<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Lora Vaughn - Cybersecurity &amp; Leadership Insights</title><description>Writing on cybersecurity strategy, AI risk, security leadership, and lessons from 20+ years in cybersecurity.</description><link>https://loravaughn.com/</link><language>en-us</language><item><title>Your Ransomware Negotiator Might Be Playing Both Sides</title><link>https://loravaughn.com/blog/your-ransomware-negotiator-might-be-playing-both-sides/</link><guid isPermaLink="true">https://loravaughn.com/blog/your-ransomware-negotiator-might-be-playing-both-sides/</guid><description>The DigitalMint conviction proves your IR vendor pre-vetting is part of your security program, not an afterthought. Here is what to ask before the next incident, not during it.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>incident-response</category><category>security-operations</category><category>security-strategy</category><enclosure url="https://loravaughn.com/blog-photos/contract.webp" length="0" type="image/webp"/></item><item><title>We Used to Have Pockets. Then Someone Took Them</title><link>https://loravaughn.com/blog/we-used-to-have-pockets-then-someone-took-them/</link><guid isPermaLink="true">https://loravaughn.com/blog/we-used-to-have-pockets-then-someone-took-them/</guid><description>A choir practice rant about why women&apos;s clothing has no real pockets, how that happened, and why a missing pocket was never really about the pocket.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><category>personal</category><category>culture</category><category>commentary</category><enclosure url="https://loravaughn.com/blog-photos/pockets.webp" length="0" type="image/webp"/></item><item><title>The AI Questionnaire Your Vendors Aren&apos;t Ready For</title><link>https://loravaughn.com/blog/the-ai-questionnaire-your-vendors-arent-ready-for/</link><guid isPermaLink="true">https://loravaughn.com/blog/the-ai-questionnaire-your-vendors-arent-ready-for/</guid><description>Your vendors&apos; employees are using AI tools. That means your data is flowing to model providers you&apos;ve never assessed. Here are the questions to start asking.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><enclosure url="https://loravaughn.com/blog-photos/supply-chain.webp" length="0" type="image/webp"/></item><item><title>Your Tabletop Exercise Isn&apos;t Testing What You Think It Is</title><link>https://loravaughn.com/blog/your-tabletop-exercise-isnt-testing-what-you-think-it-is/</link><guid isPermaLink="true">https://loravaughn.com/blog/your-tabletop-exercise-isnt-testing-what-you-think-it-is/</guid><description>Most tabletop exercises are scripted theater that confirm what people already believe. Here&apos;s what actually breaks during a real incident, and how to design an exercise that finds it before someone else does.</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate><category>incident-response</category><category>tabletop-exercises</category><category>security-leadership</category><enclosure url="https://loravaughn.com/blog-photos/tabletop.webp" length="0" type="image/webp"/></item><item><title>Concentration Risk Wasn&apos;t Just About Loans</title><link>https://loravaughn.com/blog/concentration-risk-wasnt-just-about-loans/</link><guid isPermaLink="true">https://loravaughn.com/blog/concentration-risk-wasnt-just-about-loans/</guid><description>Community banks have managed concentration risk for a century. Then we handed every customer record to a handful of SaaS aggregators. ShinyHunters is teaching us what that actually costs.</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate><enclosure url="https://loravaughn.com/blog-photos/concentration-overlap.webp" length="0" type="image/webp"/></item><item><title>Your Vendor Questionnaire Doesn&apos;t Ask the Right OAuth Questions</title><link>https://loravaughn.com/blog/your-vendor-questionnaire-doesnt-ask-the-right-oauth-questions/</link><guid isPermaLink="true">https://loravaughn.com/blog/your-vendor-questionnaire-doesnt-ask-the-right-oauth-questions/</guid><description>Regulators have been citing 4th party risk for years. OAuth token chains are how it actually executes, and most vendor programs aren&apos;t built to catch it. Here&apos;s what to ask.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate><enclosure url="https://loravaughn.com/blog-photos/tangledconnections.webp" length="0" type="image/webp"/></item><item><title>Phishing Tests Don&apos;t Work. Fight Me.</title><link>https://loravaughn.com/blog/phishing-tests-dont-work-fight-me/</link><guid isPermaLink="true">https://loravaughn.com/blog/phishing-tests-dont-work-fight-me/</guid><description>Phishing simulation click rates are a metric, not a security outcome. AI just made real phishing dramatically harder to spot. Your tests haven&apos;t caught up.</description><pubDate>Mon, 27 Apr 2026 00:00:00 GMT</pubDate><category>security-culture</category><category>hacklore</category><category>human-risk</category><enclosure url="https://loravaughn.com/blog-photos/phishing-test-dont-work.webp" length="0" type="image/webp"/></item><item><title>NIST Just Stopped Doing Part of Your Job. Now What?</title><link>https://loravaughn.com/blog/nist-just-stopped-doing-part-of-your-job-now-what/</link><guid isPermaLink="true">https://loravaughn.com/blog/nist-just-stopped-doing-part-of-your-job-now-what/</guid><description>NIST is no longer enriching every CVE in the National Vulnerability Database. If CVSS scores were the backbone of your vulnerability management program, you have a problem that predates this announcement.</description><pubDate>Tue, 21 Apr 2026 00:00:00 GMT</pubDate><category>vulnerability-management</category><category>risk-management</category><category>ciso</category><enclosure url="https://loravaughn.com/blog-photos/system-vulnerability.webp" length="0" type="image/webp"/></item><item><title>Your AI Vendor Said Their Model Is Accurate, Explainable, and Compliant. Did They Prove It?</title><link>https://loravaughn.com/blog/your-ai-vendor-said-their-model-is-accurate-explainable-and-compliant-did-they-prove-it/</link><guid isPermaLink="true">https://loravaughn.com/blog/your-ai-vendor-said-their-model-is-accurate-explainable-and-compliant-did-they-prove-it/</guid><description>Community banks are getting pitched AI tools right now. Standard vendor due diligence doesn&apos;t cover what actually matters with AI. Here&apos;s what to ask before you sign anything.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate><category>community-banks</category><category>ai-governance</category><category>compliance</category><category>vendor-selection</category><enclosure url="https://loravaughn.com/blog-photos/ai-document-review.webp" length="0" type="image/webp"/></item><item><title>How to Pick an MDR Provider When You&apos;re a Community Bank</title><link>https://loravaughn.com/blog/how-to-pick-an-mdr-provider-when-youre-a-community-bank/</link><guid isPermaLink="true">https://loravaughn.com/blog/how-to-pick-an-mdr-provider-when-youre-a-community-bank/</guid><description>Every MDR vendor says they do detection and response. Here&apos;s what to actually evaluate before you sign a contract, and the questions most community banks never think to ask.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate><category>community-banks</category><category>mdr</category><category>security-operations</category><category>vendor-selection</category><category>ffiec</category><enclosure url="https://loravaughn.com/blog-photos/mag-glass-contract.webp" length="0" type="image/webp"/></item><item><title>The FFIEC CAT Is Gone. Now What?</title><link>https://loravaughn.com/blog/the-ffiec-cat-is-gone-now-what/</link><guid isPermaLink="true">https://loravaughn.com/blog/the-ffiec-cat-is-gone-now-what/</guid><description>The FFIEC retired the Cybersecurity Assessment Tool. Here&apos;s what community banks actually need to do now, what examiners are looking for instead, and how to transition without starting from scratch.</description><pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate><category>community-banks</category><category>ffiec</category><category>compliance</category><category>nist-csf</category><category>risk-management</category><enclosure url="https://loravaughn.com/blog-photos/ride-into-sunset.webp" length="0" type="image/webp"/></item><item><title>The Framework Trap: When Compliance Kills Security</title><link>https://loravaughn.com/blog/the-framework-trap-when-compliance-kills-security/</link><guid isPermaLink="true">https://loravaughn.com/blog/the-framework-trap-when-compliance-kills-security/</guid><description>Security frameworks were built to guide programs, not replace thinking. Do security right and compliance follows. Here&apos;s why most organizations have it backwards.</description><pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate><category>compliance</category><category>security-strategy</category><category>community-banking</category><enclosure url="https://loravaughn.com/blog-photos/framework.webp" length="0" type="image/webp"/></item><item><title>I Spent Eight Hours on My Home Network. I&apos;m Still Not Done.</title><link>https://loravaughn.com/blog/i-spent-eight-hours-on-my-home-network-im-still-not-done/</link><guid isPermaLink="true">https://loravaughn.com/blog/i-spent-eight-hours-on-my-home-network-im-still-not-done/</guid><description>A home network rebuild that&apos;s still in progress and already has lessons. Documentation debt is real, and it costs you more than a weekend.</description><pubDate>Tue, 17 Mar 2026 00:00:00 GMT</pubDate><category>security-operations</category><category>personal</category><category>lessons-learned</category><enclosure url="https://loravaughn.com/blog-photos/network-mess.webp" length="0" type="image/webp"/></item><item><title>Your Vendors Are Your Biggest Security Risk. Here&apos;s What to Do About It.</title><link>https://loravaughn.com/blog/your-vendors-are-your-biggest-security-risk-heres-what-to-do-about-it/</link><guid isPermaLink="true">https://loravaughn.com/blog/your-vendors-are-your-biggest-security-risk-heres-what-to-do-about-it/</guid><description>Most community banks can answer every question about their own security posture. But ask about their vendors, and you get silence. Here&apos;s how to fix that.</description><pubDate>Mon, 09 Mar 2026 00:00:00 GMT</pubDate><enclosure url="https://loravaughn.com/blog-photos/vendor-risk-hero.webp" length="0" type="image/webp"/></item><item><title>The Real AI Threat Isn&apos;t Job Loss. It&apos;s Irrelevance.</title><link>https://loravaughn.com/blog/the-real-ai-threat-isnt-job-loss-its-irrelevance/</link><guid isPermaLink="true">https://loravaughn.com/blog/the-real-ai-threat-isnt-job-loss-its-irrelevance/</guid><description>Everyone&apos;s worried AI will take their job. The bigger risk is becoming the person who can&apos;t keep up because you refused to learn how to use it.</description><pubDate>Mon, 23 Feb 2026 00:00:00 GMT</pubDate><category>ai-for-business</category><category>ai-tools</category><category>career</category><enclosure url="https://loravaughn.com/blog-photos/obsolete.jpg" length="0" type="image/jpeg"/></item><item><title>It&apos;s 2026. You Can Use the Guest WiFi.</title><link>https://loravaughn.com/blog/its-2026-you-can-use-the-guest-wifi/</link><guid isPermaLink="true">https://loravaughn.com/blog/its-2026-you-can-use-the-guest-wifi/</guid><description>A security professional scolded me for connecting to guest WiFi. Meanwhile, 100+ CISOs signed a letter asking people to stop giving exactly that advice.</description><pubDate>Thu, 12 Feb 2026 00:00:00 GMT</pubDate><category>security-culture</category><category>hacklore</category><category>practical-security</category><enclosure url="https://loravaughn.com/blog-photos/campfire.webp" length="0" type="image/webp"/></item><item><title>You Want to Try OpenClaw. Here&apos;s How to Not Wreck Yourself.</title><link>https://loravaughn.com/blog/you-want-to-try-openclaw-heres-how-to-not-wreck-yourself/</link><guid isPermaLink="true">https://loravaughn.com/blog/you-want-to-try-openclaw-heres-how-to-not-wreck-yourself/</guid><description>OpenClaw is genuinely cool technology—and a real security risk. Instead of telling you to run away, here&apos;s how to experiment with it safely.</description><pubDate>Sat, 07 Feb 2026 00:00:00 GMT</pubDate><category>ai-security</category><category>agentic-ai</category><category>openclaw</category><category>security-controls</category><enclosure url="https://loravaughn.com/blog-photos/fire-dancer.webp" length="0" type="image/webp"/></item><item><title>Why Your Incident Response Plan Will Fail (And What to Build Instead)</title><link>https://loravaughn.com/blog/why-your-incident-response-plan-will-fail-and-what-to-build-instead/</link><guid isPermaLink="true">https://loravaughn.com/blog/why-your-incident-response-plan-will-fail-and-what-to-build-instead/</guid><description>Most IR plans fail not because they&apos;re poorly written, but because plans don&apos;t survive contact with reality. Here&apos;s how to build response capability instead of just documentation.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate><category>incident-response</category><category>security-operations</category><category>crisis-management</category><category>tabletop-exercises</category><category>security-leadership</category><category>ciso</category><category>business-continuity</category><category>security-planning</category><enclosure url="https://loravaughn.com/blog-photos/ir-plan-failure-hero.webp" length="0" type="image/webp"/></item><item><title>The Drinking Bird at the Nuclear Plant</title><link>https://loravaughn.com/blog/the-drinking-bird-at-the-nuclear-plant/</link><guid isPermaLink="true">https://loravaughn.com/blog/the-drinking-bird-at-the-nuclear-plant/</guid><description>Sam Altman wants to give AI full access to everything. Your users will too. Your AI security strategy isn&apos;t competing against attackers; it&apos;s competing against tedium. Tedium wins.</description><pubDate>Sun, 01 Feb 2026 00:00:00 GMT</pubDate><category>ai-security</category><category>agentic-ai</category><category>security-controls</category><category>user-behavior</category><category>risk-management</category><category>security-leadership</category><category>openai</category><category>automation</category><enclosure url="https://loravaughn.com/blog-photos/drinking-bird.webp" length="0" type="image/webp"/></item><item><title>SIEM vs. MDR for Community Banks: What Actually Works (And What&apos;s a Waste of Money)</title><link>https://loravaughn.com/blog/siem-vs-mdr-for-community-banks-what-actually-works-and-whats-a-waste-of-money/</link><guid isPermaLink="true">https://loravaughn.com/blog/siem-vs-mdr-for-community-banks-what-actually-works-and-whats-a-waste-of-money/</guid><description>A practical guide for community banks choosing between SIEM and MDR solutions. Real costs, what examiners actually want, and a decision framework for banks under $2B in assets.</description><pubDate>Mon, 26 Jan 2026 00:00:00 GMT</pubDate><category>community-banks</category><category>siem</category><category>mdr</category><category>ffiec</category><category>compliance</category><category>security-operations</category><category>banking</category><category>virtual-ciso</category><category>threat-detection</category><category>security-budget</category><enclosure url="https://loravaughn.com/blog-photos/dark-security-monitor-screen.webp" length="0" type="image/webp"/></item><item><title>The Security Program You Actually Need (Not the One Vendors Are Selling You)</title><link>https://loravaughn.com/blog/the-security-program-you-actually-need-not-the-one-vendors-are-selling-you/</link><guid isPermaLink="true">https://loravaughn.com/blog/the-security-program-you-actually-need-not-the-one-vendors-are-selling-you/</guid><description>Most security advice assumes you&apos;re a Fortune 500. You&apos;re not. Here&apos;s what you actually need at your size, what you can skip, and how to know when to level up.</description><pubDate>Wed, 21 Jan 2026 00:00:00 GMT</pubDate><category>community-banks</category><category>fintech</category><category>startups</category><category>security-programs</category><category>right-sizing-security</category><enclosure url="https://loravaughn.com/blog-photos/security-program-you-need.webp" length="0" type="image/webp"/></item><item><title>I Built a Live Deepfake in 30 Minutes. Here&apos;s the Part That Actually Scares Me.</title><link>https://loravaughn.com/blog/i-built-a-live-deepfake-in-30-minutes-heres-the-part-that-actually-scares-me/</link><guid isPermaLink="true">https://loravaughn.com/blog/i-built-a-live-deepfake-in-30-minutes-heres-the-part-that-actually-scares-me/</guid><description>Using AI coding tools, I built a convincing live deepfake demo in 30 minutes with zero machine learning knowledge. The barrier to creating sophisticated attacks isn&apos;t technical skill anymore, it&apos;s just intent.</description><pubDate>Thu, 08 Jan 2026 00:00:00 GMT</pubDate><category>AI</category><category>Deepfakes</category><category>Fraud-Prevention</category><category>Social-Engineering</category><enclosure url="https://loravaughn.com/blog-photos/deepfake.webp" length="0" type="image/webp"/></item><item><title>Intentions, Not Resolutions: On Choosing Presence Over Urgency</title><link>https://loravaughn.com/blog/intentions-not-resolutions-on-choosing-presence-over-urgency/</link><guid isPermaLink="true">https://loravaughn.com/blog/intentions-not-resolutions-on-choosing-presence-over-urgency/</guid><description>On knowing the always-on CISO life isn&apos;t sustainable, doing it anyway, and what fractional work is teaching me about presence.</description><pubDate>Tue, 30 Dec 2025 00:00:00 GMT</pubDate><category>career</category><category>CISO</category><category>leadership</category><category>work-life-balance</category><category>fractional-CISO</category><category>new-years</category><category>intentions</category><enclosure url="https://loravaughn.com/blog-photos/being-present.webp" length="0" type="image/webp"/></item><item><title>When Everything Is Critical, Nothing Is Critical</title><link>https://loravaughn.com/blog/when-everything-is-critical-nothing-is-critical/</link><guid isPermaLink="true">https://loravaughn.com/blog/when-everything-is-critical-nothing-is-critical/</guid><description>Your vulnerability scanner flagged 10,000 issues. Your SIEM has 500 critical alerts. Every project is top priority. So what do you actually fix first?</description><pubDate>Tue, 16 Dec 2025 12:00:00 GMT</pubDate><category>vulnerability management</category><category>prioritization</category><category>security-operations</category><category>CISO</category><category>risk management</category><category>security-strategy</category><enclosure url="https://loravaughn.com/blog-photos/urgent.webp" length="0" type="image/webp"/></item><item><title>Security Theater vs. Security: How to Tell the Difference</title><link>https://loravaughn.com/blog/security-theater-vs-security-how-to-tell-the-difference/</link><guid isPermaLink="true">https://loravaughn.com/blog/security-theater-vs-security-how-to-tell-the-difference/</guid><description>That shiny new security tool looks impressive in the demo. But will it actually reduce risk? Here&apos;s how to tell security theater from real security before you waste the budget.</description><pubDate>Tue, 02 Dec 2025 12:00:00 GMT</pubDate><category>security-strategy</category><category>budget-planning</category><category>security-tools</category><category>CISO</category><category>risk-management</category><category>security-theater</category><enclosure url="https://loravaughn.com/blog-photos/security-theater-social.webp" length="0" type="image/webp"/></item><item><title>Stop Protecting Systems, Start Protecting Data</title><link>https://loravaughn.com/blog/stop-protecting-systems-start-protecting-data/</link><guid isPermaLink="true">https://loravaughn.com/blog/stop-protecting-systems-start-protecting-data/</guid><description>Why modern security strategies must shift from system-centric defenses to data-centric protection approaches.</description><pubDate>Sun, 23 Nov 2025 18:00:00 GMT</pubDate><category>data-security</category><category>security-strategy</category><category>data-protection</category><enclosure url="https://loravaughn.com/blog-photos/data-flow-abstract.webp" length="0" type="image/webp"/></item><item><title>When Your Bank Examiner Says &apos;Risk Assessment&apos; and You Break Out in Hives</title><link>https://loravaughn.com/blog/when-your-bank-examiner-says-risk-assessment-and-you-break-out-in-hives/</link><guid isPermaLink="true">https://loravaughn.com/blog/when-your-bank-examiner-says-risk-assessment-and-you-break-out-in-hives/</guid><description>Why most cybersecurity guidance for community banks is useless, and what to do instead</description><pubDate>Wed, 19 Nov 2025 00:00:00 GMT</pubDate><category>cybersecurity</category><category>banking</category><category>compliance</category><category>community-banks</category><category>risk-management</category><enclosure url="https://loravaughn.com/blog-photos/community-bank-security-hero.webp" length="0" type="image/webp"/></item><item><title>Vibe Coding: How to Write Secure Code When AI Does the Heavy Lifting</title><link>https://loravaughn.com/blog/vibe-coding-how-to-write-secure-code-when-ai-does-the-heavy-lifting/</link><guid isPermaLink="true">https://loravaughn.com/blog/vibe-coding-how-to-write-secure-code-when-ai-does-the-heavy-lifting/</guid><description>AI coding tools are powerful, but they&apos;re trained on decades of mediocre code. Here&apos;s how to harness them without inheriting every security mistake we&apos;ve been making since the 90s.</description><pubDate>Thu, 13 Nov 2025 00:00:00 GMT</pubDate><category>security</category><category>AI</category><category>development</category><category>coding</category><category>AI-coding</category><category>secure-development</category><category>copilot</category><category>claude-code</category><category>best-practices</category><enclosure url="https://loravaughn.com/blog-photos/vibe-coding-securely.webp" length="0" type="image/webp"/></item><item><title>How to Respond When Your Customer Sends You a Security Questionnaire</title><link>https://loravaughn.com/blog/how-to-respond-when-your-customer-sends-you-a-security-questionnaire/</link><guid isPermaLink="true">https://loravaughn.com/blog/how-to-respond-when-your-customer-sends-you-a-security-questionnaire/</guid><description>Your biggest deal just sent a 200-question security assessment. Here&apos;s your step-by-step playbook for responding without losing the deal or your mind.</description><pubDate>Wed, 05 Nov 2025 00:00:00 GMT</pubDate><enclosure url="https://loravaughn.com/blog-photos/security-questionnaire-hero.webp" length="0" type="image/webp"/></item><item><title>How to Get SOC 2 Certified: Startup Guide (Costs $15K-50K, Takes 3-6 Months)</title><link>https://loravaughn.com/blog/how-to-get-soc-2-certified-startup-guide-costs-15k-50k-takes-3-6-months/</link><guid isPermaLink="true">https://loravaughn.com/blog/how-to-get-soc-2-certified-startup-guide-costs-15k-50k-takes-3-6-months/</guid><description>How much does SOC 2 cost? $15K-50K for audit + $5K-30K/year in tools. Real timeline: 3-6 months prep + 4-8 weeks audit. Here&apos;s what you actually need (and what you can skip).</description><pubDate>Mon, 03 Nov 2025 12:00:00 GMT</pubDate><category>SOC2</category><category>compliance</category><category>startup-security</category><category>audits</category><category>SOC2-cost</category><category>SOC2-requirements</category><enclosure url="https://loravaughn.com/blog-photos/checklist.webp" length="0" type="image/webp"/></item><item><title>Feats of Endurance and Stupidity: What Running in Circles Teaches Us About Cybersecurity</title><link>https://loravaughn.com/blog/feats-of-endurance-and-stupidity-what-running-in-circles-teaches-us-about-cybersecurity/</link><guid isPermaLink="true">https://loravaughn.com/blog/feats-of-endurance-and-stupidity-what-running-in-circles-teaches-us-about-cybersecurity/</guid><description>What ultramarathon running teaches us about incident response and cybersecurity resilience. Lessons from a CISO on training for chaos, mental endurance, and why preparation beats reaction.</description><pubDate>Fri, 24 Oct 2025 00:00:00 GMT</pubDate><category>cybersecurity</category><category>leadership</category><category>incident-response</category><category>resilience</category><enclosure url="https://loravaughn.com/blog-photos/endless2025.webp" length="0" type="image/webp"/></item><item><title>From Jewels to Data: Why We Never Learn</title><link>https://loravaughn.com/blog/from-jewels-to-data-why-we-never-learn/</link><guid isPermaLink="true">https://loravaughn.com/blog/from-jewels-to-data-why-we-never-learn/</guid><description>The Louvre got robbed. Companies get breached. Both could&apos;ve been prevented. Here&apos;s why waiting for the &apos;oh crap&apos; moment is a terrible security strategy.</description><pubDate>Wed, 22 Oct 2025 00:00:00 GMT</pubDate><category>cybersecurity</category><category>incident-response</category><category>security-strategy</category><category>risk-management</category><enclosure url="https://loravaughn.com/blog-photos/jewels.webp" length="0" type="image/webp"/></item><item><title>Do You Need a Fractional CISO? Here&apos;s How to Tell</title><link>https://loravaughn.com/blog/do-you-need-a-fractional-ciso-heres-how-to-tell/</link><guid isPermaLink="true">https://loravaughn.com/blog/do-you-need-a-fractional-ciso-heres-how-to-tell/</guid><description>Not sure if you need security leadership yet? Here&apos;s when a fractional CISO makes sense, what your options look like, and how to avoid overspending on security too early.</description><pubDate>Mon, 20 Oct 2025 12:00:00 GMT</pubDate><category>fractional-CISO</category><category>virtual-CISO</category><category>startup-security</category><category>SMB-security</category><category>security-leadership</category><enclosure url="https://loravaughn.com/blog-photos/do-you-need-ciso.webp" length="0" type="image/webp"/></item><item><title>The Engineered Forest: Why the Best Security Programs Are Invisible</title><link>https://loravaughn.com/blog/the-engineered-forest-why-the-best-security-programs-are-invisible/</link><guid isPermaLink="true">https://loravaughn.com/blog/the-engineered-forest-why-the-best-security-programs-are-invisible/</guid><description>What a carefully managed New Hampshire forest taught me about building security programs that enable rather than block. The best security, like the best ecosystems, looks effortless but is intentionally designed.</description><pubDate>Wed, 15 Oct 2025 12:00:00 GMT</pubDate><category>security</category><category>leadership</category><category>philosophy</category><category>CISO</category><enclosure url="https://loravaughn.com/blog-photos/kancamagus.webp" length="0" type="image/webp"/></item><item><title>Is Your &apos;Smart&apos; Device Actually Smart? A Simple Test</title><link>https://loravaughn.com/blog/is-your-smart-device-actually-smart-a-simple-test/</link><guid isPermaLink="true">https://loravaughn.com/blog/is-your-smart-device-actually-smart-a-simple-test/</guid><description>Before connecting that next device to WiFi, ask one question: does the benefit actually outweigh the risk? A security professional&apos;s practical guide to smart home decisions.</description><pubDate>Tue, 23 Sep 2025 00:00:00 GMT</pubDate><category>consumer-security</category><category>iot</category><category>privacy</category><category>smart-home</category><category>practical-security</category><enclosure url="https://loravaughn.com/blog-photos/smart-home.webp" length="0" type="image/webp"/></item><item><title>When Perfect Plans Meet Imperfect Reality</title><link>https://loravaughn.com/blog/when-perfect-plans-meet-imperfect-reality/</link><guid isPermaLink="true">https://loravaughn.com/blog/when-perfect-plans-meet-imperfect-reality/</guid><description>Sometimes the consequences of IR plan failure aren&apos;t just about downtime or data. Sometimes they&apos;re about life and death.</description><pubDate>Thu, 18 Sep 2025 00:00:00 GMT</pubDate><category>incident-response</category><category>cybersecurity</category><category>healthcare</category><category>security-leadership</category><enclosure url="https://loravaughn.com/blog-photos/split-personality.webp" length="0" type="image/webp"/></item><item><title>The Question That Made Everyone in the Room Go Silent</title><link>https://loravaughn.com/blog/the-question-that-made-everyone-in-the-room-go-silent/</link><guid isPermaLink="true">https://loravaughn.com/blog/the-question-that-made-everyone-in-the-room-go-silent/</guid><description>I asked one simple question about incident response plans. The silence that followed told me everything I needed to know.</description><pubDate>Thu, 11 Sep 2025 00:00:00 GMT</pubDate><category>incident-response</category><category>cybersecurity</category><category>security-leadership</category><enclosure url="https://loravaughn.com/blog-photos/plan-chaos.webp" length="0" type="image/webp"/></item><item><title>Building an Autonomous Sunset Timelapse System: Part 2 - Historical Processing</title><link>https://loravaughn.com/blog/building-an-autonomous-sunset-timelapse-system-part-2---historical-processing/</link><guid isPermaLink="true">https://loravaughn.com/blog/building-an-autonomous-sunset-timelapse-system-part-2---historical-processing/</guid><description>Process historical camera footage into timelapse videos with Python and OpenCV. Bulk video processing, Reolink API integration, and FFmpeg automation for recovering missed captures.</description><pubDate>Fri, 05 Sep 2025 00:00:00 GMT</pubDate><category>historical-processing</category><category>api-integration</category><category>video-processing</category><category>data-pipeline</category><category>automation</category><category>python</category><category>projects</category><enclosure url="https://loravaughn.com/view.webp" length="0" type="image/webp"/></item><item><title>Building an Automated Sunset Timelapse: Part 1 - Live Capture Engineering</title><link>https://loravaughn.com/blog/building-an-automated-sunset-timelapse-part-1---live-capture-engineering/</link><guid isPermaLink="true">https://loravaughn.com/blog/building-an-automated-sunset-timelapse-part-1---live-capture-engineering/</guid><description>Build an automated Raspberry Pi sunset timelapse system with Python, FFmpeg, and RTSP. Complete tutorial with code for capturing, processing, and uploading to YouTube automatically.</description><pubDate>Thu, 04 Sep 2025 00:00:00 GMT</pubDate><category>raspberry-pi</category><category>rtsp</category><category>computer-vision</category><category>automation</category><category>python</category><category>live-capture</category><category>projects</category><enclosure url="https://loravaughn.com/view.webp" length="0" type="image/webp"/></item><item><title>Your Cybersecurity Degree May Not Have Prepared You for the Real World</title><link>https://loravaughn.com/blog/your-cybersecurity-degree-may-not-have-prepared-you-for-the-real-world/</link><guid isPermaLink="true">https://loravaughn.com/blog/your-cybersecurity-degree-may-not-have-prepared-you-for-the-real-world/</guid><description>Why choosing the right cybersecurity program matters, and how to match your degree to your career goals.</description><pubDate>Thu, 28 Aug 2025 00:00:00 GMT</pubDate><category>cybersecurity</category><category>education</category><category>computer-science</category><category>hot-take</category><enclosure url="https://loravaughn.com/blog-photos/cyber-degrees.webp" length="0" type="image/webp"/></item><item><title>How NOT to Find a Cybersecurity Mentor: A Guide for Career Seekers</title><link>https://loravaughn.com/blog/how-not-to-find-a-cybersecurity-mentor-a-guide-for-career-seekers/</link><guid isPermaLink="true">https://loravaughn.com/blog/how-not-to-find-a-cybersecurity-mentor-a-guide-for-career-seekers/</guid><description>Turning a real-world example into lessons for breaking into cybersecurity the right way</description><pubDate>Thu, 21 Aug 2025 00:00:00 GMT</pubDate><category>career-transition</category><category>cybersecurity</category><category>builder-mindset</category><enclosure url="https://loravaughn.com/blog-photos/mentor-me-now.webp" length="0" type="image/webp"/></item><item><title>When Life Gives You Network Timeouts, Make Automated Sunsets</title><link>https://loravaughn.com/blog/when-life-gives-you-network-timeouts-make-automated-sunsets/</link><guid isPermaLink="true">https://loravaughn.com/blog/when-life-gives-you-network-timeouts-make-automated-sunsets/</guid><description>How I turned camera API failures into an automated sunset timelapse system using Raspberry Pi, RTSP streaming, and YouTube uploads. A story about pivoting when technology doesn&apos;t cooperate.</description><pubDate>Tue, 19 Aug 2025 00:00:00 GMT</pubDate><category>raspberry-pi</category><category>automation</category><category>python</category><category>iot</category><category>security</category><category>open-source</category><category>camera</category><category>timelapse</category><category>youtube-api</category><category>home-automation</category><enclosure url="https://loravaughn.com/blog-photos/sunset-timelapse-hero.webp" length="0" type="image/webp"/></item><item><title>Automating Ourselves Into a Cybersecurity Crisis</title><link>https://loravaughn.com/blog/automating-ourselves-into-a-cybersecurity-crisis/</link><guid isPermaLink="true">https://loravaughn.com/blog/automating-ourselves-into-a-cybersecurity-crisis/</guid><description>How AI automation in cybersecurity is eliminating entry-level roles and creating a dangerous skills gap, and why we must act now to prevent a workforce crisis.</description><pubDate>Thu, 14 Aug 2025 00:00:00 GMT</pubDate><category>cybersecurity</category><category>workforce-development</category><category>ai-automation</category><category>talent-pipeline</category><category>security-leadership</category><category>apprenticeships</category><category>incident-response</category><category>soc-operations</category><enclosure url="https://loravaughn.com/blog-photos/cyber-crisis.webp" length="0" type="image/webp"/></item><item><title>The Unexpected Joy of Unemployment (and Building Geeky Little Things)</title><link>https://loravaughn.com/blog/the-unexpected-joy-of-unemployment-and-building-geeky-little-things/</link><guid isPermaLink="true">https://loravaughn.com/blog/the-unexpected-joy-of-unemployment-and-building-geeky-little-things/</guid><description>Rediscovering my inner builder, and giving my weather-obsessed husband the gift of livestreamed skies.</description><pubDate>Fri, 01 Aug 2025 00:00:00 GMT</pubDate><category>career-transition</category><category>tech-projects</category><category>livestreaming</category><category>smart-home</category><category>ai-tools</category><category>personal-blog</category><category>cybersecurity</category><category>builder-mindset</category><enclosure url="https://loravaughn.com/blog-photos/LoraPowerTools.webp" length="0" type="image/webp"/></item><item><title>Basically A Tribute to Dr. Lewis I. Patterson</title><link>https://loravaughn.com/blog/basically-a-tribute-to-dr-lewis-i-patterson/</link><guid isPermaLink="true">https://loravaughn.com/blog/basically-a-tribute-to-dr-lewis-i-patterson/</guid><description>Honoring the beloved Birmingham-Southern College professor whose high standards, dry wit, and quiet encouragement shaped generations of computer science students.</description><pubDate>Mon, 28 Jul 2025 00:00:00 GMT</pubDate><category>dr-lewis-patterson</category><category>birmingham-southern-college</category><category>alabama-tech-community</category><category>tech-mentorship</category><category>professor-tribute</category><category>bsc-computer-science</category><category>in-memoriam</category><category>life-lessons-in-tech</category><category>basically</category><enclosure url="https://loravaughn.com/blog-photos/dr.Patterson.webp" length="0" type="image/webp"/></item></channel></rss>