// SPEAKER · CISO · WRITER · COMMUNITY
Lora
Vaughn.
Cybersecurity leader who's protected billions in assets. Now helping organizations get security right through speaking and fractional CISO work.
EX-NSA · 2X CISO · F500 EXPERIENCE · CISSP
// 01 / SPEAKING
Book Lora for your next event
Engaging keynotes with actionable insights. No vendor pitches. No buzzwords.
"Best presenter all day."
ISC2 Security Congress 2025
"Best talk so far in clarity and content value."
ISC2 Security Congress 2024
"Amazing speaker, actionable content."
ISC2 Security Congress 2025
Plan for Chaos: Why Most IR Plans Fail Big
Real stories from incident response failures: what actually breaks and how to build muscle memory before you need it.
The Spy in Your Pocket: Mobile Security for Everyone
Your smartphone knows more about you than your closest friends. Here's what to do about it, no jargon required.
// 02 / FRACTIONAL CISO
Need a Fractional CISO?
Not ready for a full-time hire? I help startups, SMBs, and community banks build security programs that actually work, without the enterprise price tag or consultant-speak.
- ✓ Fractional CISO services: Part-time security leadership
- ✓ SOC 2 & compliance readiness: Audit prep without the panic
- ✓ Incident response planning: Build the playbook before you need it
- ✓ Post-incident stabilization: Just had a breach? Let's fix it.
// 03 / RECENT WRITING
How I think about security
No buzzwords. No vendor pitches. Just real talk.
Your Ransomware Negotiator Might Be Playing Both Sides
The DigitalMint conviction proves your IR vendor pre-vetting is part of your security program, not an afterthought. Here is what to ask before the next incident, not during it.
We Used to Have Pockets. Then Someone Took Them
A choir practice rant about why women's clothing has no real pockets, how that happened, and why a missing pocket was never really about the pocket.
The AI Questionnaire Your Vendors Aren't Ready For
Your vendors' employees are using AI tools. That means your data is flowing to model providers you've never assessed. Here are the questions to start asking.
// 04 / TRACK RECORD
By the numbers
// Speaking
- ISC2 Security Congress (2024, 2025)
- WiCyS Conference
- Southeast Cybersecurity Summit
- Rapid7 UNITED
// Recognition
- CISOs Connect A100, 2024 and 2025
- LinkedIn Learning Instructor
- CISSP Certified