エピソード

  • Episode 12: One Year of Distilled Security, Auditor Quality, and Starting Your Own Company
    2025/05/02

    Join us as we reflect on:

    • One Year of Podcasting: The crew celebrates a full year of episodes, favorite topics, behind-the-scenes production, and where the show is headed next—including a new studio setup and future sponsors.
    • Audit Quality and Risk: A deep dive into the evolution of cybersecurity audits, the growing influence of low-cost providers, and what actually makes an audit valuable and trustworthy.
    • Third-Party Risk Management: How companies can assess vendor SOC 2 reports, triage risk among their vendors, and build defensible compliance practices.
    • Operational vs. Commercial Risk: The importance of translating audit findings into business impact and strengthening vendor partnerships for long-term resilience.
    • Bourbon Review – Jefferson’s Tropics: A tasting of a tropical-aged bourbon matured in Singapore’s climate, featuring notes of toffee and spice.
    • BSides Pittsburgh Update: Details on ticket sales, sponsor opportunities, and how to get involved with the local security community’s flagship event.
    • Entrepreneurship & Starting a Business: A thoughtful discussion on what it really takes to start your own business—when to consider it, how to prepare, and why it’s often more work (and growth) than expected.


    Timestamps
    00:00 – Intro & 1-Year Milestone
    01:00 – Year in Review
    02:40 – Behind the Scenes
    04:45 – Favorite Moments
    06:10 – Studio Upgrades
    07:55 – Sponsors Chat
    08:45 – Confetti Recap
    10:00 – Auditor Quality
    20:00 – GRC Realities
    29:00 – SOC 2 Reports
    38:30 – Vendor Risk
    54:00 – Designing Resilience
    57:45 – Audit Takeaways
    1:02:00 – Bourbon Review
    1:06:10 – BSides Update
    1:09:00 – Starting a Business
    1:36:00 – Wrap-Up & Cheers

    Hosts

    • Justin Leapline - LinkedIn
    • Joe Wynn - LinkedIn
    • Rick Yocum - LinkedIn

    Connect with Us

    • Website: Distilled Security Podcast
    • Twitter: @DisSecPod
    • Email: hello@distilledsecuritypodcast.com

    続きを読む 一部表示
    1 時間 38 分
  • Episode 11: Encrypted Messaging, Data Breaches, and Vulnerability Management
    2025/04/14

    Episode 11 of the Distilled Security Podcast is here!


    Join us as we cover:

    • Signal, Encrypted Messaging, and Corporate Policy: A deep dive into the use of Signal in sensitive discussions—including a political mishap—and the implications for corporate communication policies, discovery, and compliance.
    • Oracle Cloud Breach Allegations: Evaluating breach claims, early response tactics, and the value of proactive key and credential rotation.
    • DNA Data, 23andMe, and Privacy Concerns: With 23andMe filing for bankruptcy, the team explores risks associated with sharing genetic data and broader privacy implications when personal information changes hands.
    • Hospital Data as Business Assets: A surprising look at how some companies are buying bankrupt hospitals—primarily for access to their medical datasets.
    • Vulnerability Management in the Real World: Tips on building practical, risk-based vulnerability management programs, understanding scanner severity versus real-world risk, and developing responsive processes that scale.

    Spirits:

    • Calumet Farm Small Batch Bourbon Whiskey https://www.calumetbourbon.com/smallbatch

    Hosts

    • Justin Leapline - LinkedIn
    • Joe Wynn - LinkedIn
    • Rick Yocum - LinkedIn

    Connect with Us

    • Website: Distilled Security Podcast
    • Twitter: @DisSecPod
    • Email: hello@distilledsecuritypodcast.com

    続きを読む 一部表示
    1 時間 30 分
  • Episode 10: Navigating Budget Cuts, Talent Shortages, and Cybersecurity Resilience
    2025/03/12

    Episode 10 of the Distilled Security Podcast is here!

    Join us as we explore:

    • Security in Times of Budget Cuts: How organizations can navigate layoffs and reduced funding while maintaining a strong security posture.
    • The Cybersecurity Talent Shortage: Why security hiring remains challenging, the need for apprenticeship models, and how organizations can develop internal talent pipelines.
    • BSides Pittsburgh: Put this on your calendar and submit talks.
    • Cyber Crisis Readiness: The importance of C-suite participation in tabletop exercises and cyber incident planning.

    References

    • Early Education by David Barton - https://www.youtube.com/watch?v=io-O59eakMk
    • BSides Pittsburgh CFP - https://www.bsidespgh.com/cfp

    Spirits: Lady of the Glen – A 10-year-old cask strength Scotch whisky finished in Oloroso sherry casks.

    Hosts

    • Justin Leapline - LinkedIn
    • Joe Wynn - LinkedIn
    • Rick Yocum - LinkedIn

    Connect with Us

    • Website: Distilled Security Podcast
    • Twitter: @DisSecPod
    • Email: hello@distilledsecuritypodcast.com

    続きを読む 一部表示
    1 時間 34 分
  • Episode 9: Security Budgets, AI Risks, and Data Sovereignty
    2025/02/06


    Episode 9 of the Distilled Security Podcast is here!

    Join us as we explore:

    • Security on a Budget: How teams can optimize tools, manage resource constraints, and build an effective security strategy with limited funding.
    • AI and Efficiency: The impact of AI on job performance, along with the risks of AI-powered note-taking and data classification.
    • Data Breaches & Industry Challenges: Lessons from Marriott’s data breaches, security concerns in the hospitality industry, and evolving consumer protection mandates.
    • Regulatory Shifts & Compliance: A discussion on HIPAA’s 2023 overhaul, required vs. addressable regulations, and the role of dual audits in compliance assurance.
    • Data Sovereignty & Government Oversight: How security teams navigate data sovereignty risks, government requests for information, and evolving security standards.
    • Multi-Factor Authentication & Risk Mitigation: The importance of MFA and its role in strengthening security posture is increasing.

    Spirits

    • Heigold Single Barrel Cask Strength https://www.rabbitholedistillery.com/pages/single-barrel-release

    Hosts

    • Justin Leapline - LinkedIn
    • Joe Wynn - LinkedIn
    • Rick Yocum - LinkedIn

    References

    2025 HIPAA Security Rule Guide and Compliance Checklist // https://www.seisollc.com/insights/2025-hipaa-rule-guide


    Connect with Us

    • Website: Distilled Security Podcast
    • Twitter: @DisSecPod
    • Email: hello@distilledsecuritypodcast.com

    続きを読む 一部表示
    1 時間 18 分
  • Episode 8: Whiskey, Quantum Computing, and Executive Protection
    2025/01/07


    🎙️ Episode 8 of the Distilled Security Podcast is here! 🔐🥃

    🔎 Join us as we explore:

    • The Whiskey Rebellion and Craft Distilling: A dive into the history of the Whiskey Rebellion and what it means for today’s distillers. Learn about Iron City Distilling, creating national brand-quality spirits, and the significance of the Bessemer brand name.
    • Whiskey Craftsmanship: Insights into chamber still distillation, the balance of maturation versus aging, and premium craft whiskey production.
    • Executive Protection and Privacy: Strategies for workplace safety, reducing online risks, and managing personal branding in crises.
    • Quantum Computing Risks: A look at Google's Willow chip, the implications of quantum computing on cybersecurity, and the need for post-quantum cryptographic protocols.
    • Modern Password Challenges: Discussing the future of passwordless login, phishing risks, dark web breaches, and the evolving standards of password compliance.

    🌟 Spirit: Iron City Distilling Distillers Reserve – A 6-Year Craft Masterpiece!

    🎙️ Hosts

    • Justin Leapline - LinkedIn
    • Joe Wynn - LinkedIn
    • Rick Yocum - LinkedIn

    🤝 Guest

    • Eddie Kubit - LinkedIn


    📲 Connect with Us

    • Website: Distilled Security Podcast
    • Twitter: @DisSecPod
    • Email: hello@distilledsecuritypodcast.com

    🕐 Time Stamps

    [00:00:00] Introduction
    [00:00:09] Eddie’s Career Transition
    [00:03:00] Whiskey Rebellion and Craft Distilling
    [00:06:00] Joining Iron City Distilling
    [00:10:00] Unique Approach at Iron City Distilling
    [00:19:00] Traditional Whiskey Making Process
    [00:28:30] Executive Protection and Privacy
    [00:39:00] Practical Security Measures for Executives
    [00:50:00] Google’s Quantum Computing and Cybersecurity Risks
    [00:57:00] Post-Quantum Cryptography
    [01:06:00] Modern Password Practices
    [01:20:00] Closing Thoughts

    続きを読む 一部表示
    1 時間 22 分
  • Episode 7: Certifications, Mentorship, and Auditor Missteps
    2024/12/10

    Welcome to Episode 7 of the Distilled Security Podcast!

    In this episode, hosts Justin, Rick, and Joe are joined by special guest Brandon Eckert to explore his fascinating journey in cybersecurity, share industry insights, and enjoy a fun debate on Thanksgiving favorites. Here’s what’s in store:

    Topics Covered:

    🔹 Navigating a Career in Cybersecurity
    Reflections on starting out in cybersecurity, overcoming challenges in small-town IT careers, and the role of certifications in shaping career success.

    🔹 The Value of Certifications
    How certifications like OSCP contribute to career growth, practical knowledge, and their relationship with networking and formal education.

    🔹 Mentorship and the Pittsburgh Cybersecurity Community
    The importance of fostering growth, mentoring local talent, and giving back to the Pittsburgh security community.

    🔹 Networking vs. Certifications
    A discussion on what matters more for career advancement and the unique benefits of each.

    🔹 Auditor Stories and Lessons Learned
    Hear hilarious and insightful tales from hospital audits, ethical dilemmas, and tips for managing challenging auditor experiences.

    🔹 Business Continuity Challenges
    How organizations can prepare for rare but impactful events, like solar flares, while building strong auditor relationships.

    🔹 Thanksgiving Favorites
    A lighthearted wrap-up featuring turkey tips, stuffing recipes, and the ultimate leftover turkey sandwich.

    🔸 Links
    Widow Jane Black Opal: https://widowjane.com/

    🔸 Spirits
    Widow Jane Black Opal
    A rare blend of bourbons, each aged for at least 20 years and finished in Japanese Mizunara oak. Notes of toffee, plum, and tobacco make this whiskey an extraordinary treat.

    🔸Hosts

    • Justin Leapline
    • Joe Wynn
    • Rick Yocum

    🔸 Guest
    🙋🏻‍♂️ Brandon Eckert

    🎙 Connect with Us
    Website: Distilled Security Podcast
    X: @DisSecPod
    Email: hello@distilledsecuritypodcast.com

    続きを読む 一部表示
    1 時間 19 分
  • Episode 6: SEC Penalties, M&A Security, and Due Diligence
    2024/11/08

    Episode 6: SEC Penalties, M&A Security, and Due Diligence


    Welcome back to the Distilled Security Podcast! In this episode, hosts Justin, Rick, and Joe dive into the latest in cybersecurity, from regulatory challenges to pop culture:

    Topics Covered

    1. SEC Penalties for Cybersecurity Disclosures
      Discussing recent SEC penalties due to lapses in cybersecurity disclosure, the implications for companies, and how organizations can stay compliant.
    2. Cybersecurity Materiality and Disclosure Practices
      Tips on navigating the materiality assessment of cybersecurity incidents and ensuring compliance with auditors' disclosure requirements.
    3. Preparedness Through Tabletop Exercises
      Exploring tabletop exercises as a method to enhance readiness for cybersecurity disclosures.
    4. Security in Mergers & Acquisitions
      The importance of aligning security philosophies, protecting supply chain integrity, and fast decision-making in M&A processes.
    5. Pre-Mortem Analyses for Risk Mitigation
      Utilizing pre-mortem analyses to identify risks in acquisitions and ensure security compatibility before a merger.
    6. Best Practices for Selling a Company with Strong Security
      Tips on audit readiness, maintaining a secure posture, and what security leaders should prioritize to avoid penalties or discounts during acquisitions.
    7. Information Control in Modern Warfare
      How controlling information plays a strategic role, with examples from cyberpunk themes to illustrate the power of data control.
    8. Favorite Cybersecurity Movies
      A fun review of iconic cybersecurity movies, highlighting elements like data movement, IP address inaccuracies, and common movie hacking tropes.
    9. Due Diligence Strategies for Small Businesses
      Key steps for conducting effective due diligence, including using a risk-based approach to compliance and managing contracts efficiently.

    Links

    • Cyber Scoop

    Spirits

    • Barrell Seagrass - A unique blend of American and Canadian rye whiskeys, each carefully selected and finished in Martinique Rhum, Madeira, and apricot brandy barrels.

    Hosts

    • Justin Leapline
    • Joe Wynn
    • Rick Yocum

    Connect with Us

    • Website: Distilled Security Podcast
    • Twitter: @DisSecPod
    • Email: hello@distilledsecuritypodcast.com

    Time Stamps

    • [00:01:25] SEC penalties for cybersecurity disclosure lapses
    • [00:05:16] Working with external auditors on cybersecurity disclosures
    • [00:09:30] Assessing cybersecurity materiality in disclosures
    • [00:11:45] Tabletop exercises to improve disclosure preparedness
    • [00:14:36] Cybersecurity considerations in M&A
    • [00:19:12] Making fast, informed security decisions
    • [00:23:06] Pre-mortems for assessing acquisition risks
    • [00:25:12] Compatibility of security philosophies in M&A
    • [00:30:20] Securing supply chains in acquisitions
    • [00:34:23] Steps to sell a company securely
    • [00:37:06] Preparing for audits in the sale process
    • [00:42:07] Hosts discuss favorite cybersecurity movies
    • [00:45:57] The strategic role of information in warfare
    • [00:48:49] Data transport themes in cyberpunk films
    • [00:52:36] The infamous fake IP addresses in movies
    • [00:56:01] Due diligence for small businesses and startups
    • [01:00:47] Centralized vs. decentralized security strategies
    • [01:02:20] Adopting a risk-based approach for security questionnaires
    • [01:06:05] Negotiating buyer risk assessments
    • [01:10:11] Leveraging compliance automation tools
    • [01:12:55] Managing contract risks effectively
    • [01:16:10] Ensuring alignment between contract terms and security questionnaires
    続きを読む 一部表示
    1 時間 17 分
  • Episode 5: Resume Reviews, Counter-Espionage, and Incident Response
    2024/10/02

    Join hosts Justin, Rick, and Joe as they cover:

    • Resume Review Insights: Joe offers valuable tips on resume writing, focusing on showcasing accomplishments and using metrics to stand out.
    • Passion Projects and Hobbies: The team discusses how personal projects and volunteer work can make resumes more compelling by demonstrating a passion for the field.
    • Community Engagement at TRISS: The hosts invite listeners to their booth at the upcoming Three Rivers Information Security Symposium (TRISS), where they will be offering resume reviews and engaging with attendees.
    • Counter-Espionage and Pagers: A fascinating look at the use of pagers in recent counter-espionage operations, analyzing their effectiveness and ethical concerns.
    • Supply Chain Security Concerns: A discussion on the risks tied to supply chain vulnerabilities, focusing on hardware inspections.
    • Tabletop Exercises in Cybersecurity: The hosts highlight the importance of tabletop exercises to prepare organizations for security incidents, contrasting them with current trends in incident response training.
    • School Violence Threats: An examination of the rise in school violence threats and the challenges schools face in managing these situations.

    Links

    • Three Rivers Information Security Symposium (TRISS)
    • US Maritime Trade and Port Cybersecurity

    Spirits

    • Boone 1833 12-Year-Old, Snyder's Flask (discontinued) - https://boonedistilling.com/

    Hosts

    • Justin Leapline - LinkedIn
    • Joe Wynn - LinkedIn
    • Rick Yocum - LinkedIn

    Connect with Us

    • Website: Distilled Security Podcast
    • Twitter: @DisSecPod
    • Email: hello@distilledsecuritypodcast.com


    続きを読む 一部表示
    1 時間 4 分