
Global Big Four professional services firm delivering CREST, CHECK, and CBEST-accredited penetration testing and red teaming services from London, serving the UK's largest enterprises and regulated organisations.
CBEST is the Bank of England's intelligence-led red teaming framework for systemically important UK financial institutions. It requires two CREST-accredited, CBEST-approved suppliers working together: a Threat Intelligence provider and a Red Team provider whose consultants hold CCRTS qualifications under a CCRTM-managed engagement. The providers below carry CBEST accreditation in our directory; the list opens with our Featured partner, clearly labelled, followed by the wider set.
Related: STAR-FS penetration testing companies · Threat-led penetration testing (TLPT) · UK penetration testing companies
CBEST is the Bank of England's framework for intelligence-led penetration testing of systemically important UK financial institutions: the banks, insurers, and financial market infrastructures regulated by the Bank, the PRA, and the FCA. Introduced in 2014, it uses bespoke cyber threat intelligence to simulate the specific real-world attackers most likely to target the financial sector, testing an organisation's detection and response against a realistic, goal-oriented attack on its live production systems.
A CBEST assessment involves two distinct accredited suppliers working together: a Threat Intelligence provider, which builds the bespoke intelligence picture and the target scenarios, and a Red Team provider, which executes the simulated attack. Both must be CREST-accredited and approved under the CBEST scheme. Red Team providers must hold CBEST certification and deploy consultants holding the CCRTS qualification (CREST Certified Red Team Specialist), and the engagement must be managed by a CCRTM (CREST Certified Red Team Manager). These requirements keep the pool of eligible providers deliberately small.
The providers below are CREST members carrying CBEST accreditation in our directory. CBEST engagements are substantial programmes, typically running several months end to end and coordinated with the regulator throughout, so shortlist on demonstrated financial-sector red team experience, CCRTS and CCRTM staffing, and clean operational tradecraft. Always confirm a supplier's current scheme status directly with CREST and the Bank of England before appointing them.

UK offensive security consultancy delivering CREST-accredited penetration testing, adversary simulation and CBEST, TIBER-EU and TBEST threat-led testing, mainly for financial services and other large organisations.

Global Big Four professional services firm delivering CREST, CHECK, and CBEST-accredited penetration testing and red teaming services from London, serving the UK's largest enterprises and regulated organisations.

Elite UK offensive security consultancy specialising in CBEST/STAR/TIBER red teaming, advanced adversary simulation, and CREST-accredited penetration testing for FTSE 100 clients.

CREST and CHECK-accredited UK penetration testing consultancy with CBEST approval, specialising in infrastructure, application, and simulated attack assessments across the public and private sectors.

Subscription-based offensive cybersecurity firm delivering continuous cyber attack services with CREST STAR and CBEST accreditations from its London headquarters.
CBEST is the Bank of England's framework for intelligence-led penetration testing of systemically important UK financial institutions, including banks, insurers, and financial market infrastructures regulated by the Bank, the PRA, and the FCA. It uses bespoke threat intelligence to simulate the real-world attackers most likely to target the financial sector, run against the organisation's live production systems and coordinated with the regulator.
A CBEST assessment uses two accredited suppliers: a Threat Intelligence provider and a Red Team provider, both CREST-accredited and approved under the CBEST scheme. The Red Team provider must hold CBEST certification and deploy consultants holding the CCRTS qualification (CREST Certified Red Team Specialist), with the engagement managed by a CCRTM (CREST Certified Red Team Manager).
CBEST is the Bank of England's regulator-led scheme for the UK's most systemically important financial firms. STAR-FS is the CREST-run scheme that financial firms can commission themselves using the same pool of accredited providers and qualifications. TIBER-EU is the European Central Bank's equivalent framework, mandated under DORA for significant EU financial entities. All three are forms of threat-led penetration testing.
CBEST is a substantial programme rather than a fixed-scope test. Engagements typically run several months end to end, spanning a threat-intelligence and scoping phase, weeks of active red teaming, and a reporting and replay phase, all coordinated with the regulator. Costs sit at the top of the red team range, commonly £50,000 or more depending on scope.