Skip to main content
Currently onloravaughn.com→ visit Vaughn Cyber Group
Lora Vaughn

// POSTS TAGGED "insights"

Insights.

All posts tagged insights.

← back to all posts

The Slow Call Is Still the Job

Security leadership rewards speed. The calls I am proudest of during an active incident were the ones I forced myself to slow down on. That is a trained discipline, not a personality trait, and most playbooks never write it down.

security-leadershipincident-responsecareerinsights

Your Vendor's Auditor Is Also a Vendor

SR Bancorp's breach came through the firm hired to audit its controls. Most vendor risk programs never ask who has access to the data behind the audit itself.

vendor-riskcommunity-bankingthird-party-riskinsights

When Your Vendor Gets Breached, You Find Out Last

A fintech software vendor got hit with ransomware and up to 1.35 million banking customers were exposed. Most of their banks did the questionnaire, got the SOC 2, and still found out months late. The control that matters isn't the one you audited.

community-bankingvendor-riskincident-responseinsights

Your AI Policy Doesn't Cover the Part That Can Actually Hurt You

79% of organizations are deploying AI agents. 6% have updated their governance to match. The gap isn't in the models. It's in what those agents are connected to.

ai-governanceai-securitysecurity-leadershipcommunity-bankingpractical-securityinsights

The CISO Who Buries Bad News Isn't Wrong. The System Is.

95% of CISOs feel pressured to suppress compliance findings. The industry response is that they need more backbone. That's the wrong read.

cisosecurity-leadershipgovernancecareersecurity-operationsinsights

Your Incident Response Plan Is Modeling the Wrong Threat Actor

LockBit dominated tabletops for years. The ransomware ecosystem has rotated. The groups hitting organizations right now are not the ones your IR team practiced against, and that gap has consequences.

ransomwareincident-responsecommunity-bankingsecurity-leadershipinsights
Featured image for Your AI Agent Has a Supply Chain. Did You Audit It?

Your AI Agent Has a Supply Chain. Did You Audit It?

One in four MCP servers expose AI agents to remote code execution. Most teams deploying agents do not know what an MCP server is. That is a supply chain problem disguised as an AI launch.

ai-securitysupply-chainvendor-riskai-governanceinsights
Featured image for "We Have an AI Policy" Is the New "We Passed the Audit"

"We Have an AI Policy" Is the New "We Passed the Audit"

OpenAI just admitted prompt injection isn't getting solved, and companies are wiring AI agents into production anyway. A policy document is not a control.

ai-governancesecurity-theatercommunity-bankingai-securityinsights
Featured image for Your no-code MVP can't legally hold the data it was built for

Your no-code MVP can't legally hold the data it was built for

No-code and AI app builders are great for prototypes, but they won't sign the agreement that lets you legally handle regulated data. Here's the line every founder needs to know before real data shows up.

hipaacompliancehealthcarestartup-securityinsights
Featured image for Your Ransomware Negotiator Might Be Playing Both Sides

Your Ransomware Negotiator Might Be Playing Both Sides

The DigitalMint conviction proves your IR vendor pre-vetting is part of your security program, not an afterthought. Here is what to ask before the next incident, not during it.

incident-responsesecurity-operationssecurity-strategyinsights