Skip to main content
Currently onloravaughn.com→ visit Vaughn Cyber Group

Speaker · CISO · Writer

Lora
Vaughn

I help security leaders make decisions they can defend, on stage, in writing, and in the room when it matters.

Ex NSA · 2x CISO · CISSP · CISOs Connect A100

Writing

How I think about security

  • third-party-risk

    The Vendor of My Vendor Is My Vendor

    Jack Henry, IDScan.net, and LexisNexis. Three companies that aren't banks, all of them a community bank's problem, and not one of them chosen by the bank. Why the failures keep landing a tier or two below the line where your vendor program stops looking.

  • ciso

    The Reporting Line Debate Is a Distraction

    Everyone argues about where the CISO should report. That's the wrong argument. The real fix is a written mandate around the budget you'll have to challenge, and it doesn't require a new box on the chart.

  • career

    My Brain Is Built for Incidents. It's the Other 320 Days That Need a System.

    The wiring that makes me lose my keys is the same wiring that goes calm and fast when everything is on fire. What twenty years in security taught me about working with my brain instead of against it.

  • community-banking

    The Most Expensive Attack on Your Bank Won't Use Malware

    Business email compromise still outearns ransomware every year, and it beats banks that have EDR, MFA, and a clean exam. The control that stops it is a process, not a product, and most institutions never test it.

Lora Vaughn speaking on stage
Photo: Michael Roberts / ISC2 Security Congress 2025

Speaking

Want me on your stage?

Lora Vaughn is a fractional CISO and cybersecurity speaker with 20+ years securing banks, digital payments, and financial products at scale. She is a two time CISO (MoneyGram, Simmons Bank), a former NSA analyst, a CISSP, and a two time CISOs Connect A100 honoree. She writes practical, no buzzword security guidance from Birmingham, Alabama.