
β Distilled Security Podcast8 jul Β· 1 u 56 min
Episode 26: How to Run a Conference, Why Most Pen Tests Fail, and HIPAA's Ransomware Reckoning
<p>In this episode, we're joined by Jon Buhagiar, Director of Information Technology at RareMed Solutions; a published Sybex/Wiley author of Cisco and Microsoft certification guides; and a longtime amateur radio enthusiast. We get into what it actually takes to run a security conference from the ground up, why so many penetration tests end up wasting everyone's money, and how compliance and cyber insurance keep reshaping the way organizations work. Plus, as always, a bourbon. </p><p></p><p>π€ Jon's world β rare-disease specialty pharmacy, patient assistance programs, book writing, and ham radio<br />ποΈ Running BSides Pittsburgh: revenue, expenses, marketing, volunteers, speakers, and sponsors<br />ποΈ The real economics of ticket pricing, free tickets, and the venue/affordability squeeze<br />π§βπ€βπ§ Dividing responsibilities and appointing workstream leads as an event grows<br />π― Scoping as the make-or-break of a good pen test β and the human element that tooling misses<br />π Chaining vulnerabilities and what separates a checkbox test from a real one<br />πΈ Why pen testing so often becomes an ineffective use of resources<br />π Compliance and contractual drivers vs. genuine risk reduction<br />π‘οΈ A risk-based, scenario-driven approach focused on resilience and continuous improvement<br />π€ Engaging pen testers as partners and maturing the process over time<br />π Security as a constant state of change β compliance, cyber insurance, and government scoring<br />π₯ HIPAA compliance, risk analysis, and the ransomware reckoning facing healthcare<br />π₯ Bourbon tasting and discussion</p><p></p><p>β±οΈ Timestamps<br />00:00 Intro<br />01:26 Guest introduction & background<br />02:18 RareMed Solutions & patient assistance programs<br />05:01 Book writing & amateur radio<br />08:11 BSides Pittsburgh overview<br />15:04 Running a conference: planning & organization<br />22:05 Marketing & audience engagement<br />25:07 Dividing responsibilities as you grow<br />27:59 The value of ticket pricing<br />31:50 BSides & the conference model<br />46:11 Penetration testing & scoping<br />57:28 The purpose of pen testing<br />58:23 When pen testing goes wrong<br />01:00:16 Reasons for pen testing & compliance drivers<br />01:03:04 Continuous monitoring, testing & detection<br />01:06:19 Is your company ready for a pen test?<br />01:07:07 A risk-based approach<br />01:13:58 Scenario-based testing & resilience<br />01:17:31 Evaluating the value of pen testing<br />01:29:01 The constant state of change<br />01:31:01 Compliance & cyber insurance<br />01:32:19 Bourbon tasting<br />01:36:32 Government scoring & risk analysis<br />01:50:36 HIPAA compliance & ransomware<br />01:55:01 Wrap-up & call to action</p><p></p><p>π§ Distilled Security Podcast</p><p>Cybersecurity, GRC, and leadership, one pour at a time.</p><p></p><p>ποΈ Hosts</p><ul><li><b>Justin Leapline</b> β @justinleapline</li><li><b>Joe Wynn</b> β @wynnjoe</li><li><b>Rick Yocum</b> β @rickyocum<p></p></li></ul><p>π€ Guest</p><ul><li><b>Jon Buhagiar </b><a rel="noopener noreferrer nofollow" href="http://linkedin.com/in/jonbuhagiar" target="_blank">linkedin.com/in/jonbuhagiar</a></li></ul><p></p><p>π¬ Send Us Your Questions!</p><p><a rel="noopener noreferrer nofollow" href="mailto:ask@distilledsecuritypodcast.com" target="_blank">ask@distilledsecuritypodcast.com</a></p><p></p><p>π Connect with Us</p><p></p><p><b>Website:</b> <a rel="noopener noreferrer nofollow" href="http://distilledsecuritypodcast.com" target="_blank">distilledsecuritypodcast.com</a></p><p><b>X:</b> @DisSecPod</p><p><b>YouTube:</b> @distilledsecurity</p><p><b>Email:</b> <a rel="noopener noreferrer nofollow" href="mailto:hello@distilledsecuritypodcast.com" target="_blank">hello@distilledsecuritypodcast.com</a></p><p></p><p>π Like, comment, and subscribe for monthly</p><p>security and compliance insights.</p>