Episode 26: How to Run a Conference, Why Most Pen Tests Fail, and HIPAA's Ransomware Reckoning episode artwork

EPISODE · Jul 8, 2026 · 1H 56M

Episode 26: How to Run a Conference, Why Most Pen Tests Fail, and HIPAA's Ransomware Reckoning

from Distilled Security Podcast · host Justin Leapline, Joe Wynn, and Rick Yocum

In this episode, we're joined by Jon Buhagiar, Director of Information Technology at RareMed Solutions; a published Sybex/Wiley author of Cisco and Microsoft certification guides; and a longtime amateur radio enthusiast. We get into what it actually takes to run a security conference from the ground up, why so many penetration tests end up wasting everyone's money, and how compliance and cyber insurance keep reshaping the way organizations work. Plus, as always, a bourbon. 🎤 Jon's world — rare-disease specialty pharmacy, patient assistance programs, book writing, and ham radio🏗️ Running BSides Pittsburgh: revenue, expenses, marketing, volunteers, speakers, and sponsors🎟️ The real economics of ticket pricing, free tickets, and the venue/affordability squeeze🧑‍🤝‍🧑 Dividing responsibilities and appointing workstream leads as an event grows🎯 Scoping as the make-or-break of a good pen test — and the human element that tooling misses🔗 Chaining vulnerabilities and what separates a checkbox test from a real one💸 Why pen testing so often becomes an ineffective use of resources📋 Compliance and contractual drivers vs. genuine risk reduction🛡️ A risk-based, scenario-driven approach focused on resilience and continuous improvement🤝 Engaging pen testers as partners and maturing the process over time🔄 Security as a constant state of change — compliance, cyber insurance, and government scoring🏥 HIPAA compliance, risk analysis, and the ransomware reckoning facing healthcare🥃 Bourbon tasting and discussion⏱️ Timestamps00:00 Intro01:26 Guest introduction & background02:18 RareMed Solutions & patient assistance programs05:01 Book writing & amateur radio08:11 BSides Pittsburgh overview15:04 Running a conference: planning & organization22:05 Marketing & audience engagement25:07 Dividing responsibilities as you grow27:59 The value of ticket pricing31:50 BSides & the conference model46:11 Penetration testing & scoping57:28 The purpose of pen testing58:23 When pen testing goes wrong01:00:16 Reasons for pen testing & compliance drivers01:03:04 Continuous monitoring, testing & detection01:06:19 Is your company ready for a pen test?01:07:07 A risk-based approach01:13:58 Scenario-based testing & resilience01:17:31 Evaluating the value of pen testing01:29:01 The constant state of change01:31:01 Compliance & cyber insurance01:32:19 Bourbon tasting01:36:32 Government scoring & risk analysis01:50:36 HIPAA compliance & ransomware01:55:01 Wrap-up & call to action🎧 Distilled Security PodcastCybersecurity, GRC, and leadership, one pour at a time.🎙️ HostsJustin Leapline – @justinleaplineJoe Wynn – @wynnjoeRick Yocum – @rickyocum🎤 GuestJon Buhagiar linkedin.com/in/jonbuhagiar📬 Send Us Your [email protected]🌐 Connect with UsWebsite: distilledsecuritypodcast.comX: @DisSecPodYouTube: @distilledsecurityEmail: [email protected]👍 Like, comment, and subscribe for monthlysecurity and compliance insights.

Episode metadata supplied by the publisher feed · Published Jul 8, 2026

Embed this episode

Ready to play

Episode 26: How to Run a Conference, Why Most Pen Tests Fail, and HIPAA's Ransomware Reckoning

0:00 1:56:00

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of Distilled Security Podcast?

This episode is 1 hour and 56 minutes long.

When was this Distilled Security Podcast episode published?

This episode was published on July 8, 2026.

Can I download this Distilled Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!