Skip to main content
Currently onloravaughn.com→ visit Vaughn Cyber Group
Lora Vaughn

// POSTS TAGGED "insights"

Insights.

All posts tagged insights.

← back to all posts
Featured image for Your Vendors Are Your Biggest Security Risk. Here's What to Do About It.

Your Vendors Are Your Biggest Security Risk. Here's What to Do About It.

Most community banks can answer every question about their own security posture. But ask about their vendors, and you get silence. Here's how to fix that.

community-bankingvendor-riskthird-party-riskinsights
Featured image for It's 2026. You Can Use the Guest WiFi.

It's 2026. You Can Use the Guest WiFi.

A security professional scolded me for connecting to guest WiFi. Meanwhile, 100+ CISOs signed a letter asking people to stop giving exactly that advice.

security-culturehacklorepractical-securityinsights
Featured image for Why Your Incident Response Plan Will Fail (And What to Build Instead)

Why Your Incident Response Plan Will Fail (And What to Build Instead)

Most IR plans fail not because they're poorly written, but because plans don't survive contact with reality. Here's how to build response capability instead of just documentation.

incident-responsesecurity-operationscrisis-managementtabletop-exercisessecurity-leadershipcisobusiness-continuitysecurity-planninginsights
Featured image for The Drinking Bird at the Nuclear Plant

The Drinking Bird at the Nuclear Plant

Sam Altman wants to give AI full access to everything. Your users will too. Your AI security strategy isn't competing against attackers; it's competing against tedium. Tedium wins.

ai-securityagentic-aisecurity-controlsuser-behaviorrisk-managementsecurity-leadershipopenaiautomationinsights
Featured image for SIEM vs. MDR for Community Banks: What Actually Works (And What's a Waste of Money)

SIEM vs. MDR for Community Banks: What Actually Works (And What's a Waste of Money)

A practical guide for community banks choosing between SIEM and MDR solutions. Real costs, what examiners actually want, and a decision framework for banks under $2B in assets.

community-bankssiemmdrffieccompliancesecurity-operationsbankingvirtual-cisothreat-detectionsecurity-budgetinsights
Featured image for The Security Program You Actually Need (Not the One Vendors Are Selling You)

The Security Program You Actually Need (Not the One Vendors Are Selling You)

Most security advice assumes you're a Fortune 500. You're not. Here's what you actually need at your size, what you can skip, and how to know when to level up.

community-banksfintechstartupssecurity-programsright-sizing-securityinsights
Featured image for Intentions, Not Resolutions: On Choosing Presence Over Urgency

Intentions, Not Resolutions: On Choosing Presence Over Urgency

On knowing the always-on CISO life isn't sustainable, doing it anyway, and what fractional work is teaching me about presence.

careercisoleadershipwork-life-balancefractional-cisonew-yearsintentionsinsights
Featured image for When Your Bank Examiner Says 'Risk Assessment' and You Break Out in Hives

When Your Bank Examiner Says 'Risk Assessment' and You Break Out in Hives

Why most cybersecurity guidance for community banks is useless, and what to do instead

cybersecuritybankingcompliancecommunity-banksrisk-managementinsights
Featured image for How to Respond When Your Customer Sends You a Security Questionnaire

How to Respond When Your Customer Sends You a Security Questionnaire

Your biggest deal just sent a 200-question security assessment. Here's your step-by-step playbook for responding without losing the deal or your mind.

vendor-riskcompliancesales-enablementinsights
Featured image for How to Get SOC 2 Certified: Startup Guide (Costs $15K-50K, Takes 3-6 Months)

How to Get SOC 2 Certified: Startup Guide (Costs $15K-50K, Takes 3-6 Months)

How much does SOC 2 cost? $15K-50K for audit + $5K-30K/year in tools. Real timeline: 3-6 months prep + 4-8 weeks audit. Here's what you actually need (and what you can skip).

soc2compliancestartup-securityauditssoc2-costsoc2-requirementsinsights