© Mapbox, © OpenStreetMap
Tudor Damian

Tudor Damian

Cybersecurity, AI & Cloud Advisor @ D3 Cyber

Cluj-Napoca, Romania

Actions

With over 20 years in the IT industry, Tudor is a Certified Ethical Hacker and Microsoft MVP who loves everything about technology. In his day-to-day role, he advises organizations on Cybersecurity, AI & Cloud Governance, helps improve their security posture, and assists them in moving past "paper tiger" compliance strategies.

Being a regular presence at local and international events, Tudor combines deep industry experience with a genuine passion for sharing knowledge. After hundreds of talks and training sessions, his goal remains the same: to help IT professionals cut through the noise and build effective strategies dealing with AI-driven threats, Post-Quantum Cryptography challenges, Zero Trust adoption, and the high-stakes transition from traditional software (SDLC) to the probabilistic world of AI development (ADLC), all of this while facing an ever-growing EU regulatory compliance landscape.

Badges

Area of Expertise

  • Business & Management
  • Information & Communications Technology
  • Law & Regulation

Topics

  • Cybersecurity
  • Cloud Strategy
  • IT Governance
  • IT Risk Management
  • Security & Compliance
  • AI and Cybersecurity
  • Managed Security Services
  • Cybersecurity Regulations and Compliance
  • vCISO
  • GDPR
  • NIS2
  • CRA
  • ISO 27001
  • DORA
  • Managed Services
  • Cloud Migration
  • Vulnerability Management
  • Business Continuity & Disaster Recovery
  • Cloud & DevOps
  • Systems & Network Administration
  • Data Protection
  • Business Process Optimization

Four Regulations, One Control Set: Ending the Compliance Pile-Up

The grace period is over, and it's not just one law anymore, it's many of them stacked on top of each other. Things like NIS2, DORA, the AI Act, or the CRA, each with its own deadlines, its own auditors, and its own fines, and they're all hitting your desk at the same time.

Most companies run a separate program per law: separate owner, evidence, audit, the same control tested four times, and it still misses where the regimes disagree. We'll map where one piece of evidence satisfies NIS2, DORA, the CRA and the AI Act at once, and which controls carry most of the weight.

You'll walk away with a practical map of the overlaps, a shortlist of controls that are designed to help you, and a governance plan that builds resilience, not just something to show auditors.

Cognitive Surrender: Why Your Brain is Giving Up to AI

We use AI every day to write, code, and make decisions. Feels like a productivity win, right? Wharton researchers gave it a name: Cognitive Surrender, taking an answer AI gives you without ever questioning it. In their trials, when the AI was wrong and the person used it anyway, the wrong answer went through nearly 80% of the time. Only one in five people caught it.

As AI mistakes get harder to spot (made-up data, code that looks fine but isn't, hallucinations delivered with total confidence), our own laziness about checking becomes the real problem. If the machine does all the thinking for you, you lose the skill to catch it when it screws up. Research found the damage outlasts the session too, people kept repeating a biased AI's errors after it was gone.

We'll trace what daily AI use is doing to judgment, and lay out what rebuilds the habit. Instead taking the easy way out and using AI less, let's learn how to stay sharp enough to keep control.

Your Encryption Has an Expiry Date: Surviving Q-Day and AI-Speed Attacks

Two clocks are running at once. Q-Day is when quantum computers break today's encryption, and under the EU's roadmap, high-risk use cases come off quantum-vulnerable crypto by 2030. The other clock is AI: attackers run reconnaissance and lateral movement through agents faster than any human team. Anthropic's GTG-1002 report, published last year, put a number on it: 80 to 90% of a real intrusion, run by the model alone.

They compound each other. HNDL (harvest now, decrypt later) means stolen data waits for Q-Day, and AI-speed attacks mean that data was already taken way before most teams noticed.

The session works through the inventory-first path into a PQC migration, what defending against a machine-speed attacker looks like day to day, and how much crypto-agility the next transition demands.

Seeing Isn't Believing: Deepfakes and the Zero Trust Identity Crisis

Deepfakes are now cheap, fast, and good enough to fool both busy humans and corporate security controls. Voice fraud, executive impersonation, fake "leaks," and AI-generated video approvals for fraudulent wire transfers are no longer theoretical. Real attacks have already bypassed standard Zero Trust defenses by exploiting the one thing the architecture was built on: identity verification.

This session covers how modern synthetic media is made, where it hits hardest, and the tells that still matter - then goes straight into what breaks at the architecture level. When an attacker can wear a manager's face on a live call, biometrics and voice authentication stop being controls. We'll walk through what replaces them: cryptographic identity, hardware-bound authentication (FIDO2), C2PA provenance-at-capture, and behavioral verification that current AI cannot trivially fake. At least, not yet.

We'll also cover what the EU AI Act and platform disclosure requirements actually change - and what they don't. You'll leave with a practical checklist for your teams and a clear picture of how Zero Trust needs to evolve to survive the synthetic identity era.

Killing the Paper Tiger: Security That Holds When the Auditor Leaves

Most companies treat security like a checklist: pass the annual audit, buy the tools, file the policy binder, stay one click from a very bad day. That's the Paper Tiger trap. Looks tough on a slide, does nothing when a real attack lands.

Compliance isn't security. An audit tells you a control was documented on the day someone checked, and nothing about the other 364 days, which is where incidents happen.

Closing that gap takes honest risk assessments naming the threats specific to your business, architecture built to take a hit, and day-to-day management that keeps working once the rulebook and reality disagree. You'll walk away with a plan to turn your strategy from a laminated poster into something that actually protects your business, every day.

Trained by You, Replacing You: The Real Cost of AI Automating Everything

The industrial revolution replaced muscle. Now, while AI is now slowly replacing thinking, white-collar workers are basically training the systems built to take their jobs. And blue-collar work won't sit this one out either, once the robots catch up.

Losing jobs is the visible problem. It isn't the one that should worry you most: Anthropic's GTG-1002 report describes an AI agent running 80 to 90% of a real intrusion on its own, and nobody centrally controls capability like that. The AI Act excludes military use outright, and export controls assume a chokepoint that will just end up being cancelled by open-weight models. We fought this exact battle in the 1990s over cryptography, and lost.

The session tracks how the AI disruption is landing, and what it would take for a global agreement to be worth signing, since nothing exists yet.

Your AI is Probably Out of Control (And You Know It)

AI governance isn't just an IT thing anymore. Costs jump around unpredictably. People in your company are already using AI tools you don't even know about. And vendors keep sneaking AI into software you already use, quietly, without telling anyone. A policy sitting in a folder won't stop a leak, and it won't stop a model that just makes stuff up with total confidence.

We start with where AI is already running in your business. Then the record ISO 42001 and the AI Act both expect: how systems were built and changed. It ends with guardrails that shut an agent down mid-task the second it breaks a rule. The Digital Omnibus, published this summer, pushed high-risk obligations out a year, but transparency duties are already in force.

For CIOs, CISOs, and whoever has to say whether the company is compliant.

DefCamp 2026 Sessionize Event Upcoming

November 2026 Bucharest, Romania

CDC Germany Upcoming

September 2026 Hanau am Main, Germany

NT Conference Upcoming

September 2026 Portorož, Slovenia

Infosek 2026 Upcoming

September 2026 Nova Gorica, Slovenia

Defense-X

June 2026 Sibiu, Romania

The Developers

June 2026 Cluj-Napoca, Romania

Digital Identity - meetup

Women in Tech & Women4Cyber

June 2026 Cluj-Napoca, Romania

news.ro Leaders Lounge - Cybersecurity

May 2026 Bucharest, Romania

PoliHack v19

April 2026 Cluj-Napoca, Romania

PeakIT #008

April 2026 Braşov, Romania

Microsoft MVP Summit 2026

March 2026 Redmond, Washington, United States

NDC Security 2026 Sessionize Event

March 2026 Oslo, Norway

Winter ELSA Law School 2026

February 2026 Trento, Italy

Hek.si 2026

February 2026 Ljubljana, Slovenia

Defcon Cluj meetup

December 2025 Cluj-Napoca, Romania

DefCamp 2025 Sessionize Event

November 2025 Bucharest, Romania

IT Days 2025

November 2025 Cluj-Napoca, Romania

Timisoara Cyber Forum 2025

October 2025 Timişoara, Romania

Infosek 2025

September 2025 Nova Gorica, Slovenia

CyberSea Festival 2025

July 2025 Constanţa, Romania

Qubit Conference 2025

May 2025 Prague, Czechia

CIO Summit 2025

April 2025 Ljubljana, Slovenia

PeakIT #007

April 2025 Braşov, Romania

Microsoft MVP Summit 2025

March 2025 Redmond, Washington, United States

Hek.si 2025

February 2025 Ljubljana, Slovenia

NDC Security 2025 Sessionize Event

January 2025 Oslo, Norway

DefCamp 2024 Sessionize Event

November 2024 Bucharest, Romania

IT Days 2024

November 2024 Cluj-Napoca, Romania

SecureWorld in the era of Artificial Intelligence Sessionize Event

October 2024

Transylvania Insurance Days

October 2024 Cluj-Napoca, Romania

DEFCON Cluj Meetup

September 2024 Cluj-Napoca, Romania

DefCamp Cluj-Napoca Sessionize Event

May 2024 Cluj-Napoca, Romania

Microsoft MVP Summit 2024

March 2024 Redmond, Washington, United States

Hek.si 2024

February 2024

NDC Security 2024 Sessionize Event

January 2024 Oslo, Norway

DefCamp 2023

November 2023 Bucharest, Romania

IT Days 2023

November 2023 Cluj-Napoca, Romania

Experts Live Europe 2023

September 2023 Prague, Czechia

The Developers

June 2023 Cluj-Napoca, Romania

Microsoft MVP Summit 2023

April 2023 Redmond, Washington, United States

Limitl3ss - IT Summit of Transylvania

March 2023 Târgu Mureş, Romania

Defcamp 2022

November 2022 Bucharest, Romania

IT Days 2022

November 2022 Cluj-Napoca, Romania

Infosek 2022

September 2022 Nova Gorica, Slovenia

IT Days 2021

November 2021 Cluj-Napoca, Romania

DefCamp 2021

November 2021 Bucharest, Romania

PeakIT #004

October 2021 Braşov, Romania

Techorama 2021 Spring Edition Sessionize Event

May 2021 Antwerpen, Belgium

Hek.si 2021

February 2021 Ljubljana, Slovenia

EuropeClouds Summit Sessionize Event

October 2020

Collabdays Lisbon 2020 Sessionize Event

October 2020 Lisbon, Portugal

Cloud & Datacenter Conference Germany 2020 Sessionize Event

May 2020 Hanau am Main, Germany

Experts Live Europe 2019 Sessionize Event

November 2019 Prague, Czechia

DefCamp 2019

November 2019 Bucharest, Romania

KulenDayz 2019 Sessionize Event

September 2019 Osijek, Croatia

Microsoft Inspire 2019

July 2019 Las Vegas, Nevada, United States

ITCamp 2019 Sessionize Event

June 2019 Cluj-Napoca, Romania

Cloud & Datacenter Conference Germany 2019 Sessionize Event

May 2019 Hanau am Main, Germany

Hyper-V and Hybrid Cloud Community Day Sessionize Event

May 2019 Hanau am Main, Germany

Microsoft MVP Summit 2019

March 2019 Redmond, Washington, United States

Experts Live Europe 2018 Sessionize Event

October 2018 Prague, Czechia

Microsoft Inspire 2018

July 2018 Las Vegas, Nevada, United States

ITCamp 2018 Sessionize Event

June 2018 Cluj-Napoca, Romania

Microsoft Cloud & Datacenter Conference Germany 2018

March 2018 Hanau am Main, Germany

Microsoft MVP Summit 2018

March 2018 Redmond, Washington, United States

Defcamp 2017

November 2017 Bucharest, Romania

Experts Live 2017

August 2017 Berlin, Germany

Microsoft Inspire 2017

July 2017 Washington, District of Columbia, United States

ITCamp 2017

May 2017 Cluj-Napoca, Romania

Future Decoded 2016

October 2016 London, United Kingdom

Microsoft Ignite 2016

September 2016 Atlanta, Georgia, United States

ITCamp 2016

May 2016 Cluj-Napoca, Romania

Defcamp 2015

November 2015 Bucharest, Romania

Future Decoded 2015

November 2015 London, United Kingdom

ITCamp 2015

May 2015 Cluj-Napoca, Romania

Microsoft Ignite 2015

May 2015 Chicago, Illinois, United States

DefCamp 2014

November 2014 Bucharest, Romania

Microsoft TechEd Europe 2014

October 2014 Barcelona, Spain

ITCamp 2014

May 2014 Cluj-Napoca, Romania

Microsoft TechEd Europe 2013

June 2013 Madrid, Spain

ITCamp 2013

May 2013 Cluj-Napoca, Romania

ITCamp 2012

May 2012 Cluj-Napoca, Romania

ITCamp 2011

May 2011 Cluj-Napoca, Romania

Tudor Damian

Cybersecurity, AI & Cloud Advisor @ D3 Cyber

Cluj-Napoca, Romania

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top