Speaker · CISO · Writer
Lora
Vaughn
I help security leaders make decisions they can defend, on stage, in writing, and in the room when it matters.
Ex NSA · 2x CISO · CISSP · CISOs Connect A100
Writing
How I think about security
vendor-risk
Your Security Rating Is a Credit Score From a Company That's Never Met You
Security ratings platforms grade your vendors from the parking lot, bill somebody for the number, and hand your board a red dot to ask you about. Here's what the score actually measures and what deserves your diligence hours instead.
third-party-risk
The Vendor of My Vendor Is My Vendor
Jack Henry, IDScan.net, and LexisNexis. Three companies that aren't banks, all of them a community bank's problem, and not one of them chosen by the bank. Why the failures keep landing a tier or two below the line where your vendor program stops looking.
ciso
The Reporting Line Debate Is a Distraction
Everyone argues about where the CISO should report. That's the wrong argument. The real fix is a written mandate around the budget you'll have to challenge, and it doesn't require a new box on the chart.
career
My Brain Is Built for Incidents. It's the Other 320 Days That Need a System.
The wiring that makes me lose my keys is the same wiring that goes calm and fast when everything is on fire. What twenty years in security taught me about working with my brain instead of against it.

Speaking
Want me on your stage?
Lora Vaughn is a fractional CISO and cybersecurity speaker with 20+ years securing banks, digital payments, and financial products at scale. She is a two time CISO (MoneyGram, Simmons Bank), a former NSA analyst, a CISSP, and a two time CISOs Connect A100 honoree. She writes practical, no buzzword security guidance from Birmingham, Alabama.