In December 2025, the Bank of England launched its second System-Wide Exploratory Scenario (SWES) with 46 participating organisations. The exercise tested how the UK financial system could respond to a severe economic shock and downturn in private markets. This shows the importance of testing resilience across the financial sector, not just within individual organisations.
In this article, we are going to discuss the reasons for the introduction of STAR-FS outside CBEST. Also about organisations that need to consider the introduction of STAR-FS outside CBEST, the assessment process and the items tested, and the differences between STAR-FS and CBEST.
Key Takeaways
STAR-FS was introduced in 2024 to extend the concept of threat-led testing beyond CBEST.
Firms that are not systemic organisations can employ STAR-FS to enhance their cyber resilience.
Threat intelligence is used to define the test approach and real attack scenarios.
The STAR-FS Assessment process is divided into four phases: Initiation, Threat Intelligence, Penetration Testing, and Closure.
Important Business Services are used to define testing, along with the underlying systems, people, and processes.
Testing includes protection, detection, and response against real attack paths.
Source: https://qualysec.com/crest- ...