Releasing Your Inner TIBER in Regulated Adversary Simulations - Marko Buuri
Marko Buuri (Central Bank of Finland)
Disobey 2026 · Main Stage
Overview
This talk by Marko Buuri, an expert from the Central Bank of Finland, provides an in-depth look into the TIBER (Threat Intelligence-Based Ethical Red Teaming) framework. TIBER is a sophisticated cybersecurity testing methodology gaining significant traction, particularly within the financial sector across Europe. Buuri’s presentation demystifies the framework, explaining its origins, core phases, and the specialized skills required for its successful implementation. He highlights its importance as a robust mechanism for financial institutions to validate their security controls against the most advanced and persistent cyber threats in real-world production environments.

Key moments
- 0:00 Introduction to TIBER framework and its scope
- 2:00 Speaker's TIBER experience and talk motivation
- 4:40 Understanding unique cyber threats to financial sector
- 7:40 TIBER's focus on advanced threat actor simulations
- 8:40 Real-world example: Sophisticated threat actor UNC 2891
Releasing Your Inner TIBER in Regulated Adversary Simulations - Marko Buuri
Speakers: Marko Buuri, Central Bank of Finland
Conference: Disobey
YouTube: https://www.youtube.com/watch?v=z6KIEEknKjM
Overview
This talk by Marko Buuri, an expert from the Central Bank of Finland, provides an in-depth look into the TIBER (Threat Intelligence-Based Ethical Red Teaming) framework. TIBER is a sophisticated cybersecurity testing methodology gaining significant traction, particularly within the financial sector across Europe. Buuri’s presentation demystifies the framework, explaining its origins, core phases, and the specialized skills required for its successful implementation. He highlights its importance as a robust mechanism for financial institutions to validate their security controls against the most advanced and persistent cyber threats in real-world production environments.
The motivation behind Buuri’s talk is twofold: to inform CISOs and security managers about TIBER as a leading best practice for risk-managed red team testing, and to guide aspiring cyber threat intelligence (CTI) experts and red teamers on how to participate in these complex, yet professionally rewarding, assignments. Given the high-stakes nature of financial services, TIBER offers a structured, regulator-approved approach to confront sophisticated adversaries. Buuri emphasizes that while TIBER originated in the financial sector, its principles are broadly applicable to any organization operating in a high-requirements environment that needs to verify security controls through red teaming in production.
Background
▶ Watch: Introduction to TIBER framework and its scope (0:00)
The genesis of the TIBER framework lies in the evolving landscape of cyber threats and the limitations of traditional security testing methodologies. Around the 2010s, global enterprises faced a surge in highly sophisticated breaches attributed to Advanced Persistent Threats (APTs) – a new term describing capable, motivated, often nation-linked actors. These incidents revealed that existing security architectures and validation methods were insufficient against such advanced adversaries. This realization spurred two major developments: the Zero Trust Architecture concept and the formalization and popularization of cybersecurity red teaming.
The financial sector, historically an early adopter of advanced security practices, took notice. Several European national central banks collaborated to create TIBER-EU in 2018, a voluntary guidance document outlining best practices for organizing red team tests in production environments within the financial sector. This framework provided a template for national jurisdictions to adapt, leading to versions like TIBER-FI in Finland and TIBER-SE in Sweden. A significant shift occurred a year ago with the introduction of DORA (Digital Operational Resilience Act), a comprehensive piece of European legislation for the financial sector. DORA made TLPTs (Threat-Led Penetration Tests), which TIBER fulfills, a mandatory requirement for the largest financial entities, transforming TIBER from a best practice into a regulatory obligation.
TIBER specifically targets the most capable and advanced threat actors, such as organized crime groups and nation-linked entities. It focuses on scenarios where adversaries attempt to penetrate and operate within the IT estate of banks, insurance companies, or payment system providers. This explicitly scopes out less sophisticated threats like generic Distributed Denial of Service (DDoS) attacks or consumer-facing scams, which, while serious, do not require the advanced simulation capabilities of TIBER. The framework aims to simulate attacks that go beyond what simple configuration reviews, vulnerability scanning, or even scoped penetration tests can uncover, seeking to uncover vulnerabilities against adversaries fluent in OPSEC (operational security), employing custom tools alongside public ones, and executing complex multi-stage campaigns.
Marko Buuri illustrates this with a practical example: the UNC2891 threat actor, first publicly reported by Mandiant in 2022. This financially motivated group demonstrated high technical skill and fluency in their operations. Group-IB documented their campaigns, including one targeting an ATM network. In this scenario, UNC2891 physically accessed the bank's LAN network connected to ATMs, deployed a Raspberry Pi device, moved laterally, installed rootkits, used novel Linux process hiding techniques, established C2 channels, and aimed to manipulate backend systems for fraudulent cash withdrawals. This incident, while eventually detected due to network monitoring and diligent forensics, exemplifies the level of sophistication and the multi-phase attack paths (penetration, through, and out, mapped to the Unified Kill Chain) that TIBER projects are designed to simulate.
Key Findings
▶ Watch: Speaker's TIBER experience and talk motivation (2:00)
The TIBER framework stands out as a paramount solution for advanced security testing in high-stakes environments, particularly within the European financial sector. Marko Buuri posits it as arguably "the best framework out there" for organizations requiring rigorous verification of security controls in production. A pivotal development highlighted is the Digital Operational Resilience Act (DORA), which transformed TIBER from a voluntary best practice into a mandatory regulatory requirement for significant financial entities across EU member states. This legislative backing underscores the framework's critical importance in enhancing the cyber resilience of the financial ecosystem.
TIBER projects are characterized by a unique, authority-driven structure. Unlike typical security engagements initiated by the client, the local TPT authority identifies and mandates which large entities must perform these tests regularly. Projects typically span 12 to 18 months, involving distinct stakeholders: the entity’s Control Team (steering group), external Cyber Threat Intelligence (CTI) Providers, Red Team Providers, and the entity’s internal Blue Team (security operations, unaware of the test until closure), all overseen by an authority-appointed Test Manager. This multi-party collaboration ensures comprehensive oversight and execution.
A core innovation in the TIBER red teaming phase is the concept of "Dchaining" or staggering the attack approach. Recognizing that initial access activities (e.g., phishing, brute-forcing) are often noisy and prone to early detection, TIBER projects frequently provide the red team with initial "leg-ups" – pre-established access points like compromised accounts or laptops. This allows testers to bypass the highly monitored perimeter and focus on exploring internal controls, privilege escalation, and lateral movement closer to critical production systems. Buuri emphasizes that this approach maximizes learning by concentrating efforts on the areas where organizations often have the most significant control gaps, rather than getting stuck in perimeter defenses that may already be robust.
Furthermore, the framework emphasizes continuous learning and adaptability throughout the testing process. Should the red team identify alternative, potentially more effective attack paths not initially outlined in the threat intelligence scenarios, these opportunities are discussed with the Control Team. While only one path might be executed, the unexecuted ideas are documented for post-test review, ensuring that all potential learnings are captured. In scenarios where a red team's activities are detected by the blue team and the scenario is "burned," TIBER mandates planning for independent scenarios, allowing other attack paths to continue. Moreover, if all red team avenues are exhausted, the project can pivot to purple teaming mode, where the blue team becomes aware of the test, and collaboration focuses on enhancing detection and response capabilities, maximizing the remaining testing time for defensive improvements.
Technical Deep Dive
▶ Watch: Understanding unique cyber threats to financial sector (4:40)
The TIBER framework orchestrates advanced adversary simulations through a structured, multi-phase project lifecycle: Preparation, Testing (Cyber Threat Intelligence and Red Teaming), and Closure. Each phase is meticulously designed to ensure realism, maximize learning, and manage risk, especially given that tests occur in live production environments.
The Preparation Phase (project organization, planning, scope definition, service provider sourcing, and initial risk management) sets the stage. Crucially, the scope in TIBER is not a traditional list of assets to be comprehensively tested. Instead, the Control Team identifies the entity's critical business functions (e.g., interbank payments, customer payment services, deposit taking, lending) and then lists all IT assets supporting these functions. This broad asset list forms the basis for the CTI team's analysis, focusing on assets valuable to criminals and their underlying technologies, integration, internet footprint, vulnerability history, and usage patterns.
The heart of the TIBER methodology lies in the Testing Phase, which is split into two distinct, yet interconnected, activities:
Cyber Threat Intelligence (CTI) Activity
This phase, typically lasting four to six weeks, is foundational. Its primary purpose is to generate realistic, bespoke scenario descriptions for the red team. CTI analysts work with two main datasets:
- Target Entity Information: Unlike typical OSINT-driven threat intelligence, TIBER mandates direct engagement with the target entity. Analysts receive internal documentation, conduct interviews, and host workshops to gain a deep understanding of the scoped IT assets and their operational context. This internal perspective is vital for crafting truly relevant scenarios.
- Threat Landscape in the Financial Sector: Analysts leverage public and commercial threat intelligence sources, as well as proprietary research, to identify active threat actor groups specifically targeting financial entities. These include nation-linked actors with sinister motivations and organized crime groups primarily seeking monetary gains.
The CTI team then performs an exercise of matching these two datasets. They identify overlaps between the threat actors' known TTPs (Tactics, Techniques, and Procedures) and the technologies and systems used by the target entity. This matching process leads to the development of a long list of potential scenarios. From this list, a minimum of three detailed scenarios are selected and refined. Each scenario is a narrative outlining:
- A named threat actor (e.g., UNC2891).
- Their motivation for attacking this specific entity.
- The target they are after (e.g., payment messaging systems).
- The specific TTPs they will employ, often structured using the Unified Kill Chain (In, Through, Out phases) to describe the attack path from initial penetration to final objective execution.
Buuri provides concrete examples of common initial access vectors and targets:
- Initial Access Vectors: Compromised service partners (IT consultants), poisoned open-source software components, VPN zero-days, and physical break-ins.
- Targets: Payment materials and messaging systems (for fraudulent transactions), data exfiltration for double extortion, and on-premises legacy systems which, despite cloud migration efforts, remain prevalent and often vulnerable in financial institutions.
To facilitate the CTI process, some member states, like Finland, implement a generic threat landscape report. Provided by the central bank and sourced from national CERTs, this baseline report ensures that projects don't start from a blank slate regarding known financial sector threats, balancing thoroughness with the limited timeframe of the CTI phase.
Red Teaming Activity
Following the CTI phase, the red teamers (who are typically new to the project at this point) receive the detailed TI report and scenarios. This phase typically lasts a minimum of three months. Their initial task involves meticulous planning, mapping out specific attack paths for each scenario, often referencing frameworks like MITRE ATT&CK to define precise TTPs.
As discussed in Key Findings, a defining technical aspect is the use of "Dchaining" or staggering the approach with leg-ups. This means the red team often begins testing from an assumed compromised state, bypassing initial, noisy access vectors. Leg-ups are critical for maximizing learning and can be of two types:
- Information Leg-ups: Tips or advice from the Control Team (e.g., "look at this system," "avoid that honeypot").
- Access Leg-ups: Covertly provided IT changes, permissions, or accounts activated by the Control Team on behalf of the red team. These are often necessary to pivot between highly segmented internal IT environments or to resume testing after a scenario is detected. Buuri highlights significant challenges with access leg-ups due to the stringent IT change management processes and Access Management (AM) processes in financial institutions, especially concerning privileged roles. Successfully implementing these requires extensive pre-planning and coordination to avoid disrupting live operations or alerting the blue team prematurely.
The red team's execution also involves continuous adaptation. If testers identify more effective attack vectors or opportunities during the test, these are discussed, and a decision is made on whether to pursue them or table them for later review, ensuring that the most impactful findings are pursued. In case of detection and a "burned" scenario, TIBER projects are designed with redundancy, allowing other scenarios to continue. If all red team avenues are exhausted, transitioning to purple teaming allows the red and blue teams to collaborate, with the blue team aware of the ongoing activities but not actively blocking, to maximize detection and response learnings.
Demo / Proof of Concept
▶ Watch: TIBER's focus on advanced threat actor simulations (7:40)
The talk itself does not feature a live technical demonstration or a proof of concept (PoC) of an attack. Marko Buuri explicitly states at the outset that he would not be doing any technical deep dives, but rather focusing on the framework and its elements.
However, Buuri effectively substitutes a live demo with a detailed real-world case study of the UNC2891 threat actor. This serves as a conceptual "proof of concept" for the type of sophisticated, multi-stage attack that TIBER aims to simulate and defend against. He meticulously breaks down the UNC2891 attack on an ATM network, illustrating:
- Initial Access: Physical entry to the LAN network connecting ATMs, deploying a Raspberry Pi.
- Through Phase (Lateral Movement & Persistence): Breaching systems, installing custom rootkits, using novel Linux process hiding techniques, establishing Command and Control (C2) channels, and moving laterally towards backend servers.
- Out Phase (Objective Execution): Bringing in custom tooling with the end goal of manipulating backend systems to enable fraudulent cash withdrawals from ATMs.
Buuri maps these TTPs onto the Unified Kill Chain, demonstrating the level of sophistication and the multi-layered approach that TIBER's threat intelligence phase must envision and the red team phase must execute. This detailed example, drawn from Mandiant and Group-IB reports, concretely illustrates the calibre of adversary TIBER is designed to counter, providing a vivid mental picture of the complex scenarios that red teamers are expected to simulate.
Defensive Implications
▶ Watch: Real-world example: Sophisticated threat actor UNC 2891 (8:40)
The TIBER framework offers profound defensive implications for financial institutions and, by extension, any organization operating in a high-security, regulated environment. For CISOs and security managers, TIBER provides an unparalleled, structured methodology for validating security controls against real-world, advanced threats in production. This goes beyond compliance checkboxes, offering deep insights into an organization's actual resilience. The framework's emphasis on risk management throughout the 12-18 month project lifecycle, coupled with clear phasing and deliverables, ensures that high-risk testing is conducted safely and yields actionable learnings. CISOs are encouraged to adopt this open-source framework, adapting it to their specific organizational context if not mandated by DORA.
For Blue Teams (Security Operations Centers, Incident Response teams), TIBER implicitly highlights the critical need for robust internal detection and response capabilities. The "Dchaining" approach, where red teams are often given "leg-ups" to bypass perimeter defenses, means that the true test lies in an organization's ability to detect and respond to threats that have already gained initial access. This shifts defensive focus from merely preventing initial breaches to comprehensive internal monitoring, threat hunting, and rapid containment. The UNC2891 example underscores this, where network monitoring and diligent forensics were crucial in detecting the advanced threat actor, discovering rootkits, and hidden processes after initial compromise.
Furthermore, the challenges highlighted with "access leg-ups" reveal a tension between rigid IT change management and Access Management (AM) processes and the agility required for advanced testing. While these strict controls are vital for operational security, they can impede the covert activation of test accounts or network pivots. Defenders need to find ways to integrate "out-of-band" or expedited, yet auditable, processes for TIBER-like simulations, ensuring that testing can proceed without compromising live operations or being unduly delayed.
Finally, the potential for purple teaming if a red team scenario is burned offers a valuable defensive opportunity. Instead of simply ending the test, pivoting to a collaborative mode allows the blue team to directly learn from the red team's techniques, improving their detection rules, playbooks, and overall incident response posture in a controlled environment. The requirement for red teamers to communicate clearly with non-technical control team members also underscores the importance of security professionals being able to articulate complex technical risks in business terms, fostering better understanding and support for security initiatives across the organization.
Key Takeaways
- TIBER is a Mandated, Advanced Red Teaming Framework: Driven by the DORA regulation, TIBER (or TLPTs) is now a mandatory, comprehensive framework for critical financial entities in Europe, designed to test resilience against sophisticated cyber threats in production environments.
- Threat Intelligence-Based Scenarios are Crucial: TIBER's core strength lies in its CTI phase, which develops realistic, bespoke attack scenarios based on internal entity data and the latest financial sector threat intelligence, often using the Unified Kill Chain for structured narratives.
- "Dchaining" and Leg-ups Maximize Learning: To overcome noisy initial access and focus on internal controls, TIBER projects use "Dchaining" and "leg-ups" (information or access) to allow red teams to start mid-attack, ensuring valuable learnings about an organization's ability to detect and respond to internal threats.
- High Professionalism and Communication are Essential: Red teamers and CTI analysts must possess not only top-tier technical skills and OPSEC but also excellent communication abilities to articulate complex technical actions and risks to non-technical control teams, ensuring effective project management and risk oversight.
- Focus on Real-World, Advanced Adversaries: TIBER targets the capabilities of nation-state or organized crime-linked threat actors, aiming to simulate their TTPs against critical IT assets like payment systems and legacy on-premises infrastructure.
- Career Path Emphasizes Enterprise IT Experience: Aspiring TIBER professionals are advised to first gain expertise in enterprise IT environments to understand how technologies are used and operated before specializing in security testing.
About the Speaker(s)
Marko Buuri works at the Central Bank of Finland, where he plays a pivotal role in the country's cybersecurity resilience efforts. He has been deeply involved in the implementation of TIBER-FI, Finland's national version of the TIBER framework, since 2020. Throughout these years, Buuri has participated in all TIBER projects organized in Finland, extending his experience to similar initiatives in Nordic and broader European contexts. His professional responsibilities explicitly include providing guidance and answering questions related to the adoption and participation in the TIBER framework, making him a central figure in its deployment and ongoing development.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Buuri is precisely the right person to give this talk — he's been inside every TIBER-FI project since 2020 and sits at the regulator's table, which gives him access to operational texture you won't find in the public TIBER-EU guidance documents. The content is substantive for its lane: a policy/framework briefing that gets into structural mechanics (CTI phase design, leg-up taxonomy, burned-scenario contingency planning) rather than staying at the brochure level.
Heather Calloway (CISO) — SOLID
A competent, practitioner-credible walkthrough of TIBER from someone who has actually run these programs — not a vendor, not an academic. The DORA mandate is the real news here, and Buuri understands the operational complexity involved. But this is a framework orientation, not a decision-forcing talk, and it stops well short of telling security leaders what the hardest failure modes actually are.