Audit methodology · Last verified
CBEST Threat Intelligence-Led Assessments
CBEST is the Bank of England, PRA and FCA's intelligence-led penetration testing regime for assessing cyber resilience of systemically important firms. Since 2014 it has assessed firms and financial market infrastructures the regulators judge systemically important, using red-team-style testing on live production systems rather than a written standard.
- Class
- Audit methodology
- Owner
- Bank of England, Prudential Regulation Authority (PRA) and Financial Conduct Authority (FCA)
- Last verified
What it is
"CBEST promotes an intelligence-led penetration testing approach that mimics the actions of cyber attackers' intent on compromising an organisation's important business services (IBSs)."
"CBEST is a targeted assessment that allows regulators and firms to better understand weaknesses and vulnerabilities and take remedial actions, thereby improving the resilience of systemically important firms."
"Since 2014, CBEST has been an important part of the Bank of England (BoE), Prudential Regulation Authority (PRA), and Financial Conduct Authority (FCA) (together, the 'regulators') collective supervisory toolkit to assess the cyber resilience of firms and FMIs."
The assessment runs in four phases — Initiation, Threat Intelligence, Penetration Testing and Closure — against live production systems, using externally supplied, realistic threat scenarios rather than a checklist audit.
CBEST issues no certificate to the assessed firm. It is a recurring, regulator-supervised assessment regime, not a credential the firm can hold or display.
Who owns it
The Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority run CBEST jointly, as part of their shared supervisory toolkit for the UK financial sector.
Who assesses it
Service providers must themselves be accredited: "The TISP must be CBEST accredited" (Threat Intelligence Service Provider) and "The PTSP must be CBEST accredited" (Penetration Testing Service Provider). That accreditation runs through CREST — "CREST performs a very important function. The regulator has reviewed the CREST company accreditation processes, Codes of Conduct and Ethics" — and requires named individual credentials: CCTIM ("CREST Certified Threat Intelligence Manager") for TISPs and CCSAM ("CREST Certified Simulated Attack Manager") for PTSPs.
Who asks for it
"The firm/FMI is requested by the regulator to undertake a CBEST assessment as part of the supervisory cycle."
A firm can also take part by agreement rather than instruction: participation may be "agreed in consultation with the regulator."
A third route is remedial: an assessment can be "triggered by the regulator...in support of post incident remediation activity."
Sources
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.