Qualysec
Blog

CREST Accredited Penetration Testing for HKMA iCAST (Hong Kong)

Explore CREST penetration testing for HKMA iCAST in Hong Kong, covering intelligence-led threat simulations, provider requirements, and key deliverables.

Published on September 15, 2026
Read Time: 14 min
CONNECT WITH US

Identification of vulnerabilities is just one step in assessing the bank’s cyber resilience. Financial organizations must know if attackers can take advantage of the vulnerabilities identified in order to gain access to important banking systems. This is where penetration testing companies with CREST-accreditation become relevant, particularly for institutions preparing for HKMA’s intelligence-led testing requirements. 

The Hong Kong Monetary Authority developed its Cyber Resilience Assessment Framework in 2016. The first assessment round covered 30 authorized institutions. Its iCAST component uses relevant cyber intelligence to simulate real-life attacks and assess how effectively institutions can detect, respond to, and withstand threats. 

In this guide, we will discuss CREST-accredited penetration testing in Hong Kong. What HKMA iCAST is, the importance of CREST certification, how the test is conducted, and how to develop attack scenarios. We will also discuss what providers should offer and how to choose the best iCAST provider for banks.

Key Takeaways

  • HKMA iCAST employs threat-led attack simulations to test cyber resilience.
  • CREST certification is essential in validating provider and tester proficiency.
  • iCAST tests detection, response, and recovery capabilities beyond vulnerabilities.
  • Effective testing starts with threat intelligence and scenario design.
  • Attack scenarios should reflect critical banking functions and real TTPs.
  • Banks should assess providers for CREST scope, HKMA experience, and methodology.
  • Strong engagements deliver clear findings and practical remediation priorities.

What Is HKMA iCAST?

Intelligence-led Cyber Attack Simulation Testing (iCAST) represents the components of red team testing within the HKMA’s Cyber Resilience Assessment Framework (C-RAF). This is being carried out via the Cybersecurity Fortification Initiative (CFI). This process goes beyond the regular penetration test. iCAST represents a live cyber attack simulation of an actual threat against the key operations of a bank. For example, payment processing, core banking, and authentication services.

Some of the key characteristics of iCAST are:

  • Threat intelligence: Uses intelligence regarding the activities of actual threat actors who are attacking banks.
  • Critical function testing: Evaluates the impacts that an attack would have on critical banking functions and operations.
  • Simulation of a realistic attack: Simulates a multi-stage attack using actual TTPs (tactics, techniques, and procedures).
  • Red teaming: Tests the performance of the bank as a whole when attacked.

What CREST Requirements Should iCAST Providers Meet? 

The iCAST service providers must be CREST-accredited for conducting intelligence-led security testing. CFI Annex 1 defines competency requirements for roles such as the iCAST Manager, Specialist, Infrastructure Tester, and Web Application Tester. Each person must hold the required professional certification or an equivalent qualification for their assigned role.

By working with an accredited CREST provider, you will be able to:

  • Comply with HKMA criteria for competent and objective security testing.
  • Follow controlled testing processes through attack simulations.
  • Ensure that your confidential banking systems and data remain safe during testing.
  • Create a set of guidelines to be followed during the test.
  • Collect evidence of flaws in detection, reaction, and resilience.

Difference Between iCAST and Traditional Penetration Testing

Aspect Traditional penetration test HKMA iCAST
Starting point Known vulnerabilities and security control checklists Sector-specific threat intelligence about attackers targeting banks
Objective Find and report technical vulnerabilities Test detection, response, and recovery for critical functions
Method Usually focuses on a specific system, application, or network Uses adversary emulation to recreate multi-stage attacks based on real-world TTPs, often mapped to MITRE ATT&CK
Outcome A list of vulnerabilities with severity ratings Evidence of security gaps, monitoring blind spots, and response weaknesses, along with a prioritised remediation roadmap

Need help meeting HKMA iCAST requirements

Let Qualysec’s experts evaluate your security posture so you can meet regulatory requirements and protect critical banking operations with confidence.

Talk to a Security Expert

HKMA iCAST Compliance

How can you select a CREST-accredited iCAST provider?

Selecting an iCAST service provider should not only include determining whether they are members of CREST. Look for providers with proven experience delivering Hong Kong banking red teaming services, particularly those familiar with HKMA C-RAF, iCAST, and threat-led testing. 

Verifying CREST membership and current accreditation status

Ensure that the accreditation of the provider is validated by the CREST Marketplace. Ensure that the accreditation applies to the services you are seeking via the iCAST process. 

In practice, you should:

  • Verify the legal entity: Ensure that the proper legal entity is accredited.
  • Ensure proper accreditation scope: Ensure that the accreditation applies to the relevant discipline of security testing.
  • Verify the accreditation status: Ensure that the accreditation is up-to-date.
  • Ensure tester certifications: Confirm that the testers assigned to your project have the proper professional certifications.
  • Distinguish between accreditation and certification: Verify both the provider’s accreditation and the individual testers’ qualifications where required.

Assess experience with HKMA C-RAF and Hong Kong banking iCAST

CREST accreditation alone does not demonstrate iCAST experience. Find one who has real-world experience with HKMA C-RAF, threat-led testing, and financial services. 

Look for:

  • Relevant experience: Experience in conducting iCAST or similar threat-led assessments for banks or regulated financial institutions.
  • Critical-function testing: Put payment systems, core banking, digital channels, or other critical functions to the test.
  • Regulatory knowledge: Understanding of the requirements and reporting expectations of the HKMA.
  • Local threat intelligence: Use of Threat intelligence-led security testing in Hong Kong and APAC-specific threat intelligence to develop realistic scenarios.
  • Blue Team coordination: Experience working with the bank’s White Team and Blue Team during testing. 

Evaluating methodology, reporting quality, and regulatory alignment

Request clarification from the service provider about the transition from threat intelligence to attack simulation to remediation. The method should be based on your critical functions and agreed testing goals.

Methodology expectations

The strategy should consist of:

  • Threat intelligence: Create a Threat Intelligence Report (TIR).
  • Scenario Design: Design attack scenarios to encompass critical functions and appropriate TTPs.
  • Controlled simulation: Simulate the scenarios while following a set of agreed rules of engagement.
  • Post-exercise analysis: Review detection, response, and remediation requirements.

The provider should explain how they applied MITRE ATT&CK to map the adversary behaviours and how they support the testing methodology.

Reporting expectations

Request a redacted sample red-team report to evaluate the quality of the provider’s reporting. It should include:

  • Executive summary: Key risks and their impact on critical functions.
  • Attack narrative: The attack path from initial access to objective achievement or containment.
  • MITRE ATT&CK mapping: Relevant techniques and identifiers.
  • Detection assessment: Alerts, visibility gaps, and missed activity.
  • Detection timelines: How quickly different stages of the attack were identified.
  • Risk-rated findings: Root causes, impact, and severity.
  • Remediation roadmap: Prioritised actions to address identified weaknesses.

A provider should clearly show how their testing and reporting will help you understand the paths to attack. Also, gaps in detection, effectiveness of response, and remediation priorities.

How Does the HKMA iCAST Testing Process Work?

The HKMA iCAST compliance testing process is based on a multi-stage and structured approach to emulate realistic threat actor activities. The iCAST cyber resilience assessment follows a structured, multi-stage approach while safeguarding the bank’s business processes. It is designed and aligned with the HKMA C-RAF v2.0, which goes through three stages:

Step 1: The Threat Intelligence Phase

The procedure begins with collecting and analyzing threat intelligence relevant to the banking industry.

  • Collect threat intelligence for the sector: Look into known threat actors who target banks and other financial organizations.
  • Characterize threat actors: Evaluate advanced persistent threat (APT) groups and cybercrime groups who may pose a threat to the institution.
  • Map attacker behaviour: Map relevant tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework.
  • Determine possible attack vectors: Figure out how the attack techniques may affect the institution’s systems and resources.
  • Threat Intelligence Report (TIR): Summarize the intelligence and use it to create iCAST scenarios.

Step 2: Designing iCAST Attack Scenarios

The provider leverages the TIR to create realistic attack scenarios for the bank.

  • Identify critical targets: Identify critical functions, including payment systems, core banking, and the digital banking channels.
  • Develop realistic scenarios: Bring relevant threat actor TTPs to attack paths for the institution.
  • Establish appropriate limits of testing: Establish operating boundaries and rules of engagement prior to testing.
  • Define goals and criteria: Define what is being achieved in each scenario and how it will be measured as successful.
  • Get formal approval: Scenarios and testing plan shall be formally approved by the appropriate governance stakeholders.
  • Safeguard production systems: Add safeguards to ensure that unacceptable impacts to banking operations or customers are avoided.

Step 3: Executing the iCAST Simulation Test

After the scenarios are accepted, the red team conducts the simulated attack on the agreed-upon targets.

  • Perform the scenarios: The red team performs the agreed environment’s TTPs as the counterpart.
  • Work with the White Team: The provider works in conjunction with your organization’s’s White Team to ensure safety and escalation during the testing process.
  • Test the Blue Team: The SOC and incident response team and the IT teams in the bank are evaluated on their ability to detect, contain, and respond to simulated attacks.
  • Track defensive performance: Document alerts, things missed, responses taken, and events contained during the exercise.
  • Ensure operational safety: Adhere to the agreed rules of engagement to reduce disturbance of production systems and critical banking services.
  • Run the simulation: iCAST engagements can be conducted over a period of weeks, and the programme can include more than one phase of the engagement.

How Does the iCAST Threat Intelligence Phase Work?

The threat intelligence phase sets the basis of any simulation by building the empirical ground. Where test activities are based on the risks that exist in the operational environment and not on hypothetical ones.

  • Sector-Specific Data Collection: Collecting data on new campaigns, malware families, and initial access vectors targeting financial institutions. From trusted sources like global threat reports and regional advisories.
  • Threat Actor Profiling: Profile the APT groups and cyber criminals who target banks and possess the capability to attack the institution.
  • Mapping the Attack Paths: Identify the means through which the identified threat actors can access the organization’s systems, external assets, third parties, and critical banking processes.
  • Creation of the Threat Intelligence Report (TIR): Document the threat actors, attack vectors, and TTPs in a formal Threat Intelligence Report (TIR). This document will serve as the starting point for building the iCAST attack scenarios.

How Are CREST-Aligned iCAST Attack Scenarios Designed?

Scenario design is done to make the threat intelligence into a clearly defined and structured scenario for your iCAST simulation.

  • Translating Intelligence to Bank Context: Modify threat actors and attack methods to fit your environment. Pay particular attention to vital services including payment platforms, core banking, and customers’ authentication portals.
  • Holistic Approach for Assessments: Scenario design should ensure assessments of people, processes, and technology. The assessments should include both technical attacks and social engineering attacks as required.
  • Creating Realistic Attack Path: Scenario design should result in the creation of a realistic attack path that involves different stages. Starting from gaining access, moving inside your network environment, maintaining access, and evasion.
  • Testing Plan Review & Approval: Submit your test plan for review by relevant parties. Identify risk levels and testing scope, and get the necessary approvals before executing the test.

What Should a CREST-Accredited iCAST Provider Deliver?

The solution offered by a CREST-accredited iCAST provider must prove what was tested and what weaknesses were revealed. A compliant iCAST engagement concludes with a comprehensive suite of structured deliverables designed to provide technical clarity to operational defenders and strategic insights to executive management.

  • Simulation Test Report: This is a comprehensive report of the simulated attack, which describes how the test attack was executed. It also describes what techniques were used to carry it out. What goals the red team reached, and where and how the attack was detected or mitigated.
  • Blue Team Report: Analysis of how your security and incident response teams reacted during the simulated attack. Covering such aspects as alert generation, quality of logging, speed of detection, investigation, and mitigation actions taken.
  • 360° Replay/Purple-Team Workshop: An interactive workshop involving the red team, blue team, and all relevant IT teams. This will help you analyze each stage of the attack, identify monitoring/detection gaps, and make improvements.
  • Risk-Rated Findings and Supporting Evidence: A detailed listing of the findings obtained from the test in descending order of their level of risk. The findings must have related evidence in the form of screenshots, logs, packet captures, or technical outputs, wherever applicable.

What mistakes should you avoid when choosing an iCAST provider?

When selecting an iCAST provider for CREST-accredited penetration testing in Hong Kong, mistakes can happen. Such as misunderstanding CREST membership, tester qualifications, and selecting providers without HKMA experience.

  • Confusing Membership with Accreditation: Do not assume CREST membership means the provider is accredited for specialised threat-led red teaming or iCAST services.
  • Overlooking Personnel Qualifications: Verify that the assigned testers have the required iCAST Manager, Specialist, or other relevant CFI qualifications.
  • Treating iCAST Like Standard Penetration Testing: Avoid providers that rely on automated scanning or basic compliance testing instead of customised adversary simulations.
  • Neglecting Local Regulatory Context: Choose a provider familiar with HKMA expectations, C-RAF requirements, and Hong Kong’s financial sector threat landscape.

Looking for the Right iCAST Partner?

Let our experts find hidden cybersecurity risks before real attackers do – so you can protect your reputation, client trust, and bottom line.

Request iCAST Consultation

Talk to a Cybersecurity expert

How Qualysec Helps in Penetration Testing for HKMA iCAST

Qualysec is a CREST-accredited specialized penetration testing company offering CREST-accredited penetration testing in Hong Kong. We help financial organizations enhance their iCAST preparedness by carrying out penetration testing, red teaming, and threat-driven security assessments. The process involved in our assessment is a combination of automation and manual testing.

  • Approach to Hybrid Security Testing: The test includes automated scanning and manual testing on web applications, APIs, mobile banking, and cloud infrastructure.
  • Threat Simulations for BFSI Industry: Multi-stage threats and TTPs based on MITRE ATT&CK are simulated through threat scenarios.
  • Testing Defenses Completely: This includes tests for your people, process, and technology for incidents, lateral movement, and SOC detection.
  • Valuable Feedback and Assistance for Remediation: Risk-rated insights, remediation instructions, and post-testing assistance are provided to help you improve security weaknesses.

Conclusion

CREST-accredited penetration testing in Hong Kong allows financial organizations to determine the capability of their security systems to withstand a real-world attack. A properly conducted iCAST test will do more than just conduct a vulnerability assessment. It tests the ability of the bank to detect an attack and respond to one. Through proper selection of a vendor, developing attack scenarios, and implementing recommendations, authorized institutions can build cyber resilience.

Ready to Validate Your Bank’s Cyber Resilience?

Get in touch with Qualysec—a CREST-accredited, specialized penetration testing company—to build a red team assessment built for your bank.

Book a Security Assessment

CREST

FAQs

What is HKMA iCAST and how does it differ from traditional penetration testing?

HKMA iCAST simulates real-world adversary attacks against a bank’s critical functions using sector-specific threat intelligence. Unlike traditional penetration testing that looks for isolated technical vulnerabilities via checklists, iCAST evaluates a bank’s end-to-end detection, response, and recovery capabilities.

Why is CREST accreditation mandatory for HKMA iCAST service providers?

CREST accreditation ensures that a security provider and its individual testers meet strict HKMA competency standards required to safely conduct specialized, threat-led adversary simulations.

What are the core phases of an HKMA iCAST engagement?

The process follows a three-step lifecycle: gathering threat intelligence to build a formal report, designing safe and tailored attack scenarios, and executing the simulation while testing the bank’s Blue Team response.

What deliverables should a bank expect from a CREST-accredited iCAST provider?

Key deliverables include a Simulation Test Report, a dedicated Blue Team performance report, risk-rated technical findings with supporting evidence, and a collaborative 360-degree review workshop.

What common mistakes should financial institutions avoid when selecting an iCAST provider?

Banks should avoid assuming general CREST membership covers specialized threat-led testing, overlooking individual tester credentials, and hiring vendors that treat iCAST like routine vulnerability scanning.

Pabitra Kumar Sahoo

About Pabitra Kumar Sahoo

Pabitra Kumar Sahoo is the Co-Founder and Chief Operating Officer (COO) at Qualysec. With a deep commitment to elevating global cybersecurity standards, he directs corporate operations and service strategy, helping enterprises mitigate compliance debt and defend their digital infrastructure through elite, human-led penetration testing.

Leave a Comment.

Your email address will not be published. Required fields are marked *

Related Blogs

Subscribe to Newsletter

Get the latest cybersecurity insights, compliance tips, and vulnerability reports delivered directly to your inbox.