Folgen

  • Episode 19: Cloudflare Outage, AI-Powered Attacks & The Rise of GRC Engineering | Distilled Security Podcast
    Dec 8 2025

    In this episode, we break down a major Cloudflare outage, explore how a nation-state used AI agents to automate a cyberattack, and discuss the growing risks around MCP integrations. We also highlight why GRC Engineering is becoming essential to modern security programs and wrap up with key regulatory updates, including CMMC changes affecting thousands of contractors.

    Topics covered:
    • Cloudflare outage impact and root cause
    • Nation-state attack using AI agents to automate intrusion steps
    • MCP (Model Context Protocol): power, risks, and examples
    • Why GRC Engineering is the future of compliance and automation
    • Updates on GDPR, ISO 27701, California AB 5866, and SEC rules
    • CMMC assessor shortages and what organizations must prepare for

    Spirit of the Episode
    • Knob Creek 21-Year Limited Release – rich caramel notes, heavy char, smooth for 100 proof

    Timestamps

    • 0:02- Cloudflare Outage Stories & Global Impact
    • 3:07- Root Cause, Not a Cyberattack & Third-Party Risk Reality
    • 10:38 - China Uses Anthropic’s Claude + MCP for Automated Cyberattacks
    • 14:17 - Full AI Attack Lifecycle Explained
    • 27:18 - MCP: The API for AI & Its Security Risks
    • 44:05 - Bourbon Break: Knob Creek 21-Year Review
    • 50:02 - GRC Engineering Deep Dive: Automation & Controls-as-Code
    • 1:24:13 - Regulatory Roundup: GDPR, ISO 27701, California AB 566, SEC SP
    • 1:44:27 - CMMC 2.0 Crisis: Auditor Shortages & DoD Contract Impact
    • 2:11:20 - Closing Thoughts & Episode Wrap-Up

    Hosts

    • Justin Leapline – @justinleapline
    • Joe Wynn – @wynnjoe
    • Rick Yocum – @rickyocum

    Connect with Us

    • Website: distilledsecuritypodcast.com
    • X: @DisSecPod
    • Email: hello@distilledsecuritypodcast.com
    Mehr anzeigen Weniger anzeigen
    2 Std. und 12 Min.
  • Episode 18: TRISS Highlights, Cloud Chaos & SaaS Lessons Learned
    Nov 10 2025

    In Episode 18 of the Distilled Security Podcast, Justin Leapline, Joe Wynn, and Rick Yokum recap their time at TRISS, share lessons on storytelling and women in tech, and break down the recent AWS us-east-1 DNS/DynamoDB outage, the Microsoft Front Door global disruption, and the F5 BIG-IP incident.

    🔍 We discuss:
    - TRISS highlights: panels, community & storytelling
    - “Breaking the glass ceiling” and unintentional bias in meetings
    - AWS & Microsoft outages: risk, resilience & when multicloud matters
    - F5 BIG-IP incident and supply chain risk
    - Launching a GRC SaaS: episki’s journey, lessons & tradeoffs

    🥃 Spirit of the episode
    Penelope Bourbon – Project X (sherry cask finish)

    ⏱️ Timestamps
    00:00 – 🥃 Intro & TRISS Recap — Highlights from TRISS: panels, community, and a keynote with Edward Norton

    02:40 – 📖 The Power of Storytelling — Why empathy and narrative matter in cybersecurity leadership

    04:40 – 👩‍💻 Women in Tech & Bias in Meetings — Real talk about unintentional bias and everyday experiences

    20:34 – ☁️ AWS & Microsoft Outages — What happened and what it says about cloud resilience

    49:38 - 🥃 Bourbon Break — Enjoying a glass of Penelope Project X

    53:30 – 🔥 F5 BIG-IP Vulnerability — Supply chain risk and patching lessons

    1:09:50 – 🚀 Launching episki (GRC SaaS) — Building simply, shipping fast, and learning from users

    1:52:22 – 🧭 Reflections & Closing Thoughts — Culture, resilience, and what’s next

    🎧 Hosts
    Justin Leapline
    Joe Wynn
    Rick Yocum

    🌐 Connect with Us
    Website: distilledsecuritypodcast.com
    X : @DisSecPod
    Email: hello@distilledsecuritypodcast.com

    Mehr anzeigen Weniger anzeigen
    1 Std. und 53 Min.
  • Episode 17: TPRM Is Worthless?! NY DFS Part 500, Security Negotiation Tips & Mezcal
    Oct 13 2025

    🎙️ Welcome back to the Distilled Security Podcast - Episode 17!


    In this episode, Justin, Joe, and Rick break down several major cybersecurity and compliance updates shaping the landscape this fall. From regulatory deadlines to the futility of checkbox TPRM exercises, the crew dives deep into what actually matters for security leaders and business owners navigating today’s risk environment.


    Also, join us at TRISS in Pittsburgh, PA, at the David this October 29,2025! We have our own booth and will be doing something fun there. Also, we are sponsoring the After Party! Please come say hi!


    🔹 Topics Covered


    NY DFS Part 500: Final Requirements Take Effect November 1

    The hosts unpack the final phase of New York’s cybersecurity regulation, what’s changing, and what companies must have in place before the enforcement deadline.


    Negotiating Security

    How smaller companies can push back or reframe due diligence requirements—substituting a SOC 2 or ISO 27001 certification with custom questionnaires, summaries, or shared evidence that reflect real security maturity instead of checklists.


    “TPRM Is Worthless”

    A candid discussion on the state of third-party risk management: why it’s often broken, what needs to change, and how to make it meaningful rather than bureaucratic.


    Department of War Announces New Cybersecurity Risk Management Construct

    The team explores the DoD’s latest cybersecurity framework announcement—what it means for contractors, how it overlaps with CMMC and NIST 800-171, and whether it will actually simplify or complicate compliance.


    🥃 Spirit Review


    One of Us Mezcal — This small-batch mezcal impresses with its earthy smoke, hints of citrus, and smooth finish. The guys compare it to other craft agave spirits they’ve tried and debate whether it pairs better with a quiet evening or post-recording celebration.


    Find it here:

    https://oneofusmezcal.com/products/cuishe-mezcal-the-wild-one


    ⏱️ Timestamps


    0:00 – Introduction & Travel Mishap

    6:25 – New Laptop Twins & Backup Strategies

    11:35 – NY DFS Part 500 Updates

    27:30 – DFS Reporting & Organizational Accountability

    33:30 – Negotiating Security Requirements

    47:46 – Cultural Nuances in Negotiation

    50:20 – Spirit Review: One of Us Mezcal

    52:55 – TPRM Is Worthless?

    57:50 – Fixing Broken Vendor Risk Workflows

    1:08:21 – Vendor Resilience vs. Security

    1:18:20 – New DoW/DoD Cybersecurity Risk Management Construct

    1:35:06 - BSides Pittsburgh Planning & Sponsorship

    1:38:35 - DSP at TRISS

    1:39:51 – Closing Remarks & Outro


    🎧 Hosts


    Justin Leapline – @justinleapline

    Joe Wynn – @wynnjoe

    Rick Yocum – @rickyocum


    🌐 Connect with Us


    Website: distilledsecuritypodcast.com

    🐦 Twitter: @DisSecPod

    📧 Email: hello@distilledsecuritypodcast.com

    Mehr anzeigen Weniger anzeigen
    1 Std. und 41 Min.
  • Episode 16: When Metrics Mislead: Security Scoring, Board Gaps, and vGRC
    Sep 8 2025


    Episode 16: When Metrics Mislead: Security Scoring, Board Gaps, and vGRC



    Episode 16 of the Distilled Security Podcast is here!


    In this episode, Justin, Joe, and Rick christen the new studio and dive into some of the trickiest challenges in measuring, reporting, and governing security programs. From maturity models to board reporting, the conversation unpacks how scoring systems can mislead, how to communicate bad news effectively, and why boards need more than just “checkbox” cyber expertise.

    The team also explores the rise of vGRC (Virtual GRC) services—what they are, how they differ from vCISO offerings, and when organizations should consider fractional models. And of course, no episode would be complete without a pour: this week, a rich Woodford Reserve Double Double Oaked bourbon.


    Topics Covered

    • New Studio Upgrade: Behind-the-scenes on mics, cameras, and why the couch had to go.

    • Measuring to the Score: The dangers of chasing maturity numbers instead of real security outcomes.

    • Scoping, Rubrics & Auditor Whim: Why assessments are subjective and how leadership often misunderstands the results.

    • Cultural Incentives: How bonuses, compliance checkboxes, and “auditor shopping” distort security reporting.

    • Prepping for New Tools: Setting expectations with leadership when visibility spikes after deploying monitoring or vulnerability tools.

    • Boards and Cybersecurity Expertise: Should cyber knowledge be mandated at the board level—or does it risk creating the illusion of safety?

    • Virtual GRC vs. vCISO: What fractional GRC services really deliver, how they differ from vCISO roles, and why naming clarity matters.

    • Bourbon Review: Woodford Reserve Double Double Oaked — syrupy, smooth, and perfect for a holiday pour.

    Hosts

    • Justin Leapline
    • Joe Wynn
    • Rick Yocum

    Connect with Us
    🌐 Website: distilledsecuritypodcast.com
    🐦 Twitter: @DisSecPod
    📧 Email: hello@distilledsecuritypodcast.com


    Mehr anzeigen Weniger anzeigen
    1 Std. und 54 Min.
  • Episode 15: Community Building, Art of Convincing, and GTD Strategies
    Aug 6 2025

    🎙️ Welcome back to the Distilled Security Podcast!

    In this episode, hosts Justin Leapline, Joe Wynn, and Rick Yocum sit down with James Ringold (Senior Security Cloud Solution Architect at Microsoft and President of ISSA Pittsburgh) to talk all about building stronger cybersecurity communities.

    From the behind-the-scenes of BSides Pittsburgh 2025 to engaging the next generation through mentorship and student-led talks, this episode offers practical insights on how to grow inclusive, vendor-neutral spaces that truly support people in security.

    Topics Covered

    • BSides Pittsburgh 2025 Highlights

    What made this year’s event stand out — from arcade machines and pastries to great speakers and a welcoming atmosphere.

    • Running an Inclusive Security Chapter

    Insights into leading ISSA Pittsburgh, maintaining momentum, and building a vendor-neutral space that feels open to everyone.

    • The Power of Consistency

    Why showing up regularly and following through matters when growing a security community.

    • Mentoring the Next Generation

    The importance of mentorship chains, student-led initiatives, and creating low-pressure environments for future leaders.

    • Engaging Students Beyond Attendance

    How to get students truly involved, from submitting talks to building long-term relationships that support career growth.

    • Authenticity and Community Building

    Why empathy, storytelling, and invitation—not pressure—are essential for creating lasting, supportive security ecosystems.

    Timestamps:

    00:00:00 – Intro & Guest Welcome
    00:02:20 – BSides Pittsburgh 2025 Preview
    00:24:10 – Building Inclusive Security Communities
    00:41:20 – Mentorship & Student Talks
    01:11:00 – Whiskey Tasting: Grand Traverse Distillery
    01:33:00 – Growing Through Empathy & Local Leadership
    01:48:30 – Final Reflections & Outro

    Links

    • ISSA Pittsburgh
    • BSides Pittsburgh

    Hosts

    • Justin Leapline
    • Joe Wynn
    • Rick Yocum

    Guest

    • James Ringold


    Connect with Us

    • Website: distilledsecuritypodcast.com
    • Twitter: @DisSecPod
    • Email: hello@distilledsecuritypodcast.com


    Mehr anzeigen Weniger anzeigen
    1 Std. und 54 Min.
  • Episode 14: AI Risks, Threat Modeling, and The Future of Vibe Coding
    Jul 8 2025

    Episode 14 of the Distilled Security Podcast is here!

    This week, the team welcomes guest John Zeolla, a cybersecurity expert and AI enthusiast, for a deep dive into the risks, realities, and potential of artificial intelligence.


    Topics include:

    • Shadow AI in the Enterprise: Why business leaders are adopting AI faster than CISOs can assess the risks—and how features are outpacing controls.

    • Third-Party AI Risk: Understanding vendor integrations with ChatGPT and others, and how contracts alone can’t guarantee security.

    • Data Sprawl and Provenance: How uncontrolled data flows and poor identity scoping create dangerous exposure in generative AI platforms.

    • Threat Modeling for AI: Why traditional frameworks like STRIDE still apply—and how techniques like “LLM as a judge” are reshaping modern risk analysis.

    • Hallucinations, Misuse, and Insider Access: From AI-summarized HR documents to leaked board data, the team explores how improper permissions are amplified by intelligent agents.

    • AI in Real Business Use: From customer support chatbots to code review tools, where AI adds value—and where it creates new points of failure.

    • Governance and Culture: The role of CISOs, legal, and finance leaders in aligning AI ambition with responsible oversight.

    • Bourbon Review – Elijah Craig Private Barrel Pick: A smooth 94-proof selection sponsored by Liberty Liquors (MD), bringing sweet caramel and balance to this week’s pour.

    • BSides Pittsburgh Preview: With nearly 1,000 tickets sold, the team teases event highlights, panel interviews, and John's upcoming talk on "vibe coding."


    Timestamps

    00:00 – Welcome & Introductions
    02:20 – What’s “Shadow AI”?
    06:45 – Third-Party Risk & AI Integrations
    11:10 – Contracts ≠ Security
    14:00 – Data Sprawl & Identity Challenges
    19:05 – Threat Modeling for AI
    23:40 – “LLM as a Judge” in Risk Analysis
    28:15 – Hallucinations & Misuse Scenarios
    33:00 – Insider Access Amplified by AI
    36:30 – Real-World Use Cases (Chatbots, Code Review, etc.)
    41:55 – Governance, Culture & CISO Alignment
    48:20 – Bourbon Review: Elijah Craig Private Barrel
    52:30 – BSides PGH Preview & John’s “Vibe Coding” Talk
    57:00 – Final Thoughts & Wrap-Up


    Hosts

    • Justin Leapline – LinkedIn
    • Joe Wynn – LinkedIn
    • Rick Yocum – LinkedIn

    Guest

    • John Zeolla – Zenable.io

    Connect with Us

    • Website: distilledsecuritypodcast.com
    • Twitter: @DisSecPod
    • Email: hello@distilledsecuritypodcast.com


    Mehr anzeigen Weniger anzeigen
    1 Std. und 23 Min.
  • Episode 13: Insider Threats, the CISO's Role, and Reporting Lines
    Jun 13 2025

    Episode 13 of the Distilled Security Podcast is here!

    Join us as we explore:

    • The Coinbase Breach: A breakdown of Coinbase’s recent insider-driven breach, including social engineering, bribery of offshore contractors, and how the company responded publicly and operationally.
    • Building Insider Threat Programs: The crew shares practical approaches to detecting insider misuse, behavioral monitoring, and the potential for "job descriptions as code."
    • CISO Liability and Insurance: Discussion on the evolving legal exposure for CISOs, personal liability, and whether directors and officers (D&O) insurance is a must-have.
    • Board-Level Cyber Risk: Should cybersecurity roll up to the audit committee or its own risk committee? The team explores where security leadership best fits in organizational governance.
    • Communication and Legal Risk: How careless comments—public or internal—can be used against organizations, and why CISOs and leaders must strike a balance between transparency and caution.
    • Modern Risk Management: Turning technical issues into business risk conversations, why documentation matters, and how strong risk communication can help CISOs avoid being scapegoated.
    • BSides Pittsburgh Update: With over 600 tickets already sold, the team gives updates on ticket tiers, t-shirts, speaker schedules, and why you should register by June 13.
    • Bourbon Review – Widow Jane Lucky 13: To celebrate episode 13, the crew samples Widow Jane Lucky 13—a smooth, toffee-forward bourbon aged 13 years.
    • Reporting Lines: Where and how security should be structured within the organization, from effectiveness to liability and more.

    Hosts

    • Justin Leapline - LinkedIn
    • Joe Wynn - LinkedIn
    • Rick Yocum - LinkedIn

    Connect with Us

    • Website: Distilled Security Podcast
    • Twitter: @DisSecPod
    • Email: hello@distilledsecuritypodcast.com
    Mehr anzeigen Weniger anzeigen
    1 Std. und 23 Min.
  • Episode 12: One Year of Distilled Security, Auditor Quality, and Starting Your Own Company
    May 2 2025

    Join us as we reflect on:

    • One Year of Podcasting: The crew celebrates a full year of episodes, favorite topics, behind-the-scenes production, and where the show is headed next—including a new studio setup and future sponsors.
    • Audit Quality and Risk: A deep dive into the evolution of cybersecurity audits, the growing influence of low-cost providers, and what actually makes an audit valuable and trustworthy.
    • Third-Party Risk Management: How companies can assess vendor SOC 2 reports, triage risk among their vendors, and build defensible compliance practices.
    • Operational vs. Commercial Risk: The importance of translating audit findings into business impact and strengthening vendor partnerships for long-term resilience.
    • Bourbon Review – Jefferson’s Tropics: A tasting of a tropical-aged bourbon matured in Singapore’s climate, featuring notes of toffee and spice.
    • BSides Pittsburgh Update: Details on ticket sales, sponsor opportunities, and how to get involved with the local security community’s flagship event.
    • Entrepreneurship & Starting a Business: A thoughtful discussion on what it really takes to start your own business—when to consider it, how to prepare, and why it’s often more work (and growth) than expected.


    Hosts

    • Justin Leapline - LinkedIn
    • Joe Wynn - LinkedIn
    • Rick Yocum - LinkedIn

    Connect with Us

    • Website: Distilled Security Podcast
    • Twitter: @DisSecPod
    • Email: hello@distilledsecuritypodcast.com

    Mehr anzeigen Weniger anzeigen
    1 Std. und 38 Min.