エピソード

  • Episode 28: Flock Cameras & Privacy, Hacking Water Systems & How to Pick a Good Bourbon
    2026/09/10

    This episode covers the growing controversy around Flock cameras: what they are, how their centralized license plate reader network enables powerful searches across jurisdictions, the documented cases of abuse by law enforcement,and why the real problem isn't the technology itself but the lack of governance and oversight. We also explore the broader privacy implications of always-on surveillance in public spaces and where the line should be drawn.

    Then we break down a coordinated cyberattack that hit 30+ water systems across 12 states, exposing just how vulnerable US critical infrastructure really is.With 90% of community water systems having zero IT security budget,we discuss what basic OT hygiene should look like and spotlight the volunteer group Water Watch Center doing incredible work to fill the gap.

    And for something a little different we do a deep dive into how to actually pick a good bourbon. Red flags on the shelf, what terms like "small batch" and "handcrafted" really mean, why older isn't always better, the massive barrel surplus reshaping the industry, and the distillation process behind what's actually in your glass.

    🥃 Spirit Review: Boondocks Port Finished Straight Bourbon Whiskey 6 years, finished in port wine barrels, picked up in Kentucky

    Takeaways

    • Flock cameras raise concerns about privacy, abuse, and the need for oversight
    • The use of surveillance technology has broader ethical and societal implications Surveillance technology presents ethical and moral dilemmas
    • The need for checks and balances and governance in surveillance technology Marketing gimmicks can influence consumer choices
    • Proof and distillation process impact the quality of whiskey
    • The whiskey industry is experiencing a surplus of barrels
    • Availability of specific bourbon in Pennsylvania Water utilities face cybersecurity challenges due to limited budgets and resources.
    • Basic cybersecurity measures, such as removing unnecessary internet access, replacing default credentials, and using multi-factor authentication, are crucial for protecting critical infrastructure.

    Chapters

    • 00:00 Introduction to Flock Cameras
    • 03:00 Capabilities and Controversy
    • 08:12 Ethical Implications and Privacy Concerns
    • 16:00 Data Collection and Surveillance Technology
    • 30:36 Challenges of Surveillance Technology
    • 36:04 Ethical and Moral Considerations
    • 41:43 Governance and Oversight
    • 52:37 Privacy Concerns and Public Trust
    • 57:24 Impact of Marketing Gimmicks
    • 58:07 Significance of Proof and Distillation Process
    • 01:00:42 Surplus of Barrels in the Whiskey Industry
    • 01:07:11 Tasting Notes and Availability of Specific Bourbon
    • 01:25:27 Hacking of Utilities and Water Systems
    • 01:26:15 Challenges Faced by Water Utilities
    • 01:38:24 Implications of Compromised Water Systems
    • 01:43:17 Role of Volunteer Organizations and Basic Cybersecurity Measures


    Hosts
    Justin Leapline – @justinleapline
    Joe Wynn – @wynnjoe
    Rick Yocum – @rickyocum

    Send Us Your Questions!
    ask@distilledsecuritypodcast.com


    Connect with Us
    Website: distilledsecuritypodcast.com
    X: @DisSecPod
    Email: hello@distilledsecuritypodcast.com

    👍 Subscribe for monthly security and compliance insights.

    続きを読む 一部表示
    1 時間 52 分
  • Episode 27: AI Hacking AI, EU AI Act Delays, CMMC Updates & The Duress Code Case
    2026/08/13

    In Episode 27, we recap BSides Pittsburgh 2026 (914 attendees, best turnout yet), then dive into AI models breaking out of sandboxes and hacking Hugging Face, the EU AI Act transparency rules now in effect, the CMMC Phase 2 pause and what it doesn't change, and the precedent, setting case of a US citizen criminally charged for using a phone duress code at the border.

    Plus Wayne Gretzky No. 99 Whisky. 🥃

    ⏱️ Timestamps

    00:00 – Intro 01:28 – BSides Pittsburgh 2025 Recap & Numbers 05:33 – Villages, Sponsors & Planning for Next Year 10:46 – The After-After Party at The Lion 🍸 20:43 – AI Hacking AI: The Hugging Face Incident 25:46 – What CISOs Should Do Now 33:54 – Agentic IR Teams & Kill Switch Governance 45:00 – AI Patching & Configuration Management 57:04 – EU AI Act: The Deadline That Wasn't 1:04:33 – AI Inventory & Third-Party SaaS Risk 1:23:56 – 🥃 Spirit: Wayne Gretzky No. 99 Whisky 1:28:37 – CMMC Phase 2 Pause: What It Means 1:44:15 – Duress Code Case & Corporate Travel Policy 2:04:00 – Digital Privacy at the Border & Employee Training 2:15:37 – Wrap-Up

    🎙️ Hosts

    • Justin Leapline – @justinleapline
    • Joe Wynn – @wynnjoe
    • Rick Yocum – @rickyocum

    📬 Send Us Your Questions!
    ask@distilledsecuritypodcast.com

    🌐 Connect with Us
    Website: distilledsecuritypodcast.com


    X: @DisSecPod
    Email: hello@distilledsecuritypodcast.com

    👍 Like, comment, and subscribe for monthly security and compliance insights.

    続きを読む 一部表示
    2 時間 17 分
  • Episode 26: How to Run a Conference, Why Most Pen Tests Fail, and HIPAA's Ransomware Reckoning
    2026/07/08

    In this episode, we're joined by Jon Buhagiar, Director of Information Technology at RareMed Solutions; a published Sybex/Wiley author of Cisco and Microsoft certification guides; and a longtime amateur radio enthusiast. We get into what it actually takes to run a security conference from the ground up, why so many penetration tests end up wasting everyone's money, and how compliance and cyber insurance keep reshaping the way organizations work. Plus, as always, a bourbon.

    🎤 Jon's world — rare-disease specialty pharmacy, patient assistance programs, book writing, and ham radio
    🏗️ Running BSides Pittsburgh: revenue, expenses, marketing, volunteers, speakers, and sponsors
    🎟️ The real economics of ticket pricing, free tickets, and the venue/affordability squeeze
    🧑‍🤝‍🧑 Dividing responsibilities and appointing workstream leads as an event grows
    🎯 Scoping as the make-or-break of a good pen test — and the human element that tooling misses
    🔗 Chaining vulnerabilities and what separates a checkbox test from a real one
    💸 Why pen testing so often becomes an ineffective use of resources
    📋 Compliance and contractual drivers vs. genuine risk reduction
    🛡️ A risk-based, scenario-driven approach focused on resilience and continuous improvement
    🤝 Engaging pen testers as partners and maturing the process over time
    🔄 Security as a constant state of change — compliance, cyber insurance, and government scoring
    🏥 HIPAA compliance, risk analysis, and the ransomware reckoning facing healthcare
    🥃 Bourbon tasting and discussion

    ⏱️ Timestamps
    00:00 Intro
    01:26 Guest introduction & background
    02:18 RareMed Solutions & patient assistance programs
    05:01 Book writing & amateur radio
    08:11 BSides Pittsburgh overview
    15:04 Running a conference: planning & organization
    22:05 Marketing & audience engagement
    25:07 Dividing responsibilities as you grow
    27:59 The value of ticket pricing
    31:50 BSides & the conference model
    46:11 Penetration testing & scoping
    57:28 The purpose of pen testing
    58:23 When pen testing goes wrong
    01:00:16 Reasons for pen testing & compliance drivers
    01:03:04 Continuous monitoring, testing & detection
    01:06:19 Is your company ready for a pen test?
    01:07:07 A risk-based approach
    01:13:58 Scenario-based testing & resilience
    01:17:31 Evaluating the value of pen testing
    01:29:01 The constant state of change
    01:31:01 Compliance & cyber insurance
    01:32:19 Bourbon tasting
    01:36:32 Government scoring & risk analysis
    01:50:36 HIPAA compliance & ransomware
    01:55:01 Wrap-up & call to action

    🎧 Distilled Security Podcast

    Cybersecurity, GRC, and leadership, one pour at a time.

    🎙️ Hosts

    • Justin Leapline – @justinleapline
    • Joe Wynn – @wynnjoe
    • Rick Yocum – @rickyocum

    🎤 Guest

    • Jon Buhagiar linkedin.com/in/jonbuhagiar

    📬 Send Us Your Questions!

    ask@distilledsecuritypodcast.com

    🌐 Connect with Us

    Website: distilledsecuritypodcast.com

    X: @DisSecPod

    YouTube: @distilledsecurity

    Email: hello@distilledsecuritypodcast.com

    👍 Like, comment, and subscribe for monthly

    security and compliance insights.

    続きを読む 一部表示
    1 時間 56 分
  • Episode 18: TRISS Highlights, Cloud Chaos & SaaS Lessons Learned
    2025/11/10

    In Episode 18 of the Distilled Security Podcast, Justin Leapline, Joe Wynn, and Rick Yokum recap their time at TRISS, share lessons on storytelling and women in tech, and break down the recent AWS us-east-1 DNS/DynamoDB outage, the Microsoft Front Door global disruption, and the F5 BIG-IP incident.

    🔍 We discuss:
    - TRISS highlights: panels, community & storytelling
    - “Breaking the glass ceiling” and unintentional bias in meetings
    - AWS & Microsoft outages: risk, resilience & when multicloud matters
    - F5 BIG-IP incident and supply chain risk
    - Launching a GRC SaaS: episki’s journey, lessons & tradeoffs

    🥃 Spirit of the episode
    Penelope Bourbon – Project X (sherry cask finish)

    ⏱️ Timestamps
    00:00 – 🥃 Intro & TRISS Recap — Highlights from TRISS: panels, community, and a keynote with Edward Norton

    02:40 – 📖 The Power of Storytelling — Why empathy and narrative matter in cybersecurity leadership

    04:40 – 👩‍💻 Women in Tech & Bias in Meetings — Real talk about unintentional bias and everyday experiences

    20:34 – ☁️ AWS & Microsoft Outages — What happened and what it says about cloud resilience

    49:38 - 🥃 Bourbon Break — Enjoying a glass of Penelope Project X

    53:30 – 🔥 F5 BIG-IP Vulnerability — Supply chain risk and patching lessons

    1:09:50 – 🚀 Launching episki (GRC SaaS) — Building simply, shipping fast, and learning from users

    1:52:22 – 🧭 Reflections & Closing Thoughts — Culture, resilience, and what’s next

    🎧 Hosts
    Justin Leapline
    Joe Wynn
    Rick Yocum

    🌐 Connect with Us
    Website: distilledsecuritypodcast.com
    X : @DisSecPod
    Email: hello@distilledsecuritypodcast.com

    続きを読む 一部表示
    1 時間 53 分
  • Episode 10: Navigating Budget Cuts, Talent Shortages, and Cybersecurity Resilience
    2025/03/12

    Episode 10 of the Distilled Security Podcast is here!

    Join us as we explore:

    • Security in Times of Budget Cuts: How organizations can navigate layoffs and reduced funding while maintaining a strong security posture.
    • The Cybersecurity Talent Shortage: Why security hiring remains challenging, the need for apprenticeship models, and how organizations can develop internal talent pipelines.
    • BSides Pittsburgh: Put this on your calendar and submit talks.
    • Cyber Crisis Readiness: The importance of C-suite participation in tabletop exercises and cyber incident planning.

    References

    • Early Education by David Barton - https://www.youtube.com/watch?v=io-O59eakMk
    • BSides Pittsburgh CFP - https://www.bsidespgh.com/cfp

    Spirits: Lady of the Glen – A 10-year-old cask strength Scotch whisky finished in Oloroso sherry casks.

    Hosts

    • Justin Leapline - LinkedIn
    • Joe Wynn - LinkedIn
    • Rick Yocum - LinkedIn

    Connect with Us

    • Website: Distilled Security Podcast
    • Twitter: @DisSecPod
    • Email: hello@distilledsecuritypodcast.com

    続きを読む 一部表示
    1 時間 34 分
  • Episode 12: One Year of Distilled Security, Auditor Quality, and Starting Your Own Company
    2025/05/02

    Join us as we reflect on:

    • One Year of Podcasting: The crew celebrates a full year of episodes, favorite topics, behind-the-scenes production, and where the show is headed next—including a new studio setup and future sponsors.
    • Audit Quality and Risk: A deep dive into the evolution of cybersecurity audits, the growing influence of low-cost providers, and what actually makes an audit valuable and trustworthy.
    • Third-Party Risk Management: How companies can assess vendor SOC 2 reports, triage risk among their vendors, and build defensible compliance practices.
    • Operational vs. Commercial Risk: The importance of translating audit findings into business impact and strengthening vendor partnerships for long-term resilience.
    • Bourbon Review – Jefferson’s Tropics: A tasting of a tropical-aged bourbon matured in Singapore’s climate, featuring notes of toffee and spice.
    • BSides Pittsburgh Update: Details on ticket sales, sponsor opportunities, and how to get involved with the local security community’s flagship event.
    • Entrepreneurship & Starting a Business: A thoughtful discussion on what it really takes to start your own business—when to consider it, how to prepare, and why it’s often more work (and growth) than expected.


    Hosts

    • Justin Leapline - LinkedIn
    • Joe Wynn - LinkedIn
    • Rick Yocum - LinkedIn

    Connect with Us

    • Website: Distilled Security Podcast
    • Twitter: @DisSecPod
    • Email: hello@distilledsecuritypodcast.com

    続きを読む 一部表示
    1 時間 38 分
  • Episode 21: AI Notetakers Are Illegal, GRC Tools Are Lying, and ISO 42001 Changes Everything
    2026/02/18

    In this episode of the Distilled Security Podcast, we break down three converging forces reshaping how organizations manage AI risk — and what you need to do about it now.

    🔹 BIPA + AI Notetakers — A class action lawsuit exposes unauthorized biometric data collection, why a single Illinois meeting participant creates liability, the Shopify wiretapping dismissal, and the steps you should take today to audit your AI tools
    🔹 GRC Engineering Meets AI — Real AI compliance tools vs. vaporware, using LLMs for policy drafting and control mapping, the hallucination accountability problem, building AI guardrails as code, and the NIST RFI on AI Agent Security (comments due March 9, 2026)
    🔹 ISO 42001 Deep Dive — The first AI Management System standard, how it differs from ISO 27001, AI Impact Assessments vs. traditional risk assessments, stakeholder engagement requirements, and why certification is becoming essential for EU AI Act compliance

    🥃 Spirit Review: Redbreast 12 Cask Strength
    https://www.redbreastwhiskey.com/en-us/whiskey-collections/redbreast-cask-strength-whiskey/

    ⏱️ Timestamps

    0:00 Intro & Episode Overview
    2:04 BIPA & AI Notetakers
    25:08 GRC Engineering Meets AI
    1:07:15 🥃 Spirit Review: Redbreast 12 Cask Strength (Irish Whiskey)
    1:11:17 ISO 42001
    1:49:30 Outro & wrap-up

    🎙️ Hosts
    Justin Leapline – @justinleapline
    Joe Wynn – @wynnjoe
    Rick Yocum – @rickyocum

    🌐 Connect with Us
    Website: distilledsecuritypodcast.com
    X: @DisSecPod
    Email: hello@distilledsecuritypodcast.com

    👍 Like, comment, and subscribe for weekly security and compliance insights.

    続きを読む 一部表示
    1 時間 51 分
  • Episode 15: Community Building, Art of Convincing, and GTD Strategies
    2025/08/06

    🎙️ Welcome back to the Distilled Security Podcast!

    In this episode, hosts Justin Leapline, Joe Wynn, and Rick Yocum sit down with James Ringold (Senior Security Cloud Solution Architect at Microsoft and President of ISSA Pittsburgh) to talk all about building stronger cybersecurity communities.

    From the behind-the-scenes of BSides Pittsburgh 2025 to engaging the next generation through mentorship and student-led talks, this episode offers practical insights on how to grow inclusive, vendor-neutral spaces that truly support people in security.

    Topics Covered

    • BSides Pittsburgh 2025 Highlights

    What made this year’s event stand out — from arcade machines and pastries to great speakers and a welcoming atmosphere.

    • Running an Inclusive Security Chapter

    Insights into leading ISSA Pittsburgh, maintaining momentum, and building a vendor-neutral space that feels open to everyone.

    • The Power of Consistency

    Why showing up regularly and following through matters when growing a security community.

    • Mentoring the Next Generation

    The importance of mentorship chains, student-led initiatives, and creating low-pressure environments for future leaders.

    • Engaging Students Beyond Attendance

    How to get students truly involved, from submitting talks to building long-term relationships that support career growth.

    • Authenticity and Community Building

    Why empathy, storytelling, and invitation—not pressure—are essential for creating lasting, supportive security ecosystems.

    Timestamps:

    00:00:00 – Intro & Guest Welcome
    00:02:20 – BSides Pittsburgh 2025 Preview
    00:24:10 – Building Inclusive Security Communities
    00:41:20 – Mentorship & Student Talks
    01:11:00 – Whiskey Tasting: Grand Traverse Distillery
    01:33:00 – Growing Through Empathy & Local Leadership
    01:48:30 – Final Reflections & Outro

    Links

    • ISSA Pittsburgh
    • BSides Pittsburgh

    Hosts

    • Justin Leapline
    • Joe Wynn
    • Rick Yocum

    Guest

    • James Ringold


    Connect with Us

    • Website: distilledsecuritypodcast.com
    • Twitter: @DisSecPod
    • Email: hello@distilledsecuritypodcast.com


    続きを読む 一部表示
    1 時間 54 分