Skip to content

Solutions / By sector

Financial Services

Payment fraud, account takeover and DORA operational-resilience testing for banks, payment institutions and fintechs.

What you receive

  • DORA threat-led penetration testing
  • Real-time payment fraud scoring
  • Mule-network detection
  • Regulator-ready resilience evidence

When you need this

Three situations that call for it. If none of them is yours, it probably is not the right spend.

  • 01

    Your TLPT designation letter has arrived

    The competent authority has named you for threat-led testing, and the scope is live production with a control team of only a few people permitted to know it is happening. That is a different engagement from an annual penetration test, and most of the difference sits in the preparation.

  • 02

    Instant payments removed your recall window

    The ten seconds in the instant payments rules is the time in which the funds must reach the payee, so they are gone before any batch review would have run — the decision has to happen before execution rather than after it. Mule detection stops being a reconciliation task and becomes a real-time one.

  • 03

    Your core runs on a third party's ICT

    DORA places the ICT third-party arrangement inside your own accountability, including the register of information and a documented exit strategy. The awkward part is usually contractual — the right to test the provider was never written into the agreement.

How it runs

  1. 01

    Where you actually are

    A working session to establish what is already in place and what your regulator, your auditor or your board is going to ask for. Usually the gap is narrower than feared and differently shaped.

  2. 02

    What the obligation really requires

    We separate what the text mandates from what a consultancy has told you it mandates. Several of the controls sold against these regimes are not required by them.

  3. 03

    A scoped programme

    The specific modules and engagements that close the gap, sequenced by what your deadline is and what depends on what — not by what is easiest to sell you.

  4. 04

    Evidence, not a gap report

    The output is the artefact your assessor accepts: test results, control evidence and a record of what changed. A document describing your gaps is not evidence that you closed them.

No lock-in

Scoping costs nothing and carries no obligation. If the answer is that you do not need this, that is a legitimate outcome of the call.

Who turns up

The engineer on your scoping call is on the delivery team. We do not hand you to a different group after signature.

Scope

What this does not cover

  • This is not a DORA certification — no such thing exists — only the technical evidence a competent authority asks to see.

  • Anti-money-laundering work — transaction monitoring, sanctions screening, suspicious activity reporting — falls outside this scope.

  • Certification evidence for ISO 27001 or PCI DSS is not assembled here; that work sits under By mandate, alongside the DORA page.

Measured against

DORA Regulation (EU) 2022/2554, Art. 26
The scope of a threat-led test is validated by the competent authority before it runs, and the authority issues the attestation that it was performed properly afterwards.
DORA Regulation (EU) 2022/2554, Art. 19
A major ICT incident requires a three-stage report to the competent authority — initial, intermediate and final — on fixed deadlines.
TIBER-EU
The ECB's intelligence-led red team framework, aligned to the DORA testing rules and run against production with a small control team.

If the scope is wrong

Tell us on the call. Re-scoping before we start costs nothing; discovering it at the readout costs you the engagement.

Questions

The ones we are actually asked.

Can you run a TLPT if we have never done a red team?

The first one usually tests your control team's process rather than your network. Institutions with no prior red team often get more from a scoped detection exercise first, and we will say so before you commit to the larger engagement. Article 27 sets what a threat-led tester has to meet, and the competent authority validates the scope — ask any provider, us included, to show that before anything else is discussed.

Can a mule account be caught before the payment leaves?

Some of them. A decision taken inside the execution path can only use what is already known — device, account age, beneficiary history, the shape of the transfer — so a share will pass. Those are found afterwards by the pattern across accounts rather than one account at a time.

Do you need production access to test resilience?

For threat-led testing under DORA, yes — the regulation expects live systems, which is why the control team and the risk-management agreement are the hardest part of scoping. Non-production testing is possible, but it answers a smaller question.

Next step

See what an attacker sees

We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.

30 min

A scoping call, with an engineer rather than a sales rep.

What it costs

Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.

Under attack now?

Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.