Threat-Led Penetration Testing and iCAST: Proof your controls hold against a real adversary.

Threat-led penetration testing for regulated financial institutions across APAC. Intelligence-led adversary simulation structured to satisfy MAS TLPT, HKMA iCAST, and equivalent regulatory frameworks, and to produce findings your programme can act on.

MAS TRM in Singapore. HKMA iCAST in Hong Kong. Delivered and documented.
OVERVIEW

What is threat-led penetration testing?

Threat-led penetration testing (TLPT) is an intelligence-led adversary simulation conducted against a financial institution’s live production environment, using threat intelligence specific to the institution and its operating markets to design the attack scenarios. It is distinct from standard penetration testing in scope, methodology, and regulatory standing. 

TLPT engagements simulate the tactics, techniques, and procedures of threat actors targeting the institution, and assess whether the institution’s people, processes, and technology can detect and respond to them. The engagement tests the live environment because that is what regulators and the institution itself need to confirm.

  • Threat intelligence phase
    Institution-specific threat profile developed prior to testing
  • Red team operations
    in live production environment, full-scope, multi-vector, extended duration
  • Blue team assessment
    Evaluation of detection and response capability against live adversary simulation
  • Purple team debrief
    Collaborative findings review with offensive and defensive teams
  • Regulatory documentation
    Findings structured for submission to MAS, HKMA, BNM, or other applicable regulators
  • Executive and board debrief
    Findings contextualised for governance review

Your institution has documented, regulator-ready evidence that its security controls have been tested against the threat actors and attack patterns most relevant to its operating environment. Findings are structured for regulatory submission and programme action. Both are required. Each strengthens the other.

THE CHALLENGE

Annual penetration testing satisfies a compliance requirement. Threat-led penetration testing tells you whether your controls hold.

Regulators across APAC have concluded that point-in-time penetration testing does not produce meaningful evidence of institutional resilience. MAS, HKMA, and BNM have each developed threat-led testing frameworks that require financial institutions to simulate the adversaries actually targeting the sector. 

China-nexus adversaries targeting financial services increased activity by 38% in 2025, with cross-domain tradecraft designed to evade standard controls. Standard security testing does not replicate that.

What threat-led penetration testing validates:

Detection capability tested against live adversary behaviour.
Lateral movement paths to critical systems confirmed or blocked.
Incident response procedures validated under real conditions.
Threat actors relevant to your sector assessed against your controls.
THEOS APPROACH 

Intelligence-led penetration testing. Practitioner-delivered. Regulator-ready.

Institution-Specific Threat Intelligence

Every TLPT engagement begins with a threat intelligence phase specific to your institution. Theos develops a threat profile based on your sector, your operating markets, your technology environment, and the threat actors known to target institutions like yours. Attack scenarios are designed around that profile.

Live Production Environment Operations

TLPT is conducted against the live production environment. Theos works with your institution and regulator to agree rules of engagement, scope boundaries, and communication protocols. The blue team responds to what it detects, with no advance knowledge of the engagement, replicating the conditions under which a real adversary would operate.. Theos works with your institution and regulator to agree the rules of engagement, the scope boundaries, and the communication protocols that govern the engagement. The blue team, your security operations team, does not know testing is underway, because that is the condition under which a real adversary would operate.

Full-Spectrum Adversary Simulation

Theos red teams operate across the full attack surface relevant to financial institutions: external perimeter, internal network, identity and access management, cloud environments, core banking and payment infrastructure, and social engineering against your people.

Regulatory Documentation Structured for Submission

TLPT findings are documented to the standard each applicable regulator requires. Theos produces the evidence pack, the executive summary, and the structured findings documentation that MAS, HKMA, and BNM examinations expect. The deliverable is regulatory evidence, structured for examination.

Purple Team Debrief

Following the red team phase, Theos facilitates a purple team debrief with your offensive and defensive teams. Detection gaps are identified and addressed in real time. Detection logic is updated based on the specific techniques used in the engagement.

BENEFITS 

What Theos Threat-Led Penetration Testing delivers.

Regulatory compliance

Documented evidence structured for MAS TLPT, HKMA iCAST, and BNM RMiT submission.

Threat assessment

Know whether your controls hold against the threat actors targeting your institution.

Detection validation

Confirm whether your SOC or MDR provider catches real adversary behaviour in a live environment.

Response testing

Validate whether incident response procedures function under actual adversary pressure.

Board evidence

Practitioner-led, regulator-ready documentation of your institution’s resilience posture.

Programme intelligence

Findings feed into MDR detection tuning, VAPT scope prioritisation, and IR playbook development.

HOW IT WORKS

How a Theos TLPT engagement runs.

1

Scoping and Regulatory Alignment

Theos works with your institution and, where required, your regulator to agree engagement scope, rules of engagement, communication protocols, and the regulatory framework governing the engagement.

2

Threat Intelligence Phase

Theos develops an institution-specific threat profile, the threat actors most relevant to your sector and markets, their known TTPs, and the objectives they pursue against financial institutions like yours. Attack scenarios are designed around this intelligence.

3

Red Team Operations

Theos red team operates in your live environment. Full-scope, multi-vector, extended duration. The blue team responds to activity as they would a real incident, detection and response capability is assessed under live conditions.

4

Purple Team Debrief

Attack scenarios are replayed collaboratively with your offensive and defensive teams. Detection gaps are identified, detection logic is updated, and the blue team leaves the debrief with an improved programme.

5

Regulatory Documentation and Debrief

Findings are documented to regulatory submission standard. Executive debrief conducted with senior leadership. Regulatory evidence pack delivered for MAS, HKMA, or BNM submission as applicable.

WHEN DO YOU NEED PURPLE TEAMING

When threat-led penetration testing is required.

Your institution meets the regulatory threshold for TLPT

MAS TRM penetration testing requirements, HKMA iCAST, and BNM RMiT each define thresholds based on size, systemic importance, or designation, above which threat-led testing is a supervisory requirement. If your institution meets or approaches that threshold, TLPT is a regulatory obligation. Theos can confirm the applicable requirements for your institution and markets.

You are approaching a regulatory examination

Regulators across APAC are examining how institutions have demonstrated security resilience, beyond security compliance reporting. A completed TLPT engagement, with structured findings documentation, is the most direct evidence an institution can produce. Theos structures all deliverables for regulatory submission from the outset.

Your board requires resilience evidence beyond compliance reporting

Boards of regulated financial institutions are accountable for cybersecurity governance. TLPT provides documented, practitioner-led evidence of institutional resilience that compliance testing cannot produce, and that boards, insurers, and regulators increasingly expect to see.

You have made significant technology or organisational changes

Cloud migrations, system transformations, and significant organisational changes alter the attack surface and the detection environment. TLPT following significant change validates that your programme has kept pace with your environment.
WHY THEOS

Why Theos Threat-Led Penetration Testing.

APAC regulatory frameworks. Practitioner knowledge. Regulator-ready delivery.

Theos practitioners operate with direct knowledge of MAS TRM TLPT requirements, HKMA iCAST methodology, and BNM RMiT advanced testing expectations. Engagements are designed to satisfy the specific requirements of the regulator your institution answers to, not a generic TIBER-EU adaptation that does not account for APAC supervisory expectations.

Threat intelligence that reflects this region.

TLPT is only as credible as the threat intelligence that underpins it. Theos builds threat profiles based on the adversaries and attack patterns active in APAC financial services, the threat actors targeting your sector in your operating markets. The engagement simulates the threat your institution actually faces.

Findings that satisfy both regulators and programme teams

TLPT documentation that satisfies a regulatory examination and a debrief that produces actionable programme improvements are two different deliverables. Theos produces both. Regulatory evidence is structured for submission. Programme findings are structured for remediation. Neither is treated as secondary to the other.

Connected to your full security programme

TLPT findings feed directly into your MDR detection programme, your VAPT scope priorities, and your IR playbooks. Clients who engage Theos across multiple service lines benefit from intelligence that compounds, a detection gap identified in TLPT becomes a detection rule in MDR, and a lateral movement path identified becomes a VAPT priority.

CREST-accredited delivery

Theos holds CREST accreditation across our offensive security services practice, delivering CREST TLPT across APAC to the standards regulators require. TLPT engagements are conducted by CREST-certified practitioners, meeting the accreditation requirements that MAS TRM and HKMA iCAST carry.

GET PROTECTED TODAY

Security is not a product you buy. It is an outcome you earn.

Your institution may meet every compliance requirement in your market. Threat-led penetration testing tells you whether your controls hold against a real adversary. Structured for your regulator. Built for your programme.

We deliver outcomes.

Talk to Theos
FAQ

Frequently Asked Questions

What is the difference between threat-led penetration testing and standard red teaming?

Standard red teaming is an objective-led adversary simulation, the engagement is designed around achieving specific outcomes such as accessing critical systems or exfiltrating data. Threat-led penetration testing is a regulatory framework that governs how the engagement is designed, conducted, and documented. TLPT requires a formal threat intelligence phase, engagement of the blue team under live conditions, a structured purple team debrief, and documentation produced to regulatory submission standard. Theos delivers both, and can design engagements that satisfy regulatory TLPT requirements while producing the depth of findings associated with a full red team operation.

Does my institution need TLPT or can standard penetration testing satisfy the requirement?

Whether your institution requires TLPT depends on your designation under applicable regulatory frameworks, primarily your size, systemic importance, and the markets you operate in. MAS, HKMA, and BNM each define specific thresholds. Theos can review the applicable requirements for your institution and confirm which framework applies. For institutions below the TLPT threshold, Theos can design engagements that exceed standard penetration testing requirements without the full regulatory TLPT structure.

How long does a TLPT engagement take?

TLPT engagements at Theos typically run between eight and sixteen weeks from scoping completion to final deliverable, depending on the complexity of the environment, the scope of red team operations, and the regulatory framework requirements. The extended duration reflects the requirement for a meaningful threat intelligence phase, red team operations of sufficient duration to replicate persistent adversary behaviour, and the structured purple team and documentation phases that follow. Theos will confirm the expected timeline during scoping.

How is the threat intelligence phase conducted?

Theos develops an institution-specific threat profile based on your sector, your operating markets, your technology environment, and your publicly available information. The profile identifies the threat actors most likely to target your institution, the techniques they are known to use against financial institutions in your markets, and the objectives they typically pursue. Attack scenarios for the red team phase are designed around this intelligence. The threat intelligence output is a deliverable in its own right and is included in the regulatory evidence pack.

What documentation is produced for regulatory submission?

Theos produces a full regulatory evidence pack including: the threat intelligence report, rules of engagement documentation, red team operations log, blue team assessment findings, purple team debrief outcomes, and a structured findings report formatted for the applicable regulator. For MAS TLPT, HKMA iCAST, and BNM submissions, documentation is structured to align with the specific format and content requirements each regulator publishes. An executive summary suitable for board review is included.

LET US HELP YOU!

LET US HELP YOU!