Speaker · CISO · Writer
Lora
Vaughn
I help security leaders make decisions they can defend, on stage, in writing, and in the room when it matters.
Ex NSA · 2x CISO · CISSP · CISOs Connect A100
Writing
How I think about security
third-party-risk
The Vendor of My Vendor Is My Vendor
Jack Henry, IDScan.net, and LexisNexis. Three companies that aren't banks, all of them a community bank's problem, and not one of them chosen by the bank. Why the failures keep landing a tier or two below the line where your vendor program stops looking.
ciso
The Reporting Line Debate Is a Distraction
Everyone argues about where the CISO should report. That's the wrong argument. The real fix is a written mandate around the budget you'll have to challenge, and it doesn't require a new box on the chart.
career
My Brain Is Built for Incidents. It's the Other 320 Days That Need a System.
The wiring that makes me lose my keys is the same wiring that goes calm and fast when everything is on fire. What twenty years in security taught me about working with my brain instead of against it.
community-banking
The Most Expensive Attack on Your Bank Won't Use Malware
Business email compromise still outearns ransomware every year, and it beats banks that have EDR, MFA, and a clean exam. The control that stops it is a process, not a product, and most institutions never test it.

Speaking
Want me on your stage?
Lora Vaughn is a fractional CISO and cybersecurity speaker with 20+ years securing banks, digital payments, and financial products at scale. She is a two time CISO (MoneyGram, Simmons Bank), a former NSA analyst, a CISSP, and a two time CISOs Connect A100 honoree. She writes practical, no buzzword security guidance from Birmingham, Alabama.