Speaker · CISO · Writer
Lora
Vaughn
I help security leaders make decisions they can defend, on stage, in writing, and in the room when it matters.
Ex NSA · 2x CISO · CISSP · CISOs Connect A100
Writing
How I think about security
ai
Whose No Counts
Everybody wants AI. Nobody wants the data center next door. 'Not in my backyard' works fine, as long as you have the power to make it stick.
career
I'm Speaking at ISC2 Security Congress 2026. Twice.
Two sessions at ISC2 Security Congress in Aurora, Colorado this October: one on making career decisions with the MOVE framework, one on threat modeling when your resources don't match your threat. Here's where to find me.
vendor-risk
Your Security Rating Is a Credit Score From a Company That's Never Met You
Security ratings platforms grade your vendors from the parking lot, bill somebody for the number, and hand your board a red dot to ask you about. Here's what the score actually measures and what deserves your diligence hours instead.
third-party-risk
The Vendor of My Vendor Is My Vendor
Jack Henry, IDScan.net, and LexisNexis. Three companies that aren't banks, all of them a community bank's problem, and not one of them chosen by the bank. Why the failures keep landing a tier or two below the line where your vendor program stops looking.

Speaking
Want me on your stage?
Lora Vaughn is a fractional CISO and cybersecurity speaker with 20+ years securing banks, digital payments, and financial products at scale. She is a two time CISO (MoneyGram, Simmons Bank), a former NSA analyst, a CISSP, and a two time CISOs Connect A100 honoree. She writes practical, no buzzword security guidance from Birmingham, Alabama.