This handbook outlines the methodology for designing and conducting cyber stress tests. A cyber stress test is defined as ‘a targeted assessment of the resilience of individual organisations and their ability to withstand and recover from significant cybersecurity incidents, ensuring the provision of critical services, in different risk scenarios.’ The handbook aims to support national authorities in assessing the cybersecurity and resilience of critical sector entities. The document includes phases for preparation, execution, and evaluation, and provides templates, threat scenarios, and recommendations for test implementation.
Author: European Union Agency for Cybersecurity (ENISA)
Status: Adopted / Published
Adoption date: 2025-05-15
Last updated: 02 Sept 2025
Category: Guidance
Subcategory: Official guidance