On October 31, the first BSides cybersecurity conference took place in Chișinău (Cybercor, UTM).

This event, organized by volunteers on a non-profit basis, focused exclusively on practically significant content, with no hidden marketing goals.

The audience included security specialists, system administrators, cloud architects, researchers, DevOps engineers, students, and IT managers. The atmosphere was direct and professional.

Only useful information from practicing experts. The event began with a workshop on SIEM/SOAR, setting a technical and authentic tone.

BSides offers honest discussions, applied learning, and experience sharing. For the first time in Chișinău, this global format successfully brought together the private sector, universities, and government institutions for a productive dialogue.

Relevant questions were asked, disagreements were constructively discussed, and practical solutions were shared.

Main Presentations: Key Theses

The conference was packed with reports from leading industry specialists:

  • Stephan Berger (InfoGuard AG), in his Keynote speech, addressed the industry with a clear warning: companies invest millions in EDR, XDR, and Zero Trust, but often neglect the basics — complete system inventory, regular updates, and proper logs.
  • Vitalie Esanu presented data on the “TikTok Landscape in Moldova,” noting over 3 million accounts tagged with MD. His conclusion: social networks are the main channels for manipulation and attacks, which any security strategy must take into account.
  • Alexey Shulenkov (DAAC digital), in his report on “Risk Management in the Digital Supply Chain,” continuing Stephan Berger’s thought, emphasized the importance of correct risk assessment when using third-party solutions and the need to consistently implement basic security practices. Every vendor integration becomes a potential vulnerability.
  • Artur Reaboi explained the practical aspects of “Cloud-Native applications on Kubernetes” security. He noted that Kubernetes requires careful configuration, and misconfigurations are not theoretical but real vulnerabilities requiring access control and network isolation.
  • Ionut Baltariu (Bitdefender) revealed a growing attack tactic in the presentation “Fake jobs, real malware.” Attackers use fake job offers to conduct a hybrid attack on an organization.
  • Catalina Iosub (CrowdStrike), in the report “AI vs AI — The New Battlefield,” discussed the current reality: attackers use AI for sophisticated phishing, and defense teams respond with AI systems for automatic analysis and response.
  • Mihai Tutulan (Pentalog) conducted a “Deconstruction of a Failure” using a real incident as an example. The lesson: many “unavoidable incidents” were actually “incidents we were not prepared for” (due to weak network segmentation, untested backups, etc.).
  • Bogdan Miron (D3 Cyber), in the report “Finding Signals in the Noise,” demonstrated how AI and Data Science improve threat hunting through pattern analysis and contextual interpretation, yielding practical results.
  • Cristian Cornea (Zerotak Security) spoke about “Offensive Security for SCADA/OT systems.” He emphasized that in industrial environments, mistakes can stop factories or affect people’s lives, so security testing requires surgical precision.

From Presentations to Practice: Risk Management and Recommended Actions

As a Community Sponsor, DAAC digital supported the community. Alexey Shulenkov’s presentation was largely devoted to the presence of multiple vulnerabilities in the supply chain, how they are exploited, and how organizations ignore this problem.

He emphasized the need for a systemic approach to selecting vendors and their assessment methods.

We hope that BSides will become a catalyst for moving from theory to practice.

Real results appear when the following practices, combining systemic vendor assessment and general cyber hygiene, become routine:

  1. Inventory all vendors (including SaaS applications) and all digital assets.
  2. Classify vendors by risk level.
  3. Establish and review clear minimum requirements for them (MFA, updates, logs, audit rights, incident notification).
  4. Request full software component documentation (SBOM).
  5. Check the storage and usefulness of logs for incident investigation.
  6. Test the full restoration process from backups.
  7. Organize and schedule regular joint incident simulation exercises involving third-party vendors (including SLAs and post-incident analysis).

These are basic practices that are often ignored, but without them, any security strategy remains only on paper.

Conclusion

The first BSides in Chișinău set a high standard: no “fluff,” but real practical content.

This event showed that Moldova has a mature technical community, ready to discuss cybersecurity at a serious practical level.

We hope that such a format for specialists will become regular and successful, and for our part, we will be glad to continue supporting the development of cybersecurity in the country.

For detailed information about our cybersecurity solutions, please visit the dedicated page: Cyber Security.

Share the article, choose your platform!
Published On: November 3rd, 2025
/
Categories: News, Blog, Blog Cybersecurity, Events
/
Tags: , ,
/
Leave A Comment

Subscribe and get the latest IT news

Always up to date!