GERMANY Law and Practice Contributed by: Josefine Spengler and Svetlana Ulrici, Annerton
TLPT Cycles Where TLPT is mandatory, the supervisory authority (BaFin) follows a minimum “at least every three years” cycle for TLPT, subject to supervisory expectations and entity-specific risk. Tester Requirements A specific RTS governing DORA TLPT specifies requirements for: • the use of internal testers (and conditions/stand - ards for doing so); • the scope and methodology across the TLPT phases; and • governance around execution, closure and reme - diation. TIBER-EU tests are typically delivered with specialised external threat intelligence providers and red-team testers, with clear expectations around competence and controlled testing on live systems. The Bundes - bank provides supporting documentation and pro - curement guidance references to help entities select suitable providers under the TIBER model. Recognition of Equivalent Tests From Other Jurisdictions A key design feature of TIBER-EU is the facilitation of mutual recognition of tests across European jurisdic - tions, provided the test meets the framework’s man - datory requirements. This is particularly relevant for cross-border groups seeking to avoid duplicative test - ing and to align evidence of resilience across multiple supervisory audiences.
nomic Area (EEA), GDPR transfer rules apply in par - allel with DORA/outsourcing governance. The main lawful mechanisms are: • adequacy decisions (where available for the desti - nation jurisdiction); • Standard Contractual Clauses (SCCs), often com - bined with supplementary measures; • Binding Corporate Rules (BCRs) for intra-group transfers; and • narrow derogations (eg, Article 49 GDPR) for exceptional cases (not a scalable outsourcing solu - tion). Supervisory expectations post-Schrems II centre on a documented, case-specific assessment of third- country risks and – where needed – supplementary measures (eg, encryption with key control, organisa - tional and contractual safeguards) to ensure “essen - tially equivalent” protection. 3.6 Threat-Led Penetration Testing Germany’s primary “mandatory” threat-led penetra - tion testing (TLPT) regime is DORA (EU-wide). DORA establishes TLPT as an advanced testing requirement for selected financial entities, operationalised through a dedicated Regulatory Technical Standard (RTS) adopted at EU level and aligned with the TIBER-EU methodology. In parallel, Germany has an established threat-intel - ligence-based red teaming framework, TIBER-DE, operated through the Bundesbank as the national competence centre. TIBER-DE is the German national implementation of TIBER-EU and has been used as a high-quality testing standard for the German financial sector. Entities Required to Perform TLPT TLPT is not universal for all DORA entities. Competent authorities (in Germany, typically BaFin, and for cer - tain institutions also the ECB within its remit) identify which financial entities must conduct TLPT. TIBER-DE can be used as a supervisory/oversight tool to test cyber-resilience in the financial sector; partici - pation and timing are generally co-ordinated with the relevant authorities under the TIBER approach.
4. Cyber-Resilience 4.1 Cyber-Resilience Legislation
Cyber-resilience requirements in Germany are gov - erned by a layered framework of EU regulations and national implementing laws, rather than by a single, standalone statute. The regulatory focus has shift - ed from purely organisational cybersecurity duties towards a broader concept of resilience that also addresses products, services and supply chains.
152 CHAMBERS.COM
Powered by FlippingBook