Answers
What is TLPT / CBEST?
In short
TLPT (Threat-Led Penetration Testing) under DORA, and CBEST under the Bank of England, are intelligence-led red-team exercises against critical financial-services firms.
Short answer
TLPT (Threat-Led Penetration Testing) under DORA, and CBEST under the Bank of England, are intelligence-led red-team exercises against critical financial-services firms.
What this actually means in practice
Both follow a controlled framework: threat intelligence sets a credible attack scenario, a red team executes it, and a control group inside the firm observes detection and response. Outputs feed directly into resilience improvement.
The most common pitfall
Scoping TLPT/CBEST narrowly to pass — and missing the detection gaps the regulator most cares about.
What to do next
Run a tabletop precursor before commissioning the live exercise.
Frequently asked questions
Does Forth Systems help with this?
Yes — Forth Systems works with banks, payment institutions, insurers and infrastructure operators on exactly this kind of work. Engagements start with a fixed-scope assessment so you see the shape before committing.
How experienced is the team?
Engagements are staffed by named, UK-based senior engineers — not a rotating offshore pool. References from the second line of comparable clients are available on request.
Where are you based?
Edinburgh-based, delivering UK-wide with onsite presence in London and across Scotland as required.
How fast can we start?
Most engagements start within 2-4 weeks of a signed SoW, faster where an existing supplier framework is in place.
