Skip to main content
Currently onloravaughn.com→ visit Vaughn Cyber Group

Speaker · CISO · Writer

Lora
Vaughn

I help security leaders make decisions they can defend, on stage, in writing, and in the room when it matters.

Ex NSA · 2x CISO · CISSP · CISOs Connect A100

Writing

How I think about security

  • career

    I'm Speaking at ISC2 Security Congress 2026. Twice.

    Two sessions at ISC2 Security Congress in Aurora, Colorado this October: one on making career decisions with the MOVE framework, one on threat modeling when your resources don't match your threat. Here's where to find me.

  • vendor-risk

    Your Security Rating Is a Credit Score From a Company That's Never Met You

    Security ratings platforms grade your vendors from the parking lot, bill somebody for the number, and hand your board a red dot to ask you about. Here's what the score actually measures and what deserves your diligence hours instead.

  • third-party-risk

    The Vendor of My Vendor Is My Vendor

    Jack Henry, IDScan.net, and LexisNexis. Three companies that aren't banks, all of them a community bank's problem, and not one of them chosen by the bank. Why the failures keep landing a tier or two below the line where your vendor program stops looking.

  • ciso

    The Reporting Line Debate Is a Distraction

    Everyone argues about where the CISO should report. That's the wrong argument. The real fix is a written mandate around the budget you'll have to challenge, and it doesn't require a new box on the chart.

Lora Vaughn speaking on stage
Photo: Michael Roberts / ISC2 Security Congress 2025

Speaking

Want me on your stage?

Lora Vaughn is a fractional CISO and cybersecurity speaker with 20+ years securing banks, digital payments, and financial products at scale. She is a two time CISO (MoneyGram, Simmons Bank), a former NSA analyst, a CISSP, and a two time CISOs Connect A100 honoree. She writes practical, no buzzword security guidance from Birmingham, Alabama.