TIBER_EUPreparation Phasevoice-validated

TIBER_EU Preparation: Preparation Phase

TIBER_EU

AL
Adam Lundqvist
Founder at SQUR · last verified 2026-10-06

Regulation text

The preparation phase establishes the test foundation: scoping the critical functions and supporting infrastructure to be tested, identifying the test manager and stakeholders, agreeing on the procurement of qualified threat intelligence and red team providers, and securing approval from competent authorities.

ATT&CK techniques this article tests · 15

TechniqueWhy it mapsConfidence
T1592.0011. Scoping critical functions requires detailed host information. This technique involves collecting data on victim hosts to understand the environment for the test.
90%
T1593.0011. Understanding network architecture is crucial for defining the test scope. This technique involves collecting network topology and configuration data.
90%
T1596.0011. Identifying test managers, stakeholders, and procurement processes is part of the preparation phase. This technique involves gathering organizational details.
80%
T1087.0011. Identifying key personnel and potential red team targets is essential for stakeholder engagement and test planning. This technique involves discovering user accounts.
85%
T10181. Identifying systems within the test scope is a core activity. This technique involves discovering remote systems accessible from the network.
85%
T11901. Identifying potential entry points for the red team is a key part of initial access planning. This technique involves identifying vulnerable public applications.
80%
T1566.0011. Planning potential phishing scenarios is crucial for simulating realistic initial access. This technique involves crafting and deploying phishing attempts.
80%
T10051. Gathering internal system data is necessary for comprehensive scoping and understanding the target environment. This technique involves collecting data from local filesystems.
75%
T10391. Identifying shared resources relevant to critical functions aids in defining the test scope. This technique involves accessing data from network shares.
75%
T1027.0011. Red team planning includes methods to bypass detection. This technique involves obfuscating code or data to evade security controls.
70%
T1071.0011. Planning Command and Control (C2) channels is vital for red team operations. This technique involves using common application protocols for C2.
70%
T14861. Defining potential impact scenarios is part of the test objectives. This technique involves encrypting data to cause disruption.
65%
T1547.0011. Planning persistence methods is essential for simulating advanced threat actor behavior. This technique involves configuring programs to run at system startup.
65%
T10681. Identifying potential vulnerabilities for privilege escalation is a key red team planning activity. This technique involves exploiting system flaws to gain higher privileges.
60%
T1021.0011. Planning how the red team might move laterally within the scoped environment is critical. This technique involves using remote services for lateral movement.
60%

Defending mitigations · 5

MitigationWhat it doesConfidence
M10311. Identifying and planning for tools/techniques that should be blocked helps define the test boundaries and expected defenses. This mitigation prevents execution of malicious tools.
85%
M10381. Managing access for test participants and red team members is crucial for controlling the test environment. This mitigation ensures proper creation and deletion of accounts.
85%
M10471. Planning for logging and monitoring during the test ensures visibility into red team activities. This mitigation involves collecting and reviewing system logs.
80%
M10351. Scoping network boundaries for the test restricts red team activities to the defined environment. This mitigation limits network access to critical resources.
75%
M10281. Ensuring test environments are configured securely helps establish a baseline for the red team exercise. This mitigation hardens operating system settings.
70%

Underlying weaknesses · 7

CWEWhy it persistsConfidence
CWE-2001. Scoping aims to identify critical data and systems, which, if exposed, represent a significant weakness.
90%
CWE-2871. Red teams will test authentication mechanisms; weaknesses here allow unauthorized access.
85%
CWE-2691. Red teams will test privilege escalation; weaknesses in privilege management allow unauthorized elevation.
85%
CWE-791. This common web vulnerability is frequently exploited by red teams for initial access or data exfiltration.
80%
CWE-891. This critical database vulnerability is a prime target for red teams to gain access or exfiltrate data.
80%
CWE-221. File system access vulnerabilities are often exploited by red teams to access sensitive files.
75%
CWE-7321. Red teams test resource access; incorrect permissions allow unauthorized access to critical assets.
75%

What SQUR Covers

Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.

What SQUR Does Not Cover

Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.

Provenance

Mapped Q2.2026 using gemini-2.5-flash · €0.0181 compute · voice-rubric self-validated · 2 hallucination(s) dropped at validation