Playing With Fire: Securing AI Without Shutting Off the Stove with Nakeea Neischer - Ep 239

NAKEEA NEISCHER IMAGENakeea Neischer is the Director of IT and CISO at RxVantage, a healthcare SaaS platform that serves as a bridge between medical providers and life science companies. With more than 10 years in security, Nakeea has built her approach around a philosophy she describes through baking, gathering the right ingredients of people, process, and tools, then figuring out how those pieces combine into something the whole business can actually use. She joins the show to talk candidly about blast radius risk with AI agents, why she believes the industry has quietly shifted from prevention to recovery as the true measure of a security program, and why she thinks fear, not the technology itself, is security's biggest obstacle right now. 

 

apple
spotify
stitcher
google podcast
Deezer
iheartradio
tunein
partner-share-lg

Here’s a glimpse of what you’ll learn: 

 

  • Why Nakeea compares building a security program to being the chef who has to bake a cake everyone enjoys
  • How Nakeea thinks about blast radius as her single biggest concern with deploying AI agents
  • Why Nakeea uses fire as her central analogy for AI, dangerous, necessary, and not something you can simply avoid
  • How third party vendor risk has quietly gotten worse as vendors move faster on AI than the organizations that use them
  • Why Nakeea argues patching alone is already too late against machine speed zero day exploits
  • Why Nakeea believes the industry has shifted from asking can we prevent a breach to asking how fast can we recover
  • Nakeea's take on why security teams need to extend AI the same grace they've started giving breached organizations



In this episode…

Nakeea opens by describing the core tension every SaaS security leader faces, protecting an organization internally while also defending an entire platform full of client data, all while AI reshapes both sides of that equation at once. She leans on her baking analogy to explain why security can't be only about tools, arguing that leadership habits, employee behavior, and business priorities all have to be understood before any framework or technical control gets layered on top, and that a security leader's real job is producing an outcome the whole business can live with, not simply locking everything down. She's candid that this balance is uncomfortable by design, since being too secure creates the same kind of failure as being too loose.

The conversation turns to where Nakeea sees the sharpest risk in AI adoption, and she keeps returning to a single word, blast radius. She argues that comfort is the real danger, the same way a homeowner who has never been robbed eventually forgets to lock the back door, and that once an AI agent has access inside a network, the questions that matter are how much segmentation exists and what is truly off limits to it. She uses fire as her governing metaphor throughout, arguing that AI is exactly like fire in a home: genuinely dangerous, capable of burning everything down, and yet not something any household actually gives up, because the answer is learning to use it correctly rather than refusing to use it at all. She connects this to the Hugging Face sandbox incident as a preview of the test-and-learn process the industry is now going through, and argues that fighting AI with AI, rather than trying to out-work it manually, is the only realistic path forward. She also floats a concrete use case, feeding an organization's SSPs and frameworks into an AI system with carefully scoped, read only access to audit compliance gaps far faster than a manual review, while cautioning that the right approach is feeding in pieces at a time rather than dumping a sensitive document in all at once.

The back half of the episode gets pointed about how fast organizations actually need to move. Nakeea explains that third party vendor risk has quietly gotten worse, since a company that is behind on AI internally is still relying on vendors who are moving fast on AI regardless, and that bureaucratic approval timelines that once felt normal are now themselves a security liability given how quickly zero day exploits move. She argues patching can no longer be treated as sufficient on its own, and that organizations need AI actively watching their own networks for abnormal behavior in real time, catching an intrusion the moment it happens rather than waiting for a SOC analyst to notice hours later. Drawing a comparison to her own daughters navigating early adulthood after years of academic perfectionism, she argues mistakes are only failures when people stop trying to learn from them, a lesson she believes applies just as much to AI vendors as to young adults. She closes with a broader argument that the industry has shifted from asking whether a breach can be prevented to asking how well an organization recovers from one, and makes the case that AI, like human security teams, deserves the same grace to learn through mistakes the industry has already extended to breached organizations.

 

 

Resources mentioned in this episode

 

Matthew Connor on LinkedIn
CyberLynx Website
Nakeea Neischer on LinkedIn
RxVantage LinkedIn
Darktrace Website
Abnormal AI Website

 

Sponsor for this episode...

 

This episode is brought to you by CyberLynx.

CyberLynx is a Bethesda managed IT and cybersecurity company. Local techs you know, not a call center. Month-to-month. 24/7 intrusion detection.

We help growing companies with managed IT, help desk, backup and recovery, and a fractional CIO.

Talk to us at https://cyberlynx.com/contact, info@cyberlynx.com, or 301-798-9170.

 

Check out previous episodes:

 

Build Versus Buy: The Risk of Vibe Coding Your Security Stack with Andrew Dutton - Ep 238 

The Security Sidecar: Wrapping Code in Real Time Defense with Aby Rao - Ep 237

Doing More With Less: A Department of Three Punching at Twenty with Tony Bryson - Ep 236

 

Transcript: 

 

 

Cyber Business Podcast

Nakeea Neischer

Director of IT and CISO 

RxVantage


Matthew Connor: Matthew Connor here, host of the Cyber Business Podcast. Today we're joined by Nakeea Neischer, Director of IT and CISO at RxVantage. Nakeea, welcome to the show.

Nakeea Neischer: Thank you. Thank you for having me.

Matthew Connor: Thanks for coming on. Before we get too far in, a quick word from our sponsors.

Sponsor Break — CyberLynx: Hackers are using AI to conduct machine-speed attacks. Is your security keeping up? CyberLynx sells industry-leading AI-powered cybersecurity solutions that detect threats in real time, so you know about an attack before the damage is done, not after. Learn more at cyberlynx.com. That's cyberlynx.com.

Matthew Connor: And now, back to our show. Nakeea, for those who aren't familiar, can you tell us about RxVantage and your role there as Director of IT and CISO?

Nakeea Neischer: Sure. RxVantage is a healthcare SaaS platform, being a bridge between providers and life science.

Matthew Connor: Love it. And I think the challenge I see immediately, in today's day and age, when it comes to being a SaaS provider, is we're now in this era of AI, which is fun and exciting, and I love it to death. However, how do you balance that, the entire thing, because as a SaaS provider, not only do you have your internal people you've got to keep happy and moving forward in your IT director role, so you're taking care of the internal organization, but on top of that you've got the whole SaaS platform, you've got client data, all this other stuff you've also got to defend and protect. So now that there's AI, what's your strategy, how should people be looking at this, balancing AI when it comes to security versus productivity?

Nakeea Neischer: Sure, that's actually a very relevant and interesting question. Our company, being a full SaaS company, probably like many others now, I'd say we have to remember that security isn't just tool-focused. A lot of times, the moment anyone hears security, you think tools, you think software, and we forget the people aspect sometimes. I find, just from my experience, I've been in security for probably a little over ten years now, that we have to balance people and tools, of course, and just the reality of understanding how the two coincide, as well as keeping the business in mind. So, as you stated, we have customers, we have data, we have all these particulars we have to keep secure, you have to keep their information secure, you want to keep the business running, ultimately that's your goal as a director and CISO. So you have to think about the basics, the boring stuff, I say boring because people who aren't in security forget about the frameworks and the compliance, everyone wants to get really knee-deep in all the technical things. So we have to start with our base, add on our technical tools, and then in this role, in a CISO role, in a director role, you have to be kind of like the chef in the kitchen, you have all the ingredients and you have to be able to bake a good cake that everyone's able to enjoy. And by that I mean the business as a whole. So it's a very interesting position, because you have to bake it, and then you have to think, at the end, what's the outcome of your program?

Matthew Connor: I love that, and I love that analogy too, because it really is kind of like baking, the basics are measuring everything properly, making sure you've got the right ingredients, choosing the right ingredients and the right amounts. If all you do is focus on the frosting, and you're a great artisan of the frosting, okay, but your cake sucks and nobody wants to eat it.

Nakeea Neischer: But you don't want to be so secure that you create bottlenecks, but you have to be secure, because ultimately that's your job. So it's ultimately your job to figure out, first and foremost, understand your business, your company structure, what do they find secure, what's important to them, where do their jewels sit? You also have to think about the individuals in the company, what are leadership's habits, what are the engineers' habits, what are the things we do as people? If you really keep your people hat on, and have a strategy, I love the word strategy, people around me know I love the word strategy, if you have a strategy, you're really thinking, okay, this is my job, but how am I going to implement security, how am I going to do it, how is this actually going to be something reasonable that I can either get people to follow with the what's-in-it-for-me method, and not give too much. And even if they give you a little kickback for some of the rules you're setting, some of the security standards and guides you're changing, you understand, and most importantly, leadership and the board understand that you're doing the best you can. And keeping the company in mind, that's the whole concept, to really keep the company in mind. When I'm at work, it's whomever I'm working for right now, it's RxVantage, it's keeping them secure. What are my everyday steps, that really is the main goal, you do that, you're pretty much okay.

Matthew Connor: Yeah, and I couldn't agree more, and I think this is where AI can really shine in doing both of those, and I'll give you an example. I think it's no secret that I'm a huge fan of Darktrace and products like that, because I think what's really interesting is we see companies using AI in a way that allows the organization to operate and stay focused on operations and doing their job without security being at odds with it. The traditional way of securing things is often at odds with operations, right, traditionally it was like, the more I let you do, the more dangerous it is for us, and so the only really secure thing, the only truly secure computer is one that's unplugged and buried, and now I know it's super secure, but here's where I think it gets really interesting, and we get a glimpse of the fun future. Let's take a product like Darktrace email, where you've got AI, specifically machine learning, looking at the email as it comes in. Where's the traditional security gateway, that uses filters, all kinds of stuff still comes through, and stuff you want to come through doesn't come through, and it's not really smart. So you get things like DocuSign scams, you can't block DocuSign, because people need those as part of their business, so it becomes really challenging when threat actors leverage a legitimate platform like DocuSign, for traditional filters to block that. However, to anybody in the field, or even AI, it becomes really obvious that that DocuSign is a scam, versus the legitimate one. So I think those are really interesting examples of things where we're getting to a future where Jane in accounting gets to focus on accounting, and she doesn't have to worry, I don't think it's a hot take, but I think we're going to a future where we don't have to worry about the end user being the weakest link anymore, because security will take care of that, the AI security products will check the email, check the link, check everything, and if somebody gets through whatever vulnerability, it's like, hey, that's weird, this shouldn't be happening, let me stop it. I know everybody has that reaction when I say it, but I think that's the future, and let me have it.

Nakeea Neischer: So I won't disagree, I won't go as far as to say I believe we're getting to a point where we won't worry about the end user. I do believe those of us in the industry like AI, but we also kind of look at it with a little wink, because for it being able to make our jobs easier, make our jobs faster, my biggest concern with AI always is blast radius, because of where it can sit on the network and within an organization. So when it comes to security, with us implementing it and using it, we have to consider what security parameters we're putting around the agents. If you're using these agents, the end user may not be thinking about it, we may be so focused on securing the end user and get so comfortable, because the thing is, comfortability, anyone, if you've been in your home long enough, you've maybe gone to bed and forgotten to lock the back door, or if you have a child, they may have forgotten to close the window. So comfort and comfortability, going forward, using AI and AI agents in security will probably be an issue, because once it's in, then it becomes about blast radius, what security controls do you have in place, what kind of segmentation, what's off-limits to this agent? All of us in the industry have heard recently about the Hugging Face hack, so thinking about even setting perimeters, segmentation, and controls, knowing it can be smart enough to look for flaws or create ways to get out of the environment it's only supposed to be looking at. These are the things we're talking about. For me it feels like playing with fire, we all have it, we cook with it, we need it, it keeps us warm, can it also burn your home down, yes, but at the same time, are we going to shut off our stoves? No.

Matthew Connor: I think that's the perfect analogy, because the reality is fire is dangerous, it does kill people, it does burn houses down, AI at the same time has that same potential, and I think you do kind of fight fire with fire.

Nakeea Neischer: I see the future as being AI securing AI. There are products coming out now, like Secure AI from Darktrace, not to be some crazy fanboy, but it's a great example. I think these are early days, we're such early days of AI that right now it feels like being a science-fiction author trying to figure out where things are going all the time, and I think these give us glimpses. I think you see it if you've spent any time, I've spent the last eight years or so with Tesla and their full self-driving, going from the drunk-toddler driving, because it was really bad when it came out, it was so bad, to where now it's a better driver than I am, and it's eight times safer than the average driver, and it's still not there yet, and that's what's really interesting. So I think we see where AI has its advantages, and I think it's going to be AI securing AI, because, as you said, the Hugging Face example is interesting, because you think you put it in a sandbox, and to be fair, it was told to use any means possible to do its job, and it was like, I can't do it in this confined environment, let me find a way out of here, I need the internet, fair enough. However, it's a great lesson, I think, of, hey, we are humans, and we don't move at machine speed, and these are really creative machines that are moving at machine speed, we can't keep up. What can keep up? I'm not going to try to keep up with a lion, that doesn't make sense, I need lions to keep up with lions, that's a weird analogy that doesn't quite make sense, but you get the idea. Having AI secure AI makes sense, because then you give it guidelines to secure that. I think that's the future we're going to, but we're in a funny space today.

Matthew Connor: I'd agree, and the reality may be very uncomfortable.

Nakeea Neischer: This is what I'd consider an uncomfortable truth to add to that, how we're all going to learn is through trial and error because of it. We, myself included, we don't want to be on the error part, but there's trial and error, because you're going to have to use AI agents. Actually, in the Hugging Face incident, if you read it, I was all into it, how they broke up into teams and things, the only way through it is to use agents to fight agents, and have your controls, create, like you said, your sandbox. For those of us in production, we have our segmentations and all these different things, but as we continue through the age of AI, as AI is learning, we are going to learn. So the AI will continue learning its capabilities, and we as people will continue learning our capabilities. I believe it's also going to push a lot of human ambition, so there'll be a lot of ambitious people doing a lot of ambitious things. So is it going to push things along faster? Yes, I believe so, back to my fire analogy, as dangerous as it is, none of us are going to throw out our stoves and seal up our fireplaces. We learned how to use it appropriately, and we all do the best we can, every night we make dinner and try not to burn our homes down, and then we teach our children. Same thing with AI, there's a lot of fear because it's so new, it's so powerful. I do believe right now this is where AI governance is coming into play, we don't have a real industry standard yet, and quite honestly, I'm wondering if we will actually have a real industry standard, because of how flexible AI is and how you can use it according to different industries, that's a thought right now. I'll still continue to speak and advise people to do their best to set up AI governance committees within their organizations, talk about it, have discussions, don't dawdle and delay, but definitely have some sort of policy, procedure, and thought process around how your company is using AI, and use cases. I love a good use case, why is it that you want this, why do you feel you need access to this particular form of AI, what's the business use of it, let's discuss security, let's discuss business needs, let's see how we can help you, the user, do your job efficiently while keeping us safe. I love a good use case, I love a good trial period, because then we get to see, without kind of setting and forgetting. I do not like a set-and-forget mentality in security, that's something we just can't do, I'm the continuous-monitoring person. So we have to take some of those same concepts with AI. I'd say the biggest issue probably in security would be the fear of it, I feel like we're very early in AI, but we're too far ahead for security leaders to be afraid.

Matthew Connor: No, I think you're spot on, there's no going back, and it's a matter of learning how to control fire versus not. And I think that, in this day where AI can be so beneficial to the end user, it's just amazing, in under four years, how we went from, oh, that's better than Google, to, wow, this is better than me. It's wild, in four years how far it's come, and I'd say in the last few months it went from, oh, that's really good, to, oh wow, that's better than me, and I'm talking about security experts and experienced developers. AI has gotten so good now that I have to wonder, are we not now at the place, and really, September 2026 is an entirely different place than we were even in May of 2026, and I have to wonder, are we at the point where organizations need to start saying, how do we safely put in AI to help you do your job very efficiently, so that you're really more managing AI, you become a superpowered, super-AI-charged individual, making your job so much more fun? I mean, most knowledge-worker jobs now should be infinitely easier and more fun when AI is assisting the worker. But are we at that place? I'm curious, your take, do you think we're at the place where it's time to focus on integrating AI for every worker, where possible, to make their job better, faster, and more productive? Or are we still a little too early?

Nakeea Neischer: I think what you've stated is exactly where AI governance and AI governance committees come into play. So, as a collective, security, do I believe we're generally a little bit lagging in that area? Yes. You raise a valid point, which is, at this point in the game, do we allow the entire organization access to AI? That really depends on how much awareness security leadership has of people's knowledge in their organization about AI. Do people understand what it is, do people understand it's not here to replace you, it's here to assist you, do people understand what PII is? They have to have an understanding of what they're using, what their everyday task is, what sort of company information they have access to. We're at the point where every company has third-party vendors, security has this whole third-party vendor risk, we know that whole thing, we've talked about it continuously, but third-party vendor risk has now been bumped up, because where you as an organization may be behind on AI, your third-party vendor is not, they're ramping up AI and giving you updates and patches and plugging AI into things. Where are you, where do we as an organization stand, are we giving training, do we understand we don't work in a silo when it comes to AI security, are we bringing together legal, privacy, stakeholders, production, are we bringing these perspectives into the AI committee? Do we even have an AI committee, for some organizations, and if you do, what's its purpose? Now, when I was little, my mom would say, chop chop, we have to move a little faster, and on establishing this, even if we're moving slower, the vendors we're using are not. Our employees and staff, they want to make their jobs easier, who doesn't? So, to answer your question, have we gotten to the place where we can let everyone use it? If that question were a poll, and my name wasn't on it, I'd probably say no, because I speak to, I have colleagues, I have friends, and we're just starting. Are we finally at the place where we realize our trains have to move faster, so it doesn't get too far ahead of us as a security industry? I think the correct response is that what you're saying is where we should be going, hopefully that's where we're going, hopefully we can all be there next year. But right now, establish your committees, establish your boundaries and your borders and your controls, review your frameworks, please get into your tokens, your APIs, your MFAs, your SSOs, get into everything you can think of, organize that, and then begin to move a little faster, if that makes sense.

Matthew Connor: Perfect sense. And I've got a question for you on that. So for every security professional, and I think what you said is spot on, you've got to be focused on that, I think every good CISO, every good security professional, is all about the frameworks and really digging into the fundamentals and having solid fundamentals. I think where we are today is, when the bad guys have access to AI that allows them zero-day exploits like never before, finding vulnerabilities, ten years ago, five years ago, and every day before that, since the dawn of the computer, we thought that if your software and hardware were patched, you were safe, you were doing great, because manufacturers were having their hackathons, working on keeping those things plugged, and you had to be an elite hacker to find a zero-day exploit. So the odds of that happening to your organization were virtually none, that was all true up until about a year or so ago. And now, with Mythos and the power of AI, an inexperienced hacker can find a zero-day exploit without writing any code themselves. So, that being the case in the world we live in now, do the fundamentals, at some level, no matter how well we do them, fail us as an industry, because we're all now subject to zero-day exploits that even the manufacturers aren't aware of, like never before? And if that's the case, is it not because it was AI that found it? And yes, manufacturers are starting to use AI to find them themselves and patch them at an unprecedented speed, great, however, I think the fundamental flaw in security today is that we're all subject to zero-day exploits like never before, and the only way to stop that isn't through patching, patching is already too late. We have to be using AI internally on security, to be able to see, wait a second, Adobe shouldn't be doing that, wait, what's that happening on the network, we can't see it, the SOC, by the time it's gotten to the SOC and an analyst catches it, it's already way too late, these things are happening at machine speed. So are we now at a place where organizations have to be leveraging AI to monitor their networks and endpoints for signs of abnormal behavior, even from users, and say, nope, I've got to stop that and call an adult?

Nakeea Neischer: I think we're at the place where we all should be using some form of AI agent to protect some aspects of our network. Maybe you don't want it all over the network, again, that takes me back to blast radius, if something happens, how big, how much of your network would go down? Should we be using some form of it, absolutely. Is it up to us to determine how, yes. So should you use it, yes, how much of it, that's on you. Recovery has never been bigger than it is right now, because of something like a zero-day, what's your recovery plan if something were to happen, how fast can your organization recover from it, how fast can we get things back up, have we tested that? Back to the fundamentals, I think these are realistic, really realistic, questions to ask. And in this whole AI conversation, the biggest change for us too would be the speed, the speed at which we have to work, meaning the speed at which we have to get things approved. That in itself, an organization may want to take a look at, what are your processes and procedures for getting serious security things or business needs approved, how long does it take? Because the longer it takes people to make these decisions and get changes done, the clock is ticking on what could be an open vulnerability, just because your process is too slow, and that day and age is pretty much over. We have to make decisions, the best example I can give is a military moment, when you're in the military and you're moving and making decisions, you do not have a whole bunch of time to sit and make a decision bottled up with a bunch of bureaucracy.

Matthew Connor: Nope. I think that's well said. And I can't help but think, I don't think I've heard anybody say they're doing this, and I'm kind of curious, I think we're now suddenly at the point with things like Claude Fable 5 and 5.1, where if I had to go and work on the framework for an organization, and we needed to audit all of these different systems doing that manually, I think by the time you get through the entire thing, it's like printing an encyclopedia, by the time you've printed it, it's already outdated, it takes so long. Is this something organizations are doing now, or should be doing, where they feed their current framework, their SSPs, their everything, into Claude, and give it directed access, okay, here's our Microsoft tenant with read-only access, I want you to audit it, see what we've got, here's the firewalls' read-only access, I want you to audit all these systems, compare it to our framework, what are we doing well, are we missing it? Are people doing that, should people do that, should people not do that, because that seems wild. What do you think?

Nakeea Neischer: Well, now a whole SSP is very detailed, that's very, very detailed, so that would take, ha, that's something you could bring to your AI committee.

Matthew Connor: That's right.

Nakeea Neischer: What is it, what are you willing to share, because SSPs are daunting, and assessments are daunting, and using AI would definitely make the assessment and the review faster. However, we don't have to eat the elephant all at one time, we can take it one bite at a time, we can put pieces of an assessment right into AI, you can put pieces in, you can feel secure while you're actually using AI and making your job easier, you don't have to feed any AI tool everything all at once, so you can take the time and also remain really confident in your role as a security person, knowing, look, I really took a look at what I'm doing here, I can back up some reasoning. So you don't have to feed it everything all at once for it to assist you, and that still speeds up the work.

Matthew Connor: Couldn't agree more, I think that's great, I think it's pretty obvious, I lean towards, yeah, let's feed it all in there, see what it says. But that goes, I mean, I don't believe in doing that on some free version of ChatGPT, where now your SSP is part of ChatGPT's collective knowledge that can be used everywhere. Obviously governance rules there, and you've got to keep that confined within your organization, and I think we've come so far, in such a short period of time, with all of the major LLMs, to provide organizations with a much more secure way of keeping that data confined to just their organization. So we've come a long way, and we're starting to see that even with how, you know, Grok's new model is super cool, and how they're keeping your data very specifically on your one machine and letting you run that, and you're seeing it in Claude now too, they're doing great stuff where, by default, it doesn't get access to things, and it walks you through making sure you've got these guidelines, and it's thinking about the guidelines and recommending to people, so that the end user doesn't accidentally give more permissions than they should, versus where we were even a year ago, where guardrails were an afterthought, it was speed, trial and error.

Nakeea Neischer: Yes, it's trial and error, it's like a child walking, you're going to take a few falls, get back up, and keep going. I really think there's no way through this, or out of it, except through it, and through those experiences, even though I don't want to be part of that, but still. I tell my, I have two daughters who are both in college, and they're now getting to experience the real world more, and unlike, they were exceptional students, and got free rides to school, to the university, because they were such good students. The problem with that is they're used to there being a perfect answer, you can study and get all the answers right, which they always did, and so they believe there's a right and wrong for everything, and that mistakes are a bad thing, and trying to convince a young adult that mistakes are a good thing, because you learn from them, and it's only a failure when you stop and give up, and these are all just learning things. And I have to wonder, as a whole, as the security industry, have we, thanks to all the breaches, gotten to the point where now people feel like, look, it's not a matter of if but when we'll be breached? So it used to be, you lose your job, we got breached, you're fired, you must have done something wrong, and now it's more like, well, you've been doing everything right, there's nothing more we could have done, we've done our best, we're fine. But shouldn't the same be applied to AI? Shouldn't that same level of learning and forgiveness, that these are learning pains, we're going to go through this, there are going to be mistakes, we're going to learn from them and we're going to get ahead, shouldn't that be applied? And shouldn't we be kinder to ourselves and the organization, saying, look, there are going to be mistakes, Anthropic is going to make mistakes, OpenAI is going to make mistakes, Google is going to make mistakes, everybody's going to make mistakes, myself included, this organization included, but we're going to learn, and we're going to move faster and be better tomorrow than we were today. Isn't that how people, are we there, or am I just, once again, too optimistic there, even though no one wants to be? But I think we're there. I say I think we're there because we all in the industry know we have to focus on recovery, so if you're focused on recovery, that means you understand there's a possibility your number can get called, and what you have is a plan to get past it. Because quite honestly, when it comes to a breach, a data leak, a hack, however you call it, it's how you recover, that really, really is what shows who you are as a security lead, and shows your team's chops. It really is, how are we recovering? I don't believe anyone feels like we're at the "prevent the breach" stage anymore, we're past that, we're way past that. It's literally, how are we recovering, and the biggest two things I see are how are we recovering, and how are we using AI, how are we, what are we doing as an industry? Everyone has their own way of either ignoring it, using it slowly, or trying to figure out how to open the door for everyone else in the organization, those are the two or three really important things I'd see right now when it comes to AI: recovery, how are we going to open the door for everyone else, and then us figuring out how to govern what we're already using, how are we governing it, I mean, heck, for some people, are you governing it at all? So yeah, I say those three are pretty important right now with regard to AI, because it's not going anywhere. We're all going to be bringing patties and seasonings to this fire and this cookout, let's say, get your marshmallows ready, because it's going to be a bonfire.

Matthew Connor: That's right, it's not going anywhere. No, totally agree, Nakeea, this has been so much fun, I can't thank you enough for coming on the show today. But before we go, can you tell everybody where they can find out more about you and more about RxVantage?

Nakeea Neischer: Sure, you can find out more about RxVantage on the RxVantage site, rxvantage.com. I can be found on LinkedIn, Nakeea Neischer, on LinkedIn, I make some posts from time to time about things I find a little interesting. That's really it, I do have some speaking engagements coming up for security and life science topics, so I'll be around.

Matthew Connor: I love it, well, thanks so much for coming on, and until next time.

Nakeea Neischer: Thank you, thank you for having me. Have a great afternoon, everyone.


Read On

Legacy Vulnerabilities, Machine Speed Attacks, and Routing AI Safely with Mike Hiltz - Ep 225

Legacy Vulnerabilities, Machine Speed Attacks, and Routing AI Safely with Mike Hiltz - Ep 225

Mike Hiltz is the VP and CISO of Nference, a biomedical AI company that works with academic medical...

Read more
Why Patch Management Is No Longer Frontline Defense with Brett Price - Ep 234

Why Patch Management Is No Longer Frontline Defense with Brett Price - Ep 234

Brett Price is the Global CISO at Quint, a publicly owned company that builds hospitality and...

Read more
Why UNICEF USA Is One of the Hardest Security Jobs with Andrew Nuxoll - Ep 232

Why UNICEF USA Is One of the Hardest Security Jobs with Andrew Nuxoll - Ep 232

Andrew Nuxoll is the Managing Director of IT Operations and Cybersecurity at UNICEF USA, the United...

Read more