Episode 26: How to Run a Conference, Why Most Pen Tests Fail, and HIPAA's Ransomware Reckoning

Episode 26: How to Run a Conference, Why Most Pen Tests Fail, and HIPAA's Ransomware Reckoning

July 8, 2026 · 1h 56m · Episode 26

About this episode

The episode discusses the intricacies of running a security conference, the pitfalls of penetration testing, and the impact of compliance and cyber insurance on organizations.

In this episode, we're joined by Jon Buhagiar, Director of Information Technology at RareMed Solutions; a published Sybex/Wiley author of Cisco and Microsoft certification guides; and a longtime amateur radio enthusiast. We get into what it actually takes to run a security conference from the ground up, why so many penetration tests end up wasting everyone's money, and how compliance and cyber insurance keep reshaping the way organizations work. Plus, as always, a bourbon. 🎤 Jon's world — rare-disease specialty pharmacy, patient assistance programs, book writing, and ham radio 🏗️ Running BSides Pittsburgh: revenue, expenses, marketing, volunteers, speakers, and sponsors 🎟️ The real economics of ticket pricing, free tickets, and the venue/affordability squeeze 🧑‍🤝‍🧑 Dividing responsibilities and appointing workstream leads as an event grows 🎯 Scoping as the make-or-break of a good pen test — and the human element that tooling misses 🔗 Chaining vulnerabilities and what separates a checkbox test from a real one 💸 Why pen testing so often becomes an ineffective use of resources 📋 Compliance and contractual drivers vs. genuine risk reduction 🛡️ A risk-based, scenario-driven…

People in this episode

Hosts: Justin Leapline, Joe Wynn, Rick Yocum

Guest: Jon Buhagiar

Topics covered

Keywords

Mentioned in this episode

Organizations: RareMed Solutions, Cisco, Microsoft, BSides Pittsburgh, HIPAA

Explore listener stats, chart rankings, contacts and more on the Distilled Security Podcast podcast page.