Skip to main content
Currently onloravaughn.com→ visit Vaughn Cyber Group

// POSTS TAGGED "insights"

Insights.

All posts tagged insights.

← back to all posts

The Vendor of My Vendor Is My Vendor

Jack Henry, IDScan.net, and LexisNexis. Three companies that aren't banks, all of them a community bank's problem, and not one of them chosen by the bank. Why the failures keep landing a tier or two below the line where your vendor program stops looking.

third-party-riskvendor-riskcommunity-bankinginsights

The Reporting Line Debate Is a Distraction

Everyone argues about where the CISO should report. That's the wrong argument. The real fix is a written mandate around the budget you'll have to challenge, and it doesn't require a new box on the chart.

cisosecurity-leadershipgovernanceorg-designinsights

My Brain Is Built for Incidents. It's the Other 320 Days That Need a System.

The wiring that makes me lose my keys is the same wiring that goes calm and fast when everything is on fire. What twenty years in security taught me about working with my brain instead of against it.

careersecurity-leadershippersonalinsights

The Most Expensive Attack on Your Bank Won't Use Malware

Business email compromise still outearns ransomware every year, and it beats banks that have EDR, MFA, and a clean exam. The control that stops it is a process, not a product, and most institutions never test it.

community-bankingfraud-preventionsmb-securityinsights

The Authority Gap Is a Conflict of Interest Problem

Everyone agrees the CISO role is accountable for more than it controls. Almost nobody names the mechanism. Here's what actually has to change.

cisosecurity-leadershipgovernancerisk-managementinsights

The Slow Call Is Still the Job

Security leadership rewards speed. The calls I am proudest of during an active incident were the ones I forced myself to slow down on. That is a trained discipline, not a personality trait, and most playbooks never write it down.

security-leadershipincident-responsecareerinsights

Your Vendor's Auditor Is Also a Vendor

SR Bancorp's breach came through the firm hired to audit its controls. Most vendor risk programs never ask who has access to the data behind the audit itself.

vendor-riskcommunity-bankingthird-party-riskinsights

When Your Vendor Gets Breached, You Find Out Last

A fintech software vendor got hit with ransomware and up to 1.35 million banking customers were exposed. Most of their banks did the questionnaire, got the SOC 2, and still found out months late. The control that matters isn't the one you audited.

community-bankingvendor-riskincident-responseinsights

Your AI Policy Doesn't Cover the Part That Can Actually Hurt You

79% of organizations are deploying AI agents. 6% have updated their governance to match. The gap isn't in the models. It's in what those agents are connected to.

ai-governanceai-securitysecurity-leadershipcommunity-bankingpractical-securityinsights

The CISO Who Buries Bad News Isn't Wrong. The System Is.

95% of CISOs feel pressured to suppress compliance findings. The industry response is that they need more backbone. That's the wrong read.

cisosecurity-leadershipgovernancecareersecurity-operationsinsights