Threat-Led Penetration Testing: What TLPT Actually Means
In some jurisdictions a supervised regulatory programme with prescribed intelligence and a regulator in the room. In marketing, a synonym for red teaming. The difference is worth establishing.
TLPT is used two ways, and the gap between them is large enough that a proposal using the phrase should be asked which it means.
The regulated meaning
In several jurisdictions, threat-led penetration testing is a defined, supervised programme rather than a service a firm sells. The characteristics that make it that:
- Prescribed threat intelligence. A separate provider produces a targeted intelligence report on adversaries realistically relevant to the institution, and the test is built from it — not from what the testing team finds interesting.
- Regulator involvement. The supervisor is aware, and in some frameworks approves the scope and observes.
- Prescribed scope. Critical functions are identified by criteria in the framework rather than by the institution's preference.
- Separation of duties. The intelligence provider and the testing provider are usually required to be different organisations, and both may need accreditation.
- Formal closure. A remediation plan submitted and tracked rather than a report filed.
The point of the machinery is comparability: a supervisor can compare results across institutions because the method was prescribed.
The marketing meaning
Elsewhere the phrase is used to mean "a red team informed by threat intelligence", which is what a competent red team already is. Used this way it describes good practice rather than a programme, and carries no supervisory weight at all.
Neither usage is dishonest. Confusing them is expensive, because one costs several times the other.
Reading a claim
Three questions settle it:
- Under which framework? A supervised programme is always named — the framework has a name, a version and published requirements. "We follow TLPT principles" is the marketing meaning.
- Who produces the threat intelligence? If the answer is "we do", it is not the regulated variety, which generally requires separation.
- Is your regulator involved? If nobody has told them, it is a red team.
Where India stands
Indian regulation does not currently impose a TLPT programme of the supervised kind on the broad population of regulated entities. The RBI's 2026 Directions treat red teaming permissively — the word is "may" — which is covered in red teaming under the RBI's 2026 Directions.
That makes a red team here a risk decision rather than a compliance one, which is a better position to buy from: nobody is buying it to satisfy a form, so it only gets bought when it will change something. Security Brigade maintains the paragraph-level reading at red teaming requirements.
Anyone operating across borders should establish which regime binds each entity separately. A group with a European or UK-regulated arm may face a supervised programme there and nothing equivalent in India, for the same business.
Continue reading
All articles →Choosing a Red Team Provider
Every firm answers yes to every capability question. Six that are harder to answer generically, and what a real answer sounds like.
Red Teaming and SEBI CSCRF
What the Cyber Security and Cyber Resilience Framework asks of regulated entities, where adversarial testing sits within it, and how the tiering decides how much applies to you.
Social Engineering Assessments and the Consent They Require
Testing people is not testing systems. What can be assessed, what must be agreed first, and why individual results should almost never leave the room.