Vulnerability assessment and penetration testing are no longer isolated technical exercises. They are becoming part of a governed, auditable resilience capability.
Overview
Financial institutions depend on sophisticated technology environments, external service providers and interconnected platforms. As a result, vulnerability assessment and penetration testing have moved from good practice to a supervisory baseline in operational resilience programs.
DORA entered into application on 17 January 2025 and establishes a harmonized framework for digital operational resilience across EU financial entities, including ICT risk management, incident reporting, third-party risk and digital operational resilience testing. In Switzerland, supervisory expectations around operational risk and resilience have also strengthened, with increased focus on ICT, cyber risks, critical data and operational resilience.
The question is no longer whether a bank performs tests. The question is whether testing is risk-based, scoped against critical services, connected to remediation, evidenced to management and capable of demonstrating improvement over time.
From point-in-time testing to resilience cycle
Traditional vulnerability assessment often produces a list of findings. Penetration testing often produces a report. These are useful, but insufficient if findings are not prioritized, assigned, remediated, retested and translated into control improvements.
A resilience-oriented model treats testing as a cycle. It begins with asset and service mapping, threat landscape assessment and criticality classification. It then defines testing scope, executes vulnerability assessment or penetration testing, triages findings, manages remediation, retests closure and reports residual risk.
The cycle must include both technical and governance evidence. Technical evidence shows what was found and fixed. Governance evidence shows who accepted risk, who approved exceptions, whether deadlines were met and whether repeated findings indicate systemic weaknesses.
The role of VA, PT and TLPT
Vulnerability assessment identifies known weaknesses across systems, applications, networks and configurations. Penetration testing evaluates whether vulnerabilities can be exploited in realistic attack paths. Threat-led penetration testing goes further, using threat intelligence and realistic adversary scenarios to test critical or important functions.
Under DORA, Article 26 requires designated financial entities to carry out threat-led penetration testing at least every three years, covering critical or important functions and live production systems, with competent authority involvement in scope validation. Not every entity will be subject to TLPT, but the direction is clear: testing must be risk-based and connected to business-critical services.
For Swiss institutions, cyber-risk expectations emphasize threat landscape identification, scenario-based cyber exercises, outsourcing and operational resilience. VA and PT should therefore be integrated into the broader ICT risk and operational resilience framework rather than managed as isolated technical deliverables.
What a defensible testing program includes
A defensible program starts with an accurate asset inventory and a mapping of critical services. Without this, testing may cover easy-to-test systems while missing the platforms that matter most for business continuity, data confidentiality and regulatory obligations.
The program should define testing frequency, scope, methodology, provider selection, independence requirements, safe testing rules, data handling, evidence standards and remediation SLAs. It should also define how third-party and outsourced systems are included, especially where they support critical or important functions.
Findings should be classified by exploitability, business impact, exposure, control weakness and remediation scope. Severity alone is not enough. A medium technical vulnerability on a critical payment platform may require more urgent management attention than a high vulnerability on an isolated test environment.
Board evidence and continuous improvement
Senior management and boards do not need exploit scripts. They need an accurate view of resilience. Reporting should show critical findings, aging, remediation performance, recurring weaknesses, accepted risks, third-party dependencies and trend lines across testing cycles.
The strongest organizations use VA and PT findings to improve architecture, secure development, identity controls, segmentation, logging, patch management, vendor management and incident response. The objective is not simply to close tickets. It is to reduce the probability and impact of disruption.
Our Approach
- Resilience Testing Framework - Define testing scope, methodology, frequency, roles, reporting and escalation aligned with critical services and ICT risk.
- Vulnerability Assessment Program - Perform periodic technical assessments across infrastructure, applications, cloud, identity and workplace environments.
- Penetration Testing - Execute controlled tests to validate exploitable paths, control weaknesses and remediation priorities.
- Remediation Governance - Track findings through ownership, deadlines, retesting, exceptions and residual risk acceptance.
- Board Reporting - Provide management-level evidence of testing coverage, remediation maturity and resilience improvement.

