Home/Services/TIBER-EU Red Teaming
security service

TIBER-EU Red Teaming

TIBER-EU red teaming aligned to the ECB framework: intelligence-led attacks on your live estate, coordinated with your authority. Get a fixed quote.

Manual, expert-ledEvidence-based findingsFree remediation retest

TIBER-EU red teaming is a controlled, intelligence-led attack on your live production estate that mimics the groups actually targeting European financial firms, run to the shape the European Central Bank laid out in its framework. We plan it, source real threat intelligence, break in the way a motivated adversary would, and give you a report your board and your regulator can both read.

What TIBER-EU red teaming actually covers

This is not a scoped web app test with a start URL and a login. A TIBER-style engagement starts from the outside with almost nothing, picks the critical business functions that would hurt if they went down or leaked, and works toward them across email, exposed services, cloud tenants, staff, and physical entry points. The point is to find out whether your live defenses and your response team notice, and how far a real intruder would get before someone pulled the alarm.

SafetyBis runs these engagements across Europe as a threat-intelligence-based red team provider aligned to the TIBER-EU framework. We do not issue our own regulatory accreditation, and no vendor should tell you they do. Formal TIBER tests are coordinated with your competent authority and its TIBER Cyber Team, who validate the process; our job is the intelligence and the attack, delivered to the framework’s standard so the test counts.

Targeted threat intelligence report profiling the actors that hit your sector
Attack against your critical economic and business functions, chosen with you
Initial access via phishing, exposed infrastructure or a supplier, then lateral movement
Live testing that measures detection and response, not just vulnerabilities
Purple-teaming replay so your blue team sees each step it missed
A red team test report and remediation plan mapped to your critical functions

How a TIBER-EU engagement runs, phase by phase

The framework splits the work into three formal stages, each with named artifacts. We keep the same shape whether you are doing a full regulator-facing test or a TIBER-aligned rehearsal before the real one. The threat-led penetration testing model runs long by design, usually a few months end to end, because the intelligence and the stealth take time.

Preparation phase

You stand up a small White Team who know the test is happening and control it. We agree the critical functions in scope, the rules of engagement, the legal cover, and the flags that count as success. For a formal test your authority’s TIBER Cyber Team joins here to validate scope and process. Nothing touches production until this is signed.

Scoping the critical functions

We work out which systems, if breached, would actually threaten your operations or your customers: the payment rail, the core banking platform, the trade settlement flow, the customer database. Those become the targets. Everything else is a route, not a goal.

Testing phase

This has two halves. First, threat intelligence: a provider builds a Targeted Threat Intelligence report describing the specific actors likely to attack your firm, their tooling and their favored techniques, referenced to MITRE ATT&CK. Then the red team turns that intelligence into attack scenarios and executes them against the live estate.

Threat intelligence

Good intelligence is what separates TIBER from a generic red team. We ground each scenario in what a named category of attacker really does against European finance, so the test rehearses a plausible breach rather than a textbook one.

Red team execution

We attempt initial access, establish a foothold, escalate, move laterally and reach for the flags, staying quiet enough to test whether your monitoring catches us. Tooling is a mix of custom implants, Cobalt Strike or Sliver for command and control, and hands-on tradecraft; the emphasis is on realistic operator behavior, not noisy scanning.

Closure phase

We stop, come clean to the blue team, and walk them through every step in a replay. You get the red team test report, the blue team writes its own account, and together you produce a remediation plan and a test summary the authority reviews. Attestation of the process, where required, is handled with your TIBER Cyber Team.

10–14
weeks for a typical threat-led engagement
100%
manual operator tradecraft, no scanner dumps
Free
purple-team replay so your defenders learn every step

The attack techniques we bring

Because the goal is realism, the technique set is broad. We do not limit ourselves to one entry route, because a real intruder does not either.

Social engineering and initial access

Spear-phishing against named staff, pretext calls, and payload delivery that beats mail filtering. Most breaches we replay start with one convincing email, not an exploit.

External infrastructure and cloud

We map your internet-facing surface, hunt for exposed admin panels, forgotten VPN gateways, leaked credentials, and misconfigured AWS, Azure or GCP tenants that hand over a foothold without a single phish.

Lateral movement and privilege escalation

Once inside, we go after Active Directory, Kerberos abuse, credential harvesting, and the trust relationships between systems that let a low-value box reach a high-value one. This is where detection usually fails, so it is where we spend our time.

Reaching the flags

The final act is proving impact on a critical function without causing harm: showing we could move funds, exfiltrate the customer database, or halt a settlement process, then stopping short of the damage.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

What you receive

The deliverables are built for two audiences at once. Your executives need to understand business risk in a page; your engineers need enough detail to reproduce and fix every step.

Red team test report

A full narrative of the attack path, each technique tagged to MITRE ATT&CK, with the evidence, the detection gaps, and a CVSS-scored breakdown of the technical findings that made the path possible.

Remediation plan and replay

A prioritized fix list you can hand straight to your teams, plus the purple-team session where we rerun the attack with your defenders watching, so remediation is understood, not just documented. A retest of the fixes is included.

How this maps to European supervision

TIBER-EU is the European Central Bank’s common framework for threat-led testing, and national implementations exist across the euro area and beyond. It is increasingly the accepted way to meet the advanced-testing expectations that regulators place on significant financial entities. For firms in scope of DORA, a TIBER-style test aligns closely with the threat-led penetration testing obligations in Regulation (EU) 2022/2554, Articles 24 to 27, and the accompanying regulatory technical standards on TLPT.

Working with your authority

Where a formal, regulator-recognized test is required, the process is owned by your competent authority and its TIBER Cyber Team. We slot in as the red team provider and coordinate with them throughout, delivering to the framework so the outcome is one the supervisor accepts.

ISO 27001 and internal assurance

Even outside a formal mandate, the results feed your ISO 27001 risk treatment and give your board defensible evidence that controls work against a real adversary, not a checklist.

Why manual red teaming beats an automated tool

A scanner tells you a port is open. It cannot phone your finance team, forge a plausible invoice, sit quietly on a compromised laptop for two weeks, or decide which of three routes to a payment system your monitoring is least likely to see. TIBER exists precisely because those human decisions are what a real attacker makes, and only a human operator can rehearse them. Automated testing has a place earlier in your program, at the vulnerability layer. Threat-led red teaming answers a different question: when a capable adversary comes for your critical functions, does anyone stop them?

Scenarios we commonly run for European financial firms

Every test is grounded in your own threat intelligence, but a few scenarios recur because they match how attackers really behave against the sector. We usually run two or three in a single engagement, each aimed at a different critical function.

The finance-team invoice compromise

An operator phishes a member of the finance or treasury team, lands on their workstation, and pivots toward the payment approval system. The flag is proving we could alter or authorize a transfer. This scenario tests both technical controls and the human process around money movement, which is where fraud losses actually happen.

The exposed remote-access foothold

We find a forgotten VPN concentrator, an internet-facing management interface, or a set of leaked credentials from a past breach, and use it to get inside without touching a single employee. Firms are often surprised how much of their perimeter they had lost track of.

The third-party and supply-chain route

Many financial breaches arrive through a supplier or a managed service provider with standing access. Where scope allows, we model that trust relationship and show what an attacker who compromised your vendor could reach inside your network.

Pricing

Threat-led red teaming is priced by the breadth of the estate, the number of critical functions in scope, the depth of the intelligence phase, and whether the test is a full regulator-facing exercise or a scoped rehearsal. Every engagement is fixed-price after a scoping call, never billed by the hour.

Engagement What’s included Timeline Price
Red-team readiness Scoped adversary simulation against one critical function, phishing plus external access, findings report and replay 3–4 weeks from €12,000
TIBER-aligned test Targeted threat intelligence, multi-scenario attack across chosen critical functions, full red team report, remediation plan 8–12 weeks €18,000–€35,000
Formal regulator-facing test Full framework delivery coordinated with your authority’s TIBER Cyber Team, White/Blue team support, closure artifacts 10–16 weeks from €35,000
Purple-team add-on Extended collaborative replay and detection-engineering workshop with your SOC after the test 3–5 days from €4,500
Custom / group estate Multi-entity or cross-border financial group, scoped after a free call on scoping custom

Every engagement is fixed-price, quoted after a free 20-minute scoping call, with the replay and a retest of fixes included. Get a fixed quote

FAQ

How much does a TIBER-EU red teaming engagement cost?
A scoped threat-led engagement starts from €12,000, with a typical TIBER-aligned test landing between €18,000 and €35,000 depending on the number of critical functions and the depth of the intelligence phase. You get a fixed quote after a free scoping call.
Are you an accredited TIBER-EU provider?
Formal TIBER tests are validated by your competent authority and its TIBER Cyber Team, who own the process. We act as the red team provider, deliver to the TIBER-EU framework, and coordinate with the authority so the test meets its standard. We do not claim to issue regulatory accreditation ourselves.
How long does a threat-led penetration testing engagement take?
A full TIBER-aligned test usually runs 8 to 12 weeks because the threat intelligence and the stealthy attack both take time. A scoped readiness exercise can be done in 3 to 4 weeks.
Will the test disrupt our live services?
No. We operate carefully on production, agree destructive actions in advance with your White Team, and stop short of causing harm once we have proven access to a critical function. Availability is never the price of the test.
Does this satisfy DORA threat-led testing requirements?
A TIBER-style engagement aligns closely with the TLPT obligations in Regulation (EU) 2022/2554, Articles 24 to 27, and the RTS on threat-led penetration testing. For a formal DORA TLPT, the exercise is coordinated with your authority, and we deliver the red team component to that standard.
Who on our side needs to know the test is happening?
Only a small White Team. The point is to test your blue team and monitoring without warning, so detection is measured honestly. We help you set up that control group during the preparation phase.
What is the difference between this and a normal penetration test?
A penetration test scopes a system and finds its vulnerabilities. Threat-led red teaming starts with real intelligence on who attacks your sector, works across your whole estate toward critical business functions, and measures whether your people and defenses detect and respond. It answers a broader question about real-world resilience.
Are the findings kept confidential?
Yes. We work under NDA, handle all evidence and the red team report through secure channels, and share results only with your nominated White Team and, for a formal test, your authority.

Related services

Who needs this

Banks, payment institutions, insurers, trading venues and other significant financial entities across Europe that face a supervisory expectation for advanced, intelligence-led testing, or that want honest proof their detection and response would stop a real attacker before a formal TIBER or DORA exercise.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "TIBER-EU Red Teaming"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.