<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:psc="http://podlove.org/simple-chapters" xmlns:podcast="https://podcastindex.org/namespace/1.0"><channel><title><![CDATA[Distilled Security Podcast]]></title><description><![CDATA[<p>Join us on Distilled Security as we delve into the fascinating world of cybersecurity. Each episode, we break down intriguing topics, analyze the latest news, and engage in in-depth conversations with our hosts and invited guests. Whether you're a seasoned professional or just curious about cybersecurity, our podcast offers valuable insights and thought-provoking discussions to keep you informed and entertained. Tune in and stay ahead of the curve in the ever-evolving landscape of cybersecurity.</p>]]></description><link>https://distilledsecuritypodcast.com</link><generator>Riverside.fm (https://riverside.com)</generator><lastBuildDate>Mon, 13 Jul 2026 03:44:10 GMT</lastBuildDate><atom:link href="https://api.riverside.com/hosting/ckvmajW9.rss" rel="self" type="application/rss+xml"/><author><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></author><pubDate>Sun, 31 May 2026 23:26:31 GMT</pubDate><copyright><![CDATA[2026 Justin Leapline, Joe Wynn, and Rick Yocum]]></copyright><language><![CDATA[en]]></language><ttl>60</ttl><category><![CDATA[Business]]></category><category><![CDATA[Technology]]></category><itunes:author>Justin Leapline, Joe Wynn, and Rick Yocum</itunes:author><itunes:summary>&lt;p&gt;Join us on Distilled Security as we delve into the fascinating world of cybersecurity. Each episode, we break down intriguing topics, analyze the latest news, and engage in in-depth conversations with our hosts and invited guests. Whether you&apos;re a seasoned professional or just curious about cybersecurity, our podcast offers valuable insights and thought-provoking discussions to keep you informed and entertained. Tune in and stay ahead of the curve in the ever-evolving landscape of cybersecurity.&lt;/p&gt;</itunes:summary><itunes:type>episodic</itunes:type><itunes:owner><itunes:name>Justin Leapline, Joe Wynn, and Rick Yocum</itunes:name><itunes:email>justin@episki.com</itunes:email></itunes:owner><itunes:explicit>no</itunes:explicit><itunes:category text="Business"/><itunes:category text="Technology"/><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><item><title><![CDATA[Episode 26: How to Run a Conference, Why Most Pen Tests Fail, and HIPAA's Ransomware Reckoning]]></title><description><![CDATA[<p>In this episode, we're joined by Jon Buhagiar, Director of Information Technology at RareMed Solutions; a published Sybex/Wiley author of Cisco and Microsoft certification guides; and a longtime amateur radio enthusiast. We get into what it actually takes to run a security conference from the ground up, why so many penetration tests end up wasting everyone's money, and how compliance and cyber insurance keep reshaping the way organizations work. Plus, as always, a bourbon. </p><p></p><p>🎤 Jon's world — rare-disease specialty pharmacy, patient assistance programs, book writing, and ham radio<br />🏗️ Running BSides Pittsburgh: revenue, expenses, marketing, volunteers, speakers, and sponsors<br />🎟️ The real economics of ticket pricing, free tickets, and the venue/affordability squeeze<br />🧑‍🤝‍🧑 Dividing responsibilities and appointing workstream leads as an event grows<br />🎯 Scoping as the make-or-break of a good pen test — and the human element that tooling misses<br />🔗 Chaining vulnerabilities and what separates a checkbox test from a real one<br />💸 Why pen testing so often becomes an ineffective use of resources<br />📋 Compliance and contractual drivers vs. genuine risk reduction<br />🛡️ A risk-based, scenario-driven approach focused on resilience and continuous improvement<br />🤝 Engaging pen testers as partners and maturing the process over time<br />🔄 Security as a constant state of change — compliance, cyber insurance, and government scoring<br />🏥 HIPAA compliance, risk analysis, and the ransomware reckoning facing healthcare<br />🥃 Bourbon tasting and discussion</p><p></p><p>⏱️ Timestamps<br />00:00 Intro<br />01:26 Guest introduction &amp; background<br />02:18 RareMed Solutions &amp; patient assistance programs<br />05:01 Book writing &amp; amateur radio<br />08:11 BSides Pittsburgh overview<br />15:04 Running a conference: planning &amp; organization<br />22:05 Marketing &amp; audience engagement<br />25:07 Dividing responsibilities as you grow<br />27:59 The value of ticket pricing<br />31:50 BSides &amp; the conference model<br />46:11 Penetration testing &amp; scoping<br />57:28 The purpose of pen testing<br />58:23 When pen testing goes wrong<br />01:00:16 Reasons for pen testing &amp; compliance drivers<br />01:03:04 Continuous monitoring, testing &amp; detection<br />01:06:19 Is your company ready for a pen test?<br />01:07:07 A risk-based approach<br />01:13:58 Scenario-based testing &amp; resilience<br />01:17:31 Evaluating the value of pen testing<br />01:29:01 The constant state of change<br />01:31:01 Compliance &amp; cyber insurance<br />01:32:19 Bourbon tasting<br />01:36:32 Government scoring &amp; risk analysis<br />01:50:36 HIPAA compliance &amp; ransomware<br />01:55:01 Wrap-up &amp; call to action</p><p></p><p>🎧 Distilled Security Podcast</p><p>Cybersecurity, GRC, and leadership, one pour at a time.</p><p></p><p>🎙️ Hosts</p><ul><li><b>Justin Leapline</b> – @justinleapline</li><li><b>Joe Wynn</b> – @wynnjoe</li><li><b>Rick Yocum</b> – @rickyocum<p></p></li></ul><p>🎤 Guest</p><ul><li><b>Jon Buhagiar </b><a rel="noopener noreferrer nofollow" href="http://linkedin.com/in/jonbuhagiar" target="_blank">linkedin.com/in/jonbuhagiar</a></li></ul><p></p><p>📬 Send Us Your Questions!</p><p><a rel="noopener noreferrer nofollow" href="mailto:ask@distilledsecuritypodcast.com" target="_blank">ask@distilledsecuritypodcast.com</a></p><p></p><p>🌐 Connect with Us</p><p></p><p><b>Website:</b> <a rel="noopener noreferrer nofollow" href="http://distilledsecuritypodcast.com" target="_blank">distilledsecuritypodcast.com</a></p><p><b>X:</b> @DisSecPod</p><p><b>YouTube:</b> @distilledsecurity</p><p><b>Email:</b> <a rel="noopener noreferrer nofollow" href="mailto:hello@distilledsecuritypodcast.com" target="_blank">hello@distilledsecuritypodcast.com</a></p><p></p><p>👍 Like, comment, and subscribe for monthly</p><p>security and compliance insights.</p>]]></description><guid isPermaLink="false">4f25b9d3-951d-454e-9a47-9cc4369c999c</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Wed, 08 Jul 2026 15:07:06 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/dc9d433666776035f5e3a9a7f4d3cad006a9dabbab0c8e037bd5523cd7fd1fd3/eyJlcGlzb2RlSWQiOiI0ZjI1YjlkMy05NTFkLTQ1NGUtOWE0Ny05Y2M0MzY5Yzk5OWMiLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE0ZTYyZWIwNzFiOWI5ODhkODY0M2EwL2Rpc3RpbGxlZC1zZWN1cml0eS1wb2RjYXN0LWNvbXBvc2VyLTIwMjYtNy04X18xNi00Ny03Lm1wMyJ9.mp3" length="222732268" type="audio/mpeg"/><itunes:summary>&lt;p&gt;In this episode, we&apos;re joined by Jon Buhagiar, Director of Information Technology at RareMed Solutions; a published Sybex/Wiley author of Cisco and Microsoft certification guides; and a longtime amateur radio enthusiast. We get into what it actually takes to run a security conference from the ground up, why so many penetration tests end up wasting everyone&apos;s money, and how compliance and cyber insurance keep reshaping the way organizations work. Plus, as always, a bourbon. &lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;🎤 Jon&apos;s world — rare-disease specialty pharmacy, patient assistance programs, book writing, and ham radio&lt;br /&gt;🏗️ Running BSides Pittsburgh: revenue, expenses, marketing, volunteers, speakers, and sponsors&lt;br /&gt;🎟️ The real economics of ticket pricing, free tickets, and the venue/affordability squeeze&lt;br /&gt;🧑‍🤝‍🧑 Dividing responsibilities and appointing workstream leads as an event grows&lt;br /&gt;🎯 Scoping as the make-or-break of a good pen test — and the human element that tooling misses&lt;br /&gt;🔗 Chaining vulnerabilities and what separates a checkbox test from a real one&lt;br /&gt;💸 Why pen testing so often becomes an ineffective use of resources&lt;br /&gt;📋 Compliance and contractual drivers vs. genuine risk reduction&lt;br /&gt;🛡️ A risk-based, scenario-driven approach focused on resilience and continuous improvement&lt;br /&gt;🤝 Engaging pen testers as partners and maturing the process over time&lt;br /&gt;🔄 Security as a constant state of change — compliance, cyber insurance, and government scoring&lt;br /&gt;🏥 HIPAA compliance, risk analysis, and the ransomware reckoning facing healthcare&lt;br /&gt;🥃 Bourbon tasting and discussion&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;⏱️ Timestamps&lt;br /&gt;00:00 Intro&lt;br /&gt;01:26 Guest introduction &amp;amp; background&lt;br /&gt;02:18 RareMed Solutions &amp;amp; patient assistance programs&lt;br /&gt;05:01 Book writing &amp;amp; amateur radio&lt;br /&gt;08:11 BSides Pittsburgh overview&lt;br /&gt;15:04 Running a conference: planning &amp;amp; organization&lt;br /&gt;22:05 Marketing &amp;amp; audience engagement&lt;br /&gt;25:07 Dividing responsibilities as you grow&lt;br /&gt;27:59 The value of ticket pricing&lt;br /&gt;31:50 BSides &amp;amp; the conference model&lt;br /&gt;46:11 Penetration testing &amp;amp; scoping&lt;br /&gt;57:28 The purpose of pen testing&lt;br /&gt;58:23 When pen testing goes wrong&lt;br /&gt;01:00:16 Reasons for pen testing &amp;amp; compliance drivers&lt;br /&gt;01:03:04 Continuous monitoring, testing &amp;amp; detection&lt;br /&gt;01:06:19 Is your company ready for a pen test?&lt;br /&gt;01:07:07 A risk-based approach&lt;br /&gt;01:13:58 Scenario-based testing &amp;amp; resilience&lt;br /&gt;01:17:31 Evaluating the value of pen testing&lt;br /&gt;01:29:01 The constant state of change&lt;br /&gt;01:31:01 Compliance &amp;amp; cyber insurance&lt;br /&gt;01:32:19 Bourbon tasting&lt;br /&gt;01:36:32 Government scoring &amp;amp; risk analysis&lt;br /&gt;01:50:36 HIPAA compliance &amp;amp; ransomware&lt;br /&gt;01:55:01 Wrap-up &amp;amp; call to action&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;🎧 Distilled Security Podcast&lt;/p&gt;&lt;p&gt;Cybersecurity, GRC, and leadership, one pour at a time.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;🎙️ Hosts&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Justin Leapline&lt;/b&gt; – @justinleapline&lt;/li&gt;&lt;li&gt;&lt;b&gt;Joe Wynn&lt;/b&gt; – @wynnjoe&lt;/li&gt;&lt;li&gt;&lt;b&gt;Rick Yocum&lt;/b&gt; – @rickyocum&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;🎤 Guest&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Jon Buhagiar &lt;/b&gt;&lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;http://linkedin.com/in/jonbuhagiar&quot; target=&quot;_blank&quot;&gt;linkedin.com/in/jonbuhagiar&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;📬 Send Us Your Questions!&lt;/p&gt;&lt;p&gt;&lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;mailto:ask@distilledsecuritypodcast.com&quot; target=&quot;_blank&quot;&gt;ask@distilledsecuritypodcast.com&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;🌐 Connect with Us&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Website:&lt;/b&gt; &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;http://distilledsecuritypodcast.com&quot; target=&quot;_blank&quot;&gt;distilledsecuritypodcast.com&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;X:&lt;/b&gt; @DisSecPod&lt;/p&gt;&lt;p&gt;&lt;b&gt;YouTube:&lt;/b&gt; @distilledsecurity&lt;/p&gt;&lt;p&gt;&lt;b&gt;Email:&lt;/b&gt; &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;mailto:hello@distilledsecuritypodcast.com&quot; target=&quot;_blank&quot;&gt;hello@distilledsecuritypodcast.com&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;👍 Like, comment, and subscribe for monthly&lt;/p&gt;&lt;p&gt;security and compliance insights.&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>01:56:00</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>26</itunes:episode><itunes:title>Episode 26: How to Run a Conference, Why Most Pen Tests Fail, and HIPAA&apos;s Ransomware Reckoning</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Episode 24: 2 Years, 24 Episodes & The State of Security in the Age of AI]]></title><description><![CDATA[<p>In this episode, we celebrate our 2nd anniversary and Episode 24 of Distilled Security! We cover the Vercel breach, how a Roblox script led to compromised Google Workspace credentials via an unauthorized OAuth connection. Then we dive into HackerOne, pausing their own bug bounty program, overwhelmed by low-quality, AI-generated submissions. And we close out with the State of Vibe-Coded Security—4,783 AI-assisted apps scanned, 727 critical issues found, and the real question: are you vibe coding or vibe deploying? Plus, a quick look at Claude for Security dropping into public beta and what that means for the industry. </p><p>All of that, and we crack open a Peerless Double Oak to toast two years of Distilled Security. 🥃</p><p><strong>⏱️ TIMESTAMPS:</strong></p><p>00:00 – Intro &amp; 2-Year Anniversary 🎉<br />01:26 – Behind the Scenes &amp; Favorite Moments<br />08:26 – Podcast Metrics &amp; Global Reach<br />24:20 – BSides Pittsburgh 2025 Update 🛡️<br />34:31 – The Vercel Breach &amp; OAuth Risk<br />58:57 – HackerOne Pauses Bug Bounty<br />1:16:05 – Spirit: Peerless Double Oak 🥃<br />1:20:27 – Vibe Coding vs. Vibe Deploying<br />1:26:46 – Claude for Security &amp; AI News<br />1:41:27 – Cheers to Two Years! 🥃</p><p><strong>🎙️ Hosts</strong><br />Justin Leapline – @justinleapline<br />Joe Wynn – @wynnjoe<br />Rick Yocum – @rickyocum</p><p><strong>📬 Send Us Your Questions!</strong><br />ask@distilledsecuritypodcast.com</p><p><strong>🌐 Connect with Us</strong><br />Website: distilledsecuritypodcast.com<br />X: @DisSecPod<br />Email: hello@distilledsecuritypodcast.com</p><p>👍 Like, comment, and subscribe for monthly security and compliance insights</p>]]></description><link>https://share.transistor.fm/s/c00db1db</link><guid isPermaLink="false">6868a08c-c21d-4bd4-907d-65ee61ca7f67</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Thu, 14 May 2026 13:27:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/f714a97d4ff9fce306ecd2dbc27605e48b0f408fd1824f3c91ead4fab9cbbbab/eyJlcGlzb2RlSWQiOiI1MDIyY2ViOC0wY2JiLTRhOTYtYjcxZC02YmZhMWM1ZDlhODciLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy8yNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgvZXBpc29kZXMvNTAyMmNlYjgtMGNiYi00YTk2LWI3MWQtNmJmYTFjNWQ5YTg3Lzk2OWE1ZjgwLm1wMyJ9.mp3" length="101864322" type="audio/mpeg"/><itunes:summary>&lt;p&gt;In this episode, we celebrate our 2nd anniversary and Episode 24 of Distilled Security! We cover the Vercel breach, how a Roblox script led to compromised Google Workspace credentials via an unauthorized OAuth connection. Then we dive into HackerOne, pausing their own bug bounty program, overwhelmed by low-quality, AI-generated submissions. And we close out with the State of Vibe-Coded Security—4,783 AI-assisted apps scanned, 727 critical issues found, and the real question: are you vibe coding or vibe deploying? Plus, a quick look at Claude for Security dropping into public beta and what that means for the industry. &lt;/p&gt;&lt;p&gt;All of that, and we crack open a Peerless Double Oak to toast two years of Distilled Security. 🥃&lt;/p&gt;&lt;p&gt;&lt;strong&gt;⏱️ TIMESTAMPS:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;00:00 – Intro &amp;amp; 2-Year Anniversary 🎉&lt;br /&gt;01:26 – Behind the Scenes &amp;amp; Favorite Moments&lt;br /&gt;08:26 – Podcast Metrics &amp;amp; Global Reach&lt;br /&gt;24:20 – BSides Pittsburgh 2025 Update 🛡️&lt;br /&gt;34:31 – The Vercel Breach &amp;amp; OAuth Risk&lt;br /&gt;58:57 – HackerOne Pauses Bug Bounty&lt;br /&gt;1:16:05 – Spirit: Peerless Double Oak 🥃&lt;br /&gt;1:20:27 – Vibe Coding vs. Vibe Deploying&lt;br /&gt;1:26:46 – Claude for Security &amp;amp; AI News&lt;br /&gt;1:41:27 – Cheers to Two Years! 🥃&lt;/p&gt;&lt;p&gt;&lt;strong&gt;🎙️ Hosts&lt;/strong&gt;&lt;br /&gt;Justin Leapline – @justinleapline&lt;br /&gt;Joe Wynn – @wynnjoe&lt;br /&gt;Rick Yocum – @rickyocum&lt;/p&gt;&lt;p&gt;&lt;strong&gt;📬 Send Us Your Questions!&lt;/strong&gt;&lt;br /&gt;ask@distilledsecuritypodcast.com&lt;/p&gt;&lt;p&gt;&lt;strong&gt;🌐 Connect with Us&lt;/strong&gt;&lt;br /&gt;Website: distilledsecuritypodcast.com&lt;br /&gt;X: @DisSecPod&lt;br /&gt;Email: hello@distilledsecuritypodcast.com&lt;/p&gt;&lt;p&gt;👍 Like, comment, and subscribe for monthly security and compliance insights&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>01:42:31</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>24</itunes:episode><itunes:title>Episode 24: 2 Years, 24 Episodes &amp; The State of Security in the Age of AI</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Episode 6: SEC Penalties, M&A Security, and Due Diligence]]></title><description><![CDATA[<p><strong>Episode 6: SEC Penalties, M&amp;A Security, and Due Diligence</strong></p><p><br />Welcome back to the <em>Distilled Security Podcast</em>! In this episode, hosts Justin, Rick, and Joe dive into the latest in cybersecurity, from regulatory challenges to pop culture:</p><p>Topics Covered</p><ol><li><strong>SEC Penalties for Cybersecurity Disclosures</strong><br />Discussing recent SEC penalties due to lapses in cybersecurity disclosure, the implications for companies, and how organizations can stay compliant.</li><li><strong>Cybersecurity Materiality and Disclosure Practices</strong><br />Tips on navigating the materiality assessment of cybersecurity incidents and ensuring compliance with auditors' disclosure requirements.</li><li><strong>Preparedness Through Tabletop Exercises</strong><br />Exploring tabletop exercises as a method to enhance readiness for cybersecurity disclosures.</li><li><strong>Security in Mergers &amp; Acquisitions</strong><br />The importance of aligning security philosophies, protecting supply chain integrity, and fast decision-making in M&amp;A processes.</li><li><strong>Pre-Mortem Analyses for Risk Mitigation</strong><br />Utilizing pre-mortem analyses to identify risks in acquisitions and ensure security compatibility before a merger.</li><li><strong>Best Practices for Selling a Company with Strong Security</strong><br />Tips on audit readiness, maintaining a secure posture, and what security leaders should prioritize to avoid penalties or discounts during acquisitions.</li><li><strong>Information Control in Modern Warfare</strong><br />How controlling information plays a strategic role, with examples from cyberpunk themes to illustrate the power of data control.</li><li><strong>Favorite Cybersecurity Movies</strong><br />A fun review of iconic cybersecurity movies, highlighting elements like data movement, IP address inaccuracies, and common movie hacking tropes.</li><li><strong>Due Diligence Strategies for Small Businesses</strong><br />Key steps for conducting effective due diligence, including using a risk-based approach to compliance and managing contracts efficiently.</li></ol><p><strong>Links</strong></p><ul><li><a href="https://cyberscoop.com/" rel="noopener noreferrer nofollow"><strong>Cyber Scoop</strong></a></li></ul><p><strong>Spirits</strong></p><ul><li><strong>Barrell Seagrass</strong> - A unique blend of American and Canadian rye whiskeys, each carefully selected and finished in Martinique Rhum, Madeira, and apricot brandy barrels.</li></ul><p><strong>Hosts</strong></p><ul><li><a href="https://www.linkedin.com/in/justinleapline/" rel="noopener noreferrer nofollow">Justin Leapline</a></li><li><a href="https://www.linkedin.com/in/wynnjoe/" rel="noopener noreferrer nofollow">Joe Wynn </a></li><li><a href="https://www.linkedin.com/in/rickyocum/" rel="noopener noreferrer nofollow">Rick Yocum </a></li></ul><p><strong>Connect with Us</strong></p><ul><li><strong>Website:</strong> Distilled Security Podcast</li><li><strong>Twitter:</strong><a href="https://x.com/DisSecPod" rel="noopener noreferrer nofollow"> @DisSecPod</a></li><li><strong>Email:</strong> hello@distilledsecuritypodcast.com</li></ul><p><strong>Time Stamps</strong></p><ul><li>[00:01:25] SEC penalties for cybersecurity disclosure lapses</li><li>[00:05:16] Working with external auditors on cybersecurity disclosures</li><li>[00:09:30] Assessing cybersecurity materiality in disclosures</li><li>[00:11:45] Tabletop exercises to improve disclosure preparedness</li><li>[00:14:36] Cybersecurity considerations in M&amp;A</li><li>[00:19:12] Making fast, informed security decisions</li><li>[00:23:06] Pre-mortems for assessing acquisition risks</li><li>[00:25:12] Compatibility of security philosophies in M&amp;A</li><li>[00:30:20] Securing supply chains in acquisitions</li><li>[00:34:23] Steps to sell a company securely</li><li>[00:37:06] Preparing for audits in the sale process</li><li>[00:42:07] Hosts discuss favorite cybersecurity movies</li><li>[00:45:57] The strategic role of information in warfare</li><li>[00:48:49] Data transport themes in cyberpunk films</li><li>[00:52:36] The infamous fake IP addresses in movies</li><li>[00:56:01] Due diligence for small businesses and startups</li><li>[01:00:47] Centralized vs. decentralized security strategies</li><li>[01:02:20] Adopting a risk-based approach for security questionnaires</li><li>[01:06:05] Negotiating buyer risk assessments</li><li>[01:10:11] Leveraging compliance automation tools</li><li>[01:12:55] Managing contract risks effectively</li><li>[01:16:10] Ensuring alignment between contract terms and security questionnaires</li></ul>]]></description><link>https://share.transistor.fm/s/9a773fb0</link><guid isPermaLink="false">5489d224-da2c-4865-8273-542435baf3b0</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Fri, 08 Nov 2024 14:56:32 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/bb16119607b1484bb4246e2788bc4c03777ecdcd1e8fe9def1a4a9286ae91541/eyJlcGlzb2RlSWQiOiJmMWNkNjg1Yi1jNjU3LTQzOWEtOWUyMy1iOTBkNzY2ZDkxZTciLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy8yNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgvZXBpc29kZXMvZjFjZDY4NWItYzY1Ny00MzlhLTllMjMtYjkwZDc2NmQ5MWU3L2RjZDk3OWM1Lm1wMyJ9.mp3" length="74276965" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;strong&gt;Episode 6: SEC Penalties, M&amp;amp;A Security, and Due Diligence&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;Welcome back to the &lt;em&gt;Distilled Security Podcast&lt;/em&gt;! In this episode, hosts Justin, Rick, and Joe dive into the latest in cybersecurity, from regulatory challenges to pop culture:&lt;/p&gt;&lt;p&gt;Topics Covered&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;strong&gt;SEC Penalties for Cybersecurity Disclosures&lt;/strong&gt;&lt;br /&gt;Discussing recent SEC penalties due to lapses in cybersecurity disclosure, the implications for companies, and how organizations can stay compliant.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Cybersecurity Materiality and Disclosure Practices&lt;/strong&gt;&lt;br /&gt;Tips on navigating the materiality assessment of cybersecurity incidents and ensuring compliance with auditors&apos; disclosure requirements.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Preparedness Through Tabletop Exercises&lt;/strong&gt;&lt;br /&gt;Exploring tabletop exercises as a method to enhance readiness for cybersecurity disclosures.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Security in Mergers &amp;amp; Acquisitions&lt;/strong&gt;&lt;br /&gt;The importance of aligning security philosophies, protecting supply chain integrity, and fast decision-making in M&amp;amp;A processes.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Pre-Mortem Analyses for Risk Mitigation&lt;/strong&gt;&lt;br /&gt;Utilizing pre-mortem analyses to identify risks in acquisitions and ensure security compatibility before a merger.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Best Practices for Selling a Company with Strong Security&lt;/strong&gt;&lt;br /&gt;Tips on audit readiness, maintaining a secure posture, and what security leaders should prioritize to avoid penalties or discounts during acquisitions.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Information Control in Modern Warfare&lt;/strong&gt;&lt;br /&gt;How controlling information plays a strategic role, with examples from cyberpunk themes to illustrate the power of data control.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Favorite Cybersecurity Movies&lt;/strong&gt;&lt;br /&gt;A fun review of iconic cybersecurity movies, highlighting elements like data movement, IP address inaccuracies, and common movie hacking tropes.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Due Diligence Strategies for Small Businesses&lt;/strong&gt;&lt;br /&gt;Key steps for conducting effective due diligence, including using a risk-based approach to compliance and managing contracts efficiently.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;strong&gt;Links&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;https://cyberscoop.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;&lt;strong&gt;Cyber Scoop&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Spirits&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Barrell Seagrass&lt;/strong&gt; - A unique blend of American and Canadian rye whiskeys, each carefully selected and finished in Martinique Rhum, Madeira, and apricot brandy barrels.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Hosts&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;https://www.linkedin.com/in/justinleapline/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Justin Leapline&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.linkedin.com/in/wynnjoe/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Joe Wynn &lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.linkedin.com/in/rickyocum/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Rick Yocum &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Connect with Us&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Website:&lt;/strong&gt; Distilled Security Podcast&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Twitter:&lt;/strong&gt;&lt;a href=&quot;https://x.com/DisSecPod&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; @DisSecPod&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Email:&lt;/strong&gt; hello@distilledsecuritypodcast.com&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Time Stamps&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;[00:01:25] SEC penalties for cybersecurity disclosure lapses&lt;/li&gt;&lt;li&gt;[00:05:16] Working with external auditors on cybersecurity disclosures&lt;/li&gt;&lt;li&gt;[00:09:30] Assessing cybersecurity materiality in disclosures&lt;/li&gt;&lt;li&gt;[00:11:45] Tabletop exercises to improve disclosure preparedness&lt;/li&gt;&lt;li&gt;[00:14:36] Cybersecurity considerations in M&amp;amp;A&lt;/li&gt;&lt;li&gt;[00:19:12] Making fast, informed security decisions&lt;/li&gt;&lt;li&gt;[00:23:06] Pre-mortems for assessing acquisition risks&lt;/li&gt;&lt;li&gt;[00:25:12] Compatibility of security philosophies in M&amp;amp;A&lt;/li&gt;&lt;li&gt;[00:30:20] Securing supply chains in acquisitions&lt;/li&gt;&lt;li&gt;[00:34:23] Steps to sell a company securely&lt;/li&gt;&lt;li&gt;[00:37:06] Preparing for audits in the sale process&lt;/li&gt;&lt;li&gt;[00:42:07] Hosts discuss favorite cybersecurity movies&lt;/li&gt;&lt;li&gt;[00:45:57] The strategic role of information in warfare&lt;/li&gt;&lt;li&gt;[00:48:49] Data transport themes in cyberpunk films&lt;/li&gt;&lt;li&gt;[00:52:36] The infamous fake IP addresses in movies&lt;/li&gt;&lt;li&gt;[00:56:01] Due diligence for small businesses and startups&lt;/li&gt;&lt;li&gt;[01:00:47] Centralized vs. decentralized security strategies&lt;/li&gt;&lt;li&gt;[01:02:20] Adopting a risk-based approach for security questionnaires&lt;/li&gt;&lt;li&gt;[01:06:05] Negotiating buyer risk assessments&lt;/li&gt;&lt;li&gt;[01:10:11] Leveraging compliance automation tools&lt;/li&gt;&lt;li&gt;[01:12:55] Managing contract risks effectively&lt;/li&gt;&lt;li&gt;[01:16:10] Ensuring alignment between contract terms and security questionnaires&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>01:17:21</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>6</itunes:episode><itunes:title>Episode 6: SEC Penalties, M&amp;A Security, and Due Diligence</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Episode 3: Crowdstrike, North Korean Spies, and CISO Scapegoats]]></title><description><![CDATA[<p><strong>Episode 3 of the Distilled Security Podcast is here!</strong></p><p><br />Join us this week as we jump into: </p><p><br /></p><ul><li><strong>CrowdStrike Incident Analysis:</strong> A deep dive into a recent mishap by CrowdStrike that led to significant financial losses and operational disruptions, including 5.4 billion in estimated losses.</li><li><strong>Vendor Accountability:</strong> Exploring the legal and financial repercussions of security vendor failures.</li><li><strong>Business Continuity Planning:</strong> The importance of preparing for security vendor failures, including considering alternate vendors and the complexities of implementing such strategies.</li><li><strong>Kernel-Level Security Risks:</strong> A discussion surrounding kernel-level operations in security software, focusing on the controversy between CrowdStrike and SentinelOne.</li><li><strong>Manual Workarounds and Legacy Systems:</strong> The challenges of maintaining business operations during security incidents.</li><li><strong>Ransomware Recovery vs. Vendor Failures:</strong> Comparing ransomware attacks' impact and recovery processes with security vendor-induced failures.</li><li><strong>Password Management Vulnerabilities:</strong> The risks associated with dependency on password management systems like Thycotic/Delinea and LastPass, and the potential fallout if these systems experience downtime.</li><li><strong>BSides Pittsburgh Recap:</strong> the biggest BSidesPGH event yet. Hear the notes and highlights from the conference.</li><li><strong>North Korean Spy Hired By KnowBe4:</strong> Hear how a spy for N. Korea got by the defenses of KnowBe4, how they caught them, and steps they implemented to avoid this in the future.</li><li><strong>CISOs as Scapegoats:</strong> Are CISOs being pegged as scapegoats unfairly?</li></ul><p><br /><strong>Links</strong></p><ul><li>Crowdstrike Incident - <a href="https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/" rel="noopener noreferrer nofollow">https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/</a></li><li>SentinelOne Response to Crowdstrike - SentinalOne on Crowdstrike Outage -<a href="https://www.crn.com/news/security/2024/sentinelone-ceo-on-crowdstrike-outage-not-just-an-honest-mistake" rel="noopener noreferrer nofollow"> https://www.crn.com/news/security/2024/sentinelone-ceo-on-crowdstrike-outage-not-just-an-honest-mistake</a></li><li>BSidesPGH - <a href="https://www.bsidespgh.com/" rel="noopener noreferrer nofollow">https://www.bsidespgh.com/</a></li><li>TRISS - <a href="https://www.threeriversinfosec.com/" rel="noopener noreferrer nofollow">https://www.threeriversinfosec.com/</a></li><li>KnowBe4 // N. Korean Spy - <a href="https://blog.knowbe4.com/cyberheistnews-vol-14-31-how-the-whole-world-now-knows-about-fake-north-korean-it-workers" rel="noopener noreferrer nofollow">https://blog.knowbe4.com/cyberheistnews-vol-14-31-how-the-whole-world-now-knows-about-fake-north-korean-it-workers</a></li><li>CISO as Scapegoats - <a href="https://www.thestack.technology/were-becoming-scapegoats-how-have-cisos-responded-to-sec-cyber-risk-disclosure-rules/" rel="noopener noreferrer nofollow">https://www.thestack.technology/were-becoming-scapegoats-how-have-cisos-responded-to-sec-cyber-risk-disclosure-rules/</a></li></ul><p><br /><strong>Spirits</strong></p><ul><li>Rabbit Hole Cavehill // Four Grain Tripple Malt - <a href="https://www.rabbitholedistillery.com/pages/cavehill/" rel="noopener noreferrer nofollow">https://www.rabbitholedistillery.com/pages/cavehill/</a></li></ul><p><br /></p><p><strong>Hosts</strong></p><ul><li>Justin Leapline - https://www.linkedin.com/in/justinleapline/</li><li>Joe Wynn - https://www.linkedin.com/in/wynnjoe/</li><li>Rick Yocum - https://www.linkedin.com/in/rickyocum/</li></ul><p><br /></p><p><strong>Connect with Us</strong></p><ul><li>Website: https://distilledsecuritypodcast.com</li><li>Twitter: @DisSecPod</li><li>Email: hello@distilledsecuritypodcast.com</li></ul>]]></description><link>https://share.transistor.fm/s/5adb7b9c</link><guid isPermaLink="false">354387de-5749-4afc-95a6-4b0aedb71809</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Mon, 12 Aug 2024 18:32:56 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/a1a7d124f072d5ec1be8ab8fb31175a96606f5ad912d056644bcd7022b12bf64/eyJlcGlzb2RlSWQiOiI5OWUwMjlkZi1iOTFjLTQ3NDUtYjZkNy1hOTQzNzdmN2Y5MWIiLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy8yNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgvZXBpc29kZXMvOTllMDI5ZGYtYjkxYy00NzQ1LWI2ZDctYTk0Mzc3ZjdmOTFiLzBmZDU1YmJjLm1wMyJ9.mp3" length="68071370" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;strong&gt;Episode 3 of the Distilled Security Podcast is here!&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;Join us this week as we jump into: &lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;CrowdStrike Incident Analysis:&lt;/strong&gt; A deep dive into a recent mishap by CrowdStrike that led to significant financial losses and operational disruptions, including 5.4 billion in estimated losses.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Vendor Accountability:&lt;/strong&gt; Exploring the legal and financial repercussions of security vendor failures.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Business Continuity Planning:&lt;/strong&gt; The importance of preparing for security vendor failures, including considering alternate vendors and the complexities of implementing such strategies.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Kernel-Level Security Risks:&lt;/strong&gt; A discussion surrounding kernel-level operations in security software, focusing on the controversy between CrowdStrike and SentinelOne.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Manual Workarounds and Legacy Systems:&lt;/strong&gt; The challenges of maintaining business operations during security incidents.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Ransomware Recovery vs. Vendor Failures:&lt;/strong&gt; Comparing ransomware attacks&apos; impact and recovery processes with security vendor-induced failures.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Password Management Vulnerabilities:&lt;/strong&gt; The risks associated with dependency on password management systems like Thycotic/Delinea and LastPass, and the potential fallout if these systems experience downtime.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;BSides Pittsburgh Recap:&lt;/strong&gt; the biggest BSidesPGH event yet. Hear the notes and highlights from the conference.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;North Korean Spy Hired By KnowBe4:&lt;/strong&gt; Hear how a spy for N. Korea got by the defenses of KnowBe4, how they caught them, and steps they implemented to avoid this in the future.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CISOs as Scapegoats:&lt;/strong&gt; Are CISOs being pegged as scapegoats unfairly?&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;Links&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Crowdstrike Incident - &lt;a href=&quot;https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;SentinelOne Response to Crowdstrike - SentinalOne on Crowdstrike Outage -&lt;a href=&quot;https://www.crn.com/news/security/2024/sentinelone-ceo-on-crowdstrike-outage-not-just-an-honest-mistake&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; https://www.crn.com/news/security/2024/sentinelone-ceo-on-crowdstrike-outage-not-just-an-honest-mistake&lt;/a&gt;&lt;/li&gt;&lt;li&gt;BSidesPGH - &lt;a href=&quot;https://www.bsidespgh.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://www.bsidespgh.com/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;TRISS - &lt;a href=&quot;https://www.threeriversinfosec.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://www.threeriversinfosec.com/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;KnowBe4 // N. Korean Spy - &lt;a href=&quot;https://blog.knowbe4.com/cyberheistnews-vol-14-31-how-the-whole-world-now-knows-about-fake-north-korean-it-workers&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://blog.knowbe4.com/cyberheistnews-vol-14-31-how-the-whole-world-now-knows-about-fake-north-korean-it-workers&lt;/a&gt;&lt;/li&gt;&lt;li&gt;CISO as Scapegoats - &lt;a href=&quot;https://www.thestack.technology/were-becoming-scapegoats-how-have-cisos-responded-to-sec-cyber-risk-disclosure-rules/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://www.thestack.technology/were-becoming-scapegoats-how-have-cisos-responded-to-sec-cyber-risk-disclosure-rules/&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;Spirits&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Rabbit Hole Cavehill // Four Grain Tripple Malt - &lt;a href=&quot;https://www.rabbitholedistillery.com/pages/cavehill/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://www.rabbitholedistillery.com/pages/cavehill/&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Hosts&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Justin Leapline - https://www.linkedin.com/in/justinleapline/&lt;/li&gt;&lt;li&gt;Joe Wynn - https://www.linkedin.com/in/wynnjoe/&lt;/li&gt;&lt;li&gt;Rick Yocum - https://www.linkedin.com/in/rickyocum/&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Connect with Us&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Website: https://distilledsecuritypodcast.com&lt;/li&gt;&lt;li&gt;Twitter: @DisSecPod&lt;/li&gt;&lt;li&gt;Email: hello@distilledsecuritypodcast.com&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>01:10:52</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>3</itunes:episode><itunes:title>Episode 3: Crowdstrike, North Korean Spies, and CISO Scapegoats</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Episode 22: Is AI Good for Security, CIRCIA Starts the Clock, and the M&A Problem Nobody's Talking About]]></title><description><![CDATA[<p>In this episode of the Distilled Security Podcast, we tackle four topics shaping the cybersecurity landscape — from AI's real impact on defense to a wave of regulatory and market changes every security team needs to be tracking.</p><p><br /></p><p>🔹 Is AI Good for Security? — Anthropic's model finding hundreds of zero days, stock market panic after Claude Code's launch (CrowdStrike down 11%), the "hard things easy, easy things hard" reality of AI, why human-out-of-the-loop isn't ready yet, the coming spike in vulnerability disclosures, and how defenders should be using AI for better hygiene</p><p>🔹 CIRCIA Final Rule (May 2026) — The federal incident reporting law hitting critical infrastructure, 72-hour incident and 24-hour ransom payment notification clocks, how "substantial cyber incident" triggers differ from materiality, mid-market companies falling in scope, overlapping timelines with HIPAA/SEC/state breach laws, and building your incident response playbook now</p><p>🔹 Protecting Yourself Against a Changing Compliance Landscape — CMMC Phase 2, HIPAA overhaul, CCPA audits all converging, why a unified security program beats framework-by-framework chasing, evidence over policy in audits, engineering continuous compliance through automation, and the reality of doing this without dedicated staff</p><p>🔹 Cybersecurity M&amp;A / Consolidation Problem — Google acquiring Wiz for $32B, 10% of the cybersecurity industry changing hands, operational benefits of fewer vendors vs. pricing pressure and talent drain, the OneTrust "sticker on the side" integration warning, Cisco's Startup Studios model, and why consolidation only works if they don't break what made the acquisition special</p><p><br /></p><p>🥃 Spirit Review: WhistlePig 12 Year Old World Rye</p><p>PA Fine Wine &amp; Good Spirits Select — Finished in Madeira, Sauternes &amp; Port barrels, 86 proof</p><p>https://www.whistlepigwhiskey.com/</p><p><br /></p><p>📬 Send Us Your Questions!</p><p>ask@distilledsecuritypodcast.com</p><p><br /></p><p>🎙️ Hosts</p><p>Justin Leapline – @justinleapline</p><p>Joe Wynn – @wynnjoe</p><p>Rick Yocum – @rickyocum</p><p><br /></p><p>🌐 Connect with Us</p><p>Website: distilledsecuritypodcast.com</p><p>X: @DisSecPod</p><p>Email: hello@distilledsecuritypodcast.com</p><p><br /></p><p>👍 Like, comment, and subscribe for weekly security and compliance insights.</p>]]></description><link>https://share.transistor.fm/s/d9902f49</link><guid isPermaLink="false">95d0eaf3-c55b-4a97-8845-620b308ca34b</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Mon, 09 Mar 2026 15:41:17 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/d114640d35914fd3545f369f788842fdcd3f959c2e5994cbf466f2fa6f338efa/eyJlcGlzb2RlSWQiOiJiMmFlZmVjNC1jOWRiLTQ3ZWItYmVmMy05YjExMWY0Yzc1ZTYiLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy8yNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgvZXBpc29kZXMvYjJhZWZlYzQtYzlkYi00N2ViLWJlZjMtOWIxMTFmNGM3NWU2Lzc1M2JhYzY1Lm1wMyJ9.mp3" length="114319580" type="audio/mpeg"/><itunes:summary>&lt;p&gt;In this episode of the Distilled Security Podcast, we tackle four topics shaping the cybersecurity landscape — from AI&apos;s real impact on defense to a wave of regulatory and market changes every security team needs to be tracking.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;🔹 Is AI Good for Security? — Anthropic&apos;s model finding hundreds of zero days, stock market panic after Claude Code&apos;s launch (CrowdStrike down 11%), the &quot;hard things easy, easy things hard&quot; reality of AI, why human-out-of-the-loop isn&apos;t ready yet, the coming spike in vulnerability disclosures, and how defenders should be using AI for better hygiene&lt;/p&gt;&lt;p&gt;🔹 CIRCIA Final Rule (May 2026) — The federal incident reporting law hitting critical infrastructure, 72-hour incident and 24-hour ransom payment notification clocks, how &quot;substantial cyber incident&quot; triggers differ from materiality, mid-market companies falling in scope, overlapping timelines with HIPAA/SEC/state breach laws, and building your incident response playbook now&lt;/p&gt;&lt;p&gt;🔹 Protecting Yourself Against a Changing Compliance Landscape — CMMC Phase 2, HIPAA overhaul, CCPA audits all converging, why a unified security program beats framework-by-framework chasing, evidence over policy in audits, engineering continuous compliance through automation, and the reality of doing this without dedicated staff&lt;/p&gt;&lt;p&gt;🔹 Cybersecurity M&amp;amp;A / Consolidation Problem — Google acquiring Wiz for $32B, 10% of the cybersecurity industry changing hands, operational benefits of fewer vendors vs. pricing pressure and talent drain, the OneTrust &quot;sticker on the side&quot; integration warning, Cisco&apos;s Startup Studios model, and why consolidation only works if they don&apos;t break what made the acquisition special&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;🥃 Spirit Review: WhistlePig 12 Year Old World Rye&lt;/p&gt;&lt;p&gt;PA Fine Wine &amp;amp; Good Spirits Select — Finished in Madeira, Sauternes &amp;amp; Port barrels, 86 proof&lt;/p&gt;&lt;p&gt;https://www.whistlepigwhiskey.com/&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;📬 Send Us Your Questions!&lt;/p&gt;&lt;p&gt;ask@distilledsecuritypodcast.com&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;🎙️ Hosts&lt;/p&gt;&lt;p&gt;Justin Leapline – @justinleapline&lt;/p&gt;&lt;p&gt;Joe Wynn – @wynnjoe&lt;/p&gt;&lt;p&gt;Rick Yocum – @rickyocum&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;🌐 Connect with Us&lt;/p&gt;&lt;p&gt;Website: distilledsecuritypodcast.com&lt;/p&gt;&lt;p&gt;X: @DisSecPod&lt;/p&gt;&lt;p&gt;Email: hello@distilledsecuritypodcast.com&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;👍 Like, comment, and subscribe for weekly security and compliance insights.&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>01:56:23</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>22</itunes:episode><itunes:title>Episode 22: Is AI Good for Security, CIRCIA Starts the Clock, and the M&amp;A Problem Nobody&apos;s Talking About</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Episode 7: Certifications, Mentorship, and Auditor Missteps]]></title><description><![CDATA[<p><strong>Welcome to Episode 7 of the Distilled Security Podcast!<br /></strong><br /></p><p>In this episode, hosts Justin, Rick, and Joe are joined by special guest Brandon Eckert to explore his fascinating journey in cybersecurity, share industry insights, and enjoy a fun debate on Thanksgiving favorites. Here’s what’s in store:</p><p><strong>Topics Covered: <br /></strong><br /></p><p>🔹 <strong>Navigating a Career in Cybersecurity</strong><br />Reflections on starting out in cybersecurity, overcoming challenges in small-town IT careers, and the role of certifications in shaping career success.</p><p>🔹 <strong>The Value of Certifications</strong><br />How certifications like OSCP contribute to career growth, practical knowledge, and their relationship with networking and formal education.</p><p>🔹 <strong>Mentorship and the Pittsburgh Cybersecurity Community</strong><br />The importance of fostering growth, mentoring local talent, and giving back to the Pittsburgh security community.</p><p>🔹 <strong>Networking vs. Certifications</strong><br />A discussion on what matters more for career advancement and the unique benefits of each.</p><p>🔹 <strong>Auditor Stories and Lessons Learned</strong><br />Hear hilarious and insightful tales from hospital audits, ethical dilemmas, and tips for managing challenging auditor experiences.</p><p>🔹 <strong>Business Continuity Challenges</strong><br />How organizations can prepare for rare but impactful events, like solar flares, while building strong auditor relationships.</p><p>🔹 <strong>Thanksgiving Favorites</strong><br />A lighthearted wrap-up featuring turkey tips, stuffing recipes, and the ultimate leftover turkey sandwich.</p><p>🔸 Links<br />Widow Jane Black Opal: https://widowjane.com/</p><p>🔸 Spirits<br /><strong>Widow Jane Black Opal</strong><br />A rare blend of bourbons, each aged for at least 20 years and finished in Japanese Mizunara oak. Notes of toffee, plum, and tobacco make this whiskey an extraordinary treat.</p><p>🔸Hosts</p><ul><li><a href="https://www.linkedin.com/in/justinleapline/" rel="noopener noreferrer nofollow">Justin Leapline</a> </li><li><a href="https://www.linkedin.com/in/wynnjoe/" rel="noopener noreferrer nofollow">Joe Wynn</a></li><li><a href="https://www.linkedin.com/in/rickyocum/" rel="noopener noreferrer nofollow">Rick Yocum</a></li></ul><p>🔸 Guest<br />🙋🏻‍♂️ <a href="https://www.linkedin.com/in/brandon-eckert/" rel="noopener noreferrer nofollow">Brandon Eckert </a></p><p>🎙 Connect with Us<br />Website: <a href="https://distilledsecuritypodcast.com/" rel="noopener noreferrer nofollow">Distilled Security Podcast</a><br /> X: <a href="https://x.com/DisSecPod" rel="noopener noreferrer nofollow">@DisSecPod</a><br />Email: hello@distilledsecuritypodcast.com</p>]]></description><link>https://share.transistor.fm/s/318c010a</link><guid isPermaLink="false">dc6a6544-304f-4f45-b38b-1575be41c3dd</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Tue, 10 Dec 2024 23:01:06 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/2562189563d9ae3ee06a838862b63441d9556fc5675aa373d2c5654f7b81a3ac/eyJlcGlzb2RlSWQiOiIwNGNiNzFhYy02ZTQ5LTQ0ZDEtYjM4Ni1mZDc0NDA0MTg3NjUiLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy8yNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgvZXBpc29kZXMvMDRjYjcxYWMtNmU0OS00NGQxLWIzODYtZmQ3NDQwNDE4NzY1LzhhNTJhNDc5Lm1wMyJ9.mp3" length="75715165" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;strong&gt;Welcome to Episode 7 of the Distilled Security Podcast!&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;In this episode, hosts Justin, Rick, and Joe are joined by special guest Brandon Eckert to explore his fascinating journey in cybersecurity, share industry insights, and enjoy a fun debate on Thanksgiving favorites. Here’s what’s in store:&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Topics Covered: &lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;🔹 &lt;strong&gt;Navigating a Career in Cybersecurity&lt;/strong&gt;&lt;br /&gt;Reflections on starting out in cybersecurity, overcoming challenges in small-town IT careers, and the role of certifications in shaping career success.&lt;/p&gt;&lt;p&gt;🔹 &lt;strong&gt;The Value of Certifications&lt;/strong&gt;&lt;br /&gt;How certifications like OSCP contribute to career growth, practical knowledge, and their relationship with networking and formal education.&lt;/p&gt;&lt;p&gt;🔹 &lt;strong&gt;Mentorship and the Pittsburgh Cybersecurity Community&lt;/strong&gt;&lt;br /&gt;The importance of fostering growth, mentoring local talent, and giving back to the Pittsburgh security community.&lt;/p&gt;&lt;p&gt;🔹 &lt;strong&gt;Networking vs. Certifications&lt;/strong&gt;&lt;br /&gt;A discussion on what matters more for career advancement and the unique benefits of each.&lt;/p&gt;&lt;p&gt;🔹 &lt;strong&gt;Auditor Stories and Lessons Learned&lt;/strong&gt;&lt;br /&gt;Hear hilarious and insightful tales from hospital audits, ethical dilemmas, and tips for managing challenging auditor experiences.&lt;/p&gt;&lt;p&gt;🔹 &lt;strong&gt;Business Continuity Challenges&lt;/strong&gt;&lt;br /&gt;How organizations can prepare for rare but impactful events, like solar flares, while building strong auditor relationships.&lt;/p&gt;&lt;p&gt;🔹 &lt;strong&gt;Thanksgiving Favorites&lt;/strong&gt;&lt;br /&gt;A lighthearted wrap-up featuring turkey tips, stuffing recipes, and the ultimate leftover turkey sandwich.&lt;/p&gt;&lt;p&gt;🔸 Links&lt;br /&gt;Widow Jane Black Opal: https://widowjane.com/&lt;/p&gt;&lt;p&gt;🔸 Spirits&lt;br /&gt;&lt;strong&gt;Widow Jane Black Opal&lt;/strong&gt;&lt;br /&gt;A rare blend of bourbons, each aged for at least 20 years and finished in Japanese Mizunara oak. Notes of toffee, plum, and tobacco make this whiskey an extraordinary treat.&lt;/p&gt;&lt;p&gt;🔸Hosts&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;https://www.linkedin.com/in/justinleapline/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Justin Leapline&lt;/a&gt; &lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.linkedin.com/in/wynnjoe/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Joe Wynn&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.linkedin.com/in/rickyocum/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Rick Yocum&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;🔸 Guest&lt;br /&gt;🙋🏻‍♂️ &lt;a href=&quot;https://www.linkedin.com/in/brandon-eckert/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Brandon Eckert &lt;/a&gt;&lt;/p&gt;&lt;p&gt;🎙 Connect with Us&lt;br /&gt;Website: &lt;a href=&quot;https://distilledsecuritypodcast.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Distilled Security Podcast&lt;/a&gt;&lt;br /&gt; X: &lt;a href=&quot;https://x.com/DisSecPod&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;@DisSecPod&lt;/a&gt;&lt;br /&gt;Email: hello@distilledsecuritypodcast.com&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>01:18:50</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>7</itunes:episode><itunes:title>Episode 7: Certifications, Mentorship, and Auditor Missteps</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Episode 18: TRISS Highlights, Cloud Chaos & SaaS Lessons Learned]]></title><description><![CDATA[<p>In Episode 18 of the Distilled Security Podcast, Justin Leapline, Joe Wynn, and Rick Yokum recap their time at TRISS, share lessons on storytelling and women in tech, and break down the recent AWS us-east-1 DNS/DynamoDB outage, the Microsoft Front Door global disruption, and the F5 BIG-IP incident. </p><p>🔍 We discuss:<br />- TRISS highlights: panels, community &amp; storytelling<br />- “Breaking the glass ceiling” and unintentional bias in meetings<br />- AWS &amp; Microsoft outages: risk, resilience &amp; when multicloud matters<br />- F5 BIG-IP incident and supply chain risk<br />- Launching a GRC SaaS: episki’s journey, lessons &amp; tradeoffs</p><p>🥃 Spirit of the episode<br />Penelope Bourbon – Project X (sherry cask finish)</p><p>⏱️ Timestamps<br />00:00 – 🥃 Intro &amp; TRISS Recap — Highlights from TRISS: panels, community, and a keynote with Edward Norton</p><p>02:40 – 📖 The Power of Storytelling — Why empathy and narrative matter in cybersecurity leadership</p><p>04:40 – 👩‍💻 Women in Tech &amp; Bias in Meetings — Real talk about unintentional bias and everyday experiences</p><p>20:34 – ☁️ AWS &amp; Microsoft Outages — What happened and what it says about cloud resilience</p><p>49:38 - 🥃 Bourbon Break — Enjoying a glass of Penelope Project X</p><p>53:30 – 🔥 F5 BIG-IP Vulnerability — Supply chain risk and patching lessons</p><p>1:09:50 – 🚀 Launching episki (GRC SaaS) — Building simply, shipping fast, and learning from users</p><p>1:52:22 – 🧭 Reflections &amp; Closing Thoughts — Culture, resilience, and what’s next</p><p>🎧 Hosts<br />Justin Leapline <br />Joe Wynn <br />Rick Yocum </p><p>🌐 Connect with Us<br />Website: distilledsecuritypodcast.com<br />X : @DisSecPod<br />Email: hello@distilledsecuritypodcast.com</p>]]></description><link>https://share.transistor.fm/s/728ba78c</link><guid isPermaLink="false">fdb51287-c9be-40a0-98fc-2f41aa332164</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Mon, 10 Nov 2025 20:47:21 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/90da9614199c3910ab2bb23fe296c638eb67527aed209b9e244e398f03ac76ef/eyJlcGlzb2RlSWQiOiIwNjlkNDdkMC0yMzVjLTQxNmEtODk2ZC01ZGZkOTFlZDExMDIiLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy8yNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgvZXBpc29kZXMvMDY5ZDQ3ZDAtMjM1Yy00MTZhLTg5NmQtNWRmZDkxZWQxMTAyLzljZWMyYjVhLm1wMyJ9.mp3" length="108780451" type="audio/mpeg"/><itunes:summary>&lt;p&gt;In Episode 18 of the Distilled Security Podcast, Justin Leapline, Joe Wynn, and Rick Yokum recap their time at TRISS, share lessons on storytelling and women in tech, and break down the recent AWS us-east-1 DNS/DynamoDB outage, the Microsoft Front Door global disruption, and the F5 BIG-IP incident. &lt;/p&gt;&lt;p&gt;🔍 We discuss:&lt;br /&gt;- TRISS highlights: panels, community &amp;amp; storytelling&lt;br /&gt;- “Breaking the glass ceiling” and unintentional bias in meetings&lt;br /&gt;- AWS &amp;amp; Microsoft outages: risk, resilience &amp;amp; when multicloud matters&lt;br /&gt;- F5 BIG-IP incident and supply chain risk&lt;br /&gt;- Launching a GRC SaaS: episki’s journey, lessons &amp;amp; tradeoffs&lt;/p&gt;&lt;p&gt;🥃 Spirit of the episode&lt;br /&gt;Penelope Bourbon – Project X (sherry cask finish)&lt;/p&gt;&lt;p&gt;⏱️ Timestamps&lt;br /&gt;00:00 – 🥃 Intro &amp;amp; TRISS Recap — Highlights from TRISS: panels, community, and a keynote with Edward Norton&lt;/p&gt;&lt;p&gt;02:40 – 📖 The Power of Storytelling — Why empathy and narrative matter in cybersecurity leadership&lt;/p&gt;&lt;p&gt;04:40 – 👩‍💻 Women in Tech &amp;amp; Bias in Meetings — Real talk about unintentional bias and everyday experiences&lt;/p&gt;&lt;p&gt;20:34 – ☁️ AWS &amp;amp; Microsoft Outages — What happened and what it says about cloud resilience&lt;/p&gt;&lt;p&gt;49:38 - 🥃 Bourbon Break — Enjoying a glass of Penelope Project X&lt;/p&gt;&lt;p&gt;53:30 – 🔥 F5 BIG-IP Vulnerability — Supply chain risk and patching lessons&lt;/p&gt;&lt;p&gt;1:09:50 – 🚀 Launching episki (GRC SaaS) — Building simply, shipping fast, and learning from users&lt;/p&gt;&lt;p&gt;1:52:22 – 🧭 Reflections &amp;amp; Closing Thoughts — Culture, resilience, and what’s next&lt;/p&gt;&lt;p&gt;🎧 Hosts&lt;br /&gt;Justin Leapline &lt;br /&gt;Joe Wynn &lt;br /&gt;Rick Yocum &lt;/p&gt;&lt;p&gt;🌐 Connect with Us&lt;br /&gt;Website: distilledsecuritypodcast.com&lt;br /&gt;X : @DisSecPod&lt;br /&gt;Email: hello@distilledsecuritypodcast.com&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>01:53:17</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>18</itunes:episode><itunes:title>Episode 18: TRISS Highlights, Cloud Chaos &amp; SaaS Lessons Learned</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Episode 10: Navigating Budget Cuts, Talent Shortages, and Cybersecurity Resilience]]></title><description><![CDATA[<p>Episode 10 of the Distilled Security Podcast is here!</p><p>Join us as we explore:</p><ul><li>Security in Times of Budget Cuts: How organizations can navigate layoffs and reduced funding while maintaining a strong security posture.</li><li>The Cybersecurity Talent Shortage: Why security hiring remains challenging, the need for apprenticeship models, and how organizations can develop internal talent pipelines.</li><li>BSides Pittsburgh: Put this on your calendar and submit talks.</li><li>Cyber Crisis Readiness: The importance of C-suite participation in tabletop exercises and cyber incident planning.</li></ul><p><strong>References</strong> </p><ul><li>Early Education by David Barton - https://www.youtube.com/watch?v=io-O59eakMk</li><li>BSides Pittsburgh CFP - https://www.bsidespgh.com/cfp</li></ul><p><strong>Spirits:</strong> Lady of the Glen – A 10-year-old cask strength Scotch whisky finished in Oloroso sherry casks.</p><p><strong>Hosts</strong></p><ul><li>Justin Leapline -<a href="https://www.linkedin.com/in/justinleapline/" rel="noopener noreferrer nofollow"> LinkedIn</a></li><li>Joe Wynn -<a href="https://www.linkedin.com/in/wynnjoe/" rel="noopener noreferrer nofollow"> LinkedIn</a></li><li>Rick Yocum -<a href="https://www.linkedin.com/in/rickyocum/" rel="noopener noreferrer nofollow"> LinkedIn</a></li></ul><p><strong>Connect with Us</strong></p><ul><li>Website:<a href="https://distilledsecuritypodcast.com" rel="noopener noreferrer nofollow"> Distilled Security Podcast</a></li><li>Twitter:<a href="https://twitter.com/DisSecPod" rel="noopener noreferrer nofollow"> @DisSecPod</a></li><li>Email: hello@distilledsecuritypodcast.com<p></p></li></ul>]]></description><link>https://share.transistor.fm/s/706367f1</link><guid isPermaLink="false">062c58cd-c5fe-4593-83ce-bda5d0a39ad2</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Wed, 12 Mar 2025 14:08:32 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/ed54b8693233f82d17fd2f219f52fc0e333d07a6ae9f0e87a454004db5d1b016/eyJlcGlzb2RlSWQiOiIxMDE1MzIxMy02YjNkLTQwZDQtYjQyZS01ODdlODMzZTk4OGUiLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy8yNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgvZXBpc29kZXMvMTAxNTMyMTMtNmIzZC00MGQ0LWI0MmUtNTg3ZTgzM2U5ODhlLzk2ZTZmMGFkLm1wMyJ9.mp3" length="90657291" type="audio/mpeg"/><itunes:summary>&lt;p&gt;Episode 10 of the Distilled Security Podcast is here!&lt;/p&gt;&lt;p&gt;Join us as we explore:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Security in Times of Budget Cuts: How organizations can navigate layoffs and reduced funding while maintaining a strong security posture.&lt;/li&gt;&lt;li&gt;The Cybersecurity Talent Shortage: Why security hiring remains challenging, the need for apprenticeship models, and how organizations can develop internal talent pipelines.&lt;/li&gt;&lt;li&gt;BSides Pittsburgh: Put this on your calendar and submit talks.&lt;/li&gt;&lt;li&gt;Cyber Crisis Readiness: The importance of C-suite participation in tabletop exercises and cyber incident planning.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;References&lt;/strong&gt; &lt;/p&gt;&lt;ul&gt;&lt;li&gt;Early Education by David Barton - https://www.youtube.com/watch?v=io-O59eakMk&lt;/li&gt;&lt;li&gt;BSides Pittsburgh CFP - https://www.bsidespgh.com/cfp&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Spirits:&lt;/strong&gt; Lady of the Glen – A 10-year-old cask strength Scotch whisky finished in Oloroso sherry casks.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Hosts&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Justin Leapline -&lt;a href=&quot;https://www.linkedin.com/in/justinleapline/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; LinkedIn&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Joe Wynn -&lt;a href=&quot;https://www.linkedin.com/in/wynnjoe/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; LinkedIn&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Rick Yocum -&lt;a href=&quot;https://www.linkedin.com/in/rickyocum/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; LinkedIn&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Connect with Us&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Website:&lt;a href=&quot;https://distilledsecuritypodcast.com&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; Distilled Security Podcast&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Twitter:&lt;a href=&quot;https://twitter.com/DisSecPod&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; @DisSecPod&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Email: hello@distilledsecuritypodcast.com&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>01:34:24</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>10</itunes:episode><itunes:title>Episode 10: Navigating Budget Cuts, Talent Shortages, and Cybersecurity Resilience</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Episode 12: One Year of Distilled Security, Auditor Quality, and Starting Your Own Company]]></title><description><![CDATA[<p><strong>Join us as we reflect on:</strong></p><ul><li><strong>One Year of Podcasting</strong>: The crew celebrates a full year of episodes, favorite topics, behind-the-scenes production, and where the show is headed next—including a new studio setup and future sponsors.</li><li><strong>Audit Quality and Risk</strong>: A deep dive into the evolution of cybersecurity audits, the growing influence of low-cost providers, and what actually makes an audit valuable and trustworthy.</li><li><strong>Third-Party Risk Management</strong>: How companies can assess vendor SOC 2 reports, triage risk among their vendors, and build defensible compliance practices.</li><li><strong>Operational vs. Commercial Risk</strong>: The importance of translating audit findings into business impact and strengthening vendor partnerships for long-term resilience.</li><li><strong>Bourbon Review – </strong><a href="https://jeffersonsbourbon.com/whiskeys/jeffersons-tropics-bourbon/" rel="noopener noreferrer nofollow"><strong>Jefferson’s Tropics</strong></a>: A tasting of a tropical-aged bourbon matured in Singapore’s climate, featuring notes of toffee and spice.</li><li><strong>BSides Pittsburgh Update</strong>: Details on ticket sales, sponsor opportunities, and how to get involved with the local security community’s flagship event.</li><li><strong>Entrepreneurship &amp; Starting a Business</strong>: A thoughtful discussion on what it really takes to start your own business—when to consider it, how to prepare, and why it’s often more work (and growth) than expected.</li></ul><p><br /></p><p><strong>Hosts</strong></p><ul><li>Justin Leapline -<a href="https://www.linkedin.com/in/justinleapline/" rel="noopener noreferrer nofollow"> LinkedIn</a></li><li>Joe Wynn -<a href="https://www.linkedin.com/in/wynnjoe/" rel="noopener noreferrer nofollow"> LinkedIn</a></li><li>Rick Yocum -<a href="https://www.linkedin.com/in/rickyocum/" rel="noopener noreferrer nofollow"> LinkedIn</a></li></ul><p><strong>Connect with Us</strong></p><ul><li>Website:<a href="https://distilledsecuritypodcast.com" rel="noopener noreferrer nofollow"> Distilled Security Podcast</a></li><li>Twitter:<a href="https://twitter.com/DisSecPod" rel="noopener noreferrer nofollow"> @DisSecPod</a></li><li>Email: hello@distilledsecuritypodcast.com<p></p></li></ul>]]></description><link>https://share.transistor.fm/s/1ca210ed</link><guid isPermaLink="false">288c449c-8ce5-4182-809c-6fe502492dd3</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Fri, 02 May 2025 15:06:29 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/0ddac4f66e3ecf62cbc5bb654c739f28f788bc68c7717a3918c9c0b3063d03e0/eyJlcGlzb2RlSWQiOiIxNWZkYmRkMi1jNmQ3LTRkZTQtYjhiNi1mZGM4NzIyZWMwYjUiLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy8yNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgvZXBpc29kZXMvMTVmZGJkZDItYzZkNy00ZGU0LWI4YjYtZmRjODcyMmVjMGI1LzE5ZTJkZTFmLm1wMyJ9.mp3" length="94265952" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;strong&gt;Join us as we reflect on:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;One Year of Podcasting&lt;/strong&gt;: The crew celebrates a full year of episodes, favorite topics, behind-the-scenes production, and where the show is headed next—including a new studio setup and future sponsors.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Audit Quality and Risk&lt;/strong&gt;: A deep dive into the evolution of cybersecurity audits, the growing influence of low-cost providers, and what actually makes an audit valuable and trustworthy.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Third-Party Risk Management&lt;/strong&gt;: How companies can assess vendor SOC 2 reports, triage risk among their vendors, and build defensible compliance practices.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Operational vs. Commercial Risk&lt;/strong&gt;: The importance of translating audit findings into business impact and strengthening vendor partnerships for long-term resilience.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Bourbon Review – &lt;/strong&gt;&lt;a href=&quot;https://jeffersonsbourbon.com/whiskeys/jeffersons-tropics-bourbon/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;&lt;strong&gt;Jefferson’s Tropics&lt;/strong&gt;&lt;/a&gt;: A tasting of a tropical-aged bourbon matured in Singapore’s climate, featuring notes of toffee and spice.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;BSides Pittsburgh Update&lt;/strong&gt;: Details on ticket sales, sponsor opportunities, and how to get involved with the local security community’s flagship event.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Entrepreneurship &amp;amp; Starting a Business&lt;/strong&gt;: A thoughtful discussion on what it really takes to start your own business—when to consider it, how to prepare, and why it’s often more work (and growth) than expected.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Hosts&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Justin Leapline -&lt;a href=&quot;https://www.linkedin.com/in/justinleapline/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; LinkedIn&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Joe Wynn -&lt;a href=&quot;https://www.linkedin.com/in/wynnjoe/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; LinkedIn&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Rick Yocum -&lt;a href=&quot;https://www.linkedin.com/in/rickyocum/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; LinkedIn&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Connect with Us&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Website:&lt;a href=&quot;https://distilledsecuritypodcast.com&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; Distilled Security Podcast&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Twitter:&lt;a href=&quot;https://twitter.com/DisSecPod&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; @DisSecPod&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Email: hello@distilledsecuritypodcast.com&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>01:38:10</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>12</itunes:episode><itunes:title>Episode 12: One Year of Distilled Security, Auditor Quality, and Starting Your Own Company</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Episode 20 : 2026 Kickoff: Security Resolutions, Key Deadlines, and Don’t Mislead the Feds]]></title><description><![CDATA[<p><br />In the first episode of 2026, the Distilled Security team kicks off the year with a practical discussion on security priorities, key compliance dates to watch in 2026, and why misleading the government on cybersecurity compliance can have serious consequences.</p><p>The conversation focuses on simplifying security programs, returning to core fundamentals, and learning from real-world enforcement and regulatory cases. The episode closes with a holiday pour and a preview of format changes coming next.</p><p>⏱️ <strong>Timestamps</strong></p><ul><li>0:00 Intro &amp; episode overview</li><li>0:33 2026 security resolutions: simplify &amp; back to basics</li><li>5:45 “Science projects”: removing emotion from decisions</li><li>8:36 Justin’s goals: family, travel, business &amp; AI workflows</li><li>17:52 EOS + Atomic Habits workbook (goal planning)</li><li>23:54 Key compliance dates to watch in 2026</li><li>31:45 California privacy updates &amp; risk assessments (CCPA)</li><li>35:39 EU AI Act + NIS2 enforcement ramp-up</li><li>42:48 Drink break: High West “A Midwinter Night’s Dram.”</li><li>45:04 Don’t mislead the feds: FedRAMP, SolarWinds, CMMC—wrap-up to 1:20:12</li></ul><p><strong> 🎙️ Hosts</strong></p><ul><li>Justin Leapline – @justinleapline</li><li>Joe Wynn – @wynnjoe</li><li>Rick Yocum – @rickyocum</li></ul><p><br /><strong>🌐 Connect with Us</strong></p><ul><li>Website: distilledsecuritypodcast.com</li><li>X:  @DisSecPod</li><li>Email: hello@distilledsecuritypodcast.com</li></ul><p><br />🥃 <strong>Drink of the episode: </strong>High West A Midwinter Night’s Dram</p>]]></description><link>https://share.transistor.fm/s/64241178</link><guid isPermaLink="false">15e0c7a7-efea-4448-94f6-ae7c7a3ead3c</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Mon, 26 Jan 2026 15:24:56 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/103f368a6040cf6ff10dce6539c35dc10c734a6b95f60d3be46626f3ccd0f793/eyJlcGlzb2RlSWQiOiIzOWZhNjZjMC02NWRjLTRlZjUtOTE0OS1hZjk0NTQ2MzkyMTUiLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy8yNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgvZXBpc29kZXMvMzlmYTY2YzAtNjVkYy00ZWY1LTkxNDktYWY5NDU0NjM5MjE1LzI5MzBkZDczLm1wMyJ9.mp3" length="77228961" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;br /&gt;In the first episode of 2026, the Distilled Security team kicks off the year with a practical discussion on security priorities, key compliance dates to watch in 2026, and why misleading the government on cybersecurity compliance can have serious consequences.&lt;/p&gt;&lt;p&gt;The conversation focuses on simplifying security programs, returning to core fundamentals, and learning from real-world enforcement and regulatory cases. The episode closes with a holiday pour and a preview of format changes coming next.&lt;/p&gt;&lt;p&gt;⏱️ &lt;strong&gt;Timestamps&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;0:00 Intro &amp;amp; episode overview&lt;/li&gt;&lt;li&gt;0:33 2026 security resolutions: simplify &amp;amp; back to basics&lt;/li&gt;&lt;li&gt;5:45 “Science projects”: removing emotion from decisions&lt;/li&gt;&lt;li&gt;8:36 Justin’s goals: family, travel, business &amp;amp; AI workflows&lt;/li&gt;&lt;li&gt;17:52 EOS + Atomic Habits workbook (goal planning)&lt;/li&gt;&lt;li&gt;23:54 Key compliance dates to watch in 2026&lt;/li&gt;&lt;li&gt;31:45 California privacy updates &amp;amp; risk assessments (CCPA)&lt;/li&gt;&lt;li&gt;35:39 EU AI Act + NIS2 enforcement ramp-up&lt;/li&gt;&lt;li&gt;42:48 Drink break: High West “A Midwinter Night’s Dram.”&lt;/li&gt;&lt;li&gt;45:04 Don’t mislead the feds: FedRAMP, SolarWinds, CMMC—wrap-up to 1:20:12&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt; 🎙️ Hosts&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Justin Leapline – @justinleapline&lt;/li&gt;&lt;li&gt;Joe Wynn – @wynnjoe&lt;/li&gt;&lt;li&gt;Rick Yocum – @rickyocum&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;🌐 Connect with Us&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Website: distilledsecuritypodcast.com&lt;/li&gt;&lt;li&gt;X:  @DisSecPod&lt;/li&gt;&lt;li&gt;Email: hello@distilledsecuritypodcast.com&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;🥃 &lt;strong&gt;Drink of the episode: &lt;/strong&gt;High West A Midwinter Night’s Dram&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>01:20:25</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>20</itunes:episode><itunes:title>Episode 20 : 2026 Kickoff: Security Resolutions, Key Deadlines, and Don’t Mislead the Feds</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Episode 15: Community Building, Art of Convincing, and GTD Strategies]]></title><description><![CDATA[<p><strong>🎙️ Welcome back to the Distilled Security Podcast!</strong></p><p>In this episode, hosts Justin Leapline, Joe Wynn, and Rick Yocum sit down with James Ringold (Senior Security Cloud Solution Architect at Microsoft and President of ISSA Pittsburgh) to talk all about building stronger cybersecurity communities.</p><p>From the behind-the-scenes of BSides Pittsburgh 2025 to engaging the next generation through mentorship and student-led talks, this episode offers practical insights on how to grow inclusive, vendor-neutral spaces that truly support people in security.</p><p><strong>Topics Covered</strong></p><ul><li><strong>BSides Pittsburgh 2025 Highlights</strong></li></ul><p>What made this year’s event stand out — from arcade machines and pastries to great speakers and a welcoming atmosphere.</p><ul><li><strong>Running an Inclusive Security Chapter</strong></li></ul><p>Insights into leading ISSA Pittsburgh, maintaining momentum, and building a vendor-neutral space that feels open to everyone.</p><ul><li><strong>The Power of Consistency</strong></li></ul><p>Why showing up regularly and following through matters when growing a security community.</p><ul><li><strong>Mentoring the Next Generation</strong></li></ul><p>The importance of mentorship chains, student-led initiatives, and creating low-pressure environments for future leaders.</p><ul><li><strong>Engaging Students Beyond Attendance</strong></li></ul><p>How to get students truly involved, from submitting talks to building long-term relationships that support career growth.</p><ul><li><strong>Authenticity and Community Building</strong></li></ul><p>Why empathy, storytelling, and invitation—not pressure—are essential for creating lasting, supportive security ecosystems.</p><p><strong>Timestamps:</strong></p><p>00:00:00 – Intro &amp; Guest Welcome<br /> 00:02:20 – BSides Pittsburgh 2025 Preview<br /> 00:24:10 – Building Inclusive Security Communities<br /> 00:41:20 – Mentorship &amp; Student Talks<br /> 01:11:00 – Whiskey Tasting: Grand Traverse Distillery<br /> 01:33:00 – Growing Through Empathy &amp; Local Leadership<br /> 01:48:30 – Final Reflections &amp; Outro</p><p><strong>Links</strong></p><ul><li><a href="https://pittsburghissa.org/" rel="noopener noreferrer nofollow">ISSA Pittsburgh</a></li><li><a href="https://www.bsidespgh.com/" rel="noopener noreferrer nofollow">BSides Pittsburgh</a></li></ul><p><strong>Hosts</strong></p><ul><li><a href="https://www.linkedin.com/in/justinleapline/" rel="noopener noreferrer nofollow">Justin Leapline </a></li><li><a href="https://www.linkedin.com/in/wynnjoe/" rel="noopener noreferrer nofollow">Joe Wynn </a> </li><li><a href="https://www.linkedin.com/in/rickyocum/" rel="noopener noreferrer nofollow">Rick Yocum </a></li></ul><p><strong>Guest </strong></p><ul><li><a href="https://www.linkedin.com/in/jamesringold/" rel="noopener noreferrer nofollow">James Ringold</a></li></ul><p><br /><strong>Connect with Us</strong></p><ul><li>Website: <a href="https://distilledsecuritypodcast.com/" rel="noopener noreferrer nofollow">distilledsecuritypodcast.com</a></li><li>Twitter: @DisSecPod</li><li>Email: hello@distilledsecuritypodcast.com</li></ul><p><br /></p>]]></description><link>https://share.transistor.fm/s/00fd0bc1</link><guid isPermaLink="false">d718ab9c-92f0-4b8f-97af-42f3b9dc1167</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Wed, 06 Aug 2025 13:15:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/9576878dce6c264556b74bf61c1a75337f98ac3fc04745d676cb980363969d0c/eyJlcGlzb2RlSWQiOiI0ZTc5ODk0OC0yNTFkLTQ1ZjYtODg5YS0wODg0YmZkZmNjMmEiLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy8yNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgvZXBpc29kZXMvNGU3OTg5NDgtMjUxZC00NWY2LTg4OWEtMDg4NGJmZGZjYzJhLzE3MmYxNDk1Lm1wMyJ9.mp3" length="109807746" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;strong&gt;🎙️ Welcome back to the Distilled Security Podcast!&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;In this episode, hosts Justin Leapline, Joe Wynn, and Rick Yocum sit down with James Ringold (Senior Security Cloud Solution Architect at Microsoft and President of ISSA Pittsburgh) to talk all about building stronger cybersecurity communities.&lt;/p&gt;&lt;p&gt;From the behind-the-scenes of BSides Pittsburgh 2025 to engaging the next generation through mentorship and student-led talks, this episode offers practical insights on how to grow inclusive, vendor-neutral spaces that truly support people in security.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Topics Covered&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;BSides Pittsburgh 2025 Highlights&lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;What made this year’s event stand out — from arcade machines and pastries to great speakers and a welcoming atmosphere.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Running an Inclusive Security Chapter&lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Insights into leading ISSA Pittsburgh, maintaining momentum, and building a vendor-neutral space that feels open to everyone.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;The Power of Consistency&lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Why showing up regularly and following through matters when growing a security community.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Mentoring the Next Generation&lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The importance of mentorship chains, student-led initiatives, and creating low-pressure environments for future leaders.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Engaging Students Beyond Attendance&lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;How to get students truly involved, from submitting talks to building long-term relationships that support career growth.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Authenticity and Community Building&lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Why empathy, storytelling, and invitation—not pressure—are essential for creating lasting, supportive security ecosystems.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Timestamps:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;00:00:00 – Intro &amp;amp; Guest Welcome&lt;br /&gt; 00:02:20 – BSides Pittsburgh 2025 Preview&lt;br /&gt; 00:24:10 – Building Inclusive Security Communities&lt;br /&gt; 00:41:20 – Mentorship &amp;amp; Student Talks&lt;br /&gt; 01:11:00 – Whiskey Tasting: Grand Traverse Distillery&lt;br /&gt; 01:33:00 – Growing Through Empathy &amp;amp; Local Leadership&lt;br /&gt; 01:48:30 – Final Reflections &amp;amp; Outro&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Links&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;https://pittsburghissa.org/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;ISSA Pittsburgh&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.bsidespgh.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;BSides Pittsburgh&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Hosts&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;https://www.linkedin.com/in/justinleapline/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Justin Leapline &lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.linkedin.com/in/wynnjoe/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Joe Wynn &lt;/a&gt; &lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.linkedin.com/in/rickyocum/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Rick Yocum &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Guest &lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;https://www.linkedin.com/in/jamesringold/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;James Ringold&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;Connect with Us&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Website: &lt;a href=&quot;https://distilledsecuritypodcast.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;distilledsecuritypodcast.com&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Twitter: @DisSecPod&lt;/li&gt;&lt;li&gt;Email: hello@distilledsecuritypodcast.com&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>01:54:21</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>15</itunes:episode><itunes:title>Episode 15: Community Building, Art of Convincing, and GTD Strategies</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Distilled Security Podcast Trailer]]></title><description><![CDATA[<p>Join us on Distilled Security as we delve into the fascinating world of cybersecurity. Each episode, we break down intriguing topics, analyze the latest news, and engage in in-depth conversations with our hosts and invited guests. Whether you're a seasoned professional or just curious about cybersecurity, our podcast offers valuable insights and thought-provoking discussions to keep you informed and entertained. Tune in and stay ahead of the curve in the ever-evolving landscape of cybersecurity.</p>]]></description><link>https://share.transistor.fm/s/893e842b</link><guid isPermaLink="false">b5a39468-b8a6-4924-a7de-48b989e6d06e</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Sun, 02 Jun 2024 00:52:35 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/bcd1467448a001cd35319d17a87bca281974655b1855f16f5667be953da2f5ac/eyJlcGlzb2RlSWQiOiI1YWYyYjA2Yy01Y2NjLTQ5MTEtOGVlNC1kZTVkMmUzMTE3ZDIiLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy8yNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgvZXBpc29kZXMvNWFmMmIwNmMtNWNjYy00OTExLThlZTQtZGU1ZDJlMzExN2QyLzc2OGJlN2I1Lm1wMyJ9.mp3" length="763744" type="audio/mpeg"/><itunes:summary>&lt;p&gt;Join us on Distilled Security as we delve into the fascinating world of cybersecurity. Each episode, we break down intriguing topics, analyze the latest news, and engage in in-depth conversations with our hosts and invited guests. Whether you&apos;re a seasoned professional or just curious about cybersecurity, our podcast offers valuable insights and thought-provoking discussions to keep you informed and entertained. Tune in and stay ahead of the curve in the ever-evolving landscape of cybersecurity.&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:00:45</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>1</itunes:episode><itunes:title>Distilled Security Podcast Trailer</itunes:title><itunes:episodeType>trailer</itunes:episodeType></item><item><title><![CDATA[Episode 5: Resume Reviews, Counter-Espionage, and Incident Response]]></title><description><![CDATA[<p>Join hosts Justin, Rick, and Joe as they cover:</p><ul><li><strong>Resume Review Insights:</strong> Joe offers valuable tips on resume writing, focusing on showcasing accomplishments and using metrics to stand out.</li><li><strong>Passion Projects and Hobbies:</strong> The team discusses how personal projects and volunteer work can make resumes more compelling by demonstrating a passion for the field.</li><li><strong>Community Engagement at TRISS</strong>: The hosts invite listeners to their booth at the upcoming Three Rivers Information Security Symposium (TRISS), where they will be offering resume reviews and engaging with attendees.</li><li><strong>Counter-Espionage and Pagers</strong>: A fascinating look at the use of pagers in recent counter-espionage operations, analyzing their effectiveness and ethical concerns.</li><li><strong>Supply Chain Security Concerns:</strong> A discussion on the risks tied to supply chain vulnerabilities, focusing on hardware inspections.</li><li><strong>Tabletop Exercises in Cybersecurity</strong>: The hosts highlight the importance of tabletop exercises to prepare organizations for security incidents, contrasting them with current trends in incident response training.</li><li><strong>School Violence Threats:</strong> An examination of the rise in school violence threats and the challenges schools face in managing these situations.</li></ul><p><strong>Links</strong></p><ul><li><a href="https://www.threeriversinfosec.com/" rel="noopener noreferrer nofollow">Three Rivers Information Security Symposium (TRISS)</a></li><li><a href="https://www.dhs.gov/sites/default/files/2024-09/2024aepphasellusmaritimetradeandportcybersecurity.pdf" rel="noopener noreferrer nofollow">US Maritime Trade and Port Cybersecurity</a></li></ul><p><strong>Spirits</strong></p><ul><li>Boone 1833 12-Year-Old, Snyder's Flask (discontinued) - https://boonedistilling.com/</li></ul><p><strong>Hosts</strong></p><ul><li>Justin Leapline -<a href="https://www.linkedin.com/in/justinleapline/" rel="noopener noreferrer nofollow"> LinkedIn</a></li><li>Joe Wynn -<a href="https://www.linkedin.com/in/wynnjoe/" rel="noopener noreferrer nofollow"> LinkedIn</a></li><li>Rick Yocum -<a href="https://www.linkedin.com/in/rickyocum/" rel="noopener noreferrer nofollow"> LinkedIn</a></li></ul><p><strong>Connect with Us</strong></p><ul><li>Website:<a href="https://distilledsecuritypodcast.com" rel="noopener noreferrer nofollow"> Distilled Security Podcast</a></li><li>Twitter:<a href="https://twitter.com/DisSecPod" rel="noopener noreferrer nofollow"> @DisSecPod</a></li><li>Email: hello@distilledsecuritypodcast.com</li></ul><p><br /></p>]]></description><link>https://share.transistor.fm/s/1fdca557</link><guid isPermaLink="false">c0e394bd-00bf-414a-b9a7-cb666bad576c</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Wed, 02 Oct 2024 22:50:22 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/7da59dbe7265769d6b1d1db37454f7430e00810e2bc68f52f49beaf7a96202b5/eyJlcGlzb2RlSWQiOiI2NmZlMWJjMy0xZjdkLTQ4NzAtOWFmNi1kMGJlZjU3YjM2MDUiLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy8yNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgvZXBpc29kZXMvNjZmZTFiYzMtMWY3ZC00ODcwLTlhZjYtZDBiZWY1N2IzNjA1LzFmYjIwZTY3Lm1wMyJ9.mp3" length="61134249" type="audio/mpeg"/><itunes:summary>&lt;p&gt;Join hosts Justin, Rick, and Joe as they cover:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Resume Review Insights:&lt;/strong&gt; Joe offers valuable tips on resume writing, focusing on showcasing accomplishments and using metrics to stand out.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Passion Projects and Hobbies:&lt;/strong&gt; The team discusses how personal projects and volunteer work can make resumes more compelling by demonstrating a passion for the field.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Community Engagement at TRISS&lt;/strong&gt;: The hosts invite listeners to their booth at the upcoming Three Rivers Information Security Symposium (TRISS), where they will be offering resume reviews and engaging with attendees.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Counter-Espionage and Pagers&lt;/strong&gt;: A fascinating look at the use of pagers in recent counter-espionage operations, analyzing their effectiveness and ethical concerns.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Supply Chain Security Concerns:&lt;/strong&gt; A discussion on the risks tied to supply chain vulnerabilities, focusing on hardware inspections.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Tabletop Exercises in Cybersecurity&lt;/strong&gt;: The hosts highlight the importance of tabletop exercises to prepare organizations for security incidents, contrasting them with current trends in incident response training.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;School Violence Threats:&lt;/strong&gt; An examination of the rise in school violence threats and the challenges schools face in managing these situations.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Links&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;https://www.threeriversinfosec.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Three Rivers Information Security Symposium (TRISS)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.dhs.gov/sites/default/files/2024-09/2024aepphasellusmaritimetradeandportcybersecurity.pdf&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;US Maritime Trade and Port Cybersecurity&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Spirits&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Boone 1833 12-Year-Old, Snyder&apos;s Flask (discontinued) - https://boonedistilling.com/&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Hosts&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Justin Leapline -&lt;a href=&quot;https://www.linkedin.com/in/justinleapline/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; LinkedIn&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Joe Wynn -&lt;a href=&quot;https://www.linkedin.com/in/wynnjoe/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; LinkedIn&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Rick Yocum -&lt;a href=&quot;https://www.linkedin.com/in/rickyocum/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; LinkedIn&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Connect with Us&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Website:&lt;a href=&quot;https://distilledsecuritypodcast.com&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; Distilled Security Podcast&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Twitter:&lt;a href=&quot;https://twitter.com/DisSecPod&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; @DisSecPod&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Email: hello@distilledsecuritypodcast.com&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>01:03:39</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>5</itunes:episode><itunes:title>Episode 5: Resume Reviews, Counter-Espionage, and Incident Response</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Episode 11: Encrypted Messaging, Data Breaches, and Vulnerability Management]]></title><description><![CDATA[<p><strong>Episode 11 of the Distilled Security Podcast is here!</strong></p><p><br /><strong>Join us as we cover:</strong></p><ul><li>Signal, Encrypted Messaging, and Corporate Policy: A deep dive into the use of Signal in sensitive discussions—including a political mishap—and the implications for corporate communication policies, discovery, and compliance.</li><li>Oracle Cloud Breach Allegations: Evaluating breach claims, early response tactics, and the value of proactive key and credential rotation.</li><li>DNA Data, 23andMe, and Privacy Concerns: With 23andMe filing for bankruptcy, the team explores risks associated with sharing genetic data and broader privacy implications when personal information changes hands.</li><li>Hospital Data as Business Assets: A surprising look at how some companies are buying bankrupt hospitals—primarily for access to their medical datasets.</li><li>Vulnerability Management in the Real World: Tips on building practical, risk-based vulnerability management programs, understanding scanner severity versus real-world risk, and developing responsive processes that scale.</li></ul><p><strong>Spirits: </strong></p><ul><li>Calumet Farm Small Batch Bourbon Whiskey https://www.calumetbourbon.com/smallbatch</li></ul><p><strong>Hosts</strong></p><ul><li>Justin Leapline -<a href="https://www.linkedin.com/in/justinleapline/" rel="noopener noreferrer nofollow"> LinkedIn</a></li><li>Joe Wynn -<a href="https://www.linkedin.com/in/wynnjoe/" rel="noopener noreferrer nofollow"> LinkedIn</a></li><li>Rick Yocum -<a href="https://www.linkedin.com/in/rickyocum/" rel="noopener noreferrer nofollow"> LinkedIn</a></li></ul><p><strong>Connect with Us</strong></p><ul><li>Website:<a href="https://distilledsecuritypodcast.com" rel="noopener noreferrer nofollow"> Distilled Security Podcast</a></li><li>Twitter:<a href="https://twitter.com/DisSecPod" rel="noopener noreferrer nofollow"> @DisSecPod</a></li><li>Email: hello@distilledsecuritypodcast.com<p></p></li></ul>]]></description><link>https://share.transistor.fm/s/8076fdc0</link><guid isPermaLink="false">44253fb4-b339-4dee-8254-de1eb2078102</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Mon, 14 Apr 2025 13:45:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/70c5ceb69ad384d17b65ce16c2611402177dd19843b3ef9c637d198c55a1bfca/eyJlcGlzb2RlSWQiOiI4ZmRjNDkwYi1hZjZhLTQ4YjQtYmRiMS0zN2MyZjhkNDg3YTEiLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy8yNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgvZXBpc29kZXMvOGZkYzQ5MGItYWY2YS00OGI0LWJkYjEtMzdjMmY4ZDQ4N2ExLzY5MjM1MzA2Lm1wMyJ9.mp3" length="86462645" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;strong&gt;Episode 11 of the Distilled Security Podcast is here!&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;Join us as we cover:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Signal, Encrypted Messaging, and Corporate Policy: A deep dive into the use of Signal in sensitive discussions—including a political mishap—and the implications for corporate communication policies, discovery, and compliance.&lt;/li&gt;&lt;li&gt;Oracle Cloud Breach Allegations: Evaluating breach claims, early response tactics, and the value of proactive key and credential rotation.&lt;/li&gt;&lt;li&gt;DNA Data, 23andMe, and Privacy Concerns: With 23andMe filing for bankruptcy, the team explores risks associated with sharing genetic data and broader privacy implications when personal information changes hands.&lt;/li&gt;&lt;li&gt;Hospital Data as Business Assets: A surprising look at how some companies are buying bankrupt hospitals—primarily for access to their medical datasets.&lt;/li&gt;&lt;li&gt;Vulnerability Management in the Real World: Tips on building practical, risk-based vulnerability management programs, understanding scanner severity versus real-world risk, and developing responsive processes that scale.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Spirits: &lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Calumet Farm Small Batch Bourbon Whiskey https://www.calumetbourbon.com/smallbatch&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Hosts&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Justin Leapline -&lt;a href=&quot;https://www.linkedin.com/in/justinleapline/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; LinkedIn&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Joe Wynn -&lt;a href=&quot;https://www.linkedin.com/in/wynnjoe/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; LinkedIn&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Rick Yocum -&lt;a href=&quot;https://www.linkedin.com/in/rickyocum/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; LinkedIn&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Connect with Us&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Website:&lt;a href=&quot;https://distilledsecuritypodcast.com&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; Distilled Security Podcast&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Twitter:&lt;a href=&quot;https://twitter.com/DisSecPod&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; @DisSecPod&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Email: hello@distilledsecuritypodcast.com&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>01:30:02</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>11</itunes:episode><itunes:title>Episode 11: Encrypted Messaging, Data Breaches, and Vulnerability Management</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Episode 19: Cloudflare Outage, AI-Powered Attacks & The Rise of GRC Engineering | Distilled Security Podcast]]></title><description><![CDATA[<p>In this episode, we break down a major Cloudflare outage, explore how a nation-state used AI agents to automate a cyberattack, and discuss the growing risks around MCP integrations. We also highlight why GRC Engineering is becoming essential to modern security programs and wrap up with key regulatory updates, including CMMC changes affecting thousands of contractors.</p><p><strong>Topics covered: </strong><br />• Cloudflare outage impact and root cause<br />• Nation-state attack using AI agents to automate intrusion steps<br />• MCP (Model Context Protocol): power, risks, and examples<br />• Why GRC Engineering is the future of compliance and automation<br />• Updates on GDPR, ISO 27701, California AB 5866, and SEC rules<br />• CMMC assessor shortages and what organizations must prepare for</p><p><strong>Spirit of the Episode</strong><br />• Knob Creek 21-Year Limited Release, rich caramel notes, heavy char, smooth for 100 proof</p><p><strong>Timestamps</strong></p><ul><li>0:02—Cloudflare Outage Stories &amp; Global Impact</li><li>3:07—Root Cause, Not a Cyberattack &amp; Third-Party Risk Reality</li><li>10:38 - China Uses Anthropic’s Claude + MCP for Automated Cyberattacks</li><li>14:17 - Full AI Attack Lifecycle Explained</li><li>27:18 - MCP: The API for AI &amp; Its Security Risks</li><li>44:05 - Bourbon Break: Knob Creek 21-Year Review</li><li>50:02 - GRC Engineering Deep Dive: Automation &amp; Controls-as-Code</li><li>1:24:13 - Regulatory Roundup: GDPR, ISO 27701, California AB 566, SEC SP</li><li>1:44:27 - CMMC 2.0 Crisis: Auditor Shortages &amp; DoD Contract Impact</li><li>2:11:20 - Closing Thoughts &amp; Episode Wrap-Up</li></ul><p><strong>Hosts</strong></p><ul><li>Justin Leapline – @justinleapline</li><li>Joe Wynn – @wynnjoe</li><li>Rick Yocum – @rickyocum</li></ul><p><strong>Guest</strong></p><ul><li>Matthew J. Schiavone - @Sikitch</li></ul><p><strong>Connect with Us</strong></p><ul><li>Website: distilledsecuritypodcast.com</li><li>X:  @DisSecPod</li><li>Email: hello@distilledsecuritypodcast.com</li></ul>]]></description><link>https://share.transistor.fm/s/4bf68cf9</link><guid isPermaLink="false">cdca3c1c-aadb-40f8-992a-99aaae719e02</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Mon, 08 Dec 2025 14:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/a1b1dce7f1ecde2e53c1eee1292c7a5fc048313d3fd919b7ee7f80cfef530334/eyJlcGlzb2RlSWQiOiJmODY4ZTk4Yi1iNTY3LTRjM2UtYjgzNS1iNDc1Y2I3NThjZWUiLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy8yNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgvZXBpc29kZXMvZjg2OGU5OGItYjU2Ny00YzNlLWI4MzUtYjQ3NWNiNzU4Y2VlLzk5OWM1MTM4Lm1wMyJ9.mp3" length="126887170" type="audio/mpeg"/><itunes:summary>&lt;p&gt;In this episode, we break down a major Cloudflare outage, explore how a nation-state used AI agents to automate a cyberattack, and discuss the growing risks around MCP integrations. We also highlight why GRC Engineering is becoming essential to modern security programs and wrap up with key regulatory updates, including CMMC changes affecting thousands of contractors.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Topics covered: &lt;/strong&gt;&lt;br /&gt;• Cloudflare outage impact and root cause&lt;br /&gt;• Nation-state attack using AI agents to automate intrusion steps&lt;br /&gt;• MCP (Model Context Protocol): power, risks, and examples&lt;br /&gt;• Why GRC Engineering is the future of compliance and automation&lt;br /&gt;• Updates on GDPR, ISO 27701, California AB 5866, and SEC rules&lt;br /&gt;• CMMC assessor shortages and what organizations must prepare for&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Spirit of the Episode&lt;/strong&gt;&lt;br /&gt;• Knob Creek 21-Year Limited Release, rich caramel notes, heavy char, smooth for 100 proof&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Timestamps&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;0:02—Cloudflare Outage Stories &amp;amp; Global Impact&lt;/li&gt;&lt;li&gt;3:07—Root Cause, Not a Cyberattack &amp;amp; Third-Party Risk Reality&lt;/li&gt;&lt;li&gt;10:38 - China Uses Anthropic’s Claude + MCP for Automated Cyberattacks&lt;/li&gt;&lt;li&gt;14:17 - Full AI Attack Lifecycle Explained&lt;/li&gt;&lt;li&gt;27:18 - MCP: The API for AI &amp;amp; Its Security Risks&lt;/li&gt;&lt;li&gt;44:05 - Bourbon Break: Knob Creek 21-Year Review&lt;/li&gt;&lt;li&gt;50:02 - GRC Engineering Deep Dive: Automation &amp;amp; Controls-as-Code&lt;/li&gt;&lt;li&gt;1:24:13 - Regulatory Roundup: GDPR, ISO 27701, California AB 566, SEC SP&lt;/li&gt;&lt;li&gt;1:44:27 - CMMC 2.0 Crisis: Auditor Shortages &amp;amp; DoD Contract Impact&lt;/li&gt;&lt;li&gt;2:11:20 - Closing Thoughts &amp;amp; Episode Wrap-Up&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Hosts&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Justin Leapline – @justinleapline&lt;/li&gt;&lt;li&gt;Joe Wynn – @wynnjoe&lt;/li&gt;&lt;li&gt;Rick Yocum – @rickyocum&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Guest&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Matthew J. Schiavone - @Sikitch&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Connect with Us&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Website: distilledsecuritypodcast.com&lt;/li&gt;&lt;li&gt;X:  @DisSecPod&lt;/li&gt;&lt;li&gt;Email: hello@distilledsecuritypodcast.com&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>02:12:09</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>19</itunes:episode><itunes:title>Episode 19: Cloudflare Outage, AI-Powered Attacks &amp; The Rise of GRC Engineering | Distilled Security Podcast</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Episode 2: Tailoring Security Frameworks & Leveraging AI]]></title><description><![CDATA[<p><strong>Episode 2 of the Distilled Security Podcast is here!</strong></p><p><br />Join us this week as we jump into: </p><ul><li><strong>Exploring the critical importance of tailoring security frameworks:</strong> Aligning with an organization's specific goals and objectives</li><li><strong>Highlighting frameworks like NIST CSF and CIS</strong> to advance security programs effectively</li><li>Insights on aligning KPIs with the NIST CSF framework</li><li>Complementary use of frameworks like CIS to enhance security control measurement</li><li>Perspective on compliance and regulatory requirements</li><li>The role of AI in security programs</li><li><strong>Threats posed by deepfakes:</strong> Incorporating safeguards to protect organizations from deepfake risks and effectively leverage AI within security programs</li></ul><p><strong>Chapters</strong><br />00:00:00 - Introduction and Episode Overview<br />00:00:44 - Discussion on Security Frameworks<br />00:05:43 - Tailoring Frameworks<br />00:08:19 - Mapping and Compliance Challenges<br />00:17:16 - Tailoring for Small Organizations<br />00:19:15 - Upcoming Conferences<br />00:21:30 - Bourbon Review<br />00:25:00 - Audit Preparation Tips<br />00:27:02 - AI in Security<br />00:35:09 - Privacy Concerns with AI Toys<br />00:41:22 - Deepfakes in Security<br />01:05:59 - Closing Remarks</p><p><strong>Links and references</strong><br />https://securecontrolsframework.com</p><p>https://www.nist.gov/cyberframework</p><p>https://csrc.nist.gov/pubs/sp/1300/final</p><p>https://www.cisecurity.org/insights/white-papers/cis-controls-sme-guide</p><p><strong>Drink</strong><br />Whiskey Thief Door Knocker</p><p><a href="https://www.nist.gov/cyberframework" rel="noopener noreferrer nofollow"><br /></a><strong>Hosts</strong></p><ul><li>Justin Leapline - <a href="https://www.linkedin.com/in/justinleapline/" rel="noopener noreferrer nofollow">https://www.linkedin.com/in/justinleapline/</a></li><li>Joe Wynn - <a href="https://www.linkedin.com/in/wynnjoe/" rel="noopener noreferrer nofollow">https://www.linkedin.com/in/wynnjoe/</a></li><li>Rick Yocum - <a href="https://www.linkedin.com/in/rickyocum/" rel="noopener noreferrer nofollow">https://www.linkedin.com/in/rickyocum/</a></li></ul><p>Connect with Us</p><ul><li>Website: <a href="https://distilledsecuritypodcast.com" rel="noopener noreferrer nofollow">https://distilledsecuritypodcast.com</a></li><li>Twitter: @DisSecPod</li><li>Email: hello@distilledsecuritypodcast.com</li></ul>]]></description><link>https://share.transistor.fm/s/e819c167</link><guid isPermaLink="false">34b0f39f-3807-4399-ad3d-932dfe5d2d41</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Mon, 08 Jul 2024 14:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/c776e555d8e58297a732cd21cb3711cb8fb0e6fe60c864a6b0faf5eba137880b/eyJlcGlzb2RlSWQiOiJjZDE3NTQ1My1hOTRhLTQxYmUtODAxZi05OTY4MGI3MWJmYmQiLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy8yNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgvZXBpc29kZXMvY2QxNzU0NTMtYTk0YS00MWJlLTgwMWYtOTk2ODBiNzFiZmJkL2IyYjZhMTBiLm1wMyJ9.mp3" length="62752994" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;strong&gt;Episode 2 of the Distilled Security Podcast is here!&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;Join us this week as we jump into: &lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Exploring the critical importance of tailoring security frameworks:&lt;/strong&gt; Aligning with an organization&apos;s specific goals and objectives&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Highlighting frameworks like NIST CSF and CIS&lt;/strong&gt; to advance security programs effectively&lt;/li&gt;&lt;li&gt;Insights on aligning KPIs with the NIST CSF framework&lt;/li&gt;&lt;li&gt;Complementary use of frameworks like CIS to enhance security control measurement&lt;/li&gt;&lt;li&gt;Perspective on compliance and regulatory requirements&lt;/li&gt;&lt;li&gt;The role of AI in security programs&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Threats posed by deepfakes:&lt;/strong&gt; Incorporating safeguards to protect organizations from deepfake risks and effectively leverage AI within security programs&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Chapters&lt;/strong&gt;&lt;br /&gt;00:00:00 - Introduction and Episode Overview&lt;br /&gt;00:00:44 - Discussion on Security Frameworks&lt;br /&gt;00:05:43 - Tailoring Frameworks&lt;br /&gt;00:08:19 - Mapping and Compliance Challenges&lt;br /&gt;00:17:16 - Tailoring for Small Organizations&lt;br /&gt;00:19:15 - Upcoming Conferences&lt;br /&gt;00:21:30 - Bourbon Review&lt;br /&gt;00:25:00 - Audit Preparation Tips&lt;br /&gt;00:27:02 - AI in Security&lt;br /&gt;00:35:09 - Privacy Concerns with AI Toys&lt;br /&gt;00:41:22 - Deepfakes in Security&lt;br /&gt;01:05:59 - Closing Remarks&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Links and references&lt;/strong&gt;&lt;br /&gt;https://securecontrolsframework.com&lt;/p&gt;&lt;p&gt;https://www.nist.gov/cyberframework&lt;/p&gt;&lt;p&gt;https://csrc.nist.gov/pubs/sp/1300/final&lt;/p&gt;&lt;p&gt;https://www.cisecurity.org/insights/white-papers/cis-controls-sme-guide&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Drink&lt;/strong&gt;&lt;br /&gt;Whiskey Thief Door Knocker&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.nist.gov/cyberframework&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;&lt;br /&gt;&lt;/a&gt;&lt;strong&gt;Hosts&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Justin Leapline - &lt;a href=&quot;https://www.linkedin.com/in/justinleapline/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://www.linkedin.com/in/justinleapline/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Joe Wynn - &lt;a href=&quot;https://www.linkedin.com/in/wynnjoe/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://www.linkedin.com/in/wynnjoe/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Rick Yocum - &lt;a href=&quot;https://www.linkedin.com/in/rickyocum/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://www.linkedin.com/in/rickyocum/&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Connect with Us&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Website: &lt;a href=&quot;https://distilledsecuritypodcast.com&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://distilledsecuritypodcast.com&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Twitter: @DisSecPod&lt;/li&gt;&lt;li&gt;Email: hello@distilledsecuritypodcast.com&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>01:05:20</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>2</itunes:episode><itunes:title>Episode 2: Tailoring Security Frameworks &amp; Leveraging AI</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Episode 4: Ethics in Cybersecurity, Career Development, and Data Protection]]></title><description><![CDATA[<p><strong>Episode 4: Ethics in Cybersecurity, Career Development, and Data Protection<br /></strong><br /></p><p>In Episode 4, we are joined by <strong>Doug Salah</strong> to explore some critical topics in cybersecurity and career growth.</p><p><br /><strong>Key Topics</strong></p><ul><li><strong>Doug Salah’s Cybersecurity Journey</strong>: His transition into cybersecurity and current role in the industry.</li><li><strong>Networking in Cybersecurity</strong>: The value of building connections at cybersecurity conferences.</li><li><strong>TRISS (Three Rivers Information Security Symposium)</strong>: Insights into TRISS, its scholarships, and its impact on the community.</li><li><strong>Mid-Career Development</strong>: Doug’s thoughts on transitioning mid-career, setting goals, and maintaining integrity.</li><li><strong>Cybersecurity Ethics</strong>: A deep dive into ethics in the industry, ethical decision-making, and creating a Cyber Code of Honor.</li><li><strong>The Four Agreements</strong>: How Doug relates his personal ethics to the principles in <em>The Four Agreements</em>.</li><li><strong>Featured Spirit – Compass Box Spice Tree Scotch</strong>: A review of this week’s featured Scotch.</li><li><strong>National Public Data Background Check Breach</strong>: Discussion of the recent breach and its implications for data protection.</li><li><strong>Data Protection Tips</strong>: Tips on freezing credit and using services like <em>Delete Me</em> to protect personal data.</li></ul><p><strong>Links</strong></p><ul><li><a href="https://www.threeriversinfosec.com/" rel="noopener noreferrer nofollow">Three Rivers Information Security Symposium (TRISS)</a> - <a href="https://www.threeriversinfosec.com/" rel="noopener noreferrer nofollow">https://www.threeriversinfosec.com/</a></li><li><a href="https://www.amazon.com/Four-Agreements-Practical-Personal-Freedom/dp/1878424319" rel="noopener noreferrer nofollow">The Four Agreements</a> - <a href="https://www.amazon.com/Four-Agreements-Practical-Personal-Freedom/dp/1878424319" rel="noopener noreferrer nofollow">https://www.amazon.com/Four-Agreements-Practical-Personal-Freedom/dp/1878424319</a></li><li><a href="https://joindeleteme.com/" rel="noopener noreferrer nofollow">Delete Me Service</a> - <a href="https://joindeleteme.com/" rel="noopener noreferrer nofollow">https://joindeleteme.com/</a></li><li><a href="https://cybercodeofhonor.com/" rel="noopener noreferrer nofollow">The Code Of Honor - Embracing Ethics in Cybersecurity</a></li></ul><p><strong>Spirits</strong></p><ul><li><a href="https://www.compassboxwhisky.com/products/the-spice-tree" rel="noopener noreferrer nofollow">Compass Box Spice Tree Scotch</a> - <a href="https://www.compassboxwhisky.com/products/the-spice-tree" rel="noopener noreferrer nofollow">https://www.compassboxwhisky.com/products/the-spice-tree</a></li></ul><p><strong>Hosts</strong></p><ul><li>Justin Leapline - <a href="https://www.linkedin.com/in/justinleapline/" rel="noopener noreferrer nofollow">https://www.linkedin.com/in/justinleapline/</a></li><li>Joe Wynn - <a href="https://www.linkedin.com/in/wynnjoe/" rel="noopener noreferrer nofollow">https://www.linkedin.com/in/wynnjoe/</a></li><li>Rick Yocum - <a href="https://www.linkedin.com/in/rickyocum/" rel="noopener noreferrer nofollow">https://www.linkedin.com/in/rickyocum/</a></li></ul><p><strong>Guest</strong></p><ul><li>Doug Salah - <a href="https://www.linkedin.com/in/dougsalah/" rel="noopener noreferrer nofollow">https://www.linkedin.com/in/dougsalah/</a></li></ul><p><strong>Connect with Us</strong></p><ul><li>Website:<a href="https://distilledsecuritypodcast.com" rel="noopener noreferrer nofollow"> Distilled Security Podcast</a></li><li>Twitter:<a href="https://twitter.com/DisSecPod" rel="noopener noreferrer nofollow"> @DisSecPod</a></li><li>Email: hello@distilledsecuritypodcast.com<p></p></li></ul>]]></description><link>https://share.transistor.fm/s/dfb0b1c7</link><guid isPermaLink="false">6c9e6963-fad9-4692-82e7-42f39eb267c0</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Mon, 09 Sep 2024 15:02:18 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/cd6bd8317728130715990a96b4644e4f93d6991d994f91542a55ea402ec4fe71/eyJlcGlzb2RlSWQiOiJkMjg5Y2I0NS01MGExLTRhOGQtYTRkYy0wNTgyN2VmMjQyMGUiLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy8yNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgvZXBpc29kZXMvZDI4OWNiNDUtNTBhMS00YThkLWE0ZGMtMDU4MjdlZjI0MjBlL2M4YTQ4OGUxLm1wMyJ9.mp3" length="70504837" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;strong&gt;Episode 4: Ethics in Cybersecurity, Career Development, and Data Protection&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;In Episode 4, we are joined by &lt;strong&gt;Doug Salah&lt;/strong&gt; to explore some critical topics in cybersecurity and career growth.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;Key Topics&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Doug Salah’s Cybersecurity Journey&lt;/strong&gt;: His transition into cybersecurity and current role in the industry.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Networking in Cybersecurity&lt;/strong&gt;: The value of building connections at cybersecurity conferences.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;TRISS (Three Rivers Information Security Symposium)&lt;/strong&gt;: Insights into TRISS, its scholarships, and its impact on the community.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Mid-Career Development&lt;/strong&gt;: Doug’s thoughts on transitioning mid-career, setting goals, and maintaining integrity.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Cybersecurity Ethics&lt;/strong&gt;: A deep dive into ethics in the industry, ethical decision-making, and creating a Cyber Code of Honor.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;The Four Agreements&lt;/strong&gt;: How Doug relates his personal ethics to the principles in &lt;em&gt;The Four Agreements&lt;/em&gt;.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Featured Spirit – Compass Box Spice Tree Scotch&lt;/strong&gt;: A review of this week’s featured Scotch.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;National Public Data Background Check Breach&lt;/strong&gt;: Discussion of the recent breach and its implications for data protection.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Data Protection Tips&lt;/strong&gt;: Tips on freezing credit and using services like &lt;em&gt;Delete Me&lt;/em&gt; to protect personal data.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Links&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;https://www.threeriversinfosec.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Three Rivers Information Security Symposium (TRISS)&lt;/a&gt; - &lt;a href=&quot;https://www.threeriversinfosec.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://www.threeriversinfosec.com/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.amazon.com/Four-Agreements-Practical-Personal-Freedom/dp/1878424319&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;The Four Agreements&lt;/a&gt; - &lt;a href=&quot;https://www.amazon.com/Four-Agreements-Practical-Personal-Freedom/dp/1878424319&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://www.amazon.com/Four-Agreements-Practical-Personal-Freedom/dp/1878424319&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://joindeleteme.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Delete Me Service&lt;/a&gt; - &lt;a href=&quot;https://joindeleteme.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://joindeleteme.com/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://cybercodeofhonor.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;The Code Of Honor - Embracing Ethics in Cybersecurity&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Spirits&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;https://www.compassboxwhisky.com/products/the-spice-tree&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Compass Box Spice Tree Scotch&lt;/a&gt; - &lt;a href=&quot;https://www.compassboxwhisky.com/products/the-spice-tree&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://www.compassboxwhisky.com/products/the-spice-tree&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Hosts&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Justin Leapline - &lt;a href=&quot;https://www.linkedin.com/in/justinleapline/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://www.linkedin.com/in/justinleapline/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Joe Wynn - &lt;a href=&quot;https://www.linkedin.com/in/wynnjoe/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://www.linkedin.com/in/wynnjoe/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Rick Yocum - &lt;a href=&quot;https://www.linkedin.com/in/rickyocum/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://www.linkedin.com/in/rickyocum/&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Guest&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Doug Salah - &lt;a href=&quot;https://www.linkedin.com/in/dougsalah/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://www.linkedin.com/in/dougsalah/&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Connect with Us&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Website:&lt;a href=&quot;https://distilledsecuritypodcast.com&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; Distilled Security Podcast&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Twitter:&lt;a href=&quot;https://twitter.com/DisSecPod&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; @DisSecPod&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Email: hello@distilledsecuritypodcast.com&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>01:13:25</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>4</itunes:episode><itunes:title>Episode 4: Ethics in Cybersecurity, Career Development, and Data Protection</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Episode 8: Whiskey, Quantum Computing, and Executive Protection]]></title><description><![CDATA[<p><br />🎙️ Episode 8 of the Distilled Security Podcast is here! 🔐🥃</p><p>🔎 Join us as we explore:</p><ul><li><strong>The Whiskey Rebellion and Craft Distilling</strong>: A dive into the history of the Whiskey Rebellion and what it means for today’s distillers. Learn about Iron City Distilling, creating national brand-quality spirits, and the significance of the Bessemer brand name.</li><li><strong>Whiskey Craftsmanship</strong>: Insights into chamber still distillation, the balance of maturation versus aging, and premium craft whiskey production.</li><li><strong>Executive Protection and Privacy</strong>: Strategies for workplace safety, reducing online risks, and managing personal branding in crises.</li><li><strong>Quantum Computing Risks</strong>: A look at Google's Willow chip, the implications of quantum computing on cybersecurity, and the need for post-quantum cryptographic protocols.</li><li><strong>Modern Password Challenges</strong>: Discussing the future of passwordless login, phishing risks, dark web breaches, and the evolving standards of password compliance.<p></p></li></ul><p>🌟 <strong>Spirit: </strong>Iron City Distilling Distillers Reserve – A 6-Year Craft Masterpiece!</p><p><strong>🎙️ Hosts</strong></p><ul><li>Justin Leapline -<a href="https://www.linkedin.com/in/justinleapline/" rel="noopener noreferrer nofollow"> LinkedIn</a></li><li>Joe Wynn -<a href="https://www.linkedin.com/in/wynnjoe/" rel="noopener noreferrer nofollow"> LinkedIn</a></li><li>Rick Yocum -<a href="https://www.linkedin.com/in/rickyocum/" rel="noopener noreferrer nofollow"> LinkedIn<br /></a><br /></li></ul><p>🤝 <strong>Guest</strong></p><ul><li>Eddie Kubit -<a href="https://www.linkedin.com/in/eddie-kubit-28122b3/" rel="noopener noreferrer nofollow"> LinkedIn </a></li></ul><p><br /></p><p><strong>📲 Connect with Us</strong></p><ul><li>Website:<a href="https://distilledsecuritypodcast.com" rel="noopener noreferrer nofollow"> Distilled Security Podcast</a></li><li>Twitter:<a href="https://twitter.com/DisSecPod" rel="noopener noreferrer nofollow"> @DisSecPod</a></li><li>Email: hello@distilledsecuritypodcast.com<p></p></li></ul><p>🕐 Time Stamps</p><p>[00:00:00] Introduction<br />[00:00:09] Eddie’s Career Transition<br />[00:03:00] Whiskey Rebellion and Craft Distilling<br />[00:06:00] Joining Iron City Distilling<br />[00:10:00] Unique Approach at Iron City Distilling<br />[00:19:00] Traditional Whiskey Making Process<br />[00:28:30] Executive Protection and Privacy<br />[00:39:00] Practical Security Measures for Executives<br />[00:50:00] Google’s Quantum Computing and Cybersecurity Risks<br />[00:57:00] Post-Quantum Cryptography<br />[01:06:00] Modern Password Practices<br />[01:20:00] Closing Thoughts</p>]]></description><link>https://share.transistor.fm/s/a9ba5dad</link><guid isPermaLink="false">398893b4-dcd3-4473-98a1-97800586bf36</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Tue, 07 Jan 2025 15:16:50 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/05c28561a02f3673a61ef9b428836a2607dd0755a59a6f021d491d9e8774cf92/eyJlcGlzb2RlSWQiOiJmNzM4ZTkzZC1lZjc0LTRkOTctOGQ0MC1jZjdlMzQ3ZGM4NDYiLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy8yNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgvZXBpc29kZXMvZjczOGU5M2QtZWY3NC00ZDk3LThkNDAtY2Y3ZTM0N2RjODQ2LzJjOGI3NTUxLm1wMyJ9.mp3" length="78334161" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;br /&gt;🎙️ Episode 8 of the Distilled Security Podcast is here! 🔐🥃&lt;/p&gt;&lt;p&gt;🔎 Join us as we explore:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;The Whiskey Rebellion and Craft Distilling&lt;/strong&gt;: A dive into the history of the Whiskey Rebellion and what it means for today’s distillers. Learn about Iron City Distilling, creating national brand-quality spirits, and the significance of the Bessemer brand name.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Whiskey Craftsmanship&lt;/strong&gt;: Insights into chamber still distillation, the balance of maturation versus aging, and premium craft whiskey production.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Executive Protection and Privacy&lt;/strong&gt;: Strategies for workplace safety, reducing online risks, and managing personal branding in crises.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Quantum Computing Risks&lt;/strong&gt;: A look at Google&apos;s Willow chip, the implications of quantum computing on cybersecurity, and the need for post-quantum cryptographic protocols.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Modern Password Challenges&lt;/strong&gt;: Discussing the future of passwordless login, phishing risks, dark web breaches, and the evolving standards of password compliance.&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;🌟 &lt;strong&gt;Spirit: &lt;/strong&gt;Iron City Distilling Distillers Reserve – A 6-Year Craft Masterpiece!&lt;/p&gt;&lt;p&gt;&lt;strong&gt;🎙️ Hosts&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Justin Leapline -&lt;a href=&quot;https://www.linkedin.com/in/justinleapline/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; LinkedIn&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Joe Wynn -&lt;a href=&quot;https://www.linkedin.com/in/wynnjoe/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; LinkedIn&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Rick Yocum -&lt;a href=&quot;https://www.linkedin.com/in/rickyocum/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; LinkedIn&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;🤝 &lt;strong&gt;Guest&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Eddie Kubit -&lt;a href=&quot;https://www.linkedin.com/in/eddie-kubit-28122b3/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; LinkedIn &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;📲 Connect with Us&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Website:&lt;a href=&quot;https://distilledsecuritypodcast.com&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; Distilled Security Podcast&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Twitter:&lt;a href=&quot;https://twitter.com/DisSecPod&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; @DisSecPod&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Email: hello@distilledsecuritypodcast.com&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;🕐 Time Stamps&lt;/p&gt;&lt;p&gt;[00:00:00] Introduction&lt;br /&gt;[00:00:09] Eddie’s Career Transition&lt;br /&gt;[00:03:00] Whiskey Rebellion and Craft Distilling&lt;br /&gt;[00:06:00] Joining Iron City Distilling&lt;br /&gt;[00:10:00] Unique Approach at Iron City Distilling&lt;br /&gt;[00:19:00] Traditional Whiskey Making Process&lt;br /&gt;[00:28:30] Executive Protection and Privacy&lt;br /&gt;[00:39:00] Practical Security Measures for Executives&lt;br /&gt;[00:50:00] Google’s Quantum Computing and Cybersecurity Risks&lt;br /&gt;[00:57:00] Post-Quantum Cryptography&lt;br /&gt;[01:06:00] Modern Password Practices&lt;br /&gt;[01:20:00] Closing Thoughts&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>01:21:34</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>8</itunes:episode><itunes:title>Episode 8: Whiskey, Quantum Computing, and Executive Protection</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Episode 23: Nobody read the report]]></title><description><![CDATA[<p>In this episode of the <em>Distilled Security Podcast</em>, we break down the Delve scandal—flawed SOC 2 reports, copy-pasted content, and oversight failures that expose deeper issues in compliance-as-a-service. Joined by Matthew J. Schiavone, we examine auditor accountability, quality review gaps, and key differences between SOC 2 and ISO 27001.</p><p>We also cover what companies should demand from auditors, the role of automation, and whether this scandal will drive real change in the industry.</p><p><strong> Topics Covered</strong></p><ul><li>The Delve scandal—leaked reports, copy-pasted audits &amp; pervasive deficiencies</li><li>The AICPA peer review process &amp; AC Corp's adverse findings</li><li>SOC 2 vs ISO 27001—oversight models, witness audits &amp; accreditation</li><li>The incentive structure driving compliance to the bottom</li><li>Compliance automation — what works, what doesn't &amp; AI's real role</li><li>What to ask your auditor before signing anything</li><li>Trust centers — done right vs. compliance theater</li><li>Is SOC 2 dead? What needs to change &amp; who has to change it</li></ul><p><br /></p><p><strong>Hosts</strong></p><ul><li>Justin Leapline – @justinleapline</li><li>Joe Wynn – @wynnjoe</li><li>Rick Yocum – @rickyocum</li></ul><p><strong>Hosts</strong></p><ul><li>Matthew J. Schiavone - (Sikich) </li></ul><p><br /><strong>Connect with Us</strong></p><ul><li>Website: distilledsecuritypodcast.com</li><li>X:  @DisSecPod</li><li>Email: hello@distilledsecuritypodcast.com</li></ul>]]></description><link>https://share.transistor.fm/s/2188c59d</link><guid isPermaLink="false">613b0d65-6a3e-4658-bdb0-4278efbfe070</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Tue, 14 Apr 2026 12:55:48 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/5a9bf8b24bb086b17913636d7b7ae15a9031ed29b75e6d7a9cb694b50d78a852/eyJlcGlzb2RlSWQiOiJmODY3Yjg4ZC0zYWM1LTRjZDgtYWEzYi1iMDQ3MzZhYWJjZTUiLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy8yNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgvZXBpc29kZXMvZjg2N2I4OGQtM2FjNS00Y2Q4LWFhM2ItYjA0NzM2YWFiY2U1Lzg0MzY0YTg5Lm1wMyJ9.mp3" length="126191767" type="audio/mpeg"/><itunes:summary>&lt;p&gt;In this episode of the &lt;em&gt;Distilled Security Podcast&lt;/em&gt;, we break down the Delve scandal—flawed SOC 2 reports, copy-pasted content, and oversight failures that expose deeper issues in compliance-as-a-service. Joined by Matthew J. Schiavone, we examine auditor accountability, quality review gaps, and key differences between SOC 2 and ISO 27001.&lt;/p&gt;&lt;p&gt;We also cover what companies should demand from auditors, the role of automation, and whether this scandal will drive real change in the industry.&lt;/p&gt;&lt;p&gt;&lt;strong&gt; Topics Covered&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The Delve scandal—leaked reports, copy-pasted audits &amp;amp; pervasive deficiencies&lt;/li&gt;&lt;li&gt;The AICPA peer review process &amp;amp; AC Corp&apos;s adverse findings&lt;/li&gt;&lt;li&gt;SOC 2 vs ISO 27001—oversight models, witness audits &amp;amp; accreditation&lt;/li&gt;&lt;li&gt;The incentive structure driving compliance to the bottom&lt;/li&gt;&lt;li&gt;Compliance automation — what works, what doesn&apos;t &amp;amp; AI&apos;s real role&lt;/li&gt;&lt;li&gt;What to ask your auditor before signing anything&lt;/li&gt;&lt;li&gt;Trust centers — done right vs. compliance theater&lt;/li&gt;&lt;li&gt;Is SOC 2 dead? What needs to change &amp;amp; who has to change it&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Hosts&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Justin Leapline – @justinleapline&lt;/li&gt;&lt;li&gt;Joe Wynn – @wynnjoe&lt;/li&gt;&lt;li&gt;Rick Yocum – @rickyocum&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Hosts&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Matthew J. Schiavone - (Sikich) &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;Connect with Us&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Website: distilledsecuritypodcast.com&lt;/li&gt;&lt;li&gt;X:  @DisSecPod&lt;/li&gt;&lt;li&gt;Email: hello@distilledsecuritypodcast.com&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>02:10:10</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>23</itunes:episode><itunes:title>Episode 23: Nobody read the report</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Episode 16: When Metrics Mislead: Security Scoring, Board Gaps, and vGRC]]></title><description><![CDATA[<p><strong><br />Episode 16: When Metrics Mislead: Security Scoring, Board Gaps, and vGRC<br /></strong><br /></p><p><br /></p><p><strong><br />Episode 16 of the Distilled Security Podcast is here!</strong></p><p><br />In this episode, Justin, Joe, and Rick christen the new studio and dive into some of the trickiest challenges in measuring, reporting, and governing security programs. From maturity models to board reporting, the conversation unpacks how scoring systems can mislead, how to communicate bad news effectively, and why boards need more than just “checkbox” cyber expertise.</p><p>The team also explores the rise of <strong>vGRC (Virtual GRC) services</strong>—what they are, how they differ from vCISO offerings, and when organizations should consider fractional models. And of course, no episode would be complete without a pour: this week, a rich <strong>Woodford Reserve Double Double Oaked</strong> bourbon.</p><p><strong><br />Topics Covered</strong></p><ul><li><strong>New Studio Upgrade</strong>: Behind-the-scenes on mics, cameras, and why the couch had to go.<p></p></li><li><strong>Measuring to the Score</strong>: The dangers of chasing maturity numbers instead of real security outcomes.<p></p></li><li><strong>Scoping, Rubrics &amp; Auditor Whim</strong>: Why assessments are subjective and how leadership often misunderstands the results.<p></p></li><li><strong>Cultural Incentives</strong>: How bonuses, compliance checkboxes, and “auditor shopping” distort security reporting.<p></p></li><li><strong>Prepping for New Tools</strong>: Setting expectations with leadership when visibility spikes after deploying monitoring or vulnerability tools.<p></p></li><li><strong>Boards and Cybersecurity Expertise</strong>: Should cyber knowledge be mandated at the board level—or does it risk creating the illusion of safety?<p></p></li><li><strong>Virtual GRC vs. vCISO</strong>: What fractional GRC services really deliver, how they differ from vCISO roles, and why naming clarity matters.<p></p></li><li><strong>Bourbon Review</strong>: Woodford Reserve Double Double Oaked — syrupy, smooth, and perfect for a holiday pour.<p></p></li></ul><p><strong>Hosts</strong></p><ul><li>Justin Leapline</li><li>Joe Wynn</li><li>Rick Yocum<p></p></li></ul><p><strong>Connect with Us<br /></strong> 🌐 Website:<a href="http://distilledsecuritypodcast.com?utm_source=chatgpt.com" rel="noopener noreferrer nofollow"> distilledsecuritypodcast.com<br /></a> 🐦 Twitter:<a href="https://twitter.com/DisSecPod?utm_source=chatgpt.com" rel="noopener noreferrer nofollow"> @DisSecPod<br /></a> 📧 Email: hello@distilledsecuritypodcast.com</p><p><br /></p>]]></description><link>https://share.transistor.fm/s/4999b411</link><guid isPermaLink="false">79330c8f-1b12-47e6-b529-6f1d085ae9d1</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Mon, 08 Sep 2025 13:58:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/9d94e2b7f349512ab1332feab89f52b893e6f758703f3b5185762344aca77e23/eyJlcGlzb2RlSWQiOiJmOGFmYTRlMi0xZWY0LTRmYzMtYmY0Mi1iYjdiZjM2YTdkMzkiLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy8yNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgvZXBpc29kZXMvZjhhZmE0ZTItMWVmNC00ZmMzLWJmNDItYmI3YmYzNmE3ZDM5LzlmOGI2MzNkLm1wMyJ9.mp3" length="109422811" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;strong&gt;&lt;br /&gt;Episode 16: When Metrics Mislead: Security Scoring, Board Gaps, and vGRC&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;br /&gt;Episode 16 of the Distilled Security Podcast is here!&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;In this episode, Justin, Joe, and Rick christen the new studio and dive into some of the trickiest challenges in measuring, reporting, and governing security programs. From maturity models to board reporting, the conversation unpacks how scoring systems can mislead, how to communicate bad news effectively, and why boards need more than just “checkbox” cyber expertise.&lt;/p&gt;&lt;p&gt;The team also explores the rise of &lt;strong&gt;vGRC (Virtual GRC) services&lt;/strong&gt;—what they are, how they differ from vCISO offerings, and when organizations should consider fractional models. And of course, no episode would be complete without a pour: this week, a rich &lt;strong&gt;Woodford Reserve Double Double Oaked&lt;/strong&gt; bourbon.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;br /&gt;Topics Covered&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;New Studio Upgrade&lt;/strong&gt;: Behind-the-scenes on mics, cameras, and why the couch had to go.&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Measuring to the Score&lt;/strong&gt;: The dangers of chasing maturity numbers instead of real security outcomes.&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Scoping, Rubrics &amp;amp; Auditor Whim&lt;/strong&gt;: Why assessments are subjective and how leadership often misunderstands the results.&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Cultural Incentives&lt;/strong&gt;: How bonuses, compliance checkboxes, and “auditor shopping” distort security reporting.&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Prepping for New Tools&lt;/strong&gt;: Setting expectations with leadership when visibility spikes after deploying monitoring or vulnerability tools.&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Boards and Cybersecurity Expertise&lt;/strong&gt;: Should cyber knowledge be mandated at the board level—or does it risk creating the illusion of safety?&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Virtual GRC vs. vCISO&lt;/strong&gt;: What fractional GRC services really deliver, how they differ from vCISO roles, and why naming clarity matters.&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Bourbon Review&lt;/strong&gt;: Woodford Reserve Double Double Oaked — syrupy, smooth, and perfect for a holiday pour.&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Hosts&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Justin Leapline&lt;/li&gt;&lt;li&gt;Joe Wynn&lt;/li&gt;&lt;li&gt;Rick Yocum&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Connect with Us&lt;br /&gt;&lt;/strong&gt; 🌐 Website:&lt;a href=&quot;http://distilledsecuritypodcast.com?utm_source=chatgpt.com&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; distilledsecuritypodcast.com&lt;br /&gt;&lt;/a&gt; 🐦 Twitter:&lt;a href=&quot;https://twitter.com/DisSecPod?utm_source=chatgpt.com&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; @DisSecPod&lt;br /&gt;&lt;/a&gt; 📧 Email: hello@distilledsecuritypodcast.com&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>01:53:57</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>16</itunes:episode><itunes:title>Episode 16: When Metrics Mislead: Security Scoring, Board Gaps, and vGRC</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Episode 13: Insider Threats, the CISO's Role, and Reporting Lines]]></title><description><![CDATA[<p><strong>Episode 13 of the Distilled Security Podcast is here!</strong></p><p>Join us as we explore:</p><ul><li><strong>The Coinbase Breach</strong>: A breakdown of Coinbase’s recent insider-driven breach, including social engineering, bribery of offshore contractors, and how the company responded publicly and operationally.</li><li><strong>Building Insider Threat Programs</strong>: The crew shares practical approaches to detecting insider misuse, behavioral monitoring, and the potential for "job descriptions as code."</li><li><strong>CISO Liability and Insurance</strong>: Discussion on the evolving legal exposure for CISOs, personal liability, and whether directors and officers (D&amp;O) insurance is a must-have.</li><li><strong>Board-Level Cyber Risk</strong>: Should cybersecurity roll up to the audit committee or its own risk committee? The team explores where security leadership best fits in organizational governance.</li><li><strong>Communication and Legal Risk</strong>: How careless comments—public or internal—can be used against organizations, and why CISOs and leaders must strike a balance between transparency and caution.</li><li><strong>Modern Risk Management</strong>: Turning technical issues into business risk conversations, why documentation matters, and how strong risk communication can help CISOs avoid being scapegoated.</li><li><strong>BSides Pittsburgh Update</strong>: With over 600 tickets already sold, the team gives updates on ticket tiers, t-shirts, speaker schedules, and why you should register by June 13.</li><li><strong>Bourbon Review – Widow Jane Lucky 13</strong>: To celebrate episode 13, the crew samples Widow Jane Lucky 13—a smooth, toffee-forward bourbon aged 13 years.</li><li><strong>Reporting Lines</strong>: Where and how security should be structured within the organization, from effectiveness to liability and more.</li></ul><p><strong>Hosts</strong></p><ul><li>Justin Leapline -<a href="https://www.linkedin.com/in/justinleapline/" rel="noopener noreferrer nofollow"> LinkedIn</a></li><li>Joe Wynn -<a href="https://www.linkedin.com/in/wynnjoe/" rel="noopener noreferrer nofollow"> LinkedIn</a></li><li>Rick Yocum -<a href="https://www.linkedin.com/in/rickyocum/" rel="noopener noreferrer nofollow"> LinkedIn</a></li></ul><p><strong>Connect with Us</strong></p><ul><li>Website:<a href="https://distilledsecuritypodcast.com" rel="noopener noreferrer nofollow"> Distilled Security Podcast</a></li><li>Twitter:<a href="https://twitter.com/DisSecPod" rel="noopener noreferrer nofollow"> @DisSecPod</a></li><li>Email: hello@distilledsecuritypodcast.com</li></ul>]]></description><link>https://share.transistor.fm/s/cfee33e4</link><guid isPermaLink="false">3728a387-02d3-46af-8c4a-a70911b67d04</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Fri, 13 Jun 2025 12:37:31 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/36feffa63ac7329bbb75476a18aff0cf0f7ed421aa51dc98019d3f85d4fa4149/eyJlcGlzb2RlSWQiOiJmYzExNzQyOS1kNjQ2LTRjOWEtYWVhNy02YTU4OTVhNmZkZTMiLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy8yNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgvZXBpc29kZXMvZmMxMTc0MjktZDY0Ni00YzlhLWFlYTctNmE1ODk1YTZmZGUzL2VhNTYzZWE1Lm1wMyJ9.mp3" length="79421271" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;strong&gt;Episode 13 of the Distilled Security Podcast is here!&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Join us as we explore:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;The Coinbase Breach&lt;/strong&gt;: A breakdown of Coinbase’s recent insider-driven breach, including social engineering, bribery of offshore contractors, and how the company responded publicly and operationally.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Building Insider Threat Programs&lt;/strong&gt;: The crew shares practical approaches to detecting insider misuse, behavioral monitoring, and the potential for &quot;job descriptions as code.&quot;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CISO Liability and Insurance&lt;/strong&gt;: Discussion on the evolving legal exposure for CISOs, personal liability, and whether directors and officers (D&amp;amp;O) insurance is a must-have.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Board-Level Cyber Risk&lt;/strong&gt;: Should cybersecurity roll up to the audit committee or its own risk committee? The team explores where security leadership best fits in organizational governance.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Communication and Legal Risk&lt;/strong&gt;: How careless comments—public or internal—can be used against organizations, and why CISOs and leaders must strike a balance between transparency and caution.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Modern Risk Management&lt;/strong&gt;: Turning technical issues into business risk conversations, why documentation matters, and how strong risk communication can help CISOs avoid being scapegoated.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;BSides Pittsburgh Update&lt;/strong&gt;: With over 600 tickets already sold, the team gives updates on ticket tiers, t-shirts, speaker schedules, and why you should register by June 13.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Bourbon Review – Widow Jane Lucky 13&lt;/strong&gt;: To celebrate episode 13, the crew samples Widow Jane Lucky 13—a smooth, toffee-forward bourbon aged 13 years.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Reporting Lines&lt;/strong&gt;: Where and how security should be structured within the organization, from effectiveness to liability and more.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Hosts&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Justin Leapline -&lt;a href=&quot;https://www.linkedin.com/in/justinleapline/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; LinkedIn&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Joe Wynn -&lt;a href=&quot;https://www.linkedin.com/in/wynnjoe/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; LinkedIn&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Rick Yocum -&lt;a href=&quot;https://www.linkedin.com/in/rickyocum/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; LinkedIn&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Connect with Us&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Website:&lt;a href=&quot;https://distilledsecuritypodcast.com&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; Distilled Security Podcast&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Twitter:&lt;a href=&quot;https://twitter.com/DisSecPod&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; @DisSecPod&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Email: hello@distilledsecuritypodcast.com&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>01:22:42</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>13</itunes:episode><itunes:title>Episode 13: Insider Threats, the CISO&apos;s Role, and Reporting Lines</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Episode 1: College, Exec Comp, and New CISOs]]></title><description><![CDATA[<p><strong>Welcome to the first episode of Distilled Security!<br /></strong><br /></p><p>Join us as we dive into a variety of exciting topics, including:</p><ul><li><strong>Is College Worth It?</strong>: We explore the value of higher education in today's world.</li><li><strong>Microsoft and Executive Compensation</strong>: Analyzing cybersecurity in executive pay at Microsoft.</li><li><strong>BSides Pittsburgh</strong>: Exciting talks are coming to BSidesPGH.</li><li><strong>Starting as a New CISO</strong>: Things to do first coming into a new company.</li></ul><p>Grab your favorite cocktail and tune in for an engaging and fun-filled discussion!</p><p><br /><strong>Hosts</strong></p><ul><li>Justin Leapline - https://www.linkedin.com/in/justinleapline/</li><li>Joe Wynn - https://www.linkedin.com/in/wynnjoe/</li><li>Rick Yocum - https://www.linkedin.com/in/rickyocum/</li></ul><p><strong>Connect with Us</strong></p><ul><li><strong>Website:</strong> https://distilledsecuritypodcast.com</li><li><strong>Twitter:</strong> @DisSecPod</li><li><strong>Email:</strong> hello@distilledsecuritypodcast.com</li></ul>]]></description><link>https://studio.youtube.com/video/6V0iXsWwdJ4</link><guid isPermaLink="false">771fcbbf-12a2-4d29-b7a9-b4fdfa7a101a</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Fri, 07 Jun 2024 16:30:58 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/b8dcdd4e4ac6ce6fbbf724248a4433e4d20e02f343c01448b17dd233c1e967c9/eyJlcGlzb2RlSWQiOiJmZDBkODhiZC0yZDliLTQ2MWQtOTJjZS0wMWUwMGJiN2M2YWUiLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy8yNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgvZXBpc29kZXMvZmQwZDg4YmQtMmQ5Yi00NjFkLTkyY2UtMDFlMDBiYjdjNmFlL2U3Y2EyNDU5Lm1wMyJ9.mp3" length="126690663" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;strong&gt;Welcome to the first episode of Distilled Security!&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Join us as we dive into a variety of exciting topics, including:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Is College Worth It?&lt;/strong&gt;: We explore the value of higher education in today&apos;s world.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Microsoft and Executive Compensation&lt;/strong&gt;: Analyzing cybersecurity in executive pay at Microsoft.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;BSides Pittsburgh&lt;/strong&gt;: Exciting talks are coming to BSidesPGH.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Starting as a New CISO&lt;/strong&gt;: Things to do first coming into a new company.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Grab your favorite cocktail and tune in for an engaging and fun-filled discussion!&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;Hosts&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Justin Leapline - https://www.linkedin.com/in/justinleapline/&lt;/li&gt;&lt;li&gt;Joe Wynn - https://www.linkedin.com/in/wynnjoe/&lt;/li&gt;&lt;li&gt;Rick Yocum - https://www.linkedin.com/in/rickyocum/&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Connect with Us&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Website:&lt;/strong&gt; https://distilledsecuritypodcast.com&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Twitter:&lt;/strong&gt; @DisSecPod&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Email:&lt;/strong&gt; hello@distilledsecuritypodcast.com&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>01:05:09</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>1</itunes:episode><itunes:title>Episode 1: College, Exec Comp, and New CISOs</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Episode 21: AI Notetakers Are Illegal, GRC Tools Are Lying, and ISO 42001 Changes Everything]]></title><description><![CDATA[<p>In this episode of the Distilled Security Podcast, we break down three converging forces reshaping how organizations manage AI risk — and what you need to do about it now.</p><p>🔹 BIPA + AI Notetakers — A class action lawsuit exposes unauthorized biometric data collection, why a single Illinois meeting participant creates liability, the Shopify wiretapping dismissal, and the steps you should take today to audit your AI tools<br />🔹 GRC Engineering Meets AI — Real AI compliance tools vs. vaporware, using LLMs for policy drafting and control mapping, the hallucination accountability problem, building AI guardrails as code, and the NIST RFI on AI Agent Security (comments due March 9, 2026)<br />🔹 ISO 42001 Deep Dive — The first AI Management System standard, how it differs from ISO 27001, AI Impact Assessments vs. traditional risk assessments, stakeholder engagement requirements, and why certification is becoming essential for EU AI Act compliance</p><p>🥃 Spirit Review: Redbreast 12 Cask Strength<br />https://www.redbreastwhiskey.com/en-us/whiskey-collections/redbreast-cask-strength-whiskey/</p><p>⏱️ Timestamps</p><p>0:00 Intro &amp; Episode Overview<br />2:04 BIPA &amp; AI Notetakers<br />25:08 GRC Engineering Meets AI<br />1:07:15 🥃 Spirit Review: Redbreast 12 Cask Strength (Irish Whiskey)<br />1:11:17 ISO 42001<br />1:49:30 Outro &amp; wrap-up</p><p>🎙️ Hosts<br />Justin Leapline – @justinleapline<br />Joe Wynn – @wynnjoe<br />Rick Yocum – @rickyocum</p><p>🌐 Connect with Us<br />Website: distilledsecuritypodcast.com<br />X: @DisSecPod<br />Email: hello@distilledsecuritypodcast.com</p><p>👍 Like, comment, and subscribe for weekly security and compliance insights.</p>]]></description><link>https://share.transistor.fm/s/82f35a0e</link><guid isPermaLink="false">f34f64f0-5570-4f33-a35a-2a6ae93da6bc</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Wed, 18 Feb 2026 14:54:37 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/b6b26957443d6c27781c448f363fed37ebf5a5d8f39234899451fe5484daeffb/eyJlcGlzb2RlSWQiOiI2YTVhMzUxMC02YzNhLTQ1MzMtYmFlNi1kNzM5MjUzZDkzYjQiLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy8yNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgvZXBpc29kZXMvNmE1YTM1MTAtNmMzYS00NTMzLWJhZTYtZDczOTI1M2Q5M2I0LzVkOGRmNDkyLm1wMyJ9.mp3" length="106237244" type="audio/mpeg"/><itunes:summary>&lt;p&gt;In this episode of the Distilled Security Podcast, we break down three converging forces reshaping how organizations manage AI risk — and what you need to do about it now.&lt;/p&gt;&lt;p&gt;🔹 BIPA + AI Notetakers — A class action lawsuit exposes unauthorized biometric data collection, why a single Illinois meeting participant creates liability, the Shopify wiretapping dismissal, and the steps you should take today to audit your AI tools&lt;br /&gt;🔹 GRC Engineering Meets AI — Real AI compliance tools vs. vaporware, using LLMs for policy drafting and control mapping, the hallucination accountability problem, building AI guardrails as code, and the NIST RFI on AI Agent Security (comments due March 9, 2026)&lt;br /&gt;🔹 ISO 42001 Deep Dive — The first AI Management System standard, how it differs from ISO 27001, AI Impact Assessments vs. traditional risk assessments, stakeholder engagement requirements, and why certification is becoming essential for EU AI Act compliance&lt;/p&gt;&lt;p&gt;🥃 Spirit Review: Redbreast 12 Cask Strength&lt;br /&gt;https://www.redbreastwhiskey.com/en-us/whiskey-collections/redbreast-cask-strength-whiskey/&lt;/p&gt;&lt;p&gt;⏱️ Timestamps&lt;/p&gt;&lt;p&gt;0:00 Intro &amp;amp; Episode Overview&lt;br /&gt;2:04 BIPA &amp;amp; AI Notetakers&lt;br /&gt;25:08 GRC Engineering Meets AI&lt;br /&gt;1:07:15 🥃 Spirit Review: Redbreast 12 Cask Strength (Irish Whiskey)&lt;br /&gt;1:11:17 ISO 42001&lt;br /&gt;1:49:30 Outro &amp;amp; wrap-up&lt;/p&gt;&lt;p&gt;🎙️ Hosts&lt;br /&gt;Justin Leapline – @justinleapline&lt;br /&gt;Joe Wynn – @wynnjoe&lt;br /&gt;Rick Yocum – @rickyocum&lt;/p&gt;&lt;p&gt;🌐 Connect with Us&lt;br /&gt;Website: distilledsecuritypodcast.com&lt;br /&gt;X: @DisSecPod&lt;br /&gt;Email: hello@distilledsecuritypodcast.com&lt;/p&gt;&lt;p&gt;👍 Like, comment, and subscribe for weekly security and compliance insights.&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>01:50:38</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>21</itunes:episode><itunes:title>Episode 21: AI Notetakers Are Illegal, GRC Tools Are Lying, and ISO 42001 Changes Everything</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Episode 9: Security Budgets, AI Risks, and Data Sovereignty]]></title><description><![CDATA[<p><br /><strong><em>Episode 9</em></strong><strong> of the Distilled Security Podcast is here!</strong></p><p><strong>Join us as we explore:</strong></p><ul><li>Security on a Budget: How teams can optimize tools, manage resource constraints, and build an effective security strategy with limited funding.</li><li>AI and Efficiency: The impact of AI on job performance, along with the risks of AI-powered note-taking and data classification.</li><li>Data Breaches &amp; Industry Challenges: Lessons from Marriott’s data breaches, security concerns in the hospitality industry, and evolving consumer protection mandates.</li><li>Regulatory Shifts &amp; Compliance: A discussion on HIPAA’s 2023 overhaul, required vs. addressable regulations, and the role of dual audits in compliance assurance.</li><li>Data Sovereignty &amp; Government Oversight: How security teams navigate data sovereignty risks, government requests for information, and evolving security standards.</li><li>Multi-Factor Authentication &amp; Risk Mitigation: The importance of MFA and its role in strengthening security posture is increasing.</li></ul><p><strong>Spirits</strong></p><ul><li><a href="https://www.rabbitholedistillery.com/pages/single-barrel-release" rel="noopener noreferrer nofollow">Heigold Single Barrel Cask Strength </a>https://www.rabbitholedistillery.com/pages/single-barrel-release</li></ul><p><strong>Hosts</strong></p><ul><li>Justin Leapline -<a href="https://www.linkedin.com/in/justinleapline/" rel="noopener noreferrer nofollow"> LinkedIn</a></li><li>Joe Wynn -<a href="https://www.linkedin.com/in/wynnjoe/" rel="noopener noreferrer nofollow"> LinkedIn</a></li><li>Rick Yocum -<a href="https://www.linkedin.com/in/rickyocum/" rel="noopener noreferrer nofollow"> LinkedIn</a></li></ul><p><strong>References</strong></p><p>2025 HIPAA Security Rule Guide and Compliance Checklist // https://www.seisollc.com/insights/2025-hipaa-rule-guide</p><p><br /><strong>Connect with Us</strong></p><ul><li>Website:<a href="https://distilledsecuritypodcast.com" rel="noopener noreferrer nofollow"> Distilled Security Podcast</a></li><li>Twitter:<a href="https://twitter.com/DisSecPod" rel="noopener noreferrer nofollow"> @DisSecPod</a></li><li>Email: hello@distilledsecuritypodcast.com<p></p></li></ul>]]></description><link>https://share.transistor.fm/s/92dad8b8</link><guid isPermaLink="false">c6a7720b-5bcc-4839-bf28-4aefa4cfa308</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Thu, 06 Feb 2025 13:58:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/255e243a430b24b098fc3a0c1a9e37f9aeb69efa7888371b5dd87d4334016228/eyJlcGlzb2RlSWQiOiJmZTExYTUxNi02M2E0LTQxMzQtOTMzMC0yZmViMTgxYTI2YjgiLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy8yNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgvZXBpc29kZXMvZmUxMWE1MTYtNjNhNC00MTM0LTkzMzAtMmZlYjE4MWEyNmI4LzRhNzBlNzY0Lm1wMyJ9.mp3" length="75075330" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;br /&gt;&lt;strong&gt;&lt;em&gt;Episode 9&lt;/em&gt;&lt;/strong&gt;&lt;strong&gt; of the Distilled Security Podcast is here!&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Join us as we explore:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Security on a Budget: How teams can optimize tools, manage resource constraints, and build an effective security strategy with limited funding.&lt;/li&gt;&lt;li&gt;AI and Efficiency: The impact of AI on job performance, along with the risks of AI-powered note-taking and data classification.&lt;/li&gt;&lt;li&gt;Data Breaches &amp;amp; Industry Challenges: Lessons from Marriott’s data breaches, security concerns in the hospitality industry, and evolving consumer protection mandates.&lt;/li&gt;&lt;li&gt;Regulatory Shifts &amp;amp; Compliance: A discussion on HIPAA’s 2023 overhaul, required vs. addressable regulations, and the role of dual audits in compliance assurance.&lt;/li&gt;&lt;li&gt;Data Sovereignty &amp;amp; Government Oversight: How security teams navigate data sovereignty risks, government requests for information, and evolving security standards.&lt;/li&gt;&lt;li&gt;Multi-Factor Authentication &amp;amp; Risk Mitigation: The importance of MFA and its role in strengthening security posture is increasing.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Spirits&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;https://www.rabbitholedistillery.com/pages/single-barrel-release&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Heigold Single Barrel Cask Strength &lt;/a&gt;https://www.rabbitholedistillery.com/pages/single-barrel-release&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Hosts&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Justin Leapline -&lt;a href=&quot;https://www.linkedin.com/in/justinleapline/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; LinkedIn&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Joe Wynn -&lt;a href=&quot;https://www.linkedin.com/in/wynnjoe/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; LinkedIn&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Rick Yocum -&lt;a href=&quot;https://www.linkedin.com/in/rickyocum/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; LinkedIn&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;References&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;2025 HIPAA Security Rule Guide and Compliance Checklist // https://www.seisollc.com/insights/2025-hipaa-rule-guide&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;Connect with Us&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Website:&lt;a href=&quot;https://distilledsecuritypodcast.com&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; Distilled Security Podcast&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Twitter:&lt;a href=&quot;https://twitter.com/DisSecPod&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; @DisSecPod&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Email: hello@distilledsecuritypodcast.com&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>01:18:10</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>9</itunes:episode><itunes:title>Episode 9: Security Budgets, AI Risks, and Data Sovereignty</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Episode 17: TPRM Is Worthless?! NY DFS Part 500, Security Negotiation Tips & Mezcal]]></title><description><![CDATA[<p>🎙️ Welcome back to the Distilled Security Podcast - Episode 17!</p><p><br /></p><p>In this episode, Justin, Joe, and Rick break down several major cybersecurity and compliance updates shaping the landscape this fall. From regulatory deadlines to the futility of checkbox TPRM exercises, the crew dives deep into what actually matters for security leaders and business owners navigating today’s risk environment.</p><p><br /></p><p>Also, join us at TRISS in Pittsburgh, PA, at the David this October 29,2025! We have our own booth and will be doing something fun there. Also, we are sponsoring the After Party! Please come say hi!</p><p><br /></p><p>🔹 Topics Covered</p><p><br /></p><p>NY DFS Part 500: Final Requirements Take Effect November 1</p><p>The hosts unpack the final phase of New York’s cybersecurity regulation, what’s changing, and what companies must have in place before the enforcement deadline.</p><p><br /></p><p>Negotiating Security</p><p>How smaller companies can push back or reframe due diligence requirements—substituting a SOC 2 or ISO 27001 certification with custom questionnaires, summaries, or shared evidence that reflect real security maturity instead of checklists.</p><p><br /></p><p>“TPRM Is Worthless”</p><p>A candid discussion on the state of third-party risk management: why it’s often broken, what needs to change, and how to make it meaningful rather than bureaucratic.</p><p><br /></p><p>Department of War Announces New Cybersecurity Risk Management Construct</p><p>The team explores the DoD’s latest cybersecurity framework announcement—what it means for contractors, how it overlaps with CMMC and NIST 800-171, and whether it will actually simplify or complicate compliance.</p><p><br /></p><p>🥃 Spirit Review</p><p><br /></p><p>One of Us Mezcal — This small-batch mezcal impresses with its earthy smoke, hints of citrus, and smooth finish. The guys compare it to other craft agave spirits they’ve tried and debate whether it pairs better with a quiet evening or post-recording celebration.</p><p><br /></p><p>Find it here:</p><p>https://oneofusmezcal.com/products/cuishe-mezcal-the-wild-one</p><p><br /></p><p>⏱️ Timestamps</p><p><br /></p><p>0:00 – Introduction &amp; Travel Mishap</p><p>6:25 – New Laptop Twins &amp; Backup Strategies</p><p>11:35 – NY DFS Part 500 Updates</p><p>27:30 – DFS Reporting &amp; Organizational Accountability</p><p>33:30 – Negotiating Security Requirements</p><p>47:46 – Cultural Nuances in Negotiation</p><p>50:20 – Spirit Review: One of Us Mezcal</p><p>52:55 – TPRM Is Worthless?</p><p>57:50 – Fixing Broken Vendor Risk Workflows</p><p>1:08:21 – Vendor Resilience vs. Security</p><p>1:18:20 – New DoW/DoD Cybersecurity Risk Management Construct</p><p>1:35:06 - BSides Pittsburgh Planning &amp; Sponsorship</p><p>1:38:35 - DSP at TRISS</p><p>1:39:51 – Closing Remarks &amp; Outro</p><p><br /></p><p>🎧 Hosts</p><p><br /></p><p>Justin Leapline – @justinleapline</p><p>Joe Wynn – @wynnjoe</p><p>Rick Yocum – @rickyocum</p><p><br /></p><p>🌐 Connect with Us</p><p><br /></p><p>Website: distilledsecuritypodcast.com</p><p>🐦 Twitter: @DisSecPod</p><p>📧 Email: hello@distilledsecuritypodcast.com</p>]]></description><link>https://share.transistor.fm/s/cc06dded</link><guid isPermaLink="false">3590a4f4-a182-4738-87c8-7269289c4d79</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Mon, 13 Oct 2025 14:40:15 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/a2a85b215638a5a1775d459005adb1136635a0c3259f7202a478825f659175b4/eyJlcGlzb2RlSWQiOiIzYThmMjgxMy1jMzA1LTRhZjctODhjYy1iNjhlODcwYmEwOTYiLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy8yNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgvZXBpc29kZXMvM2E4ZjI4MTMtYzMwNS00YWY3LTg4Y2MtYjY4ZTg3MGJhMDk2L2M1YTI4YTEyLm1wMyJ9.mp3" length="96701322" type="audio/mpeg"/><itunes:summary>&lt;p&gt;🎙️ Welcome back to the Distilled Security Podcast - Episode 17!&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;In this episode, Justin, Joe, and Rick break down several major cybersecurity and compliance updates shaping the landscape this fall. From regulatory deadlines to the futility of checkbox TPRM exercises, the crew dives deep into what actually matters for security leaders and business owners navigating today’s risk environment.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Also, join us at TRISS in Pittsburgh, PA, at the David this October 29,2025! We have our own booth and will be doing something fun there. Also, we are sponsoring the After Party! Please come say hi!&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;🔹 Topics Covered&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;NY DFS Part 500: Final Requirements Take Effect November 1&lt;/p&gt;&lt;p&gt;The hosts unpack the final phase of New York’s cybersecurity regulation, what’s changing, and what companies must have in place before the enforcement deadline.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Negotiating Security&lt;/p&gt;&lt;p&gt;How smaller companies can push back or reframe due diligence requirements—substituting a SOC 2 or ISO 27001 certification with custom questionnaires, summaries, or shared evidence that reflect real security maturity instead of checklists.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;“TPRM Is Worthless”&lt;/p&gt;&lt;p&gt;A candid discussion on the state of third-party risk management: why it’s often broken, what needs to change, and how to make it meaningful rather than bureaucratic.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Department of War Announces New Cybersecurity Risk Management Construct&lt;/p&gt;&lt;p&gt;The team explores the DoD’s latest cybersecurity framework announcement—what it means for contractors, how it overlaps with CMMC and NIST 800-171, and whether it will actually simplify or complicate compliance.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;🥃 Spirit Review&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;One of Us Mezcal — This small-batch mezcal impresses with its earthy smoke, hints of citrus, and smooth finish. The guys compare it to other craft agave spirits they’ve tried and debate whether it pairs better with a quiet evening or post-recording celebration.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Find it here:&lt;/p&gt;&lt;p&gt;https://oneofusmezcal.com/products/cuishe-mezcal-the-wild-one&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;⏱️ Timestamps&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;0:00 – Introduction &amp;amp; Travel Mishap&lt;/p&gt;&lt;p&gt;6:25 – New Laptop Twins &amp;amp; Backup Strategies&lt;/p&gt;&lt;p&gt;11:35 – NY DFS Part 500 Updates&lt;/p&gt;&lt;p&gt;27:30 – DFS Reporting &amp;amp; Organizational Accountability&lt;/p&gt;&lt;p&gt;33:30 – Negotiating Security Requirements&lt;/p&gt;&lt;p&gt;47:46 – Cultural Nuances in Negotiation&lt;/p&gt;&lt;p&gt;50:20 – Spirit Review: One of Us Mezcal&lt;/p&gt;&lt;p&gt;52:55 – TPRM Is Worthless?&lt;/p&gt;&lt;p&gt;57:50 – Fixing Broken Vendor Risk Workflows&lt;/p&gt;&lt;p&gt;1:08:21 – Vendor Resilience vs. Security&lt;/p&gt;&lt;p&gt;1:18:20 – New DoW/DoD Cybersecurity Risk Management Construct&lt;/p&gt;&lt;p&gt;1:35:06 - BSides Pittsburgh Planning &amp;amp; Sponsorship&lt;/p&gt;&lt;p&gt;1:38:35 - DSP at TRISS&lt;/p&gt;&lt;p&gt;1:39:51 – Closing Remarks &amp;amp; Outro&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;🎧 Hosts&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Justin Leapline – @justinleapline&lt;/p&gt;&lt;p&gt;Joe Wynn – @wynnjoe&lt;/p&gt;&lt;p&gt;Rick Yocum – @rickyocum&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;🌐 Connect with Us&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Website: distilledsecuritypodcast.com&lt;/p&gt;&lt;p&gt;🐦 Twitter: @DisSecPod&lt;/p&gt;&lt;p&gt;📧 Email: hello@distilledsecuritypodcast.com&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>01:40:42</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>17</itunes:episode><itunes:title>Episode 17: TPRM Is Worthless?! NY DFS Part 500, Security Negotiation Tips &amp; Mezcal</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Episode 14: AI Risks, Threat Modeling, and The Future of Vibe Coding]]></title><description><![CDATA[<p><strong>Episode 14 of the Distilled Security Podcast is here!</strong></p><p>This week, the team welcomes guest <strong>John Zeolla</strong>, a cybersecurity expert and AI enthusiast, for a deep dive into the risks, realities, and potential of artificial intelligence.</p><p><br />Topics include:</p><ul><li><strong>Shadow AI in the Enterprise</strong>: Why business leaders are adopting AI faster than CISOs can assess the risks—and how features are outpacing controls.<p></p></li><li><strong>Third-Party AI Risk</strong>: Understanding vendor integrations with ChatGPT and others, and how contracts alone can’t guarantee security.<p></p></li><li><strong>Data Sprawl and Provenance</strong>: How uncontrolled data flows and poor identity scoping create dangerous exposure in generative AI platforms.<p></p></li><li><strong>Threat Modeling for AI</strong>: Why traditional frameworks like STRIDE still apply—and how techniques like “LLM as a judge” are reshaping modern risk analysis.<p></p></li><li><strong>Hallucinations, Misuse, and Insider Access</strong>: From AI-summarized HR documents to leaked board data, the team explores how improper permissions are amplified by intelligent agents.<p></p></li><li><strong>AI in Real Business Use</strong>: From customer support chatbots to code review tools, where AI adds value—and where it creates new points of failure.<p></p></li><li><strong>Governance and Culture</strong>: The role of CISOs, legal, and finance leaders in aligning AI ambition with responsible oversight.<p></p></li><li><strong>Bourbon Review – Elijah Craig Private Barrel Pick</strong>: A smooth 94-proof selection sponsored by <strong>Liberty Liquors (MD)</strong>, bringing sweet caramel and balance to this week’s pour.<p></p></li><li><strong>BSides Pittsburgh Preview</strong>: With nearly 1,000 tickets sold, the team teases event highlights, panel interviews, and John's upcoming talk on "vibe coding."</li></ul><p><br /><strong>Timestamps</strong></p><p><a href="https://www.youtube.com/watch?v=L12uZJBGE7A" rel="noopener noreferrer nofollow">00:00</a> – Welcome &amp; Introductions<br /><a href="https://www.youtube.com/watch?v=L12uZJBGE7A&amp;t=140s" rel="noopener noreferrer nofollow">02:20</a> – What’s “Shadow AI”?<br /><a href="https://www.youtube.com/watch?v=L12uZJBGE7A&amp;t=405s" rel="noopener noreferrer nofollow">06:45</a> – Third-Party Risk &amp; AI Integrations<br /><a href="https://www.youtube.com/watch?v=L12uZJBGE7A&amp;t=670s" rel="noopener noreferrer nofollow">11:10</a> – Contracts ≠ Security<br /><a href="https://www.youtube.com/watch?v=L12uZJBGE7A&amp;t=840s" rel="noopener noreferrer nofollow">14:00</a> – Data Sprawl &amp; Identity Challenges<br /><a href="https://www.youtube.com/watch?v=L12uZJBGE7A&amp;t=1145s" rel="noopener noreferrer nofollow">19:05</a> – Threat Modeling for AI<br /><a href="https://www.youtube.com/watch?v=L12uZJBGE7A&amp;t=1420s" rel="noopener noreferrer nofollow">23:40</a> – “LLM as a Judge” in Risk Analysis<br /><a href="https://www.youtube.com/watch?v=L12uZJBGE7A&amp;t=1695s" rel="noopener noreferrer nofollow">28:15</a> – Hallucinations &amp; Misuse Scenarios<br /><a href="https://www.youtube.com/watch?v=L12uZJBGE7A&amp;t=1980s" rel="noopener noreferrer nofollow">33:00</a> – Insider Access Amplified by AI<br /><a href="https://www.youtube.com/watch?v=L12uZJBGE7A&amp;t=2190s" rel="noopener noreferrer nofollow">36:30</a> – Real-World Use Cases (Chatbots, Code Review, etc.)<br /><a href="https://www.youtube.com/watch?v=L12uZJBGE7A&amp;t=2515s" rel="noopener noreferrer nofollow">41:55</a> – Governance, Culture &amp; CISO Alignment<br /><a href="https://www.youtube.com/watch?v=L12uZJBGE7A&amp;t=2900s" rel="noopener noreferrer nofollow">48:20</a> – Bourbon Review: Elijah Craig Private Barrel<br /><a href="https://www.youtube.com/watch?v=L12uZJBGE7A&amp;t=3150s" rel="noopener noreferrer nofollow">52:30</a> – BSides PGH Preview &amp; John’s “Vibe Coding” Talk<br /><a href="https://www.youtube.com/watch?v=L12uZJBGE7A&amp;t=3420s" rel="noopener noreferrer nofollow">57:00</a> – Final Thoughts &amp; Wrap-Up</p><p><strong><br />Hosts</strong></p><ul><li>Justin Leapline –<a href="https://www.linkedin.com/in/justinleapline/" rel="noopener noreferrer nofollow"> LinkedIn</a></li><li>Joe Wynn –<a href="https://www.linkedin.com/in/wynnjoe/" rel="noopener noreferrer nofollow"> LinkedIn</a></li><li>Rick Yocum –<a href="https://www.linkedin.com/in/rickyocum/" rel="noopener noreferrer nofollow"> LinkedIn<br /></a><br /></li></ul><p><strong>Guest</strong></p><ul><li>John Zeolla –<a href="https://zenable.io" rel="noopener noreferrer nofollow"> Zenable.io<br /></a><br /></li></ul><p><strong>Connect with Us</strong></p><ul><li>Website:<a href="https://distilledsecuritypodcast.com" rel="noopener noreferrer nofollow"> distilledsecuritypodcast.com</a></li><li>Twitter:<a href="https://twitter.com/DisSecPod" rel="noopener noreferrer nofollow"> @DisSecPod</a></li><li>Email: hello@distilledsecuritypodcast.com</li></ul><p><br /></p>]]></description><link>https://share.transistor.fm/s/d3155aef</link><guid isPermaLink="false">82e985a3-fc5d-4255-8173-f0934c0f5c14</guid><dc:creator><![CDATA[Justin Leapline, Joe Wynn, and Rick Yocum]]></dc:creator><pubDate>Tue, 08 Jul 2025 14:30:23 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/65ffc2d8bf80f36609bc9a4fab9b330cb3c354aaef95e7b79d5a2d994a820a31/eyJlcGlzb2RlSWQiOiI1MTEyYTQzZS02NDdlLTQxN2MtOWYyYy05NWZhODViM2ExNDMiLCJwb2RjYXN0SWQiOiIyNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgiLCJhY2NvdW50SWQiOiI2NjM5NDU5OTQwZTE3MjMwYTM4NWMzOGMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy8yNmM4YmMzYy1mMTVhLTQ2YTctYWU2ZS00MzQzMWFlYTFkMTgvZXBpc29kZXMvNTExMmE0M2UtNjQ3ZS00MTdjLTlmMmMtOTVmYTg1YjNhMTQzL2MyNDJmMDAxLm1wMyJ9.mp3" length="79226510" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;strong&gt;Episode 14 of the Distilled Security Podcast is here!&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;This week, the team welcomes guest &lt;strong&gt;John Zeolla&lt;/strong&gt;, a cybersecurity expert and AI enthusiast, for a deep dive into the risks, realities, and potential of artificial intelligence.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;Topics include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Shadow AI in the Enterprise&lt;/strong&gt;: Why business leaders are adopting AI faster than CISOs can assess the risks—and how features are outpacing controls.&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Third-Party AI Risk&lt;/strong&gt;: Understanding vendor integrations with ChatGPT and others, and how contracts alone can’t guarantee security.&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Data Sprawl and Provenance&lt;/strong&gt;: How uncontrolled data flows and poor identity scoping create dangerous exposure in generative AI platforms.&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Threat Modeling for AI&lt;/strong&gt;: Why traditional frameworks like STRIDE still apply—and how techniques like “LLM as a judge” are reshaping modern risk analysis.&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Hallucinations, Misuse, and Insider Access&lt;/strong&gt;: From AI-summarized HR documents to leaked board data, the team explores how improper permissions are amplified by intelligent agents.&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;AI in Real Business Use&lt;/strong&gt;: From customer support chatbots to code review tools, where AI adds value—and where it creates new points of failure.&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Governance and Culture&lt;/strong&gt;: The role of CISOs, legal, and finance leaders in aligning AI ambition with responsible oversight.&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Bourbon Review – Elijah Craig Private Barrel Pick&lt;/strong&gt;: A smooth 94-proof selection sponsored by &lt;strong&gt;Liberty Liquors (MD)&lt;/strong&gt;, bringing sweet caramel and balance to this week’s pour.&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;BSides Pittsburgh Preview&lt;/strong&gt;: With nearly 1,000 tickets sold, the team teases event highlights, panel interviews, and John&apos;s upcoming talk on &quot;vibe coding.&quot;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;Timestamps&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=L12uZJBGE7A&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;00:00&lt;/a&gt; – Welcome &amp;amp; Introductions&lt;br /&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=L12uZJBGE7A&amp;amp;t=140s&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;02:20&lt;/a&gt; – What’s “Shadow AI”?&lt;br /&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=L12uZJBGE7A&amp;amp;t=405s&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;06:45&lt;/a&gt; – Third-Party Risk &amp;amp; AI Integrations&lt;br /&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=L12uZJBGE7A&amp;amp;t=670s&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;11:10&lt;/a&gt; – Contracts ≠ Security&lt;br /&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=L12uZJBGE7A&amp;amp;t=840s&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;14:00&lt;/a&gt; – Data Sprawl &amp;amp; Identity Challenges&lt;br /&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=L12uZJBGE7A&amp;amp;t=1145s&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;19:05&lt;/a&gt; – Threat Modeling for AI&lt;br /&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=L12uZJBGE7A&amp;amp;t=1420s&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;23:40&lt;/a&gt; – “LLM as a Judge” in Risk Analysis&lt;br /&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=L12uZJBGE7A&amp;amp;t=1695s&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;28:15&lt;/a&gt; – Hallucinations &amp;amp; Misuse Scenarios&lt;br /&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=L12uZJBGE7A&amp;amp;t=1980s&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;33:00&lt;/a&gt; – Insider Access Amplified by AI&lt;br /&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=L12uZJBGE7A&amp;amp;t=2190s&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;36:30&lt;/a&gt; – Real-World Use Cases (Chatbots, Code Review, etc.)&lt;br /&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=L12uZJBGE7A&amp;amp;t=2515s&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;41:55&lt;/a&gt; – Governance, Culture &amp;amp; CISO Alignment&lt;br /&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=L12uZJBGE7A&amp;amp;t=2900s&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;48:20&lt;/a&gt; – Bourbon Review: Elijah Craig Private Barrel&lt;br /&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=L12uZJBGE7A&amp;amp;t=3150s&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;52:30&lt;/a&gt; – BSides PGH Preview &amp;amp; John’s “Vibe Coding” Talk&lt;br /&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=L12uZJBGE7A&amp;amp;t=3420s&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;57:00&lt;/a&gt; – Final Thoughts &amp;amp; Wrap-Up&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;br /&gt;Hosts&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Justin Leapline –&lt;a href=&quot;https://www.linkedin.com/in/justinleapline/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; LinkedIn&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Joe Wynn –&lt;a href=&quot;https://www.linkedin.com/in/wynnjoe/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; LinkedIn&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Rick Yocum –&lt;a href=&quot;https://www.linkedin.com/in/rickyocum/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; LinkedIn&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Guest&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;John Zeolla –&lt;a href=&quot;https://zenable.io&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; Zenable.io&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Connect with Us&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Website:&lt;a href=&quot;https://distilledsecuritypodcast.com&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; distilledsecuritypodcast.com&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Twitter:&lt;a href=&quot;https://twitter.com/DisSecPod&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt; @DisSecPod&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Email: hello@distilledsecuritypodcast.com&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>01:22:30</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/26c8bc3c-f15a-46a7-ae6e-43431aea1d18/MjVmOS5wbmc.jpg"/><itunes:episode>14</itunes:episode><itunes:title>Episode 14: AI Risks, Threat Modeling, and The Future of Vibe Coding</itunes:title><itunes:episodeType>full</itunes:episodeType></item></channel></rss>