Skip to main content
Currently onloravaughn.com→ visit Vaughn Cyber Group

// BLOG

All posts.

Field notes from 20+ years in security. Plus the occasional detour into life, work, and whatever else is on my mind.

Threat Modeling for the Bank That Doesn't Have a Threat Intel Team

The standard threat modeling playbook assumes staff and budget many institutions don't have. Here's a working method for a security team of one to three people: four questions, free intelligence sources, and a defensible answer for the examiner.

community-bankingsecurity-strategyrisk-managementinsights

Stop Trying to Spot the Deepfake

Cybersecurity Awareness Month is about to flood your inbox with tips for spotting deepfakes. Weird blinking, bad lip sync, extra fingers. That advice has already expired. Here's what to teach instead.

ai-securitydeepfakesfraud-preventionhackloreinsights

Whose No Counts

Everybody wants AI. Nobody wants the data center next door. 'Not in my backyard' works fine, as long as you have the power to make it stick.

aidata-centerscommunityinsights

I'm Speaking at ISC2 Security Congress 2026. Twice.

Two sessions at ISC2 Security Congress in Aurora, Colorado this October: one on making career decisions with the MOVE framework, one on threat modeling when your resources don't match your threat. Here's where to find me.

careerspeakingconferencesinsights

Your Security Rating Is a Credit Score From a Company That's Never Met You

Security ratings platforms grade your vendors from the parking lot, bill somebody for the number, and hand your board a red dot to ask you about. Here's what the score actually measures and what deserves your diligence hours instead.

vendor-riskthird-party-riskcommunity-bankinginsights

The Vendor of My Vendor Is My Vendor

Jack Henry, IDScan.net, and LexisNexis. Three companies that aren't banks, all of them a community bank's problem, and not one of them chosen by the bank. Why the failures keep landing a tier or two below the line where your vendor program stops looking.

third-party-riskvendor-riskcommunity-bankinginsights

The Reporting Line Debate Is a Distraction

Everyone argues about where the CISO should report. That's the wrong argument. The real fix is a written mandate around the budget you'll have to challenge, and it doesn't require a new box on the chart.

cisosecurity-leadershipgovernanceorg-designinsights

My Brain Is Built for Incidents. It's the Other 320 Days That Need a System.

The wiring that makes me lose my keys is the same wiring that goes calm and fast when everything is on fire. What twenty years in security taught me about working with my brain instead of against it.

careersecurity-leadershippersonalinsights

The Most Expensive Attack on Your Bank Won't Use Malware

Business email compromise still outearns ransomware every year, and it beats banks that have EDR, MFA, and a clean exam. The control that stops it is a process, not a product, and most institutions never test it.

community-bankingfraud-preventionsmb-securityinsights

The Authority Gap Is a Conflict of Interest Problem

Everyone agrees the CISO role is accountable for more than it controls. Almost nobody names the mechanism. Here's what actually has to change.

cisosecurity-leadershipgovernancerisk-managementinsights