TIBER-EU Red Teaming
TIBER-EU red teaming aligned to the ECB framework: intelligence-led attacks on your live estate, coordinated with your authority. Get a fixed quote.
TIBER-EU red teaming is a controlled, intelligence-led attack on your live production estate that mimics the groups actually targeting European financial firms, run to the shape the European Central Bank laid out in its framework. We plan it, source real threat intelligence, break in the way a motivated adversary would, and give you a report your board and your regulator can both read.
What TIBER-EU red teaming actually covers
This is not a scoped web app test with a start URL and a login. A TIBER-style engagement starts from the outside with almost nothing, picks the critical business functions that would hurt if they went down or leaked, and works toward them across email, exposed services, cloud tenants, staff, and physical entry points. The point is to find out whether your live defenses and your response team notice, and how far a real intruder would get before someone pulled the alarm.
SafetyBis runs these engagements across Europe as a threat-intelligence-based red team provider aligned to the TIBER-EU framework. We do not issue our own regulatory accreditation, and no vendor should tell you they do. Formal TIBER tests are coordinated with your competent authority and its TIBER Cyber Team, who validate the process; our job is the intelligence and the attack, delivered to the framework’s standard so the test counts.
How a TIBER-EU engagement runs, phase by phase
The framework splits the work into three formal stages, each with named artifacts. We keep the same shape whether you are doing a full regulator-facing test or a TIBER-aligned rehearsal before the real one. The threat-led penetration testing model runs long by design, usually a few months end to end, because the intelligence and the stealth take time.
Preparation phase
You stand up a small White Team who know the test is happening and control it. We agree the critical functions in scope, the rules of engagement, the legal cover, and the flags that count as success. For a formal test your authority’s TIBER Cyber Team joins here to validate scope and process. Nothing touches production until this is signed.
Scoping the critical functions
We work out which systems, if breached, would actually threaten your operations or your customers: the payment rail, the core banking platform, the trade settlement flow, the customer database. Those become the targets. Everything else is a route, not a goal.
Testing phase
This has two halves. First, threat intelligence: a provider builds a Targeted Threat Intelligence report describing the specific actors likely to attack your firm, their tooling and their favored techniques, referenced to MITRE ATT&CK. Then the red team turns that intelligence into attack scenarios and executes them against the live estate.
Threat intelligence
Good intelligence is what separates TIBER from a generic red team. We ground each scenario in what a named category of attacker really does against European finance, so the test rehearses a plausible breach rather than a textbook one.
Red team execution
We attempt initial access, establish a foothold, escalate, move laterally and reach for the flags, staying quiet enough to test whether your monitoring catches us. Tooling is a mix of custom implants, Cobalt Strike or Sliver for command and control, and hands-on tradecraft; the emphasis is on realistic operator behavior, not noisy scanning.
Closure phase
We stop, come clean to the blue team, and walk them through every step in a replay. You get the red team test report, the blue team writes its own account, and together you produce a remediation plan and a test summary the authority reviews. Attestation of the process, where required, is handled with your TIBER Cyber Team.
The attack techniques we bring
Because the goal is realism, the technique set is broad. We do not limit ourselves to one entry route, because a real intruder does not either.
Social engineering and initial access
Spear-phishing against named staff, pretext calls, and payload delivery that beats mail filtering. Most breaches we replay start with one convincing email, not an exploit.
External infrastructure and cloud
We map your internet-facing surface, hunt for exposed admin panels, forgotten VPN gateways, leaked credentials, and misconfigured AWS, Azure or GCP tenants that hand over a foothold without a single phish.
Lateral movement and privilege escalation
Once inside, we go after Active Directory, Kerberos abuse, credential harvesting, and the trust relationships between systems that let a low-value box reach a high-value one. This is where detection usually fails, so it is where we spend our time.
Reaching the flags
The final act is proving impact on a critical function without causing harm: showing we could move funds, exfiltrate the customer database, or halt a settlement process, then stopping short of the damage.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
What you receive
The deliverables are built for two audiences at once. Your executives need to understand business risk in a page; your engineers need enough detail to reproduce and fix every step.
Red team test report
A full narrative of the attack path, each technique tagged to MITRE ATT&CK, with the evidence, the detection gaps, and a CVSS-scored breakdown of the technical findings that made the path possible.
Remediation plan and replay
A prioritized fix list you can hand straight to your teams, plus the purple-team session where we rerun the attack with your defenders watching, so remediation is understood, not just documented. A retest of the fixes is included.
How this maps to European supervision
TIBER-EU is the European Central Bank’s common framework for threat-led testing, and national implementations exist across the euro area and beyond. It is increasingly the accepted way to meet the advanced-testing expectations that regulators place on significant financial entities. For firms in scope of DORA, a TIBER-style test aligns closely with the threat-led penetration testing obligations in Regulation (EU) 2022/2554, Articles 24 to 27, and the accompanying regulatory technical standards on TLPT.
Working with your authority
Where a formal, regulator-recognized test is required, the process is owned by your competent authority and its TIBER Cyber Team. We slot in as the red team provider and coordinate with them throughout, delivering to the framework so the outcome is one the supervisor accepts.
ISO 27001 and internal assurance
Even outside a formal mandate, the results feed your ISO 27001 risk treatment and give your board defensible evidence that controls work against a real adversary, not a checklist.
Why manual red teaming beats an automated tool
A scanner tells you a port is open. It cannot phone your finance team, forge a plausible invoice, sit quietly on a compromised laptop for two weeks, or decide which of three routes to a payment system your monitoring is least likely to see. TIBER exists precisely because those human decisions are what a real attacker makes, and only a human operator can rehearse them. Automated testing has a place earlier in your program, at the vulnerability layer. Threat-led red teaming answers a different question: when a capable adversary comes for your critical functions, does anyone stop them?
Scenarios we commonly run for European financial firms
Every test is grounded in your own threat intelligence, but a few scenarios recur because they match how attackers really behave against the sector. We usually run two or three in a single engagement, each aimed at a different critical function.
The finance-team invoice compromise
An operator phishes a member of the finance or treasury team, lands on their workstation, and pivots toward the payment approval system. The flag is proving we could alter or authorize a transfer. This scenario tests both technical controls and the human process around money movement, which is where fraud losses actually happen.
The exposed remote-access foothold
We find a forgotten VPN concentrator, an internet-facing management interface, or a set of leaked credentials from a past breach, and use it to get inside without touching a single employee. Firms are often surprised how much of their perimeter they had lost track of.
The third-party and supply-chain route
Many financial breaches arrive through a supplier or a managed service provider with standing access. Where scope allows, we model that trust relationship and show what an attacker who compromised your vendor could reach inside your network.
Pricing
Threat-led red teaming is priced by the breadth of the estate, the number of critical functions in scope, the depth of the intelligence phase, and whether the test is a full regulator-facing exercise or a scoped rehearsal. Every engagement is fixed-price after a scoping call, never billed by the hour.
| Engagement | What’s included | Timeline | Price |
|---|---|---|---|
| Red-team readiness | Scoped adversary simulation against one critical function, phishing plus external access, findings report and replay | 3–4 weeks | from €12,000 |
| TIBER-aligned test | Targeted threat intelligence, multi-scenario attack across chosen critical functions, full red team report, remediation plan | 8–12 weeks | €18,000–€35,000 |
| Formal regulator-facing test | Full framework delivery coordinated with your authority’s TIBER Cyber Team, White/Blue team support, closure artifacts | 10–16 weeks | from €35,000 |
| Purple-team add-on | Extended collaborative replay and detection-engineering workshop with your SOC after the test | 3–5 days | from €4,500 |
| Custom / group estate | Multi-entity or cross-border financial group, scoped after a free call | on scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call, with the replay and a retest of fixes included. Get a fixed quote
FAQ
How much does a TIBER-EU red teaming engagement cost?
Are you an accredited TIBER-EU provider?
How long does a threat-led penetration testing engagement take?
Will the test disrupt our live services?
Does this satisfy DORA threat-led testing requirements?
Who on our side needs to know the test is happening?
What is the difference between this and a normal penetration test?
Are the findings kept confidential?
Related services
Banks, payment institutions, insurers, trading venues and other significant financial entities across Europe that face a supervisory expectation for advanced, intelligence-led testing, or that want honest proof their detection and response would stop a real attacker before a formal TIBER or DORA exercise.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.