TLP WHITE - FINAL What is TLPT? TLPT1 is a controlled attempt to compromise the cyber resilience of an entity by simulating the tactics, techniques and procedures of real-life threat actors. It is based on targeted threat intelligence and focuses on an entity’s people, processes and technology, with minimal foreknowledge and impact on operations. What is the purpose of a TLPT? The purpose of TLPT is to assess and provide insights on entities’ resilience capabilities against a real world simulated cyber incident. TLPT should be conducted within a set scope and incorporate a risk management process to ensure a controlled test that minimizes risk to entities. Who is G7FE-TLPT for? The G7FE-TLPT are designed to provide a guide to: (i) authorities considering the use of TLPT for the design, implementation and management of TLPT in their respective jurisdictions; (ii) entities undertaking TLPT; (iii) organizations providing cyber threat intelligence services (‘threat intelligence providers’); (iv) organizations providing penetration testing services (‘penetration testing providers’); and (v) accreditation and certification providers2. The application of the G7FE-TLPT is non-binding. However, authorities could incorporate TLPT in their assessments of certain entities’ cyber resilience by considering, among others, the following factors:  The extent to which cyber resilience is a priority from the financial stability and market integrity perspective;  The significance of some entities that provide critical functions and services across the financial sector; and  The (un)availability of other risk assessment tools and techniques for testing cyber resilience. Authorities may also consider proportionality to accommodate for the type, size, complexity, sophistication and risk profile of the targeted entities. In cases of multinational entities, authorities across different jurisdictions should plan, collaborate and coordinate such tests to achieve the optimal outcome in terms of timing, scoping and implementation. Effective TLPT involves strong multi-stakeholder engagement throughout the assessment process. For entities involved in cross-jurisdictional assessments, prior to the TLPT engagement, the entities should define the list of participating authorities as appropriate. This aims to support cross-jurisdictional assessments, promote discussions with respect to mutual acceptance of TLPT results of multinational entities across jurisdictions and develop protocols for the sharing of deliverables from the TLPT assessment. 1 In some jurisdictions this may be referred to Ethical Red Teaming. The accreditation and certification provider validates the vendors’ baseline level of proficiency to provide threat intelligence and penetration testing services. 2 TLP WHITE: Subject to standard copyright rules, this document may be distributed freely, without restriction. 2

Select target paragraph3