CBEST scenario testing with simulations
CBEST is the Bank of England’s intelligence-led penetration testing framework. Microsimulations complement it by exercising decision-making and response.
iluminr simulations let teams rehearse the decisions CBEST cares about against severe-but-plausible scenarios, and keep a record of who decided what, and when. Run them as Microsimulations, full-scale simulations, or facilitated by our team of experts.
Simulations mapped to CBEST
Mapping is indicative. Confirm scope against your own obligations.
Frequently asked questions
What is CBEST?
CBEST is the Bank of England’s intelligence-led penetration testing framework. Microsimulations complement it by exercising decision-making and response.
How do simulations help with CBEST?
Simulations let teams rehearse the decisions CBEST cares about against severe-but-plausible scenarios. iluminr keeps a record of who decided what, and when, which you can use as evidence of testing.
Which iluminr simulations map to CBEST?
Simulations mapped to CBEST include Bracing for Impact: Communications Test, Data Breach: Major Leak, Extortion: Ransomware Invasion, Inside Job: Data Breach, Trading Halt: Ransomware Chaos and Double Tap: Cyber Attack, among others.
Who should take part?
These simulations are most often run with Technology & Security, Risk, Compliance and Legal.
Can I build a 12-month CBEST testing program?
Yes. The iluminr program builder suggests a 12-month plan of simulations for CBEST. You can add or remove scenarios and export the plan as a PDF for your board.
Can we customize these simulations?
Yes. Run any template as is, tailor the roles, plans, critical services and injects to your organization, or build your own from scratch with the iluminr builder.
Is this mapping legal or compliance advice?
No. The mapping between simulations and CBEST is indicative. Confirm scope against your own obligations.

