Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Advertising and Sponsorship
    • Profile & Readership
    • Contact Us
    • Latest News
    • Privacy & Cookies Policies
    • Terms of Use
    • Advertising Terms
    • Issue 81
    • Issue 80
    • Issue 79
    • Issue 78
    • Issue 77
    • Issue 76
    • Issue 75
    • Issue 74
    • Issue 73
    • Issue 72
    • Issue 71
    • Issue 70
    • View All
    • About the Awards
    • Awards Timetable
    • Awards Winners
    • Submit Nominations
    • Testimonials
    • Media Room
    • FAQ
    • Asset Management Awards
    • Brand of the Year Awards
    • Business Awards
    • Cash Management Banking Awards
    • Banking Technology Awards
    • CEO Awards
    • Customer Service Awards
    • CSR Awards
    • Deal of the Year Awards
    • Corporate Governance Awards
    • Corporate Banking Awards
    • Digital Transformation Awards
    • Fintech Awards
    • Education & Training Awards
    • ESG & Sustainability Awards
    • ESG Awards
    • Forex Banking Awards
    • Innovation Awards
    • Insurance & Takaful Awards
    • Investment Banking Awards
    • Banking Awards
    • Banking Innovation Awards
    • Digital Banking Awards
    • Finance Awards
    • Investor Relations Awards
    • Leadership Awards
    • Islamic Banking Awards
    • Real Estate Awards
    • Project Finance Awards
    • Process & Product Awards
    • Telecommunication Awards
    • HR & Recruitment Awards
    • Trade Finance Awards
    • The Next 100 Global Awards
    • Wealth Management Awards
    • Travel Awards
    • Years of Excellence Awards
    • Publishing Principles
    • Ownership & Funding
    • Corrections Policy
    • Editorial Code of Ethics
    • Diversity & Inclusion Policy
    • Fact Checking Policy
    • Financial Awards
    • Private Banking Awards
    • Private Banking Innovation Awards
    • Retail Banking Awards
    Original content: Global Banking and Finance Review - https://www.globalbankingandfinance.com

    A global financial intelligence and recognition platform delivering authoritative insights, data-driven analysis, and institutional benchmarking across Banking, Capital Markets, Investment, Technology, and Financial Infrastructure.

    Copyright © 2010-2026 - All Rights Reserved. | Sitemap | Tags

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    1. Home
    2. >Technology
    3. >BREAK THE HACKERS, NOT THE BANKS: THE CBEST FRAMEWORK FOR THE FINANCIAL SECTOR
    Technology

    Break the Hackers, Not the Banks: The Cbest Framework for the Financial Sector

    Published by Gbaf News

    Posted on September 8, 2015

    5 min read

    Last updated: January 22, 2026

    Add as preferred source on Google
    This image illustrates a hacker focused on breaching financial institutions, highlighting the growing cybersecurity threats in the banking sector. It relates to the CBEST framework discussed in the article, emphasizing the need for robust security measures.
    Image depicting a hacker targeting financial institutions - Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Global Banking & Finance Awards 2026 — Now Open for Entries
    Global Banking & Finance Awards 2026 — Call for Entries

    Hadi Hosn, Head of Security Strategy and GRC,Dell SecureWorks EMEA

    Cyber attacks seem to hit the headlines every day, affecting businesses across all regions and industries. It’s not surprising that the financial sector, which holds a wealth of sensitive data, has become one of the main targets with large UK based financial institutions falling victim to hackers this year. Following the attack on Sony Pictures last year, a number of financial institutions organised a dummy run on their networks using controlled malware to test their cyber security; the results left them fearful for their security measures and these businesses realised the need to further develop their defences. This is where the CBEST framework comes into play.

    CBEST was established by the UK Financial Authorities (Bank of England, Her Majesty’s Treasure and the Financial Conduct Authority)to provide a set of criteria against which financial institutions can test the strength of their security procedures. Under this scheme, cyber security vendors work closely with financial institutions and help them develop best practices which prevent and minimise cyber-attacks, testing critical assets without harming or damaging the institution. For those who haven’t yet committed to the scheme, understanding CBEST may be a little overwhelming – but it should not be. CBEST can be broken down into two simple parts: the information phase, and the penetration phase. Below, we will take a look at what both stages involve and what organisations starting out through the process can expect.

    Gathering the facts: the information phase

    It is vital that organisations understand how publicallyavailable information can be used against them. In the CBEST framework, gathering open source intelligence (OSI) demonstrates how hackers can tailor their approach to ensure that they get access to privileged data. For example, a hacker may choose to infiltrate the human resource department of a national bank, and will begin by profiling the head of department with information available through LinkedIn. The threat actor will be able to see their target’s contact details, their business associates,and the companies they work with. A trawl through Twitter mightreveal the target’s interests andindustry events that he or she hasrecently attended. This information, combined with other tools, can help to form the basis of a very effective social engineering campaign.

    Businesses also need to understand the wider perspective of the cyber security industry, and how current trends can influence hackers to tailor their approach.Within the CBEST framework, this is where intelligence gathered by specialised security companies providing threat intelligence capabilities comes into play. Security service providers can offer the best advice possible if they have the very latest, most up to date information to hand.This cyber threat intelligence is built up over years of experience and research and given that CBEST security providers should aim to present their findings within four to six weeks, this experience will play a significant supporting role to the OSI carried out by the security provider. The key objective of the specialised Threat Intelligence is to determine the Threat Groups that would actively target the financial institution and their associated tactics, techniques and procedures (TTPs).

    Making a test run: the penetration phase

    Once the security vendor has gathered and consolidated its research, they can then work together with a Testing provider to create an exemplar scenario for the bank to run against their systems, demonstrating the effectiveness of hackers. For example, sophisticated organised crime groups which use spear-phishing emails to deliver remote access trojans to an endpoint, steal credentials and gain a foothold on systems of those who have responsibilities in the payments workflows. This allows them to steal large amounts of money by initiating, reviewing and approving transactions from the machines of those responsible without them ever knowing. The testing organization will replicate this threat scenario and try to demonstrate to the financial institution that the above is possible.

    Developing future security strategies

    After the test scenario is completed, the institution and the cyber security firms sit together with the findings to discuss next steps. At this stage, open communication is an essential part of the process; the security firm must feel comfortable discussing the flaws and faults in the financial institution’s network in a frank and open manner, whilst the financial institution must be ready to make best use of the improvement opportunities available. It is critical to have a feedback loop and improvement programme as a deliverable from these engagements to ensure the financial institution continuously improves and evolves security controls across the organisation.

    With so much at stake, getting cyber security right is essentialto protect the assets of millions of customers across the world. The best way of doing this is by being willing to share information and create a platform for discussion between institutions and vendors. Financial institutions must also be ready to make best use of the insight provided through CBEST and other frameworksto make the right improvements for the future. Whether that means training employees on cyber security, deploying new firewalls or hiring a managed security service provider, this opportunity allows them to develop an informed strategy which protects both their assets and their reputation.

    More from Technology

    Explore more articles in the Technology category

    Image for The Data Intelligence Gap: Why Precision Is Becoming Critical in Enterprise Sales
    The Data Intelligence Gap: Why Precision Is Becoming Critical in Enterprise Sales
    Image for How Data Observability Is Evolving in Financial Services
    How Data Observability Is Evolving in Financial Services
    Image for When Is a Dedicated Server the Right Choice for Your Business?
    When Is a Dedicated Server the Right Choice for Your Business?
    Image for Enter Now for Best IT/Technology Recruitment Agency 2026
    Enter Now for Best IT/Technology Recruitment Agency 2026
    Image for The Rise of Intelligent Automation: How Technology Is Redefining Work and Efficiency
    The Rise of Intelligent Automation: How Technology Is Redefining Work and Efficiency
    Image for How Automation Technologies Are Transforming Everyday Business Operations
    How Automation Technologies Are Transforming Everyday Business Operations
    Image for Asprofin Bank Announces Financing Initiative for Modular ‘Nanocenter’ Data Infrastructure
    Asprofin Bank Announces Financing Initiative for Modular ‘Nanocenter’ Data Infrastructure
    Image for Basel IV vs. The AI Bots: Why the Banking Rulebook Must Evolve in the Age of Algorithmic Herding
    Basel Iv Vs. The AI Bots: Why the Banking Rulebook Must Evolve in the Age of Algorithmic Herding
    Image for NordQuant Deploys Distributed Systems to Enhance Enterprise Digital Capabilities Introduction
    NordQuant Deploys Distributed Systems to Enhance Enterprise Digital Capabilities Introduction
    Image for Calling Entries for Data Center Deal of the Year 2026
    Calling Entries for Data Center Deal of the Year 2026
    Image for Nominations Now Open for Best Website Design Company 2026
    Nominations Now Open for Best Website Design Company 2026
    Image for Call for Entries: Best Digital Innovation Company (Non-Financial / Cross-Industry) 2026
    Call for Entries: Best Digital Innovation Company (Non-Financial / Cross-Industry) 2026
    View All Technology Posts
    Previous Technology PostWhat’s Next for Banks in the Uk?
    Next Technology PostForescout Helps Organisations to Securely Onboard Windows 10 Byod Devices