Get a free audit

Field Notes / Compliance

In a CBEST, Your Tester Scores Your SOC. You Never Get to Edit the Sheet.

The Bank of England has run CBEST since 2014, and most write-ups describe the attack. The part that decides what the regulator reads is the other half: a set of scored capability indicators about your detection and response, filled in by the penetration testing provider, sent straight to the regulator. The guide says it plainly. "This process is not self-certification and is not subject to vetting by individual firms/FMIs prior to receipt of the results by the regulator." Here is what is on that sheet, what the Bank found 13 firms doing wrong in 2025, and what the tier below CBEST quietly makes optional.

Author
Red Team Partners
Read
12 MIN READ
Filed
21 Sep 2026
A security operations analyst reading a threat detection alert in a server room at night, the moment a CBEST assessment records as a date and time.

01 The sheet your tester fills in about your SOC

CBEST has sat in the supervisory toolkit of the Bank of England, the PRA and the FCA since 2014 CBEST Implementation Guide 2024, Foreword . Four parties run it: the regulator, a Control Group inside the tested firm, a threat intelligence provider and a penetration testing provider. The Control Group is deliberately tiny. The guide asks for "a select number of senior individuals at the top of the security incident escalation chain", membership "as limited as possible", information shared on a need to know basis CBEST Implementation Guide 2024, s.3.2.2 .

Your SOC sits outside that circle by design. The intelligence provider is told to minimise the risk of detection by your SOC during its phase CBEST Implementation Guide 2024, s.7.2.1 . If the firm tips off system owners or SOC teams, the provider must report that to the regulator as manipulation of the process CBEST Implementation Guide 2024, s.6.4.1 . Nobody defending the estate knows, because what follows only means something if the alerts are real to the people reading them.

One item on the provider's mandatory task list is easy to skim past: "complete the Detection & Response (D&R) Capability Assessment ... of the firm/FMI based on the CBEST guidelines" CBEST Implementation Guide 2024, s.3.2.4 . The guide introduces that list as the tasks the provider completes "to satisfy the CBEST minimum criteria". An accredited CREST Certified Simulated Attack Manager runs it and vouches for the evidence and the final scores, and the work includes post-testing interviews with your SOC and incident response team CBEST Implementation Guide 2024, s.8.3 .

The CBEST version of that question set appears in the guide's references as CBEST (2024i), Detection & Response Capability Assessment, and the Bank does not publish it alongside the implementation guide. It does publish the STAR-FS equivalent. Both frameworks describe the same shape of instrument: quantitative and qualitative capability indicators, completed by the penetration testing provider, scoring detection and response. The STAR-FS sheet runs to six pages, downloads free, and reads like an examination paper about your own operations centre. The quantitative table scores monitoring on three points. Low is "No". Medium is "Yes, although limitations reduced the ability to analyse system logs". High is "Yes, all activity is monitored and the Firm/FMI possesses sufficient capacity to analyse all alerts and logs" STAR-FS D&R Assessment Guide 2024 .

The sheet keeps going in that register. Question 3.3 wants the names, positions and dates of every member of staff who was told about the testing. Question 5.1 asks what additional security controls would have allowed the client to detect each intrusion, and 5.2 asks what has been implemented to stop it happening again, or when it will be STAR-FS D&R Assessment Guide 2024 . Read those as the STAR-FS wording, because that is the version the Bank publishes. What CBEST states in its own words is that the indicators produce "an unbiased opinion of the firm/FMI's capability", from the provider, without your sign-off CBEST Implementation Guide 2024, s.8.3 .

Both outputs carry a two-week deadline. The draft penetration test report is due within a period agreed with the regulator, generally no later than two weeks after the test finishes, and the detection and response assessment goes back to the regulator no more than two weeks after execution completes CBEST Implementation Guide 2024, s.8.2, s.8.3 . Fourteen days after the last simulated attack, your supervisor holds a scored view of how your defenders performed.

02 What the Bank found in 2025

The PRA and the FCA compile an anonymised thematic report jointly, seeking alignment and input from the NCSC, and share it with firms that have never done a CBEST CBEST Implementation Guide 2024, s.10 . The 2025 edition, last updated 20 January 2026, sets out findings from 13 CBEST assessments. It also maps observed tactics, techniques and procedures to MITRE ATT&CK for the first time, and counts 469 successful tactics across those assessments 2025 CBEST thematic . That is the sharpest public figure on what works against UK financial firms when a funded, intelligence-led attacker is let loose on live systems.

Findings land in five themed areas: infrastructure security and data security; identity management and access control; detection and response; network security; and staff culture, awareness and training. Two sentences describe the clock directly. On detection: "Firms/FMIs with insufficient detection capabilities, for example poorly tuned monitoring or alerting for adverse incidents, were less able to detect potential cyberattacks in the early stages of the simulated attack." On the network: "Firms/FMIs with ineffective network monitoring, for example where there was not appropriate traffic inspection, were vulnerable to attackers obfuscating their malicious activities." 2025 CBEST thematic

Read those twice. Neither describes a missing tool. Both describe a tool that exists and is tuned badly. Alerting that fires on the wrong things, or fires on the right things into a queue nobody works. Traffic inspection that covers the perimeter and stops at the boundary where the attacker moves.

The Bank's four key messages for 2025: harden operating systems through patching and secure configuration; strengthen credentials management, enforce strong passwords, consider multi-factor authentication, prevent insecure credential storage and segment networks; achieve early detection through effective monitoring, alerting and response, which the Bank calls "key to reducing the impact from cyberattacks"; and implement risk-based remediation plans with oversight from risk managers and internal auditors 2025 CBEST thematic .

The 2024 thematic, the tenth anniversary edition, analysed the findings from participating banks, insurers, asset and investment managers, and FMIs. It named the same shape of problem: overly permissive access controls, insufficient multi-factor authentication, unpatched systems from configuration management failures, flat networks, staff falling for phishing, and on the response side insufficient monitoring, communication breakdowns during incidents and inadequate containment once a threat had been detected 2024 CBEST thematic . Hold on to that last one. The sheet asks for the hour you contained each breach, and the Bank has already told the sector that firms are slow at it.

03 The four phases and the clocks inside them

CBEST runs in four phases, and each has named sub-stages CBEST Implementation Guide 2024, s.4 .

  1. Initiation (about 6 weeks). Launch, Engagement, Scoping, Procurement. The scope is set and you procure both providers. During Scoping the regulator checks whether you are registered with the NCSC Early Warning Service and asks you to confirm your data there is current.
  2. Threat Intelligence (about 10 weeks). Direction, Intelligence, Validation, Assessment. Intelligence deliverables are produced and scenarios worked into a draft test plan. Malicious insider and supply chain scenarios are compulsory: the guide says they "should always be analysed and discussed during CBEST".
  3. Penetration Testing (about 14 weeks). PT Planning, Execution, Assessment, Review. An intelligence-led test runs against the systems behind each in-scope important business service. Your threat intelligence maturity and your detection and response capability are assessed in the same window.
  4. Closure (about 4 weeks). Remediation, Debrief, Supervision. The remediation plan is finalised, providers are debriefed, and the regulator supervises you executing it.

The regulators put the average CBEST project duration at around 9 to 12 months CBEST Implementation Guide 2024, s.4.1 . The first clock starts earlier. A CBEST notification letter asks you to contact your supervision team within 40 working days to start the process CBEST Implementation Guide 2024, s.6.1 . Eight working weeks to answer the letter. Initiation then runs about six weeks, and inside it you stand up a Control Group and procure two accredited providers.

The test phase runs closer to a real intrusion than most procurement teams expect. The minimum criteria put the assessment on live production systems including the corporate environment, unless legal or ethical restraints prevent it, covering the processes and systems behind the in-scope business services from the front door through to what sits behind them. Scenarios must assess perimeter controls, internal controls, and ingress and egress points CBEST Implementation Guide 2024, Annex A . Distributed denial of service and physical attacks are the guide's examples of scenarios that can appear in the intelligence report and stay out of the test.

Goals identified during the Intelligence phase become the flags the provider must capture. Update meetings usually run weekly, and the provider describes flags captured, flags not captured and any risks CBEST Implementation Guide 2024, s.8.2 . If progress stalls, the provider and the firm can discuss de-chaining the attack path. That leg up moves the tester to the next phase of the attack so a vulnerability gets tested rather than running out of clock, and every instance is agreed with the regulator and written into the report CBEST Implementation Guide 2024, s.8.2 . Scenario narratives use established frameworks such as MITRE ATT&CK or the Cyber Kill Chain, and the plan clarifies each step of the kill chain CBEST Implementation Guide 2024, s.8.1 .

The report has a mandated minimum contents list: one executive summary for the board, a second for technical leaders, results against the scenarios and target actions, the findings in summary and in detail with recommendations, and a breakdown of how far testers progressed through each stage of each scenario. Personally identifiable information and technical evidence are redacted before the regulator sees it CBEST Implementation Guide 2024, s.8.2 .

Nobody fails. The guide is explicit that a CBEST assessment is not a pass or fail test, and that weaknesses are reviewed with regulator feedback on your draft remediation plan CBEST Implementation Guide 2024, s.9.1 . The tail is the expensive part. The regulator tracks and reviews the remediation plan for "anything from six to 12 months, or longer" CBEST Implementation Guide 2024, s.9.3 . Add the 9 to 12 months of assessment and a CBEST occupies your security leadership for most of two years.

04 Who gets asked, and what STAR-FS makes optional

No published threshold decides this. The Bank gives three qualitative triggers CBEST Implementation Guide 2024, s.3.1 . The regulator requests one as part of the supervisory cycle, with the request list agreed by the PRA and FCA in line with thematic focus and supervisory strategy. Or you request one yourself, as part of your own cyber resilience programme and in consultation with the regulator. Or an incident has occurred and the regulator wants a CBEST to support post-incident remediation and validation. No asset size. No named list. If you are waiting to learn whether you are in scope, the answer arrives as a letter with a 40 working day clock on it.

Buyers conflate two organisations here. The Bank of England runs the accreditation process for CBEST service providers, and accredited providers must also be CREST members CBEST Implementation Guide 2024, s.6.4.1 . The guide points procurement at the register of companies approved to provide CBEST assignments, which it says sits on the CREST website CBEST Implementation Guide 2024, s.6.4 . CREST owns the individual certifications: CCTIM for the intelligence provider, CCSAM and CCSAS for the penetration testing provider, with certified individuals signing off every major deliverable CBEST Implementation Guide 2024, s.6.4.2 . CREST membership on its own is a different thing from CBEST approval, and procurement teams should check the register rather than the marketing page.

Below CBEST sits STAR-FS. The Bank of England's PRA and the FCA worked with CREST to create it. Its own guide states the relationship: "STAR-FS has been designed to replicate the rigorous approach defined within the CBEST framework ... However, STAR-FS allows for financial institutions to manage the tests themselves whilst still allowing for regulatory reporting." STAR-FS Implementation Guide 2024 The phases carry the same four names. The intelligence differs. STAR-FS uses commercially available threat intelligence services to define its scenarios. CBEST requires current and credible threat intelligence from an external accredited provider as a minimum criterion, delivered as a Targeting Report and a Threat Intelligence Report for that firm CBEST Implementation Guide 2024, Annex A . The published STAR-FS timings run shorter, with Initiation at 4 to 6 weeks, Threat Intelligence at 6 to 8 weeks and Closure at 4 weeks STAR-FS Implementation Guide 2024, Figure 2.2 .

That is the decision in front of every UK financial firm that will never receive a CBEST letter. TIBER-EU runs on the same logic across the continent and reaches Swiss institutions, which we have written up on the Swiss site. The mechanism survives the change of jurisdiction. An attacker moves, and somebody either notices or does not.

You do not need a notification letter to run the useful half of this. Ask for a test with detection objectives written in alongside the attack objectives, so the report carries two timelines: what the tester reached and when, and what your team saw and when. Start where a real intruder starts, which is what an internal, assumed-breach test models: one ordinary account inside the estate. Record every alert that fired, every alert that should have fired, and the hour containment happened. Then fix the tuning and run it again, which is the argument for continuous testing over one date a year. A scanner answers none of it, for the reasons in penetration testing versus vulnerability scanning.

We are not a CBEST provider, and this article is not a pitch for one. What we do is the attack and the clock: an operator-led test against your live estate, every finding proven by hand, the detection gaps named with the alert or log source that should have caught each step, and re-tests through the year. If your board is asking how fast you would notice, bring us the estate and we will give you the timings in writing. Talk to us and we will scope it in a call.

References

Sources

  1. Bank of England. CBEST Implementation Guide for CBEST participants, 2024 edition. bankofengland.co.uk
  2. Bank of England. CBEST threat intelligence-led assessments: implementation guide (landing page). bankofengland.co.uk
  3. Bank of England. 2025 CBEST thematic. Last updated 20 January 2026. bankofengland.co.uk
  4. Bank of England. 2024 CBEST thematic. bankofengland.co.uk
  5. Bank of England. STAR-FS Implementation Guide, March 2024. bankofengland.co.uk
  6. Bank of England. STAR-FS Detection & Response Assessment Guide, March 2024. bankofengland.co.uk
  7. CREST. CBEST membership and accreditation page. crest-approved.org