRef="TLPT-F09" status="Planned">
<Title>Complete Staging-Production Network Isolation</Title>
<ResponsibleOwner>Network Operations Team Lead</ResponsibleOwner>
<TargetDate>2025-08-31</TargetDate>
<EstimatedEffort unit="person-days">10</EstimatedEffort>
<ValidationCriteria>
<Criterion>Firewall rules block all staging-to-production traffic</Criterion>
</ValidationCriteria>
</Action>
<Action actionId="REM-010" findingRef="TLPT-F10" status="Planned">
<Title>Enhance Administrative Tool Logging</Title>
<ResponsibleOwner>SOC Manager</ResponsibleOwner>
<TargetDate>2025-10-31</TargetDate>
<EstimatedEffort unit="person-days">8</EstimatedEffort>
<ValidationCriteria>
<Criterion>All administrative tool usage logged and forwarded to SIEM</Criterion>
</ValidationCriteria>
</Action>
<Action actionId="REM-011" findingRef="TLPT-F11" status="Planned">
<Title>Develop Supply Chain Compromise SOC Playbooks</Title>
<ResponsibleOwner>SOC Manager</ResponsibleOwner>
<TargetDate>2025-09-30</TargetDate>
<EstimatedEffort unit="person-days">5</EstimatedEffort>
<ValidationCriteria>
<Criterion>Supply chain compromise playbook documented and tested</Criterion>
<Criterion>SOC analysts trained on new playbook</Criterion>
</ValidationCriteria>
</Action>
</RemediationActions>
<!-- ═══════════════════════════════════════════════════════════════════════
REMEDIATION ACTIONS — LOW PRIORITY
═══════════════════════════════════════════════════════════════════════ -->
<RemediationActions priority="Low">
<Action actionId="REM-012" findingRef="TLPT-F12" status="Planned">
<Title>Update Threat Intelligence Feeds in SIEM</Title>
<ResponsibleOwner>SOC Manager</ResponsibleOwner>
<TargetDate>2025-12-31</TargetDate>
<EstimatedEffort unit="person-days">3</EstimatedEffort>
</Action>
<Action actionId="REM-013" findingRef="TLPT-F13" status="Planned">
<Title>Standardise Server Hardening Across Fleet</Title>
<ResponsibleOwner>Infrastructure Team Lead</ResponsibleOwner>
<TargetDate>2025-12-31</TargetDate>
<EstimatedEffort unit="person-days">15</EstimatedEffort>
</Action>
<Action actionId="REM-014" findingRef="TLPT-F14" status="Planned">
<Title>Implement Dormant Privileged Account Alerting</Title>
<ResponsibleOwner>IAM Team Lead</ResponsibleOwner>
<TargetDate>2025-12-31</TargetDate>
<EstimatedEffort unit="person-days">5</EstimatedEffort>
</Action>
</RemediationActions>
<!-- ═══════════════════════════════════════════════════════════════════════
TRACKING AND VALIDATION
═══════════════════════════════════════════════════════════════════════ -->
<TrackingAndValidation>
<ReviewFrequency>Monthly review by ICT Risk Committee</ReviewFrequency>
<EscalationThreshold>Any critical action overdue by more than 2 weeks</EscalationThreshold>
<ValidationApproach>Independent retesting of critical and high findings by
RedForce Security BV upon remediation completion</ValidationApproach>
<CompetentAuthorityReporting>Remediation progress included in FINMA
TLPT summary report (August 2025)</CompetentAuthorityReporting>
</TrackingAndValidation>
</TLPTRemediationPlan>
Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).
tlpt_execution_status — fs-tlpt-execution-status
{
"factId": "c1d2e3f4-a5b6-7890-abcd-300000000006",
"evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000006",
"evidenceClassId": "tlpt-execution-report",
"factType": "tlpt_execution_status",
"data": {
"tlpt_date": "2025-06-10",
"tlpt_performed": true,
"covers_critical_functions": true,
"threat_intelligence_used": true,
"findings_count": 14,
"critical_findings": 2,
"defence_detection_rate_percent": 67.0,
"competent_authority_notified": true,
"next_tlpt_due_date": "2028-06-10"
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-06-20T09:00:00Z",
"supersededBy": null
}
tlpt_findings — fs-tlpt-findings
{
"factId": "c1d2e3f4-a5b6-7890-abcd-300000000007",
"evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000006",
"evidenceClassId": "tlpt-execution-report",
"factType": "tlpt_findings",
"data": {
"tlpt_id": "TLPT-2025-001",
"total_findings": 14,
"critical_findings": 2,
"high_findings": 4,
"remediation_plan_exists": true,
"remediation_actions_count": 14,
"remediation_completed_count": 0,
"target_completion_date": "2025-12-31"
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-07-05T09:00:00Z",
"supersededBy": null
}
fs-tlpt-execution-statusDORA-Art26-P1tlpt_datenext_tlpt_due_date{
"properties": {
"competent_authority_notified": {
"type": "boolean"
},
"covers_critical_functions": {
"type": "boolean"
},
"critical_findings": {
"minimum": 0,
"type": "integer"
},
"defence_detection_rate_percent": {
"maximum": 100,
"minimum": 0,
"type": "number"
},
"findings_count": {
"minimum": 0,
"type": "integer"
},
"next_tlpt_due_date": {
"format": "date",
"type": "string"
},
"threat_intelligence_used": {
"type": "boolean"
},
"tlpt_date": {
"format": "date",
"type": "string"
},
"tlpt_performed": {
"type": "boolean"
}
},
"required": [
"tlpt_date",
"tlpt_performed",
"covers_critical_functions",
"findings_count"
],
"type": "object"
}
fs-tlpt-findingsDORA-Art26-P1remediation_completed_counttarget_completion_date{
"properties": {
"critical_findings": {
"minimum": 0,
"type": "integer"
},
"high_findings": {
"minimum": 0,
"type": "integer"
},
"remediation_actions_count": {
"minimum": 0,
"type": "integer"
},
"remediation_completed_count": {
"minimum": 0,
"type": "integer"
},
"remediation_plan_exists": {
"type": "boolean"
},
"target_completion_date": {
"format": "date",
"type": "string"
},
"tlpt_id": {
"minLength": 1,
"type": "string"
},
"total_findings": {
"minimum": 0,
"type": "integer"
}
},
"required": [
"tlpt_id",
"total_findings",
"critical_findings",
"remediation_plan_exists"
],
"type": "object"
}