Qualysec
Blog

CREST STAR-FS: Intelligence-Led Penetration Tests (ILPT) for UK Financial Services (Beyond CBEST)

Explore CREST STAR-FS intelligence-led penetration testing for UK financial services, simulating real-world threats beyond traditional CBEST assessments.

Published on September 24, 2026
Read Time: 11 min
CONNECT WITH US

CREST STAR-FS intelligence-led penetration tests provide UK financial organisations with a structured way to assess resilience against realistic cyber attacks. Unlike vulnerability testing alone, it relies on threat intelligence and attack simulations. These assess your organisation’s ability to defend, detect, and react in case of an attack when attackers target Important Business Services.

In December 2025, the Bank of England launched its second System-Wide Exploratory Scenario (SWES) with 46 participating organisations. The exercise tested how the UK financial system could respond to a severe economic shock and downturn in private markets. This shows the importance of testing resilience across the financial sector, not just within individual organisations. 

In this article, we are going to discuss the reasons for the introduction of STAR-FS outside CBEST. Also about organisations that need to consider the introduction of STAR-FS outside CBEST, the assessment process and the items tested, and the differences between STAR-FS and CBEST.

Key Takeaways

  • STAR-FS was introduced in 2024 to extend the concept of threat-led testing beyond CBEST.
  • Firms that are not systemic organisations can employ STAR-FS to enhance their cyber resilience.
  • Threat intelligence is used to define the test approach and real attack scenarios.
  • The STAR-FS Assessment process is divided into four phases: Initiation, Threat Intelligence, Penetration Testing, and Closure.
  • Important Business Services are used to define testing, along with the underlying systems, people, and processes.
  • Testing includes protection, detection, and response against real attack paths.

What Is CREST STAR-FS Intelligence-Led Penetration Testing?

CREST STAR-FS (Simulation of Targeted Attack & Response for Financial Services) is an intelligence-driven penetration testing methodology. It is specifically aimed at the financial services sector in the United Kingdom. It was introduced in March 2024 to assist organisations in evaluating their cyber resilience by simulating real attack scenarios based on intelligence about threats. 

STAR-FS examines how an attacker could target the systems, people and processes supporting an organisation’s Important Business Services (IBS). In 2025 H2, 86% of Bank of England survey respondents cited cyberattack among their top five risks to the UK financial system. It shows the importance of testing whether critical financial services can withstand intelligence led cyber attack.

Three major outcomes are considered during a STAR-FS assessment:

  • Protection: Whether the security controls can help prevent or restrict the attacker’s access to the services and systems.
  • Detection: Whether the security teams can detect any malicious activities and realise that an attack is taking place.
  • Response: Whether the organisation can effectively respond to the attack.

CREST STAR-FS intelligence-led penetration tests use threat intelligence to develop realistic attack scenarios against the systems. 

Why Was STAR-FS Introduced Beyond CBEST?

CBEST is a threat-led testing framework designed for intelligence-led penetration testing of systemically important financial institutions and financial market infrastructures (FMIs). CREST STAR-FS intelligence led penetration tests extend threat-led testing to financial organisations outside the traditional CBEST audience. 

As cyber threats increasingly affect organisations beyond this group, regulators identified a need to extend threat-led testing to a broader range of firms. The PRA and FCA introduced STAR-FS in 2024 as a complementary framework for firms outside the scope of CBEST. In 2026 H1, 82% of respondents still identified cyberattack as a top-five risk to the UK financial system. 

How Does STAR-FS Address the Gap?

STAR-FS is based on the methods that have been applied successfully in CBEST but adjusted for non-systemic entities.

  • Extends threat-based approach: Implements intelligence-based penetration testing for more financial institutions and FMIs.
  • Applies CBEST methodologies: Employs the use of threat intelligence and attack scenarios to determine cyber resilience.
  • Addresses Important Business Services: Considers the effects of attacks on important business services as well as the technology, people, and processes behind them.
  • Provides independent assurance: Leverages threat intelligence and penetration testing skills to deliver an assessment going above simple security testing.
  • Improves resilience capabilities: Helps organisations in finding weaknesses in their protection, detection, and response to real-world cyber attacks.

Which Organisations Should Consider a CREST STAR-FS Assessment?

STAR-FS is designed for financial firms that need threat-led pentesting beyond routine penetration testing and traditional CBEST coverage. It is particularly relevant to non-systemic firms seeking deeper assurance around the resilience of their Important Business Services. 

  • Non-systemic financial firms: Organisations outside the traditional CBEST scope that need threat-led testing.
  • Banks and building societies: Firms with important customer-facing or operational services.
  • Payment and e-money firms: Organisations dependent on resilient payment and transaction systems.
  • FMIs: Market infrastructures supporting important financial services.
  • Other financial firms: Organisations with significant technology dependencies or sensitive financial data.
  • Supervisory-identified firms: Firms where additional threat-led testing is considered appropriate.

The scale of current threat-led testing also shows why deeper assessments matter. The 2025 CBEST thematic analysed 13 assessments and identified 469 successful attack tactics. It highlights the range of techniques that financial organisations may need to defend against.

How Does a CREST STAR-FS Assessment Work?

How Does a CREST STAR-FS Assessment Work

STAR-FS assessment includes four major phases: Initiation, Threat Intelligence, Penetration Testing, and Closure. The assessment is managed by the firm, and threat intelligence and penetration testing are carried out by the accredited providers. CREST STAR-FS intelligence led penetration tests follow a structured process covering initiation, threat intelligence, penetration testing, and closure. 

1. Initiation and defining the assessment scope

The evaluation begins with setting out the governance, scope, and controls required for conducting safe testing. At the same time, the company determines the Important Business Services (IBS), which will determine the scope of the assessment.

  • Establish a STAR-FS Control Group to oversee the assessment.
  • Agree roles, responsibilities, communication, and escalation routes.
  • Define the scope around the selected IBS and the systems supporting them.
  • Assess the risks associated with testing live or production systems.
  • Select and engage accredited Threat Intelligence and Penetration Testing providers.
  • Put controls in place to pause or stop testing if it creates unacceptable risk.
  • The duration of the assessment is approximately 4 to 6 weeks.

2. Threat intelligence identifies realistic attack scenarios

The Threat Intelligence phase looks into how threat actors may be able to attack the organisation. Its findings provide the foundation for the penetration testing phase.

  • Prepare the Threat Intelligence Plan for the selected scope.
  • Identify threat actors, motivations, capabilities, and means of attack.
  • Perform target analysis and reconnaissance.
  • Prepare a Targeting Report and a Threat Intelligence Report.
  • Utilise the above information to prepare realistic attack scenarios and a penetration test plan.
  • The assessment usually takes 6 to 8 weeks for completion.

3. Intelligence-led penetration testing simulates the attack

The penetration testing team employs the information collected to simulate an attack within the determined scope. Testing focuses on the systems and services supporting the selected IBS.

  • Develop a detailed Penetration Testing Plan.
  • Conduct testing of systems and services that are used in the chosen IBS.
  • Replicate the attack tactics discovered in the threat intelligence stage.
  • Implement the risk management measures that have been approved, especially during testing on live or operational systems.
  • Document the findings in the Penetration Test Report.
  • The duration of the assessment is 4 to 6 weeks.

4. Closure, reporting and remediation

In this stage, the assessment is translated into real remedial action steps. It also gives a solid foundation for follow-up with the relevant parties involved and authorities.

  • Review findings with relevant teams and stakeholders.
  • Finalise the Penetration Test Report.
  • Develop a STAR-FS Remediation Plan.
  • Assign ownership and priorities for addressing identified weaknesses.
  • Provide relevant outputs to the regulator where required.
  • Track remediation and use the findings to strengthen cyber resilience.
  • The approximate duration of the assessment is around 4 weeks.

Want a Sample Security Testing Report?

See how our experts document vulnerabilities, risk severity, and clear remediation steps.

Download Sample Report →

Security Testing Report

What Does STAR-FS Test in a Financial Institution?

The STAR-FS can measure the ability of your organisation to safeguard, detect, and respond to a cyber attack. The STAR-FS will be geared towards the systems, personnel, and processes involved with the IBS. In 2025, the NCSC reported more than 200 nationally significant cyber incidents.

I. Protection against realistic attack scenarios

The assessment will check if your current security mechanisms can block any realistic path for attacks against your critical services.

  • Tests whether attackers are able to get access to your systems initially.
  • Checks whether security controls like networking and access controls can restrict further compromise.
  • Determines any vulnerabilities that would enable an attack to move towards your critical systems.

II. Detection of targeting and intrusion

STAR-FS evaluates how well your security teams can detect any suspicious activities during an attack.

  • Tests your abilities in monitoring, alerting, and detecting threats.
  • Evaluates your SOC’s capability to detect and investigate any suspicious activities.
  • Identifies any weak points that would allow an attacker to go unnoticed.

III. Incident response and containment

The assessment also evaluates the effectiveness of your teams once there is an attack detected.

  • Tests your incident response and containment process.
  • Tests the communication and escalation among different teams.
  • Checks if you can contain an attack while providing key services.

IV. Impact on Important Business Services

STAR-FS will eventually determine whether an attack that is based on reality may impact the availability, integrity, or confidentiality of your IBS. It does not just identify vulnerabilities but also assists you in determining how an attack that is based on reality may impact your critical services.

What Accreditation Do STAR-FS Providers Need?

STAR-FS relies on specialist cybersecurity capabilities, particularly Penetration Testing, Threat Intelligence and Intelligence-Led Penetration Testing. CREST also recognises related disciplines such as Security Operations Centres (SOC) and Incident Response, which support an organisation’s ability to detect and respond to attacks.

For STAR-FS provider selection, organisations should check:

  • Penetration Testing: Relevant CREST accreditation and qualified testers.
  • Threat Intelligence: Capability to identify threat actors, motivations, tools and tactics.
  • Intelligence-Led Testing: Ability to turn threat intelligence into realistic attack simulations.
  • Detection and response expertise: Relevant SOC and incident-response capabilities where these form part of the assessment.

CREST has updated its accreditation framework in 2026. New applications now use TISA (Threat Intelligence for Simulated Attack) and TLPT (Threat-Led Penetration Testing) instead of the previous STAR TI and STAR ILPT accreditation names. This update separates threat intelligence and threat-led penetration testing into connected accreditation capabilities.

How Does Qualysec Support Intelligence-Led Security Testing?

As a CREST Accredited specialised penetration testing company, Qualysec supports financial institutions with offensive security and VAPT services that help identify weaknesses across the systems supporting critical business operations. Our approach combines automated tools with manual testing to validate whether vulnerabilities can be exploited in realistic attack scenarios.

  • Blended testing: We combine automated scanning with manual penetration testing to identify logic flaws, configuration weaknesses, and multi-step attack paths that automated tools may miss.
  • Regulatory alignment: Our assessments can support security and operational resilience requirements relevant to UK financial institutions, including testing across cloud environments, web applications, and APIs.
  • Broad technical coverage: We assess external and internal networks, web and mobile applications, APIs, and cloud-native infrastructure to provide wider visibility of your attack surface.
  • Actionable reporting: Findings are presented with clear technical context, risk prioritisation, and remediation guidance. Our dashboard also helps teams track vulnerabilities and manage re-testing.
  • Expert validation: Our security professionals manually validate findings and simulate targeted attack techniques to assess whether your protection, detection, and response controls work as expected.

This approach helps organisations move beyond vulnerability discovery and understand how identified weaknesses could affect their real-world security posture. 

Conclusion

CREST STAR-FS provides financial institutions with a structured way to test cyber resilience against realistic threats. CREST STAR-FS intelligence led penetration tests combine threat intelligence with controlled attack simulations to assess how well firms can protect, detect and respond to attacks affecting their Important Business Services. Unlike routine penetration testing, STAR-FS examines how an attack could develop across systems, people and processes. The value of the assessment comes from acting on its findings, using remediation and lessons learned to strengthen security controls and improve resilience against future threats.

Speak Directly With Qualysec’s Certified Security Experts

Discover vulnerabilities before attackers exploit them

Schedule Free Consultation
→

Security Expert

FAQs

1. What is the difference between STAR-FS and CBEST?

CBEST focuses on systemically important financial institutions and FMIs, while STAR-FS extends threat-led testing to a wider range of firms. Both use threat intelligence and realistic attack scenarios, but STAR-FS is designed to complement CBEST for non-systemic firms.

2. Who should undergo a STAR-FS assessment?

STAR-FS is mainly relevant to non-systemic financial firms seeking threat-led testing beyond routine penetration testing. Banks, payment firms, e-money firms and FMIs may consider it based on their risks and supervisory expectations.

3. Is STAR-FS mandatory for UK financial institutions?

STAR-FS is not a universal mandatory requirement for every UK financial institution.
The PRA encourages non-systemic firms to consider STAR-FS based on their cyber resilience needs and risk profile.

4. How does a STAR-FS assessment work?

A STAR-FS assessment follows four phases: Initiation, Threat Intelligence, Penetration Testing and Closure. Threat intelligence shapes realistic attack scenarios, which are tested against systems supporting the organisation’s Important Business Services.

5. How long does a STAR-FS assessment take?

The STAR-FS guide gives indicative durations of 4–6 weeks for Initiation, 6–8 weeks for Threat Intelligence, and 4–6 weeks for testing. Closure takes around four weeks, making the overall assessment roughly 18–24 weeks, depending on scope and complexity.

Chandan Sahoo

About Chandan Sahoo

Chandan Kumar Sahoo is the Co-Founder and Chief Executive Officer (CEO) at Qualysec. With over 8 years of experience in security testing and software quality assurance, he leads corporate strategy and expansion, helping organizations globally secure their web, mobile, and cloud environments.

Leave a Comment.

Your email address will not be published. Required fields are marked *

Related Blogs

Subscribe to Newsletter

Get the latest cybersecurity insights, compliance tips, and vulnerability reports delivered directly to your inbox.