Skip to main content

Threat-Led Penetration Testing: What TLPT Actually Means

In some jurisdictions a supervised regulatory programme with prescribed intelligence and a regulator in the room. In marketing, a synonym for red teaming. The difference is worth establishing.

2 min read

TLPT is used two ways, and the gap between them is large enough that a proposal using the phrase should be asked which it means.

The regulated meaning

In several jurisdictions, threat-led penetration testing is a defined, supervised programme rather than a service a firm sells. The characteristics that make it that:

  • Prescribed threat intelligence. A separate provider produces a targeted intelligence report on adversaries realistically relevant to the institution, and the test is built from it — not from what the testing team finds interesting.
  • Regulator involvement. The supervisor is aware, and in some frameworks approves the scope and observes.
  • Prescribed scope. Critical functions are identified by criteria in the framework rather than by the institution's preference.
  • Separation of duties. The intelligence provider and the testing provider are usually required to be different organisations, and both may need accreditation.
  • Formal closure. A remediation plan submitted and tracked rather than a report filed.

The point of the machinery is comparability: a supervisor can compare results across institutions because the method was prescribed.

The marketing meaning

Elsewhere the phrase is used to mean "a red team informed by threat intelligence", which is what a competent red team already is. Used this way it describes good practice rather than a programme, and carries no supervisory weight at all.

Neither usage is dishonest. Confusing them is expensive, because one costs several times the other.

Reading a claim

Three questions settle it:

  • Under which framework? A supervised programme is always named — the framework has a name, a version and published requirements. "We follow TLPT principles" is the marketing meaning.
  • Who produces the threat intelligence? If the answer is "we do", it is not the regulated variety, which generally requires separation.
  • Is your regulator involved? If nobody has told them, it is a red team.

Where India stands

Indian regulation does not currently impose a TLPT programme of the supervised kind on the broad population of regulated entities. The RBI's 2026 Directions treat red teaming permissively — the word is "may" — which is covered in red teaming under the RBI's 2026 Directions.

That makes a red team here a risk decision rather than a compliance one, which is a better position to buy from: nobody is buying it to satisfy a form, so it only gets bought when it will change something. Security Brigade maintains the paragraph-level reading at red teaming requirements.

Anyone operating across borders should establish which regime binds each entity separately. A group with a European or UK-regulated arm may face a supervised programme there and nothing equivalent in India, for the same business.