TLPT — Red Team dirigido por InteligenciaTLPT — Threat-Led Red Teaming
Ejercicio guiado por inteligencia de amenazas real, coordinado con el regulador.Exercise driven by real threat intelligence and coordinated with the regulator.
¿Qué es este servicio?What is this service?
Es un ejercicio de red team dirigido por inteligencia de amenazas: en vez de atacar con técnicas genéricas, se investiga primero qué adversarios atacan de verdad al sector en el que opera la entidad y se reproducen sus tácticas concretas. El marco europeo de referencia es TIBER-EU.
A threat-led red team exercise: instead of attacking with generic techniques, it first researches which adversaries genuinely target the sector in which the entity operates and reproduces their specific tactics. The European reference framework is TIBER-EU.
¿Para qué se usa?What is it used for?
Sirve para responder si la entidad resiste al adversario que de verdad la va a atacar, y no a uno hipotético. Tiene dos fases claramente separadas: una de inteligencia, que produce los escenarios basados en amenazas reales, y otra de ejecución, que los reproduce sobre sistemas en producción. En el ámbito regulado, participa además el supervisor.
It establishes whether the entity can withstand the adversary that will actually target it, not a hypothetical one. It has two clearly separated phases: an intelligence phase producing scenarios based on real threats, and an execution phase reproducing them against production systems. In the regulated setting, the supervisor participates too.
Qué beneficios traeBenefits it delivers
- Los escenarios se basan en amenazas documentadas contra el sector y la geografía de la entidad, no en un catálogo genérico.
- Se ejecuta sobre producción, que es el único sitio donde el resultado significa algo.
- Cumple con la exigencia regulatoria europea de pruebas dirigidas por amenazas, cuando aplica.
- El informe conjunto entre atacantes y defensores deja un plan de mejora consensuado, no una lista de reproches.
- Scenarios are based on threats documented against the sector and geography of the entity, not a generic catalogue.
- It runs against production, the only place where the result means anything.
- It satisfies the European regulatory requirement for threat-led testing, where applicable.
- The joint report between attackers and defenders leaves an agreed improvement plan rather than a list of reproaches.
¿En qué momentos es obligatorio?When is it mandatory?
Costa RicaCosta Rica
- No es obligatorio en Costa Rica: no hay un marco local equivalente a TIBER-EU.
- Para una entidad supervisada puede ser la evidencia más sólida de gestión de riesgo tecnológico, pero el Acuerdo CONASSIF 5-24 no lo exige.
- Tiene sentido si el grupo financiero también opera en Europa y quiere un solo ejercicio para ambos marcos.
- It is not mandatory in Costa Rica: there is no local framework equivalent to TIBER-EU.
- For a supervised entity it can be the strongest evidence of technology risk management, but CONASSIF Agreement 5-24 does not require it.
- It makes sense if the financial group also operates in Europe and wants a single exercise covering both frameworks.
InternacionalInternational
- DORA obliga a las entidades financieras europeas identificadas por su autoridad a someterse a pruebas de penetración dirigidas por amenazas.
- TIBER-EU es el marco de referencia para ejecutarlas, adoptado por bancos centrales de la zona.
- Estas pruebas se realizan sobre sistemas de producción y con una periodicidad definida por el marco aplicable.
- DORA requires European financial entities identified by their authority to undergo threat-led penetration testing.
- TIBER-EU is the reference framework for running them, adopted by central banks across the area.
- These tests are performed against production systems at a frequency defined by the applicable framework.
Requisitos mínimosMinimum requirements
- Madurez alta: este ejercicio no tiene sentido sin capacidad de detección y respuesta ya funcionando.
- Proveedor de inteligencia de amenazas y proveedor de pruebas, que en varios marcos deben ser independientes entre sí.
- Un equipo de control interno reducido, el único que sabe del ejercicio.
- Coordinación con el supervisor cuando el ejercicio se hace bajo un marco regulatorio.
- High maturity: the exercise makes no sense without detection and response capability already working.
- A threat intelligence provider and a testing provider, which several frameworks require to be independent of each other.
- A small internal control team, the only people who know about the exercise.
- Coordination with the supervisor when the exercise runs under a regulatory framework.
Plazo típico de entregaTypical delivery time
El rango habitual del mercado va de cuatro a nueve meses de punta a punta. La fase de inteligencia toma entre cuatro y ocho semanas, la de ejecución entre ocho y doce, y el resto es preparación, coordinación con el supervisor y cierre conjunto. Es el ejercicio más largo y más caro del catálogo ofensivo, y también el más realista.
The usual market range runs from four to nine months end to end. The intelligence phase takes four to eight weeks, execution eight to twelve, and the rest is preparation, supervisor coordination and joint closure. It is the longest and most expensive exercise in the offensive catalogue, and also the most realistic.
NomenclaturaTerminology
Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.