Distilled Security Podcast

Justin Leapline, Joe Wynn, and Rick Yocum

Join us on Distilled Security as we delve into the fascinating world of cybersecurity. Each episode, we break down intriguing topics, analyze the latest news, and engage in in-depth conversations with our hosts and invited guests. Whether you're a seasoned professional or just curious about cybersecurity, our podcast offers valuable insights and thought-provoking discussions to keep you informed and entertained. Tune in and stay ahead of the curve in the ever-evolving landscape of cybersecurity.

  1. Jul 8

    Episode 26: How to Run a Conference, Why Most Pen Tests Fail, and HIPAA's Ransomware Reckoning

    In this episode, we're joined by Jon Buhagiar, Director of Information Technology at RareMed Solutions; a published Sybex/Wiley author of Cisco and Microsoft certification guides; and a longtime amateur radio enthusiast. We get into what it actually takes to run a security conference from the ground up, why so many penetration tests end up wasting everyone's money, and how compliance and cyber insurance keep reshaping the way organizations work. Plus, as always, a bourbon. 🎤 Jon's world — rare-disease specialty pharmacy, patient assistance programs, book writing, and ham radio 🏗️ Running BSides Pittsburgh: revenue, expenses, marketing, volunteers, speakers, and sponsors 🎟️ The real economics of ticket pricing, free tickets, and the venue/affordability squeeze 🧑‍🤝‍🧑 Dividing responsibilities and appointing workstream leads as an event grows 🎯 Scoping as the make-or-break of a good pen test — and the human element that tooling misses 🔗 Chaining vulnerabilities and what separates a checkbox test from a real one 💸 Why pen testing so often becomes an ineffective use of resources 📋 Compliance and contractual drivers vs. genuine risk reduction 🛡️ A risk-based, scenario-driven approach focused on resilience and continuous improvement 🤝 Engaging pen testers as partners and maturing the process over time 🔄 Security as a constant state of change — compliance, cyber insurance, and government scoring 🏥 HIPAA compliance, risk analysis, and the ransomware reckoning facing healthcare 🥃 Bourbon tasting and discussion ⏱️ Timestamps 00:00 Intro 01:26 Guest introduction & background 02:18 RareMed Solutions & patient assistance programs 05:01 Book writing & amateur radio 08:11 BSides Pittsburgh overview 15:04 Running a conference: planning & organization 22:05 Marketing & audience engagement 25:07 Dividing responsibilities as you grow 27:59 The value of ticket pricing 31:50 BSides & the conference model 46:11 Penetration testing & scoping 57:28 The purpose of pen testing 58:23 When pen testing goes wrong 01:00:16 Reasons for pen testing & compliance drivers 01:03:04 Continuous monitoring, testing & detection 01:06:19 Is your company ready for a pen test? 01:07:07 A risk-based approach 01:13:58 Scenario-based testing & resilience 01:17:31 Evaluating the value of pen testing 01:29:01 The constant state of change 01:31:01 Compliance & cyber insurance 01:32:19 Bourbon tasting 01:36:32 Government scoring & risk analysis 01:50:36 HIPAA compliance & ransomware 01:55:01 Wrap-up & call to action 🎧 Distilled Security Podcast Cybersecurity, GRC, and leadership, one pour at a time. 🎙️ Hosts Justin Leapline – @justinleaplineJoe Wynn – @wynnjoeRick Yocum – @rickyocum 🎤 Guest Jon Buhagiar linkedin.com/in/jonbuhagiar 📬 Send Us Your Questions! ask@distilledsecuritypodcast.com 🌐 Connect with Us Website: distilledsecuritypodcast.com X: @DisSecPod YouTube: @distilledsecurity Email: hello@distilledsecuritypodcast.com 👍 Like, comment, and subscribe for monthly security and compliance insights.

  2. May 14

    Episode 24: 2 Years, 24 Episodes & The State of Security in the Age of AI

    In this episode, we celebrate our 2nd anniversary and Episode 24 of Distilled Security! We cover the Vercel breach, how a Roblox script led to compromised Google Workspace credentials via an unauthorized OAuth connection. Then we dive into HackerOne, pausing their own bug bounty program, overwhelmed by low-quality, AI-generated submissions. And we close out with the State of Vibe-Coded Security—4,783 AI-assisted apps scanned, 727 critical issues found, and the real question: are you vibe coding or vibe deploying? Plus, a quick look at Claude for Security dropping into public beta and what that means for the industry. All of that, and we crack open a Peerless Double Oak to toast two years of Distilled Security. 🥃 ⏱️ TIMESTAMPS: 00:00 – Intro & 2-Year Anniversary 🎉 01:26 – Behind the Scenes & Favorite Moments 08:26 – Podcast Metrics & Global Reach 24:20 – BSides Pittsburgh 2025 Update 🛡️ 34:31 – The Vercel Breach & OAuth Risk 58:57 – HackerOne Pauses Bug Bounty 1:16:05 – Spirit: Peerless Double Oak 🥃 1:20:27 – Vibe Coding vs. Vibe Deploying 1:26:46 – Claude for Security & AI News 1:41:27 – Cheers to Two Years! 🥃 🎙️ Hosts Justin Leapline – @justinleapline Joe Wynn – @wynnjoe Rick Yocum – @rickyocum 📬 Send Us Your Questions! ask@distilledsecuritypodcast.com 🌐 Connect with Us Website: distilledsecuritypodcast.com X: @DisSecPod Email: hello@distilledsecuritypodcast.com 👍 Like, comment, and subscribe for monthly security and compliance insights

  3. Mar 9

    Episode 22: Is AI Good for Security, CIRCIA Starts the Clock, and the M&A Problem Nobody's Talking About

    In this episode of the Distilled Security Podcast, we tackle four topics shaping the cybersecurity landscape — from AI's real impact on defense to a wave of regulatory and market changes every security team needs to be tracking. 🔹 Is AI Good for Security? — Anthropic's model finding hundreds of zero days, stock market panic after Claude Code's launch (CrowdStrike down 11%), the "hard things easy, easy things hard" reality of AI, why human-out-of-the-loop isn't ready yet, the coming spike in vulnerability disclosures, and how defenders should be using AI for better hygiene 🔹 CIRCIA Final Rule (May 2026) — The federal incident reporting law hitting critical infrastructure, 72-hour incident and 24-hour ransom payment notification clocks, how "substantial cyber incident" triggers differ from materiality, mid-market companies falling in scope, overlapping timelines with HIPAA/SEC/state breach laws, and building your incident response playbook now 🔹 Protecting Yourself Against a Changing Compliance Landscape — CMMC Phase 2, HIPAA overhaul, CCPA audits all converging, why a unified security program beats framework-by-framework chasing, evidence over policy in audits, engineering continuous compliance through automation, and the reality of doing this without dedicated staff 🔹 Cybersecurity M&A / Consolidation Problem — Google acquiring Wiz for $32B, 10% of the cybersecurity industry changing hands, operational benefits of fewer vendors vs. pricing pressure and talent drain, the OneTrust "sticker on the side" integration warning, Cisco's Startup Studios model, and why consolidation only works if they don't break what made the acquisition special 🥃 Spirit Review: WhistlePig 12 Year Old World Rye PA Fine Wine & Good Spirits Select — Finished in Madeira, Sauternes & Port barrels, 86 proof https://www.whistlepigwhiskey.com/ 📬 Send Us Your Questions! ask@distilledsecuritypodcast.com 🎙️ Hosts Justin Leapline – @justinleapline Joe Wynn – @wynnjoe Rick Yocum – @rickyocum 🌐 Connect with Us Website: distilledsecuritypodcast.com X: @DisSecPod Email: hello@distilledsecuritypodcast.com 👍 Like, comment, and subscribe for weekly security and compliance insights.

  4. Feb 18

    Episode 21: AI Notetakers Are Illegal, GRC Tools Are Lying, and ISO 42001 Changes Everything

    In this episode of the Distilled Security Podcast, we break down three converging forces reshaping how organizations manage AI risk — and what you need to do about it now. 🔹 BIPA + AI Notetakers — A class action lawsuit exposes unauthorized biometric data collection, why a single Illinois meeting participant creates liability, the Shopify wiretapping dismissal, and the steps you should take today to audit your AI tools 🔹 GRC Engineering Meets AI — Real AI compliance tools vs. vaporware, using LLMs for policy drafting and control mapping, the hallucination accountability problem, building AI guardrails as code, and the NIST RFI on AI Agent Security (comments due March 9, 2026) 🔹 ISO 42001 Deep Dive — The first AI Management System standard, how it differs from ISO 27001, AI Impact Assessments vs. traditional risk assessments, stakeholder engagement requirements, and why certification is becoming essential for EU AI Act compliance 🥃 Spirit Review: Redbreast 12 Cask Strength https://www.redbreastwhiskey.com/en-us/whiskey-collections/redbreast-cask-strength-whiskey/ ⏱️ Timestamps 0:00 Intro & Episode Overview 2:04 BIPA & AI Notetakers 25:08 GRC Engineering Meets AI 1:07:15 🥃 Spirit Review: Redbreast 12 Cask Strength (Irish Whiskey) 1:11:17 ISO 42001 1:49:30 Outro & wrap-up 🎙️ Hosts Justin Leapline – @justinleapline Joe Wynn – @wynnjoe Rick Yocum – @rickyocum 🌐 Connect with Us Website: distilledsecuritypodcast.com X: @DisSecPod Email: hello@distilledsecuritypodcast.com 👍 Like, comment, and subscribe for weekly security and compliance insights.

  5. 12/08/2025

    Episode 19: Cloudflare Outage, AI-Powered Attacks & The Rise of GRC Engineering | Distilled Security Podcast

    In this episode, we break down a major Cloudflare outage, explore how a nation-state used AI agents to automate a cyberattack, and discuss the growing risks around MCP integrations. We also highlight why GRC Engineering is becoming essential to modern security programs and wrap up with key regulatory updates, including CMMC changes affecting thousands of contractors. Topics covered: • Cloudflare outage impact and root cause • Nation-state attack using AI agents to automate intrusion steps • MCP (Model Context Protocol): power, risks, and examples • Why GRC Engineering is the future of compliance and automation • Updates on GDPR, ISO 27701, California AB 5866, and SEC rules • CMMC assessor shortages and what organizations must prepare for Spirit of the Episode • Knob Creek 21-Year Limited Release, rich caramel notes, heavy char, smooth for 100 proof Timestamps 0:02—Cloudflare Outage Stories & Global Impact3:07—Root Cause, Not a Cyberattack & Third-Party Risk Reality10:38 - China Uses Anthropic’s Claude + MCP for Automated Cyberattacks14:17 - Full AI Attack Lifecycle Explained27:18 - MCP: The API for AI & Its Security Risks44:05 - Bourbon Break: Knob Creek 21-Year Review50:02 - GRC Engineering Deep Dive: Automation & Controls-as-Code1:24:13 - Regulatory Roundup: GDPR, ISO 27701, California AB 566, SEC SP1:44:27 - CMMC 2.0 Crisis: Auditor Shortages & DoD Contract Impact2:11:20 - Closing Thoughts & Episode Wrap-UpHosts Justin Leapline – @justinleaplineJoe Wynn – @wynnjoeRick Yocum – @rickyocumGuest Matthew J. Schiavone - @SikitchConnect with Us Website: distilledsecuritypodcast.comX:  @DisSecPodEmail: hello@distilledsecuritypodcast.com

  6. 11/10/2025

    Episode 18: TRISS Highlights, Cloud Chaos & SaaS Lessons Learned

    In Episode 18 of the Distilled Security Podcast, Justin Leapline, Joe Wynn, and Rick Yokum recap their time at TRISS, share lessons on storytelling and women in tech, and break down the recent AWS us-east-1 DNS/DynamoDB outage, the Microsoft Front Door global disruption, and the F5 BIG-IP incident.  🔍 We discuss: - TRISS highlights: panels, community & storytelling - “Breaking the glass ceiling” and unintentional bias in meetings - AWS & Microsoft outages: risk, resilience & when multicloud matters - F5 BIG-IP incident and supply chain risk - Launching a GRC SaaS: episki’s journey, lessons & tradeoffs 🥃 Spirit of the episode Penelope Bourbon – Project X (sherry cask finish) ⏱️ Timestamps 00:00 – 🥃 Intro & TRISS Recap — Highlights from TRISS: panels, community, and a keynote with Edward Norton 02:40 – 📖 The Power of Storytelling — Why empathy and narrative matter in cybersecurity leadership 04:40 – 👩‍💻 Women in Tech & Bias in Meetings — Real talk about unintentional bias and everyday experiences 20:34 – ☁️ AWS & Microsoft Outages — What happened and what it says about cloud resilience 49:38 - 🥃 Bourbon Break — Enjoying a glass of Penelope Project X 53:30 – 🔥 F5 BIG-IP Vulnerability — Supply chain risk and patching lessons 1:09:50 – 🚀 Launching episki (GRC SaaS) — Building simply, shipping fast, and learning from users 1:52:22 – 🧭 Reflections & Closing Thoughts — Culture, resilience, and what’s next 🎧 Hosts Justin Leapline  Joe Wynn  Rick Yocum  🌐 Connect with Us Website: distilledsecuritypodcast.com X : @DisSecPod Email: hello@distilledsecuritypodcast.com

About

Join us on Distilled Security as we delve into the fascinating world of cybersecurity. Each episode, we break down intriguing topics, analyze the latest news, and engage in in-depth conversations with our hosts and invited guests. Whether you're a seasoned professional or just curious about cybersecurity, our podcast offers valuable insights and thought-provoking discussions to keep you informed and entertained. Tune in and stay ahead of the curve in the ever-evolving landscape of cybersecurity.

You Might Also Like