『Distilled Security Podcast』のカバーアート

Distilled Security Podcast

Distilled Security Podcast

著者: Justin Leapline Joe Wynn and Rick Yocum
無料で聴く

【Amazonプライム会員限定】今ならプレミアムプランが4か月 月額99円。

10月19日まで。※適用条件あり

Join us on Distilled Security as we delve into the fascinating world of cybersecurity. Each episode, we break down intriguing topics, analyze the latest news, and engage in in-depth conversations with our hosts and invited guests. Whether you're a seasoned professional or just curious about cybersecurity, our podcast offers valuable insights and thought-provoking discussions to keep you informed and entertained. Tune in and stay ahead of the curve in the ever-evolving landscape of cybersecurity.

2026 Justin Leapline, Joe Wynn, and Rick Yocum
経済学
エピソード
  • Episode 28: Flock Cameras & Privacy, Hacking Water Systems & How to Pick a Good Bourbon
    2026/09/10

    This episode covers the growing controversy around Flock cameras: what they are, how their centralized license plate reader network enables powerful searches across jurisdictions, the documented cases of abuse by law enforcement,and why the real problem isn't the technology itself but the lack of governance and oversight. We also explore the broader privacy implications of always-on surveillance in public spaces and where the line should be drawn.

    Then we break down a coordinated cyberattack that hit 30+ water systems across 12 states, exposing just how vulnerable US critical infrastructure really is.With 90% of community water systems having zero IT security budget,we discuss what basic OT hygiene should look like and spotlight the volunteer group Water Watch Center doing incredible work to fill the gap.

    And for something a little different we do a deep dive into how to actually pick a good bourbon. Red flags on the shelf, what terms like "small batch" and "handcrafted" really mean, why older isn't always better, the massive barrel surplus reshaping the industry, and the distillation process behind what's actually in your glass.

    🥃 Spirit Review: Boondocks Port Finished Straight Bourbon Whiskey 6 years, finished in port wine barrels, picked up in Kentucky

    Takeaways

    • Flock cameras raise concerns about privacy, abuse, and the need for oversight
    • The use of surveillance technology has broader ethical and societal implications Surveillance technology presents ethical and moral dilemmas
    • The need for checks and balances and governance in surveillance technology Marketing gimmicks can influence consumer choices
    • Proof and distillation process impact the quality of whiskey
    • The whiskey industry is experiencing a surplus of barrels
    • Availability of specific bourbon in Pennsylvania Water utilities face cybersecurity challenges due to limited budgets and resources.
    • Basic cybersecurity measures, such as removing unnecessary internet access, replacing default credentials, and using multi-factor authentication, are crucial for protecting critical infrastructure.

    Chapters

    • 00:00 Introduction to Flock Cameras
    • 03:00 Capabilities and Controversy
    • 08:12 Ethical Implications and Privacy Concerns
    • 16:00 Data Collection and Surveillance Technology
    • 30:36 Challenges of Surveillance Technology
    • 36:04 Ethical and Moral Considerations
    • 41:43 Governance and Oversight
    • 52:37 Privacy Concerns and Public Trust
    • 57:24 Impact of Marketing Gimmicks
    • 58:07 Significance of Proof and Distillation Process
    • 01:00:42 Surplus of Barrels in the Whiskey Industry
    • 01:07:11 Tasting Notes and Availability of Specific Bourbon
    • 01:25:27 Hacking of Utilities and Water Systems
    • 01:26:15 Challenges Faced by Water Utilities
    • 01:38:24 Implications of Compromised Water Systems
    • 01:43:17 Role of Volunteer Organizations and Basic Cybersecurity Measures


    Hosts
    Justin Leapline – @justinleapline
    Joe Wynn – @wynnjoe
    Rick Yocum – @rickyocum

    Send Us Your Questions!
    ask@distilledsecuritypodcast.com


    Connect with Us
    Website: distilledsecuritypodcast.com
    X: @DisSecPod
    Email: hello@distilledsecuritypodcast.com

    👍 Subscribe for monthly security and compliance insights.

    続きを読む 一部表示
    1 時間 52 分
  • Episode 27: AI Hacking AI, EU AI Act Delays, CMMC Updates & The Duress Code Case
    2026/08/13

    In Episode 27, we recap BSides Pittsburgh 2026 (914 attendees, best turnout yet), then dive into AI models breaking out of sandboxes and hacking Hugging Face, the EU AI Act transparency rules now in effect, the CMMC Phase 2 pause and what it doesn't change, and the precedent, setting case of a US citizen criminally charged for using a phone duress code at the border.

    Plus Wayne Gretzky No. 99 Whisky. 🥃

    ⏱️ Timestamps

    00:00 – Intro 01:28 – BSides Pittsburgh 2025 Recap & Numbers 05:33 – Villages, Sponsors & Planning for Next Year 10:46 – The After-After Party at The Lion 🍸 20:43 – AI Hacking AI: The Hugging Face Incident 25:46 – What CISOs Should Do Now 33:54 – Agentic IR Teams & Kill Switch Governance 45:00 – AI Patching & Configuration Management 57:04 – EU AI Act: The Deadline That Wasn't 1:04:33 – AI Inventory & Third-Party SaaS Risk 1:23:56 – 🥃 Spirit: Wayne Gretzky No. 99 Whisky 1:28:37 – CMMC Phase 2 Pause: What It Means 1:44:15 – Duress Code Case & Corporate Travel Policy 2:04:00 – Digital Privacy at the Border & Employee Training 2:15:37 – Wrap-Up

    🎙️ Hosts

    • Justin Leapline – @justinleapline
    • Joe Wynn – @wynnjoe
    • Rick Yocum – @rickyocum

    📬 Send Us Your Questions!
    ask@distilledsecuritypodcast.com

    🌐 Connect with Us
    Website: distilledsecuritypodcast.com


    X: @DisSecPod
    Email: hello@distilledsecuritypodcast.com

    👍 Like, comment, and subscribe for monthly security and compliance insights.

    続きを読む 一部表示
    2 時間 17 分
  • Episode 26: How to Run a Conference, Why Most Pen Tests Fail, and HIPAA's Ransomware Reckoning
    2026/07/08

    In this episode, we're joined by Jon Buhagiar, Director of Information Technology at RareMed Solutions; a published Sybex/Wiley author of Cisco and Microsoft certification guides; and a longtime amateur radio enthusiast. We get into what it actually takes to run a security conference from the ground up, why so many penetration tests end up wasting everyone's money, and how compliance and cyber insurance keep reshaping the way organizations work. Plus, as always, a bourbon.

    🎤 Jon's world — rare-disease specialty pharmacy, patient assistance programs, book writing, and ham radio
    🏗️ Running BSides Pittsburgh: revenue, expenses, marketing, volunteers, speakers, and sponsors
    🎟️ The real economics of ticket pricing, free tickets, and the venue/affordability squeeze
    🧑‍🤝‍🧑 Dividing responsibilities and appointing workstream leads as an event grows
    🎯 Scoping as the make-or-break of a good pen test — and the human element that tooling misses
    🔗 Chaining vulnerabilities and what separates a checkbox test from a real one
    💸 Why pen testing so often becomes an ineffective use of resources
    📋 Compliance and contractual drivers vs. genuine risk reduction
    🛡️ A risk-based, scenario-driven approach focused on resilience and continuous improvement
    🤝 Engaging pen testers as partners and maturing the process over time
    🔄 Security as a constant state of change — compliance, cyber insurance, and government scoring
    🏥 HIPAA compliance, risk analysis, and the ransomware reckoning facing healthcare
    🥃 Bourbon tasting and discussion

    ⏱️ Timestamps
    00:00 Intro
    01:26 Guest introduction & background
    02:18 RareMed Solutions & patient assistance programs
    05:01 Book writing & amateur radio
    08:11 BSides Pittsburgh overview
    15:04 Running a conference: planning & organization
    22:05 Marketing & audience engagement
    25:07 Dividing responsibilities as you grow
    27:59 The value of ticket pricing
    31:50 BSides & the conference model
    46:11 Penetration testing & scoping
    57:28 The purpose of pen testing
    58:23 When pen testing goes wrong
    01:00:16 Reasons for pen testing & compliance drivers
    01:03:04 Continuous monitoring, testing & detection
    01:06:19 Is your company ready for a pen test?
    01:07:07 A risk-based approach
    01:13:58 Scenario-based testing & resilience
    01:17:31 Evaluating the value of pen testing
    01:29:01 The constant state of change
    01:31:01 Compliance & cyber insurance
    01:32:19 Bourbon tasting
    01:36:32 Government scoring & risk analysis
    01:50:36 HIPAA compliance & ransomware
    01:55:01 Wrap-up & call to action

    🎧 Distilled Security Podcast

    Cybersecurity, GRC, and leadership, one pour at a time.

    🎙️ Hosts

    • Justin Leapline – @justinleapline
    • Joe Wynn – @wynnjoe
    • Rick Yocum – @rickyocum

    🎤 Guest

    • Jon Buhagiar linkedin.com/in/jonbuhagiar

    📬 Send Us Your Questions!

    ask@distilledsecuritypodcast.com

    🌐 Connect with Us

    Website: distilledsecuritypodcast.com

    X: @DisSecPod

    YouTube: @distilledsecurity

    Email: hello@distilledsecuritypodcast.com

    👍 Like, comment, and subscribe for monthly

    security and compliance insights.

    続きを読む 一部表示
    1 時間 56 分
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません