// SPEAKER · CISO · WRITER · COMMUNITY
Lora
Vaughn.
Cybersecurity leader who's protected billions in assets. Now helping organizations get security right through speaking and fractional CISO work.
EX-NSA · 2X CISO · F500 EXPERIENCE · CISSP
// 01 / SPEAKING
Book Lora for your next event
Engaging keynotes with actionable insights. No vendor pitches. No buzzwords.
"Best presenter all day."
ISC2 Security Congress 2025
"Best talk so far in clarity and content value."
ISC2 Security Congress 2024
"Amazing speaker, actionable content."
ISC2 Security Congress 2025
Plan for Chaos: Why Most IR Plans Fail Big
Real stories from incident response failures: what actually breaks and how to build muscle memory before you need it.
The Spy in Your Pocket: Mobile Security for Everyone
Your smartphone knows more about you than your closest friends. Here's what to do about it, no jargon required.
// 02 / FRACTIONAL CISO
Need a Fractional CISO?
Not ready for a full-time hire? I help startups, SMBs, and community banks build security programs that actually work, without the enterprise price tag or consultant-speak.
- ✓ Fractional CISO services: Part-time security leadership
- ✓ SOC 2 & compliance readiness: Audit prep without the panic
- ✓ Incident response planning: Build the playbook before you need it
- ✓ Post-incident stabilization: Just had a breach? Let's fix it.
// 03 / RECENT WRITING
How I think about security
No buzzwords. No vendor pitches. Just real talk.
Your Incident Response Plan Is Modeling the Wrong Threat Actor
LockBit dominated tabletops for years. The ransomware ecosystem has rotated. The groups hitting organizations right now are not the ones your IR team practiced against, and that gap has consequences.
Finding a Mentor Is Good Advice. Finding a Sponsor Is the Advice Nobody Gives You.
Mentors give you guidance. Sponsors spend their capital on you. Most career conversations focus on the first one. The second one is what actually moves careers.
Your AI Agent Has a Supply Chain. Did You Audit It?
One in four MCP servers expose AI agents to remote code execution. Most teams deploying agents do not know what an MCP server is. That is a supply chain problem disguised as an AI launch.
// 04 / TRACK RECORD
By the numbers
// Speaking
- ISC2 Security Congress (2024, 2025)
- WiCyS Conference
- Southeast Cybersecurity Summit
- Rapid7 UNITED
// Recognition
- CISOs Connect A100, 2024 and 2025
- LinkedIn Learning Instructor
- CISSP Certified