Speaker · CISO · Writer
Lora
Vaughn
I help security leaders make decisions they can defend, on stage, in writing, and in the room when it matters.
Ex NSA · 2x CISO · CISSP · CISOs Connect A100
Writing
How I think about security
career
I'm Speaking at ISC2 Security Congress 2026. Twice.
Two sessions at ISC2 Security Congress in Aurora, Colorado this October: one on making career decisions with the MOVE framework, one on threat modeling when your resources don't match your threat. Here's where to find me.
vendor-risk
Your Security Rating Is a Credit Score From a Company That's Never Met You
Security ratings platforms grade your vendors from the parking lot, bill somebody for the number, and hand your board a red dot to ask you about. Here's what the score actually measures and what deserves your diligence hours instead.
third-party-risk
The Vendor of My Vendor Is My Vendor
Jack Henry, IDScan.net, and LexisNexis. Three companies that aren't banks, all of them a community bank's problem, and not one of them chosen by the bank. Why the failures keep landing a tier or two below the line where your vendor program stops looking.
ciso
The Reporting Line Debate Is a Distraction
Everyone argues about where the CISO should report. That's the wrong argument. The real fix is a written mandate around the budget you'll have to challenge, and it doesn't require a new box on the chart.

Speaking
Want me on your stage?
Lora Vaughn is a fractional CISO and cybersecurity speaker with 20+ years securing banks, digital payments, and financial products at scale. She is a two time CISO (MoneyGram, Simmons Bank), a former NSA analyst, a CISSP, and a two time CISOs Connect A100 honoree. She writes practical, no buzzword security guidance from Birmingham, Alabama.