Insights

CBEST cyber resilience framework protecting UK financial institutions through intelligence-led security testing and threat simulation.
What is CBEST: An Intelligence-Led Resilience Framework

CBEST logo representing the UK intelligence-led cyber resilience testing framework.

CBEST is the UK’s flagship threat intelligence-led penetration testing framework for the financial services sector. Developed by the Bank of England in partnership with the Financial Conduct Authority (FCA) and Prudential Regulation Authority (PRA), CBEST helps financial institutions measure their ability to detect, respond to and recover from sophisticated cyber-attacks. In this guide, we explain what CBEST is, how it works, who requires it, and how accredited providers deliver CBEST assessments.

There is no set timescale for how often a firm undergoes a CBEST test, however it is likely to be at least once every 3-4 years, if the firm asks the regulator for a test, or if there is a significant cybersecurity breach at a firm and the regulator mandates one. 

The aim of CBEST is to: 

  • test a firm’s defences;  
  • assess its threat intelligence capability; and 
  • assess its ability to detect and respond to a range of external attackers as well as people on the inside.  

Firms use the assessment to plan how they can strengthen their resilience. 

The simulated attacks used in CBEST are based on current cyber threats. These include the approach a threat actor may take to attack a firm and how they might exploit a firm’s online information. 

The important thing to take away from CBEST is that it is not a pass or fail assessment. It is simply a tool to help the organisation evaluate and improve its resilience. 

CBEST primarily applies to the UK’s most systemically important financial institutions. This includes major banks, financial market infrastructure providers, payment systems and other organisations whose disruption could significantly impact the UK financial sector.

While CBEST is generally regulator-driven, many organisations use CBEST principles to strengthen their cyber resilience strategy and test their ability to defend against real-world threat actors.

What Organisations Are Subject to CBEST?

CBEST is primarily intended for the UK’s most systemically important financial institutions. This includes major banks, financial market infrastructure providers, payment systems and other organisations whose disruption could significantly affect financial stability. Firms are typically selected in consultation with the PRA and FCA as part of ongoing supervisory activities.

Benefits of CBEST Assessments

CBEST provides financial institutions with a unique opportunity to assess their cyber resilience against realistic threat scenarios. Rather than simply identifying vulnerabilities, CBEST evaluates whether an organisation can prevent, detect and respond to sophisticated attacks targeting its critical services.

Key benefits of a CBEST assessment include:

  • Realistic attack simulation based on genuine threat intelligence relevant to the organisation.
  • Validation of security controls against tactics, techniques and procedures used by real-world adversaries.
  • Improved detection and response capabilities through testing of operational security teams and incident response processes.
  • Enhanced threat intelligence maturity through a better understanding of relevant threat actors and risks.
  • Greater operational resilience by identifying weaknesses across people, processes and technology.
  • Increased regulatory confidence through demonstrable commitment to cyber resilience and risk management.

In many respects, CBEST is closer to a mature red team exercise than a traditional penetration test. However, CBEST goes further by incorporating regulator oversight, threat intelligence-led scenario development, structured resilience assessment and formal evaluation of detection and response capabilities. The result is a more comprehensive understanding of how a financial institution would withstand a genuine cyber-attack.

How is CBEST Different from Traditional Penetration Testing?

While CBEST includes penetration testing activities, it is fundamentally different from a traditional penetration test. CBEST combines specialist threat intelligence, realistic adversary emulation and assessment of an organisation’s detection and response capabilities to provide a broader view of cyber resilience.

Traditional Penetration TestingCBEST Assessment
Focuses on identifying vulnerabilities within a defined technical scope.Focuses on measuring resilience against realistic threat actor scenarios.
Scope is typically restricted to specific applications, networks or systems.Scope is aligned to critical business services and systemic risks.
Tests whether vulnerabilities exist and can be exploited.Tests whether attackers can achieve meaningful business objectives.
Usually conducted using standardised testing methodologies.Driven by bespoke threat intelligence specific to the organisation.
Emphasises vulnerability discovery and remediation.Emphasises prevention, detection, response and recovery capabilities.
Findings are often technical and directed at IT teams.Findings are strategic and relevant to technical teams, executives and regulators.
Usually performed independently of threat intelligence activity.Begins with a dedicated Threat Intelligence phase.
Measures security posture at a point in time.Measures organisational resilience against current threat actors and attack techniques.
Often conducted to satisfy compliance requirements.Conducted to support regulatory oversight and operational resilience objectives.
Typically assesses technology.Assesses people, processes and technology.

How does CBEST work? 

A firm may be selected for a CBEST assessment under one of the following circumstances: 

  • The firm/FMI is requested by the regulator to undertake a CBEST assessment as part of the supervisory cycle. The list of those requested to undertake a review is agreed by the PRA and FCA on a regular basis in line with any thematic focus and the supervisory strategy. 
  • The firm/FMI has requested to undertake a CBEST as part of its own cyber resilience programme, when agreed in consultation with the regulator. 
  • An incident or other events have occurred, which has triggered the regulator to request a CBEST in support of post incident remediation activity and validation, and consultation/agreement has been sought with the regulator. 

CBEST is broken down into phases, each of which contains a number of activities and deliverables: 

CBEST testing process showing initiation, threat intelligence, penetration testing and closure.

When the decision to hold a CBEST is made, the firm is notified in writing that a CBEST should occur by the regulator, and the firm has 40 working days to start the process. This occurs in the Initiation Phase of a CBEST. A Firm will be required to scope the elements of the test, aligned with the implementation guide, before procuring suitably qualified and accredited Threat Intelligence Service Providers (TISP), and Penetration Testing Service Providers (PTSP) – such as Prism Infosec. 

After procurement there is a Threat Intelligence Phase, which helps identify information threat actors may gain access to, and what threat actors are likely to conduct attacks. This information is shared with the firm, the regulator and the PTSP and used to develop the scenarios (usually three). A full set of Threat Intelligence reports is the expected output from this phase. After the Penetration Test Phase, the TISP will then conduct a Threat Intelligence Maturity Assessment. This is done after testing is complete to help maintain the secrecy of the testing phase.  

The next phase is the Penetration Testing Phase â€“ during this phase each of the scenarios are played out, with suitable risk management controls to evaluate the firm’s ability to detect and respond to the threat. During this phase, the PTSP works closely with the firm’s control group and regular updates are provided to the regulator on progress. After testing, the PTSP then conducts an assessment of the Detection and Response (D&R) capability of the firm. Following these elements, the PTSP will then provide a complete report on the activities they conducted, vulnerabilities they identified and the firm’s D&R capability.  

CBEST then moves into the Closure phase where a remediation plan is created by the firm and discussed with the regulator and debrief activities are carried out between the TISP, PTSP and the regulator.  

The CBEST implementation guide can be found here: 

CBEST Threat Intelligence-Led Assessments | Bank of England 

The regulator for the firms remains actively involved throughout the CBEST assessment, attending regular updates, and is consulted at significant points throughout the process as a key stakeholder. 

In a CBEST assessment, third-party entities are not often included in the scope of the test as the regulator often has no authority over them, however, where possible they should be included if they are providing core services to the firm. After all, a real-world threat actor is unlikely to respect organisational or regulatory boundaries. Inclusion of such third parties however may become more necessary if the UK passes the UK Cyber Security Resilience Bill (CSRB).  

Who can Deliver CBEST Testing

In the UK only certain firms are permitted to deliver CBEST tests. For Security testing, this is due to the mandate from the regulators that only firms which have both a CREST Certified Red Team Manager and Red Team Specialist (CCRTM and CCRTS – formerly CCSAS and CCSAM. Furthermore, the firm must have at least 14,000 hours of penetration testing experience, and the CCSAM and CCSAS must also have 4000 hours of testing financial institutions. The firm must also have demonstrated their skills through delivery of penetration testing services for financial entities which are willing to act as references, and must have been delivered within the previous 12 months prior to the application.

For Threat Intelligence a firm requires relevant experience, capabilities,  and methodologies and a qualified CREST Certified Threat Intelligence Manager. As a result, there are only 12 companies in the UK accredited to deliver CBEST security testing, and 8 firms which can deliver Threat Intelligence. Furthermore a firm who is delivering Threat Intelligence under CBEST cannot also deliver the security testing. 

Frequently Asked Questions About CBEST

Is CBEST mandatory?

CBEST is generally undertaken by organisations identified by UK regulators or those wishing to improve cyber resilience in consultation with regulators.

How often is CBEST performed?

Typically every three to four years, although timing can vary depending on regulatory requirements and organisational circumstances.

Who can perform CBEST testing?

Only accredited providers meeting CREST and regulatory requirements may deliver CBEST assessments.

Is CBEST a pass or fail assessment?

No. CBEST is designed to identify strengths and weaknesses in cyber resilience rather than provide a pass or fail result.

Conclusion – What is CBEST?

CBEST remains the UK’s leading threat intelligence-led testing framework for the financial sector. By simulating realistic attacks against people, processes and technology, CBEST provides organisations with a clear understanding of their cyber resilience and their ability to detect and respond to sophisticated threat actors.

For organisations subject to regulatory scrutiny, a well-executed CBEST assessment provides invaluable insight into security effectiveness, operational resilience and incident response capabilities.

Talk to a CBEST Accredited Provider

Prism Infosec is one of a limited number of CREST-accredited organisations authorised to deliver CBEST security testing. Our experienced consultants support financial institutions throughout the engagement lifecycle, from scope development through to remediation planning.

To discuss an upcoming CBEST assessment or learn more about our CBEST testing services, contact our team today.

About the author

Prism Social Icon
Prism Infosec
Prism Infosec’s innovative approach to the delivery of PCI projects and technical security testing was recognised with a PCI Award for Technical Excellence in January 2020. The award was presented for the delivery of a client project that was considered by the review panel to be an outstanding example of best practice.
the-cyber-scheme
pci
Crest
cbest
CHECK Penetration Testing (Dark Logo)
Cyber Incident Exercising
Cyber Incident Response Standard Level logo
Untitled design (1)
4b30d27e-0b52-4807-9ef9-9d88954e3e1c

Experiencing a security breach?
Contact the cyber security experts now