DORA TLPT &TIBER Red Teaming
Experience from TIBER projects in the financial sector. We know what is required in execution, coordination and documentation.
Objective first, approach second.
A penetration test examines defined systems. A commercial red team tests detection and response against an attacker objective; TIBER-EU and DORA TLPT are the regulatory framework for that lane. Hybrid is the approach (human-led plus assisted validation), continuous describes the rhythm and a retainer the commercial model - none of them is another testing objective, and a retainer is never a prerequisite.
Penetration Testing
Tests defined systems for weaknesses.
Manual testing for web, network, cloud, AD, mobile, SAP and AI. Finds what a compliance audit misses.
Explore Penetration TestingHybrid Pentest
Not a separate testing objective: hybrid describes the approach - human-led testing plus assisted validation.
Human ground truth plus continuous automation. For ISMS-based testing programmes with data sovereignty.
Explore Hybrid Pentest Pentest as a Service →Red Teaming
Tests detection and response against an attacker objective. TIBER-EU and DORA TLPT are the regulated lane of it.
Intelligence-led operations with no advance warning - threat intel and attack from one team. Including TIBER-EU and DORA TLPT.
Explore Red Teaming Always-On Red Teaming →Disruption and manipulation of business-critical processes
Access to internal areas without any technical attack
Anonymized extracts from completed engagements: what was actually demonstrated, not what would be theoretically possible.
Red Teaming - Your Friendly Advanced Persistent Threat.
A standard pentest tells you which vulnerabilities exist. It doesn't tell you whether a motivated attacker can chain them together, stay undetected, and reach your critical functions.
Threat intelligence and red teaming come from one team here - no translation loss between two vendors.
Track record
Among the first to complete a DORA TLPT (2024). TIBER-EU methodology, documentation for BaFin and Bundesbank.
Adversary simulation
APTs, OCGs and IABs targeting your sector, mapped to MITRE ATT&CK.
Intelligence-led red teaming
Covert, scenario-based operations - TIBER-EU methodology.
Social engineering & physical
Phishing, pretexting, tailgating, physical access.
Purple Teaming
Joint exercise with your blue team - measurably better detection.
RTaaS
Continuous, recurring operations instead of a one-off snapshot.
One team. One focus. Offensive security. No bazaar. No up-selling or cross-selling. Pentesting is not a sales vehicle for other services.
Offensive security only
No side business, no distraction - 100% focus on offensive engagements.
Senior operators only
No juniors on live engagements. The people testing you have done it 1,000× before.
Local procurement
Local B2B billing in EUR or AED through the applicable German or UAE entity.
ISO 27001 / BSI IT-Grundschutz
Certified offensive infrastructure. Your test data stays in safe hands.
From banks to energy providers, law firms, critical-infrastructure operators, logistics companies and Web3 technology leaders: companies across every industry trust our work.








Further references available upon request
OffSec licences with local billing and local instructors.
We help select individual, team and enterprise licences, structure the rollout and, where useful, combine it with instructor-led training from XPLT instructors.
Game of Active Directory bootcamps.
GOAD workshop
Game of Active Directory: attack paths, tooling and what the blue team sees of it.
Dates & pricingOne team. Three hubs. On-site execution.
Frankfurt
DACH delivery, German-language reporting, EUR invoicing, on-site work across the Rhine-Main region.
View locationDubai
MENA and GCC, AED invoicing, delivery for regulated sectors across the Emirates.
View locationReykjavík
Nordics and critical infrastructure, TIBER-IS context, English-language delivery.
View locationReady to test your defense?
Speak with a senior operator - confidential, no sales layer in between. Tell us briefly what needs testing; we come back with format, effort and price range.
