Threat-led testing, prepared for

CBEST: how to prepare (and when STAR-FS fits instead)

CBEST tests whether a realistic adversary could reach the systems behind your important business services. The testing itself is delivered by accredited providers under the Bank of England's framework; the preparation, and how well your firm holds up, is yours. This guide covers both, and where STAR-FS fits for firms outside the systemic tier.

The essentials

What CBEST is

CBEST is the Bank of England's threat-led penetration testing scheme for the UK's most systemically important financial firms and market infrastructures. Engagements simulate real adversaries against live production systems, built on bespoke threat intelligence and delivered by accredited providers, with supervisors involved throughout. Firms do not apply; testing is agreed with their regulators.

That last sentence carries the two facts that shape everything else on this page. Because participation runs through supervisors, a CBEST is something you get ready for rather than something you shop for. And because delivery sits with accredited threat intelligence and testing providers, the question for everyone else in the market, us included, is how well prepared you are when they arrive.

Reviewed July 2026.

Inside an engagement

What a CBEST engagement involves

Three phases, each with its own provider, cadence and demands on your people. The middle one gets the attention; the first and last decide whether the exercise was worth having.

Threat intelligence

An accredited threat intelligence provider builds a picture of the adversaries most likely to target your firm and the scenarios they would run. This intelligence, not a generic test plan, scripts everything that follows.

Red team testing

An accredited testing provider executes those scenarios against your live production environment, under tight controls, attempting to reach the systems that underpin your important business services the way the modelled adversary would.

Remediation and closure

Findings feed a remediation plan discussed with your supervisors. The test's value is realised here: in what changes, what is evidenced, and what the board learns about where the firm actually stands.

The fresh signal

What the 2025 CBEST thematic means for preparation

The Bank of England published thematic findings from CBEST assessments in 2025: a cross-firm view of the weaknesses threat-led tests keep surfacing. For firms facing a future test, it is the closest thing to seeing the exam board's marking notes, because thematic findings tell you where testers found the doors open at firms much like yours.

The sensible use of it is as a preparation filter: read the themes, ask which would be found at your firm tomorrow, and let the honest answers set your remediation priorities before any test window is discussed. That is a considerably cheaper way to learn each lesson than having a red team demonstrate it in production, and it pairs naturally with the scenario testing your operational resilience programme already owes the FCA.

The other route

STAR-FS: the route for everyone else

Most UK financial firms will never be invited into CBEST, and that is by design. STAR-FS, live since 2024, is the lighter CREST-run alternative: the same intelligence-led testing philosophy, but a scheme a firm can initiate for itself, without waiting for a supervisor to make the first move.

The Bank of England's 2026 priorities point non-systemic firms towards exactly this route. If your firm is under the FCA's operational resilience regime but outside the systemic tier, STAR-FS is how you get the substance of a threat-led test at a scale your firm can carry, and everything in the preparation section below applies to it just as fully.

How CBEST and STAR-FS sit alongside DORA's testing regime, and which applies to a firm scoped into more than one, is the subject of our guide to TLPT across the three regimes.

The work before the test

How to prepare, whichever scheme you face

Four assets decide how a threat-led test goes, and every one of them can be built before a test is even scheduled. This is the readiness work we deliver.

Important business services, mapped

CBEST scenarios aim at the systems behind your important business services. If your IBS mapping is stale or shallow, scoping drags and the test aims at the wrong things. Tighten the mapping first; it is the single highest-value piece of preparation.

A scenario history that stands up

Firms that have already run severe but plausible scenario exercises walk into threat intelligence workshops with evidence and vocabulary. Firms that have not are describing their crisis response from theory.

Impact tolerance evidence

Testers and supervisors will both ask what happens when a tolerance is threatened. Documented tolerances, and evidence of how breaches would be detected and escalated, turn an awkward question into a prepared answer.

A stakeholder plan

A threat-led test touches the board, the regulator, security, IT operations and sometimes third parties, over an extended period. Decide early who knows, who decides and who fronts each conversation; secrecy rules make this harder to improvise than firms expect.

Who does what

Our role: your side of the table

To be plain about the boundary: CBEST and STAR-FS testing is delivered by accredited threat intelligence and testing providers, and we are not one. What we do is make sure the firm being tested is ready: IBS mapping tightened, tolerances evidenced, scenario history built, stakeholders briefed, and an informed voice beside you when scoping is negotiated and findings land.

The wider picture, including DORA's testing obligations for firms with EU entities, is in the threat-led penetration testing guide. The preparation itself starts with the scenario testing exercise most firms already need for the FCA regime.

Quick answers

CBEST questions, answered

Who needs CBEST?

CBEST is aimed at the firms and financial market infrastructures whose disruption would matter most to UK financial stability: the systemic tier. Firms do not opt in; participation is agreed with supervisors. If you are outside that tier, STAR-FS is the route designed for you, and the Bank of England's 2026 priorities explicitly point non-systemic firms towards it.

What does a CBEST engagement involve?

Three broad phases: a threat intelligence phase that models the adversaries most relevant to your firm, a red team phase where accredited testers execute those scenarios against live systems, and a remediation phase where findings are addressed and discussed with supervisors. The whole exercise runs under the Bank of England's framework with regulators involved throughout.

What is the difference between CBEST and STAR-FS?

Both are threat-led testing frameworks for UK financial services. CBEST is the Bank of England's scheme for systemic firms, run with supervisors and initiated through them. STAR-FS, live since 2024, is the lighter CREST-run alternative that firms can initiate themselves, using the same intelligence-led approach with less regulatory ceremony. Our TLPT guide compares them alongside DORA's testing regime.

TLPT across all three regimes

Rocket above the Operational Resilience UK call to action

Ready before the window

Get test-ready on your own schedule

A call establishes where your IBS mapping, tolerances and scenario history stand today, and what a readiness programme would close before any tester arrives.