On 6th and 7th October 2026, Prism infosec’s Head of Red Team, David Viola attended the T-REX 2026 conference in Madrid.
Unlike many cybersecurity events, T-REX is not aimed at vendors or general security practitioners. It is a forum specifically for the firms and individuals responsible for delivering TIBER-EU and DORA Threat-Led Penetration Testing (TLPT) exercises. Regulators, national authorities, threat intelligence providers, red teams and test managers came together to discuss how the industry can continue to improve the quality, consistency and value of threat-led testing.
Rather than focusing on individual presentations, several common themes emerged across the two days that are likely to be relevant to any organisation either preparing for, or considering, a TIBER-EU or DORA TLPT exercise.
Quality remains more important than compliance
One of the strongest messages from regulators was that a successful test is not created by following a methodology alone.
As DORA increases demand for threat-led penetration testing across Europe, maintaining quality is becoming a major concern. Regulators acknowledged the growth in the provider market but repeatedly emphasised that experience, judgement, stability and professionalism remain critical.
There was particular discussion around provider selection. Regulators made it clear that they do not currently intend to accredit providers or publish approved supplier lists. Instead, they view provider selection as part of an organisation’s own risk management responsibilities.
Perhaps the most interesting point was that references should be tied to the individuals delivering the engagement, not just the company they work for. The quality of the people delivering a test remains one of the biggest factors in determining its overall value.
For organisations procuring TLPT services, the lesson is straightforward: focus on the team that will actually perform the work, their experience, and their ability to adapt to complex situations.
Better collaboration between Threat Intelligence and Red Teams
Another recurring discussion centred on the relationship between Threat Intelligence (TI) providers and Red Teams.
Many speakers questioned whether the traditional separation between intelligence gathering and offensive execution is always delivering the best outcome. Several argued that threat actors do not operate in this way and that greater collaboration throughout an engagement would increase realism and reduce duplicated effort.
There was also recognition that “actionable intelligence” means different things to different stakeholders. Executives require strategic context. Test managers need information to drive decision-making. Red teams need detailed, operational intelligence that can directly influence attack paths and scenario development.
Ultimately, there was broad agreement that closer collaboration between all parties throughout an engagement produces better results than treating threat intelligence as a report delivered at the beginning of the project.
For organisations undertaking a test, this is encouraging. The industry appears to be moving towards more integrated delivery models that focus on achieving outcomes rather than simply satisfying process requirements.
Identity continues to dominate the threat landscape
Several sessions explored how attack techniques have evolved during the last decade.
The conclusion was not that attackers have fundamentally changed. Rather, they continue to pursue the same objectives, but through different routes.
Identity-based compromise remains one of the most effective paths into organisations. Attacks targeting credentials, sessions and identity workflows continue to evolve as organisations deploy stronger controls.
What was particularly interesting was the repeated observation that attackers increasingly blend into legitimate activity. Successful phishing campaigns often rely on familiar business processes rather than highly sophisticated lures. Session theft, identity abuse and trusted business workflows continue to feature heavily in real-world attacks.
For defenders, this reinforces the need to look beyond traditional endpoint-centric thinking and place equal focus on protecting and monitoring identities.
AI is becoming part of the conversation
Unsurprisingly, AI was discussed extensively throughout the conference.
What was refreshing was the practical nature of the discussions. The conversation has clearly moved beyond whether AI will influence offensive security and into how it should be used safely and responsibly.
A number of providers demonstrated how AI is helping accelerate research, automate repetitive tasks and improve efficiency during complex engagements. At the same time, regulators and test managers are beginning to consider how AI should be governed within threat-led testing programmes.
One particularly useful concept discussed was classifying AI usage based on the level of authority given to it rather than the specific technology involved. This provides a more meaningful way to discuss risk and control mechanisms as AI capability continues to develop.
The broader takeaway for organisations is that AI is now relevant in two ways: attackers are using it, and organisations are increasingly deploying it themselves. Both dimensions need to be considered as part of future resilience testing.
Testing resilience, not simply proving compromise
A theme that appeared repeatedly across both regulator discussions and provider presentations was that the purpose of a threat-led penetration test is not simply to achieve a compromise.
The most valuable outcomes often come from what happens after detection.
Several case studies demonstrated situations where organisations identified suspicious activity but struggled with triage, containment or incident response. In other cases, detection technology performed as expected, but operational processes did not.
This is why TIBER-EU and DORA place such emphasis on lessons learned, replay workshops and purple-team activities. The value is not found solely in proving an attack path is possible. It comes from understanding how effectively an organisation can detect, respond and improve.
The most mature organisations are typically those that use testing outcomes to strengthen their security programme over time rather than treating the exercise as a one-off assessment.
The overall mood at T-REX 2026 was positive.
There is clear recognition that threat-led testing is expanding rapidly under DORA, but there is also a shared commitment among regulators, test managers and providers to ensure quality remains high and that organisations continue to receive meaningful value from these exercises.
The discussions were less about changing the fundamentals of TIBER and more about refining how it is delivered. Better collaboration, stronger provider capabilities, practical use of AI, improved intelligence integration and a continued focus on resilience were recurring themes throughout the event.
For organisations preparing for future TIBER-EU or DORA TLPT exercises, these developments should be viewed positively. They reflect a mature and increasingly collaborative community focused on improving outcomes rather than simply meeting regulatory expectations.
If you’d like to discuss any of the topics above, or you’re considering a future TIBER-EU, DORA TLPT, CBEST or STAR-FS exercise, please get in touch. We’d be happy to share more detail from the event and discuss how these developing practices may apply to your organisation.

