© Mapbox, © OpenStreetMap
Tudor Damian

Tudor Damian

Cybersecurity, AI & Cloud Advisor @ D3 Cyber

Cluj-Napoca, Romania

Actions

With over 20 years in the IT industry, Tudor is a Certified Ethical Hacker and Microsoft MVP who loves everything about technology. In his day-to-day role, he advises organizations on Cybersecurity, AI & Cloud Governance, helps improve their security posture, and assists them in moving past "paper tiger" compliance strategies.

Being a regular presence at local and international events, Tudor combines deep industry experience with a genuine passion for sharing knowledge. After hundreds of talks and training sessions, his goal remains the same: to help IT professionals cut through the noise and build effective strategies dealing with AI-driven threats, Post-Quantum Cryptography challenges, Zero Trust adoption, and the high-stakes transition from traditional software (SDLC) to the probabilistic world of AI development (ADLC), all of this while facing an ever-growing EU regulatory compliance landscape.

Badges

Area of Expertise

  • Business & Management
  • Information & Communications Technology
  • Law & Regulation

Topics

  • Cybersecurity
  • Cloud Strategy
  • IT Governance
  • IT Risk Management
  • Security & Compliance
  • AI and Cybersecurity
  • Managed Security Services
  • Cybersecurity Regulations and Compliance
  • vCISO
  • GDPR
  • NIS2
  • CRA
  • ISO 27001
  • DORA
  • Managed Services
  • Cloud Migration
  • Vulnerability Management
  • Business Continuity & Disaster Recovery
  • Cloud & DevOps
  • Systems & Network Administration
  • Data Protection
  • Business Process Optimization

The EU Regulation Pile-Up: Stop Running Many Compliance Programs at Once

The grace period is over, and it's not just one law anymore, it's many of them stacked on top of each other. Things like NIS2, DORA, the AI Act, or the CRA, each with its own deadlines, its own auditors, and its own fines, and they're all hitting your desk at the same time.

This session maps out exactly where these rules overlap, where they clash, and where one control can check the box for multiple regulators at once. We'll cover how to run one governance program instead of juggling multiple separate compliance efforts, and how to cut legal risk without wasting resources doing the same work twice.

You'll walk away with a practical map of the overlaps, a shortlist of controls that are designed to help you for real, and a governance plan that actually builds resilience, not just something to show auditors.

Cognitive Surrender: Why Your Brain is Giving Up to AI

We use AI every day to write, code, and make decisions. Feels like a productivity win, right? But behavioral science has a different name for it: cognitive surrender. The more thinking we hand off to AI, the less we use our own judgment. When we're rushed, we stop double-checking. And when AI gives a wrong answer with total confidence, most people just believe it, ending up worse off than if they'd skipped AI entirely.

As AI mistakes get harder to spot (made-up data, code that looks fine but isn't, hallucinations delivered with total confidence), our own laziness about checking becomes the real problem. If the machine does all the thinking for you, you lose the skill to catch it when it screws up.

This session digs into what daily AI use is doing to your memory, problem-solving, and judgment, and what to actually do about it. Not "use AI less," but how to stay sharp enough to keep control.

Your Encryption Has an Expiry Date: Surviving Q-Day and AI-Speed Attacks

The "future" of AI and quantum computing already showed up, and it's changed the rules of defense. We're not just fighting human hackers anymore, we're fighting AI agents that attack at machine speed, while "Q-Day" (the day quantum computers can crack today's encryption) puts a hard deadline on how we lock down our data.

The immediate problem is "Harvest Now, Decrypt Later": attackers are stealing your encrypted data right now, planning to crack it open once Q-Day hits. And since moving to Post-Quantum Cryptography takes years, not months, the clock's already ticking.

This session covers how to plan your PQC migration around the new standards, how to defend against AI-driven malware that moves faster than your team can react, and how to build a setup flexible enough to survive whatever attacks come next, not just the ones we're seeing today.

Seeing Isn't Believing: Deepfakes and the Zero Trust Identity Crisis

Deepfakes are now cheap, fast, and good enough to fool both busy humans and corporate security controls. Voice fraud, executive impersonation, fake "leaks," and AI-generated video approvals for fraudulent wire transfers are no longer theoretical. Real attacks have already bypassed standard Zero Trust defenses by exploiting the one thing the architecture was built on: identity verification.

This session covers how modern synthetic media is made, where it hits hardest, and the tells that still matter - then goes straight into what breaks at the architecture level. When an attacker can wear a manager's face on a live call, biometrics and voice authentication stop being controls. We'll walk through what replaces them: cryptographic identity, hardware-bound authentication (FIDO2), C2PA provenance-at-capture, and behavioral verification that current AI cannot trivially fake. At least, not yet.

We'll also cover what the EU AI Act and platform disclosure requirements actually change - and what they don't. You'll leave with a practical checklist for your teams and a clear picture of how Zero Trust needs to evolve to survive the synthetic identity era.

Killing the Paper Tiger: Building a Security Journey That Actually Works

Most companies treat cybersecurity like a checklist: pass the yearly audit, buy the expensive tools, follow the thick rulebook, and stay one click away from total collapse. That's the Paper Tiger trap: looks tough on a slide, yet it does nothing when a real attack hits.

Compliance isn't security. Static policies and once-a-year checkups just create a false sense of safety, and leave a huge gap between what the rules say and what your business actually does day to day.

This session covers how to ditch the checklist and build an actual security process: honest risk checks, architecture that can take a hit, and ongoing management that still works when the rulebook and reality don't match. You'll walk away with a plan to turn your strategy from a laminated poster into something that actually protects your business, every day.

Trained by You, Replacing You: The Real Cost of AI Automating Everything

The industrial revolution replaced muscle. AI is replacing thinking, and white-collar workers are literally training the systems built to take their jobs, while general-purpose robots mean the blue-collar workers aren't safe either anymore.

Losing jobs is the immediate problem, but it's not the scary part. Automated warfare and cyber-attacks anyone can pull off are already happening. And there's basically no rulebook for it: the EU AI Act doesn't even cover military use, and you can't do arms-control-style restrictions on open-source software running on regular computers.

We'll cover how job disruption is actually playing out, the security risks of AI that nobody controls centrally, and what kind of international agreements would be needed to get a handle on any of this. Spoiler: those agreements don't exist yet.

Your AI is Probably Out of Control (And You Know It)

AI governance isn't just an IT thing anymore. Costs jump around unpredictably. People in your company are already using AI tools you don't even know about. And vendors keep sneaking AI into software you already use, quietly, without telling anyone. A policy sitting in a folder won't stop a leak, and it won't stop a model that just makes stuff up with total confidence.

This session cuts the fluff and gives you a real plan for locking down AI use at your org, based on the stuff that actually matters (ISO 42001, the EU AI Act, agent governance tools). First, we'll figure out where AI is already hiding in your business and how risky those tools really are. Then we'll cover how to keep track of how your own AI gets built, so if something goes wrong, you've got proof of what happened. Last, we'll talk guardrails, the kind that can shut an AI down the second it breaks a rule, without slowing everything else down.

Defense-X

June 2026 Sibiu, Romania

The Developers

June 2026 Cluj-Napoca, Romania

Digital Identity - meetup

Women in Tech & Women4Cyber

June 2026 Cluj-Napoca, Romania

news.ro Leaders Lounge - Cybersecurity

May 2026 Bucharest, Romania

PoliHack v19

April 2026 Cluj-Napoca, Romania

PeakIT #008

April 2026 Braşov, Romania

Microsoft MVP Summit 2026

March 2026 Redmond, Washington, United States

NDC Security 2026 Sessionize Event

March 2026 Oslo, Norway

Winter ELSA Law School 2026

February 2026 Trento, Italy

Hek.si 2026

February 2026 Ljubljana, Slovenia

Defcon Cluj meetup

December 2025 Cluj-Napoca, Romania

DefCamp 2025 Sessionize Event

November 2025 Bucharest, Romania

IT Days 2025

November 2025 Cluj-Napoca, Romania

Timisoara Cyber Forum 2025

October 2025 Timişoara, Romania

Infosek 2025

September 2025 Nova Gorica, Slovenia

CyberSea Festival 2025

July 2025 Constanţa, Romania

Qubit Conference 2025

May 2025 Prague, Czechia

CIO Summit 2025

April 2025 Ljubljana, Slovenia

PeakIT #007

April 2025 Braşov, Romania

Microsoft MVP Summit 2025

March 2025 Redmond, Washington, United States

Hek.si 2025

February 2025 Ljubljana, Slovenia

NDC Security 2025 Sessionize Event

January 2025 Oslo, Norway

DefCamp 2024 Sessionize Event

November 2024 Bucharest, Romania

IT Days 2024

November 2024 Cluj-Napoca, Romania

SecureWorld in the era of Artificial Intelligence Sessionize Event

October 2024

Transylvania Insurance Days

October 2024 Cluj-Napoca, Romania

DEFCON Cluj Meetup

September 2024 Cluj-Napoca, Romania

DefCamp Cluj-Napoca Sessionize Event

May 2024 Cluj-Napoca, Romania

Microsoft MVP Summit 2024

March 2024 Redmond, Washington, United States

Hek.si 2024

February 2024

NDC Security 2024 Sessionize Event

January 2024 Oslo, Norway

DefCamp 2023

November 2023 Bucharest, Romania

IT Days 2023

November 2023 Cluj-Napoca, Romania

Experts Live Europe 2023

September 2023 Prague, Czechia

The Developers

June 2023 Cluj-Napoca, Romania

Microsoft MVP Summit 2023

April 2023 Redmond, Washington, United States

Limitl3ss - IT Summit of Transylvania

March 2023 Târgu Mureş, Romania

Defcamp 2022

November 2022 Bucharest, Romania

IT Days 2022

November 2022 Cluj-Napoca, Romania

Infosek 2022

September 2022 Nova Gorica, Slovenia

IT Days 2021

November 2021 Cluj-Napoca, Romania

DefCamp 2021

November 2021 Bucharest, Romania

PeakIT #004

October 2021 Braşov, Romania

Techorama 2021 Spring Edition Sessionize Event

May 2021 Antwerpen, Belgium

Hek.si 2021

February 2021 Ljubljana, Slovenia

EuropeClouds Summit Sessionize Event

October 2020

Collabdays Lisbon 2020 Sessionize Event

October 2020 Lisbon, Portugal

Cloud & Datacenter Conference Germany 2020 Sessionize Event

May 2020 Hanau am Main, Germany

Experts Live Europe 2019 Sessionize Event

November 2019 Prague, Czechia

DefCamp 2019

November 2019 Bucharest, Romania

KulenDayz 2019 Sessionize Event

September 2019 Osijek, Croatia

Microsoft Inspire 2019

July 2019 Las Vegas, Nevada, United States

ITCamp 2019 Sessionize Event

June 2019 Cluj-Napoca, Romania

Cloud & Datacenter Conference Germany 2019 Sessionize Event

May 2019 Hanau am Main, Germany

Hyper-V and Hybrid Cloud Community Day Sessionize Event

May 2019 Hanau am Main, Germany

Microsoft MVP Summit 2019

March 2019 Redmond, Washington, United States

Experts Live Europe 2018 Sessionize Event

October 2018 Prague, Czechia

Microsoft Inspire 2018

July 2018 Las Vegas, Nevada, United States

ITCamp 2018 Sessionize Event

June 2018 Cluj-Napoca, Romania

Microsoft Cloud & Datacenter Conference Germany 2018

March 2018 Hanau am Main, Germany

Microsoft MVP Summit 2018

March 2018 Redmond, Washington, United States

Defcamp 2017

November 2017 Bucharest, Romania

Experts Live 2017

August 2017 Berlin, Germany

Microsoft Inspire 2017

July 2017 Washington, District of Columbia, United States

ITCamp 2017

May 2017 Cluj-Napoca, Romania

Future Decoded 2016

October 2016 London, United Kingdom

Microsoft Ignite 2016

September 2016 Atlanta, Georgia, United States

ITCamp 2016

May 2016 Cluj-Napoca, Romania

Defcamp 2015

November 2015 Bucharest, Romania

Future Decoded 2015

November 2015 London, United Kingdom

ITCamp 2015

May 2015 Cluj-Napoca, Romania

Microsoft Ignite 2015

May 2015 Chicago, Illinois, United States

DefCamp 2014

November 2014 Bucharest, Romania

Microsoft TechEd Europe 2014

October 2014 Barcelona, Spain

ITCamp 2014

May 2014 Cluj-Napoca, Romania

Microsoft TechEd Europe 2013

June 2013 Madrid, Spain

ITCamp 2013

May 2013 Cluj-Napoca, Romania

ITCamp 2012

May 2012 Cluj-Napoca, Romania

ITCamp 2011

May 2011 Cluj-Napoca, Romania

Tudor Damian

Cybersecurity, AI & Cloud Advisor @ D3 Cyber

Cluj-Napoca, Romania

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top