Skip to main content
Currently onloravaughn.com→ visit Vaughn Cyber Group
Lora Vaughn

// POSTS TAGGED "insights"

Insights.

All posts tagged insights.

← back to all posts
Featured image for The AI Questionnaire Your Vendors Aren't Ready For

The AI Questionnaire Your Vendors Aren't Ready For

Your vendors' employees are using AI tools. That means your data is flowing to model providers you've never assessed. Here are the questions to start asking.

third-party-riskvendor-riskai-securitycommunity-bankinginsights
Featured image for Your Tabletop Exercise Isn't Testing What You Think It Is

Your Tabletop Exercise Isn't Testing What You Think It Is

Most tabletop exercises are scripted theater that confirm what people already believe. Here's what actually breaks during a real incident, and how to design an exercise that finds it before someone else does.

incident-responsetabletop-exercisessecurity-leadershipinsights
Featured image for Concentration Risk Wasn't Just About Loans

Concentration Risk Wasn't Just About Loans

Community banks have managed concentration risk for a century. Then we handed every customer record to a handful of SaaS aggregators. ShinyHunters is teaching us what that actually costs.

community-bankingvendor-riskthird-party-riskconcentration-riskinsights
Featured image for Your Vendor Questionnaire Doesn't Ask the Right OAuth Questions

Your Vendor Questionnaire Doesn't Ask the Right OAuth Questions

Regulators have been citing 4th party risk for years. OAuth token chains are how it actually executes, and most vendor programs aren't built to catch it. Here's what to ask.

third-party-riskvendor-riskoauthsaas-securityinsights
Featured image for Phishing Tests Don't Work. Fight Me.

Phishing Tests Don't Work. Fight Me.

Phishing simulation click rates are a metric, not a security outcome. AI just made real phishing dramatically harder to spot. Your tests haven't caught up.

security-culturehacklorehuman-riskinsights
Featured image for NIST Just Stopped Doing Part of Your Job. Now What?

NIST Just Stopped Doing Part of Your Job. Now What?

NIST is no longer enriching every CVE in the National Vulnerability Database. If CVSS scores were the backbone of your vulnerability management program, you have a problem that predates this announcement.

vulnerability-managementrisk-managementcisoinsights
Featured image for Your AI Vendor Said Their Model Is Accurate, Explainable, and Compliant. Did They Prove It?

Your AI Vendor Said Their Model Is Accurate, Explainable, and Compliant. Did They Prove It?

Community banks are getting pitched AI tools right now. Standard vendor due diligence doesn't cover what actually matters with AI. Here's what to ask before you sign anything.

community-banksai-governancecompliancevendor-selectioninsights
Featured image for How to Pick an MDR Provider When You're a Community Bank

How to Pick an MDR Provider When You're a Community Bank

Every MDR vendor says they do detection and response. Here's what to actually evaluate before you sign a contract, and the questions most community banks never think to ask.

community-banksmdrsecurity-operationsvendor-selectionffiecinsights
Featured image for The FFIEC CAT Is Gone. Now What?

The FFIEC CAT Is Gone. Now What?

The FFIEC retired the Cybersecurity Assessment Tool. Here's what community banks actually need to do now, what examiners are looking for instead, and how to transition without starting from scratch.

community-banksffieccompliancenist-csfrisk-managementinsights
Featured image for The Framework Trap: When Compliance Kills Security

The Framework Trap: When Compliance Kills Security

Security frameworks were built to guide programs, not replace thinking. Do security right and compliance follows. Here's why most organizations have it backwards.

compliancesecurity-strategycommunity-bankinginsights