CREST STAR Cyber Security Assessment

CREST STAR assessments use threat intelligence to shape a simulated attack against an organisation. ProCheckUp's service focuses on how relevant threats could affect critical operations and how the organisation detects and responds to them.

Who the assessment is for

  • Business services and threat scenarios selected for the exercise
  • Technical, physical and human boundaries agreed with the customer
  • Detection, escalation and response objectives

CREST STAR Assessments

CREST STAR Assessments

ProCheckUp is an approved provider of CREST STAR services.

STAR (Simulated Target Attack and Response) is a new, intelligence-led, vulnerability testing framework devised to replicate the behaviours of a real-world threat against individual clients. The testing framework has been designed to provide a bespoke assessment service, tailoring the assessment to replicate the specific threats faced by an organisation.

STAR has been created for non-financial organisations, using the same methodology as CBEST assessments, while managing the risks of a simulated attack exercise. STAR can be used by financial organisations to prepare for a CBEST assessment. STAR providers have to go through additional levels of assurance, and work with threat intelligence providers to provide intelligence led security assessments. 

ProCheckUp has formed a partnership with Digital Shadows; a threat intelligence provider. For each STAR engagement, Digital Shadows will provide ProCheckUp with a customised threat intelligence report identifying the key threats facing your organisation. The threat intelligence report is used by ProCheckUp to develop a tailored testing strategy to focus the security assessment and replicate the threats facing your business.

ProCheckUp STAR testing delivers a customised testing experience simulating the threat posed by current threat actors and Advanced Persistent Threats (APTs) to replicate the most realistic attack scenarios and deliver a comprehensive evaluation of your current threat exposure.

Preparing for the engagement

Agree the intelligence requirements, rules of engagement, authorised contacts and stopping conditions before testing. Confirm current scheme requirements and provider eligibility during scoping.

Outcomes and next steps

Findings should connect the observed attack paths to business impact and defensive improvements. The debrief helps owners prioritise actions across technology, monitoring and response.

Related services

Discuss your requirements

Contact ProCheckUp with the environment, objectives and timing you have in mind. We can discuss the appropriate scope and next steps.

Need Help?

If you have any questions about cyber security or would like a free consultation, don't hesitate to give us a call!

Our Services

Keep up to date!


For More Information Please Contact Us

Smiling Person

ACCREDITATIONS