Full Name: Lora Vaughn
Credentials: CISSP
Title: Fractional CISO & Cybersecurity Speaker
Company: Vaughn Cyber Group
Location: Birmingham, Alabama
Travel: US nationwide, virtual global
Headshot: Download (400px) →
Website: loravaughn.com
// SPEAKING
Book cybersecurity speaker Lora Vaughn, CISSP, for your next conference or event. Two-time CISO, former NSA analyst, and LinkedIn Learning instructor. Real talk and actionable insights, not compliance checkbox theater.
// FEATURED IN
// QUICK FACTS
4+ weeks preferred; rush considered
24-48 hours on inquiries
US nationwide; virtual globally. Based in Birmingham, AL.
// ABOUT LORA

Fractional CISO | Cybersecurity Speaker | LinkedIn Learning Instructor
Two-time CISO (MoneyGram serving 150M+ customers, Simmons Bank during growth from $10B to $20B+), Senior Director at Fastly (10% of global internet traffic), and former NSA analyst. 20+ years securing digital payments, banking platforms, and financial products at scale.
Featured speaker at ISC2 Security Congress, WiCyS, and the Southeast Cybersecurity Summit. LinkedIn Learning courses viewed by thousands of cybersecurity professionals. CISOs Connect A100 honoree (2024, 2025).
// SPEAKER BIOS
Lora Vaughn, CISSP, is a cybersecurity leader, keynote speaker, and LinkedIn Learning instructor who has spent 20+ years protecting organizations from nation-state adversaries, digital payment fraud, and their own bad security habits. She's allergic to security theater and corporate buzzwords. Audiences get real talk and actionable insights, not compliance checkbox theater.
Lora began her career hunting sophisticated threats as a Global Network Exploitation & Vulnerability Analyst at the National Security Agency. She brought that expertise to the private sector as CISO at MoneyGram International, where she secured digital payments for 150 million+ customers across 200+ global markets, and as CISO at Simmons Bank during its growth from $10B to $20B+ in assets. At Fastly, she led security for edge cloud infrastructure handling 10% of global internet traffic (because apparently she likes pressure).
Today, Lora is a LinkedIn Learning instructor with courses on vulnerability management viewed by thousands of cybersecurity professionals. She is a two-time CISOs Connect A100 honoree (2024, 2025) and founder of Vaughn Cyber Group, providing fractional CISO services nationwide.
Known for making security concepts accessible without dumbing them down, Lora speaks at major conferences including ISC2 Security Congress (4.7/5.0 rating), WiCyS, and the Southeast Cybersecurity Summit. Whether addressing a room of CISOs or helping small businesses stay secure without going broke, she brings the same energy: honest, practical, and occasionally funny.
Full Name: Lora Vaughn
Credentials: CISSP
Title: Fractional CISO & Cybersecurity Speaker
Company: Vaughn Cyber Group
Location: Birmingham, Alabama
Travel: US nationwide, virtual global
Headshot: Download (400px) →
Website: loravaughn.com
// 01 / SIGNATURE SESSIONS
High-impact keynotes designed to transform how your audience thinks about cybersecurity.
// FOR SECURITY PROFESSIONALS
A high-impact talk derived from ISC2 Security Congress that helps leaders move beyond check-box compliance to true resilience. Drawing from real-world incident response failures and successes across Fortune 500 banks and global payment systems, this session reveals the critical gaps that cause most IR plans to crumble under pressure.
Key Takeaways: Why tabletop exercises fail. Building muscle memory for crisis. The communication gaps that sink response efforts. Moving from compliance theater to operational readiness.
// FOR GENERAL AUDIENCES
Your smartphone knows more about you than your closest friends: where you go, who you talk to, what you buy, and even what you're thinking about buying. This engaging, accessible talk reveals the hidden ways your mobile device can betray your privacy and provides practical, no-jargon steps anyone can take to protect themselves.
Key Takeaways: What your phone tracks without you knowing. Simple settings changes that make a big difference. Spotting scams and phishing on mobile. Protecting your family's digital privacy.
// FOR GENERAL AUDIENCES
Lora built a working, real-time deepfake in 30 minutes using free tools and zero machine learning knowledge. This talk shows audiences exactly how easy that has become, why the video call you trust might not be real, and the simple habits that stop these scams before they cost someone their savings. Includes an optional live demo that turns the audience into celebrities on screen.
Key Takeaways: How real-time deepfakes are made, and why they now take minutes instead of days. Spotting deepfake scams that target you and your family. Safe words and out-of-band verification that actually work. Why a familiar face plus urgency is the real attack.
// 02 / TESTIMONIALS
"Plan for Chaos: Why Most Incident Response Plans Fail Big"
"Best presenter all day"
"Amazing speaker along with wonderful and actionable content"
"She is GOOOOD... will be referencing her slides for sure"
"Measuring Cybersecurity Success: Crafting Metrics with NIST CSF and Beyond"
"In terms of clarity and content value, the best talk so far."
"Fantastic. This will be one session I will watch again."
"Great presentation from someone who has clearly spent time honing her craft."
// 03 / SPEAKING TOPICS
Typical response within 24-48 hours.
// FEATURED ENGAGEMENTS
// LINKEDIN LEARNING
Published courses on vulnerability management viewed by thousands of cybersecurity professionals worldwide:
// 04 / BOOKING INFO
Experienced presenting to audiences from 25 to 2,500+ attendees
Based in the US. Available for speaking engagements nationwide. Virtual presentations available globally.
Looking for a cybersecurity keynote speaker who delivers practical, actionable insights without corporate buzzwords? Let's talk about your event.
Include in your inquiry: event date, audience size, topic preference, and format (keynote, workshop, panel, virtual).
// NOT LOOKING FOR A SPEAKER?
I also serve as a fractional CISO for startups, SMBs, and community banks through Vaughn Cyber Group. If your organization needs ongoing security leadership, SOC 2 readiness, or incident response planning, let's talk.
// 05 / FAQ
Lora tailors presentations for diverse audiences, from students exploring cybersecurity careers to C-suite executives making security investment decisions, SMBs protecting their businesses, and community groups learning online safety. For technical professionals: vulnerability management, incident response, and security metrics. For business leaders: startup security, SMB cybersecurity, and nonprofit security on a budget. For general audiences: mobile security, online safety, and protecting your digital legacy. All topics can be customized to match your audience's technical background.
Contact Lora directly through the "Request Speaking Info" button on this page, or connect via LinkedIn. Please include your event date, expected audience size, topic preference, and whether the engagement is in-person or virtual.
Yes. Lora is based in Birmingham, Alabama and is available for speaking engagements nationwide. Virtual presentations are also available for remote audiences.
Lora has 20+ years of cybersecurity experience including roles as CISO at MoneyGram (150M+ customers) and Simmons Bank ($20B+ assets), Senior Director at Fastly (10% of global internet traffic), and former Global Network Exploitation & Vulnerability Analyst at the National Security Agency. She's a published LinkedIn Learning instructor, CISOs Connect A100 honoree (2024, 2025), and has spoken at major conferences including ISC2 Security Congress and WiCyS.
// CONFERENCE TALKS
4.70/5.0 rating. Incident response plans are critical to any cybersecurity strategy, but the reality is that many of these plans aren't enough when faced with major, high-impact incidents. This talk dives into the gaps and misconceptions inherent in most incident response plans, why they fail during major incidents, and how to evolve beyond them.
Incident response plans are critical to any cybersecurity strategy, but the reality is that many of these plans aren't enough when faced with major, high-impact incidents. This talk dives into the gaps and misconceptions inherent in most incident response plans, why they fail during major incidents, and how to evolve beyond them.
How to use cybersecurity frameworks to create meaningful metrics that demonstrate program value and progress to leadership.
Presentation at 2022 Southeast Cybersecurity Summit about building effective bug bounty programs
Presentation at 2021 Cyber Now Summit
Transitioning from a cybersecurity student to a cybersecurity professional sounds daunting, but it doesn’t have to be.
Presentation at 2020 Cyber Now Summit
Presentation at 2018 Alabama Cyber Now Conference
// VIDEOS & COURSES
Watch Lora in action across media appearances and professional training.

LinkedIn Learning. Vulnerability management is a critical part of an effective information security program, but determining which vulnerabilities to address first is a daunting challenge. In this course, learn how to differentiate between vulnerability severity and vulnerability risk. Discover what elements can be combined to determine vulnerability severity, techniques you can use to determine the risk a vulnerability poses to your specific environment, and things to consider when building a vulnerability management program.

LinkedIn Learning. This course provides those without prior experience in the area an overview of why vulnerabilities exist, as well as an explanation of the process of managing them from start to finish. Instructor Lora Vaughn McIntosh covers the three key components of vulnerability management and the tools needed to establish a program of your own. Get an introduction to vulnerability scanning and reporting, learn how to identify which vulnerabilities to address first, discover how to vet false positives, and more.

4.74/5.0 rating. ISC2 Security Congress 2024: Most cybersecurity leaders have a good understanding of the things that need to be done to improve a security program, but how do you show senior leaders and board members those needs and progress as improvements are made? This talk shows an approach that uses the NIST Cyber Security Framework (CSF) to conduct a maturity assessment and create meaningful metrics that demonstrate program value and progress to leadership.

Transitioning from a cybersecurity student to a cybersecurity professional sounds daunting, but it doesn't have to be.

KATV Little Rock, Lora Vaughn discusses cybersecurity best practices.

Rapid7 UNITED2017 presentation
// ARTICLES
Article with insights from Lora Vaughn, about cybersecurity in banking.
A tribute to Kathy 'Kat' Vaughn, Lora's mother, who was a pioneer for women in the workforce and a source of inspiration.
Article in Business and Tech. The idea that anyone can become a successful IT or cybersecurity professional through hard work and talent is a myth. In reality, systemic barriers and biases often prevent many qualified individuals from entering or advancing in these fields.
What are some of the red flags to look for when applying for a job in cybersecurity? Lora Vaughn shares her insights.
Article in Built In. Lora Vaughn and other cybersecurity leaders discuss how developers and cybersecurity teams can work together more effectively with Tammy Xu.
Lora Vaughn of Simmons Bank: “When we collaborate and engage outside our bubbles, we can come up with stronger solutions.”