Guest Introduction
Nakeea Neischer is the Director of IT and CISO at RxVantage, a healthcare SaaS platform that serves as a bridge between medical providers and life science companies. With more than 10 years in security, Nakeea has built her approach around a philosophy she describes through baking, gathering the right ingredients of people, process, and tools, then figuring out how those pieces combine into something the whole business can actually use. She joins the show to talk candidly about blast radius risk with AI agents, why she believes the industry has quietly shifted from prevention to recovery as the true measure of a security program, and why she thinks fear, not the technology itself, is security's biggest obstacle right now.
Here's a Glimpse of What You'll Learn
- Why Nakeea compares building a security program to being the chef who has to bake a cake everyone enjoys
- How Nakeea thinks about blast radius as her single biggest concern with deploying AI agents
- Why Nakeea uses fire as her central analogy for AI, dangerous, necessary, and not something you can simply avoid
- How third party vendor risk has quietly gotten worse as vendors move faster on AI than the organizations that use them
- Why Nakeea argues patching alone is already too late against machine speed zero day exploits
- Why Nakeea believes the industry has shifted from asking can we prevent a breach to asking how fast can we recover
- Nakeea's take on why security teams need to extend AI the same grace they've started giving breached organizations
In This Episode
Nakeea opens by describing the core tension every SaaS security leader faces, protecting an organization internally while also defending an entire platform full of client data, all while AI reshapes both sides of that equation at once. She leans on her baking analogy to explain why security can't be only about tools, arguing that leadership habits, employee behavior, and business priorities all have to be understood before any framework or technical control gets layered on top, and that a security leader's real job is producing an outcome the whole business can live with, not simply locking everything down. She's candid that this balance is uncomfortable by design, since being too secure creates the same kind of failure as being too loose.
The conversation turns to where Nakeea sees the sharpest risk in AI adoption, and she keeps returning to a single word, blast radius. She argues that comfort is the real danger, the same way a homeowner who has never been robbed eventually forgets to lock the back door, and that once an AI agent has access inside a network, the questions that matter are how much segmentation exists and what is truly off limits to it. She uses fire as her governing metaphor throughout, arguing that AI is exactly like fire in a home: genuinely dangerous, capable of burning everything down, and yet not something any household actually gives up, because the answer is learning to use it correctly rather than refusing to use it at all. She connects this to the Hugging Face sandbox incident as a preview of the test-and-learn process the industry is now going through, and argues that fighting AI with AI, rather than trying to out-work it manually, is the only realistic path forward. She also floats a concrete use case, feeding an organization's SSPs and frameworks into an AI system with carefully scoped, read only access to audit compliance gaps far faster than a manual review, while cautioning that the right approach is feeding in pieces at a time rather than dumping a sensitive document in all at once.
The back half of the episode gets pointed about how fast organizations actually need to move. Nakeea explains that third party vendor risk has quietly gotten worse, since a company that is behind on AI internally is still relying on vendors who are moving fast on AI regardless, and that bureaucratic approval timelines that once felt normal are now themselves a security liability given how quickly zero day exploits move. She argues patching can no longer be treated as sufficient on its own, and that organizations need AI actively watching their own networks for abnormal behavior in real time, catching an intrusion the moment it happens rather than waiting for a SOC analyst to notice hours later. Drawing a comparison to her own daughters navigating early adulthood after years of academic perfectionism, she argues mistakes are only failures when people stop trying to learn from them, a lesson she believes applies just as much to AI vendors as to young adults. She closes with a broader argument that the industry has shifted from asking whether a breach can be prevented to asking how well an organization recovers from one, and makes the case that AI, like human security teams, deserves the same grace to learn through mistakes the industry has already extended to breached organizations.
This episode is brought to you by Cyberlynx
CyberLynx is a Bethesda managed IT and cybersecurity company. Local techs you know, not a call center. Month-to-month. 24/7 intrusion detection.
We help growing companies with managed IT, help desk, backup and recovery, and a fractional CIO. Talk to us at https://cyberlynx.com/contact, [email protected], or 301-798-9170.