Soare, Mare, Securitate Cibernetică: Sun, Sea, Cybersecurity
Reflections from the first two days in Constanța
Cybersecurity conferences are often held in anonymous hotel function rooms, apparently designed to ensure that nothing distracts delegates from the PowerPoint slides or the coffee of uncertain legal status.
CyberSea Festival has chosen a rather better formula.
The second edition of the festival is taking place from 28 to 30 July at Diplomatic Mamaia in Constanța. Organised by Women4Cyber Romania, it combines talks, practical workshops, competitions and mentoring with the rather civilised prospect of evening networking beside the Black Sea. It is deliberately aimed not only at established professionals, but also at students and young people beginning their cybersecurity careers.

Constanța has proved an excellent setting. The city is clean and welcoming, the venue is very good, and the beaches are beautiful. The days have been exceptionally hot, but the evenings beside the sea are warm and pleasant, allowing conversations begun during the formal programme to continue outside long after the last scheduled presentation.
That matters, because CyberSea is not simply a conference transplanted to a seaside resort. The location and the less formal festival structure are part of how the event works.
The war is not quite over the horizon
There is, however, an unavoidable geographical context.
From Constanța, the ongoing war in and around Ukraine feels considerably less abstract than it does from the United Kingdom. The city feels safe and normal in every ordinary sense, but it is close enough to the conflict to make it real.
In the four days immediately before the conference, drones entered Romanian airspace on four consecutive days. Romanian F-16s shot down the first three; a fourth briefly entered Romanian airspace near Sulina before leaving. Romania had already passed legislation permitting hostile or unauthorised drones to be destroyed, but these incidents marked a significant operational shift from monitoring and protesting to actively intercepting them. As I observed in a recent posting about these incursions, “give putin an inch and he’ll take your country”. Bullies are like that: small & frightened on the inside. It amuses me that the name, putin, is so similar to the Romanian word puțin, meaning “little”. Maybe we should routinely add the diacritic.
Romania is not at war, but there is ongoing probing, conflict, and harassment from russia. The Black Sea is not merely a scenic backdrop.
That gives discussions about resilience, infrastructure, disinformation, open-source intelligence and national security an unusual immediacy. These are not theoretical problems being considered safely at a distance. Some of their consequences are unfolding only a few hundred kilometres away.

An ambitious programme
The first two days have offered four parallel tracks covering presentations, workshops, competitions, demonstrations and interactive areas. The principal difficulty has been the traditional conference design flaw of providing several interesting sessions simultaneously while issuing each delegate with only one body.
The programme has covered a broad range of subjects: operational security, secure development, artificial intelligence, cyber resilience, incident response, open-source intelligence, social engineering and the human dimensions of cybersecurity.
There has been a healthy emphasis on practical work rather than merely describing problems from behind a lectern. The competitions and workshops have helped make the event feel participatory, while the range of speakers has brought together government, industry, academia, the professional community and those still preparing to enter it.

One of my highlights was Chris Kubecka’s OSINT Goldfinger workshop.
Open-source intelligence is sometimes presented as a collection of clever search techniques. Used properly, however, it is a disciplined investigative process: finding fragments of information, establishing provenance, testing competing explanations, identifying deliberate deception and understanding the limits of what the available evidence can support. And always trying to prove yourself wrong – because if you publish, you can be sure that others will try this, so better to apply rigour yourself first.
Chris’s session was impacted by AV equipment issues, but actually resulted in a more intimate event as we all crowded around a laptop. For those who remember using green screen VT100s and teletype-writers spitting out endless fanfold paper (especially if you’ve ever had to use vi on one – you have to know how to use the ed functions upon which the vi-sual version of vi was constructed and which are normally hidden from you), a high resolution colour laptop screen can still be considered luxury.
It demonstrated the value of combining technical ability with curiosity, persistence and sound judgement. Tools can find information; they cannot relieve the investigator of the tiresome human obligation to think.

Another particularly timely session (translation link at bottom of Romanian text) by Laur Neagu examined how to recognise AI-generated images and video.
This task is becoming substantially harder. The comfortable days of looking for six fingers, impossible teeth, malformed spectacles or background text resembling the final moments of a malfunctioning printer are passing rapidly. Generative systems have become much better at avoiding the conspicuous mistakes on which early detection advice relied.
The important lesson was not simply to learn a new checklist of visual peculiarities. It was to consider the whole information object: where it came from, how it was distributed, whether its context is credible, whether movement and lighting remain consistent over time, and whether there is supporting evidence from independent sources. Provenance, in other words.
The absence of an obvious mistake is not evidence of authenticity. As usual, reality has responded to the human desire for a simple checklist by becoming more complicated.

The network between the sessions
The presentations and workshops have been excellent, but an event like CyberSea is also about a different kind of networking.
The formal programme provides the subjects. The spaces between sessions provide the connections.
Over coffee, meals and warm evenings beside the sea, people exchange experiences, compare approaches, discover common problems and encounter ideas which would never have appeared in a scheduled presentation. Old professional relationships are renewed, new ones begin, and conversations move freely between technical details, policy questions, career advice and whatever unexpected subject has just captured the collective imagination.
These connections are not a decorative addition to the conference. They are part of the cybersecurity capability being built.
A future incident may be resolved more quickly because two people met here. A project may avoid a mistake because someone heard how another organisation had already made it. A student may find a mentor, an employer or simply the confidence that there is a place for them in the profession.
Experienced practitioners also have an opportunity to pass on some of what they have learnt, including the expensive lessons acquired by doing things wrong before the younger attendees were born. This arrangement remains gratifying until one of the young whipper-snappers casually teaches us something new three minutes later.
That is exactly how it should work; even for the most experienced, every day should be a school day. The moment you stop learning new things in this profession is the moment you start to become less relevant.


Investing in the people who come next
I was particularly pleased to see that free student tickets had been made available, and that students were actually present and participating. The festival explicitly provides free student access alongside its general admission programme.
The cybersecurity workforce shortage is usually discussed in terms of vacancies that need to be filled now. That immediate need is genuine, but we must also look further ahead.
The next tranche of cybersecurity professionals is currently at university, college or school. Behind them is another generation which may not yet know that this profession exists, much less that it might contain a future for them.
We therefore need to consider not only today’s specialists and tomorrow’s recruits, but the people who will be needed after them. A workforce does not spontaneously emerge fully qualified because somebody has placed the words talent pipeline in a strategy document.
Young people need access to events, practitioners and realistic examples of the work. They need opportunities to experiment, ask questions and discover that cybersecurity includes far more than the popular image of someone in a darkened room attacking a keyboard while green text cascades meaningfully down a screen.
Bringing students into the same space as experienced professionals is not merely outreach. It is long-term capacity building.
Romania’s growing cybersecurity community
There have been many familiar faces at CyberSea, including people I previously met at the Bucharest Cybersecurity Conferences in 2024 and 2025, but also many new ones.
Women4Cyber Romania has been strongly represented, including a contingent from Iași, a city of concentrated culture (combined with around 65 degrees difference between the Summer 🥵 and Winter 🥶 ambient temperatures). The community feels active, connected and notably enthusiastic.
Romania, and particularly its eastern cities and university communities, increasingly feels like a hotbed of high-technology activity. I have met a remarkable number of young, bright and highly educated people with excellent language skills. English fluency appears almost universal, frequently accompanied by fluency in several programming languages as well.
That combination of technical education, linguistic ability and enthusiasm is formidable.
It would be easy from parts of Western Europe to view countries such as Romania principally as sources of technical labour. That would badly underestimate what is developing here. This is an ecosystem with its own institutions, companies, researchers, professional networks and ambitions.
CyberSea is both a product of that ecosystem and a means of strengthening it.


Two days in
After two days, the strongest impression is the combination of seriousness and optimism.
The seriousness comes from the geopolitical setting, the pace of technological change and the increasingly visible consequences of cyber insecurity.
The optimism comes from the people: experienced practitioners willing to share what they know, younger attendees eager to acquire and challenge that knowledge, and a professional community which understands that cooperation is not optional.
Cybersecurity is both technical and social. We build resilience in systems, but also in relationships. A successful conference should therefore leave its participants with new knowledge, new contacts, new questions and slightly less confidence that any difficult problem has one tidy answer.
CyberSea has already achieved all four.
There is still another day to come, but I will leave Constanța with fresh ideas, renewed friendships and a collection of new connections. Also several hundred photographs and a modest sleep deficit, because apparently that remains an international conference standard.



One response to “CyberSea 2026: Cybersecurity, Community and the Black Sea”
Well wwritten, clear, thanks for sharing!
LikeLike