Dell Technologies AI Security with Arun Krishnamoorthy
AI has become one of the hottest topics in IT. Learn how Dell can help you make sure that as you deploy AI solutions, you do it in a secure manner.
Dell Technologies emphasizes that security is a critical aspect of their journey in accelerating customer outcomes, whether through private and hybrid cloud solutions or advancements in AI. They have established the Dell AI Factory to mass-produce AI solutions at scale with high quality and efficiency, bringing together Dell’s infrastructure, including AI PCs and data center components (compute, storage, GPU-enabled with partners like Nvidia, Intel, and AMD), along with an ecosystem of AI-enabled partners. This comprehensive approach aims to help customers accelerate their AI innovation and achieve faster time to market, recognizing security as a day-zero conversation for successful AI deployment.
Dell highlights the evolving landscape of AI, from traditional AI to generative AI and the emerging agentic AI. With agentic AI, applications will increasingly think for themselves and exercise judgment with minimal human intervention, posing significant security challenges. To address these evolving risks, Dell advocates for a cross-functional architectural approach involving IT, business, data, and security teams from the outset. They stress the importance of organizing and securing data, which fuels AI models, and implementing robust governance. The company is developing an architecture to secure AI deployments, from model training and data organization to runtime environments on-premise, in the cloud, or on AI PCs, acknowledging the shift of AI use cases to the edge.
Dell’s security strategy for AI focuses on making security and resilience an architectural design choice, providing services like strategic advisory, implementation, and continuous threat management. They offer a virtual CISO for AI, data security posture assessment to identify and reduce AI-related risks like data poisoning and prompt injection, and managed security services, including managed detection and response (MDR). Their MDR service provides full-stack visibility, proactively monitoring infrastructure, data protection environments, and cloud/container levels for threats. Dell is also partnering to develop an “AI proxy” or “AI firewall” for deep prompt-level inspection, compliance violation assessment, and malicious code detection, and offers penetration testing against OWASP Top 10 AI vulnerabilities, emphasizing a proactive and collaborative approach to securing AI implementations.
Presented by Arun Krishnamoorthy, Sr. Director, Product Management, and Adam Miller, Marketing Lead. Recorded live at Security Field Day 13 in Santa Clara, CA on May 29, 2025. Watch the entire presentation at https://techfieldday.com/appearance/dell-technologies-presents-at-security-field-day-13/ or visit https://techfieldday.com/event/xfd13/ or https://www.dell.com/en-us/shop/scc/sc/artificial-intelligence for more information.
Transcript
Hopefully you started kind of understanding the theme of where, uh, Dell is headed in terms of security and infrastructure. Um, I would say the, uh, the, the TLDR here is Dell's objective is as an essential infrastructure company, we are helping customers accelerate their outcomes, right? When you look at the last 10 years, whether it is cloud revolution, where we've given a ton of private cloud solutions, hybrid cloud solutions to customers, or the advancements we are doing in PCs today, and some of the things that I'm about to show you in terms of where we are headed from an AI standpoint, you hopefully, uh, by now you would've understood that security is a very critical aspect of that journey for us, whether it's security on the product, uh, as Justin was showing with both on and additional services, uh, we really care deeply about services and, uh, security and security outcomes for our customers.
So I want to talk a little bit about our journey on ai. It's about time on this call that we all talked to ai. Um, so for some of you that I've seen announcement amount announcements come out of Dell in the last two years.
Uh, the concept called Dell AI Factory, uh, if you think of a traditional factory, doesn't matter. It could be shoes, it could be manufacturing, it could be anything. The whole idea of a factory is can you mass produce something at scale with high quality and efficiency?
So essentially that's what Dell's done with our AI factory. We have brought together Dell's best of breed infrastructure, uh, whether it's ai, PCs or everything we do in the data centers, compute, storage, all GPU enabled with partners like Nvidia and growing to other silicon vendors in AI like Intel and a MD. Pulling all of that together, pulling an ecosystem of AI enabled partners who are the best of breed partners in the industry that are helping customers accelerate the AI journey.
So obviously names that will come to you are things like hugging face, where there are millions of models out there for customers to download. So working with that ecosystem and building a set of services around, around these products that we are selling is really geared towards helping customers accelerate, uh, their AI innovation. And, and from what we know from customers, uh, time to market AI is a one of the key metrics, uh, that that helps our customers be more competitive in their marketplace.
So this is kind of a high level view of what Dell's doing on AI factory. And I wanna talk a little bit about AI itself, right? So when we think of ai, it's definitely not a new terminology, especially the vendors in the security space have been one of the early adopters of ai.
Um, when you look at the evolution of ai, you have the traditional ai, uh, where AI has been part of everything that we have done in the last 10 years. And then two years ago, the world got exposed to generative ai, which is a new way of communicating with ai. All the innovations that that has happened in that space.
Obviously the biggest phase of that was chat, GPT. That's how we kind of got exposed to it. Um, taking natural language processing and having, helping AI generate outcomes, right?
Whether it's a text or music or code, really the productivity side of it is kind of where we have seen the last two years, uh, with generative ai. And where we are going next with AI are things that you are obviously hearing already, is things like agent ai. So from a security standpoint, uh, anything before ai, you know, was what we call kind of not deterministic, where from a security standpoint you could understand user A on device A is trying to get access to a cloud application or an ingrown application.
We know what those communication patterns are. We know what TCP IP ports, we know what network that these things traverse. We know how to block it, whether with a firewall technology or, or an ID technology.
We knew what to do with it. But as you start going into the AI space, especially agentic AI and beyond, uh, things start getting complicated for multiple reasons. One, from agentic AI and beyond.
AI is going to start thinking about, uh, itself. It needs very little human intervention. Uh, so there is a situation where an AI application that's AgTech is going to do whatever it needs to do, whether it's booking a ticket for somebody, it's going to discover the internet, do 10, 10, 20 things, and it's going to keep learning and get better and better at it.
So the, the here from a security standpoint is from agent AI and beyond. There's gonna be a ton of intelligence in these applications, and they are going to do judgment up until generative ai, the judgment is with humans, right? We are still leveraging AI to produce desirable results.
But beyond this point, it's all about, uh, it's all about applications getting smarter and self-reliant and exercising judgment. So this is a little bit of a scary trend here if you're a security practitioner. Uh, the question is, uh, how do you prepare for this?
What does the security architecture look like? What do I have to do differently to prepare for this? And I won't drain this slide.
This slide really talks about the IT risks and the business risks. Uh, if you are a business owner, every corporation that's evaluating ai, obviously one of the big concerns you have is your reputation and your privacy. You don't know what answers the LLM is going to provide to you, uh, to your customer.
Your reputation is at stake and you're not able to control some of it. So understanding guardrails on what LLMs, uh, large language models can do, and making sure that, uh, that the output is well tested, well vetted before end users can start using it. And then the answers are highly, highly high quality and highly repeatable is, is key.
So there's tons of business risks involved, and in fact, when we are working with customers, uh, we do see that security becomes a, a conversation that comes way early. Again, I referenced back to cloud, which we did 10 years ago and other transformations we have done, but for the first time I'm seeing that security is, and risk and security are, are really conversations that are starting to happen on day zero. So along those lines, uh, one of the best practices that Dell is, uh, advocating to customers is who should be, who should be in the table discussing AI and AI use cases.
Obviously the IT teams, the business teams, the data teams, and the application teams are all security teams are gonna come together, and each of them are gonna have their, their own motivations. The business is gonna be focused on use cases. Hey, what are the four or five use cases that we need to go do now that's going to help us accelerate, uh, revenues and productivity and customer experience?
IT teams are tasked on how do I build an infrastructure? We know these are large GPU based systems, power hungry, there's a lot of planning and architecture needed, so IT teams are focused on that. Data teams are focused on what data provide.
Um, so when you look at LLMs and ai, uh, there are a ton of models out there that are pre-trained, but customers need to use these pre-trained models and apply their own data to get answers specific to their business. And that's where data becomes a huge, it's not only fuel to ai, but it's also an area where a ton of governance and security has to be exercised, and the security teams have to be part of day zero to understand that they have the right tools, the right process, the right governance in place that they can start, uh, implementing from from day zero. So slightly different view of what I just told you.
This is the traditional kind of waterfall model. You envision an architecture, you implement it, you manage it, you kind of build additional security around it. This is the traditional model.
But where we see things moving, uh, and where Dell has a ton of services to help customers is how do I build that cross-functional architecture so every stakeholder understands how we are planning to deploy AI and safely deploy ai. And then the AI platform comes in, which is where Dells with the Dell AI factory solutions is helping customers accelerate it. So this is kind of like the new model we see.
It's a huge paradigm shift. And some of these dates, uh, from before and after is in the old waterfall model. Products came out every 12 months.
In the new, new AI world we live in, products are expected to go out every three to four months. So, so the ton of speed, speed is a really critical element. Uh, as we go to market.
Um, I am going to spend about 30 seconds on this slide. Uh, this is the kind of the architecture we have developed, uh, in terms of how we envision securing ai. Uh, I'm gonna spend 30 seconds, Adam, I'm going to, uh, pass it on to your able hands here.
Uh, but if you look at what's in the slide, I know it's a really busy slide, but if you work your way from left to right, left is where nine out of 10 customers are gonna go train a model on their own. They're gonna take a pre-train model, uh, from an AI marketplace such as hugging phase, and they're gonna bring that model in into their corporate development environment and start building their use cases. And those use cases are gonna be supported by the corporate data.
So if your use case is, Hey, I want to do HR related, something about people using ai, then you're going to tap into the HR database. If you are gonna make your salespeople smarter with ai, you're gonna tap into your CR sales, uh, database. So depending on where the use cases are, different types of corporate data is going to help feed, and we are helping customers a lot in terms of organizing that data.
Uh, we do know that customers have a lot of islands of different data. It could be sales data, HR data, and other data. So bringing them all together, building a data mesh and then giving it the right identity, RA permissions is one of those super critical preparatory activities before you start sending data into the ai.
And then on the far right, you'll see the whole runtime environment on how we envision, uh, these, uh, these models to run applications to run in production. There are gonna be options for customers. They're gonna choose to either run it all on on-prem, things like Dell AI Factory, they can choose to run it on a cloud, or they can choose to run it on an IPC.
Yep, I said it right? It's an A IPC, and it's, if PC is not a, uh, workforce device anymore, there's a ton of AI use cases such as developer use cases shifting right to the pc. And we are gonna see more things happen at the device level at the edge as we go on.
Great conversation so far. Just really excited to be back with you again this year. Um, one thing, and lemme get this full screen now, that architectural view, um, something that we noticed is that generally there's a lot of different approaches happening out there in the industry right now on, on AI security.
Um, some are emblematic of the rest of the security industry as a whole, where we see, you know, point solutions built for point problems, um, but not necessarily a, a view that's taking into account the way that our customers are moving, which is very quickly, again, starting with some of those public pre-trained models, adding their data in and then, uh, you know, bringing that, uh, to their users. But one of the things that, again, Arun started talking about, but I I just wanna put another point on, is that we're encouraging our customers to make security and resilience and architectural design choice because, uh, if you remember back to that, that curve of AI adoption and how that's moving, the faster that we move up that curve, the more difficult it's going to be if they don't establish that foundation today. So in order to make that architecture real for our customers, we're bringing it to them through our services organization here, whether it's strategic advisory to help them understand how, uh, that can be tailored to their exact needs, um, implementation of the, of that, uh, architecture, the ai, uh, solution hardware, as well as, uh, any security software they might need, uh, in order to do good security around that AI factory, or if it's continuous threat management through our managed services teams.
Um, this is really the way we're starting to see a lot of our customers needing to consume some of those capabilities because, um, there's a lot of things that need to happen here around securing a AI deployment that, um, really amount to a level of visibility that customers have not needed, uh, in parts of their data center as they do now for this type of solution. Yeah. Real quick question, Of course.
So, uh, we've talked about the whole conversation of the AI and and, and the strategic changes that we're seeing in, in, in the environments. Are you aligning to any specific AI framework or architecture to build this on? I saw some of the conversations before in the prior spring, but I didn't see an alignment with a framework or any type of mm-hmm.
Of practice. Is that somewhere, uh, covered in your slides? Yeah, that's a great question.
I, I don't cover all the frameworks specifically, but happy to speak to them. Um, you know, when we've built, and, and I'll just kind of focus it on the, the far left most, uh, service here. Um, when we're talking with our customers, what they're trying to understand is how they fit, um, you know, needing to secure things alongside with the rest of their AI strategy.
And we see a lot of differences from our customers globally on, on exactly what frameworks they'd like to align to. So we generally choose not to pick a specific standard, but more so, uh, work in a way that allows us to align to whatever they need, whether it's, uh, you know, taking considerations from something like O-W-A-S-P top 10 or aligning with a Mitre Atlas framework, or the various ones from NIST or iso. I mean, there's just a tremendous number of, uh, framework and regulatory bodies now looking at kind of like the way to safely implement ai.
And the way that we approach this is by working with our customers because they likely have, um, their own very specific needs for those, whether it be, uh, again, based on where they reside physically or the industry that they're in. Uh, we, we do see, uh, need to align with various different groups of those. But so just kind of continuing through this, um, we've really built our advisory services portfolio, again, to, to bring that architecture to our customers in a way that allows them to consume this based on what their needs are.
So again, whether they need that full strategy over on the left here, or whether or not they have not had time as the CISO to come up to speed on becoming an AI expert, um, our virtual CISO offer, um, which, uh, just reiterate is not a, uh, an AI agent or anything like that, but is very, uh, a virtual CISO in the traditional sense that, um, we provide that CISO level expert to be an advisor very specifically for ai. Um, our teams have been trained very specifically on AI and the risks associated to those and can work hand in hand with organizations chief information security officers and their teams in order to inform those processes and help them, you know, really improve and, uh, make decision making a little bit more rapid. But of course, given that data is the most important foundation of ai, uh, we also have very specifically, um, worked a, a service in, uh, which allows, uh, us to assess and help our customers through, uh, identification of any threat surfaces, as well as, um, talking through with them how to reduce the risks associated with ai.
Um, many of which are associated to things like OW ASP's top 10 on things like data poisoning or prompt injection, and really how to work backwards from those threats in order to how to protect that data. But again, what much of this constitutes is something that's very new for our customers, very new for security leaders to think through how they're gonna protect this. And we're seeing a tremendous amount of interest in, uh, managed security services, which, um, not only allow us to offload some of that burden, but mainly, again, you know, go back to a point that we made earlier.
Security is a team sport, and many of our customers have already invested heavily in security operations, but may not have the ability to very quickly scale in order to, uh, handle some of the rising needs for ai. So things like, uh, our managed detection and response offer, we have now very specifically built around how to either, again, manage security for our customers in totality around this, whether it's diverse sets of technologies or very specific to AI or augmenting their existing operations, whether on premises, on cloud or on device. Our managed detection and response offer is now built to take some of those very specific bits of information that we need into the CrowdStrike next generation SIM platform that our SecOps team is running on behalf of customers in order to gain some of that very deep level visibility here.
Whether it's from the infrastructure layer through, uh, you know, syslog and, and what we can take from there, uh, data security posture, uh, management modules, or even, you know, some of the cloud and containers levels. Um, what we've done here is really trying to take that full stack visibility approach. Again, security teams have been great at getting some of that level of visibility off endpoints and laptops for years, but gaining this type of, uh, continuous threat management in the data centers, uh, we are seeing as something that they now need to be doing in order to be able to really understand what's happening and, uh, for instance, if something has come in, what types of impacts that may have on their ability to continue using their ai.
One thing, and, and I'm gonna move a little bit quickly here just in the interest of time to keep us, uh, able to cover the rest of the conversation that we want to have, but one other thing that we've seen a lot of interest in from customers is the ability to very deeply inspect at the prompt level of, of what's happening, who's coming in, who's prompting our model, and what are the responses that it's gonna be sending out. So you'll see a little call out here to what we're calling, uh, like an AI proxy or an AI firewall, and that capability becomes incredibly important for our customers as, um, what they're telling us is that they need to be able to impose a very deep set of guardrails, um, around their AI to ensure that, um, their teams are using that securely. Whether that comes down to, you know, users or agents, doesn't really matter, but what this capability, um, constitutes is a managed service around inspection of those prompts and running a technology that does that for them, whether it's assessing for, you know, compliance violations or, um, let's say somebody has, uh, you know, tried to put malicious code into a prompt to see if, uh, it would execute it.
This is going to catch that, and this is going to a block the prompt, but b also, uh, you know, send that detection off to the managed detection response team so they can take a look at it. Of course. On, on that, I know we have to go for time.
Uh, if this a, uh, uh, technology just use the word will, is this technology that Dell already has, and if so, is it organic or is it a partner base? Because deploying AI firewalls can be done in so many different ways. I'm just trying to understand a little bit better what you're doing.
Yeah, it absolutely can, and great question. Um, this is one that we've chose to partner very closely on, and, um, I have been asked not to use the, uh, organization trust that, um, you know, they've already come up today and that, um, you will likely know who they are, but their product actually hasn't launched yet. But part of what's cool about this is that we are working hand in hand with them in product development here is because, um, what they've realized is that we know a thing or two about running AI and running those, uh, large on-premises solutions that our customers are looking for, as well as of course, how they're running, uh, you know, on device and on cloud LLMs as well.
Um, but they know security and they know policy enforcement and getting us together in a way that's really been collaborative in order to build those tools is just yet another way that we're bringing home this whole security as a team sport notion is because we're able to, uh, you know, work together in order to, to deliver that expertise to our customers. So this is a, a, uh, a capability that I believe they'll be launching within the next two weeks here at their conference, which is coming up toward the end of the month. Um, and, and we look to, uh, you know, be one of those kind of early, uh, adopters of that technology and operating that as a managed service on behalf of our customers.
Again, customers are moving very quickly, so they may not necessarily have time to come up to speed on that technology on day one. So whether or not we're, um, running that for them, uh, you know, end to end for, you know, indefinitely, or if we are helping them come up to speed onto it and then handing over the management to them, um, that's really where our focus has been thus far, is creating something with that, uh, partnered organization that we know will be able to use. Because ultimately, um, what they're doing as part of this is they're running an LLM inside of this tool.
Because if we think about how many prompts are gonna be thrown at, um, enterprise LLMs and enterprise models, you really have to be using AI to defend AI here. Um, so the way that this works is that our teams will be operating it, again, that partner technology on behalf of the customer. But another kind of key point in this is that this has very deep connections in with the identity tooling that our customers have is because if you're setting up AI guardrails and wanna be making sure that, um, the way that we are keeping that safe is, is based on, uh, you know, the roles of the person who's accessing it.
I think there's a great example that, you know, I, I spoke to a customer recently from the, uh, the US Navy who was trying to come up with a, a way for their strategy in order to have, um, you know, people on boats contributing their daily situational reports. And then whether you've got, you know, a boat commander or an admiral prompting that model, they needed to be able to not only verify that that's the actual person who's prompting it, but also that, um, it's able to deliver an output based on who that person is and at a, the right level of summary as opposed to the individual situational reports, but more so the daily report for that, that executive. Um, these are the types of guardrails that this technology will put in place and, and actively enforce.
Again, just, uh, moving, oh, I, I missed one here, but one of the other key pieces here that I did wanna talk about is not only are we setting up these guardrails for customers, but our, uh, we also have very specifically onboarded a new service capability, uh, in order to help customers with penetration testing directly against, um, that O-W-A-S-P top 10. And part of what we're doing here is basically saying, not only are we helping you set up all those AI guardrails, but we're helping you test against 'em and make sure that they're continuously properly implemented. Um, that capability we find, uh, really marrying up well with the combination of, uh, managed detection and response as well as, uh, this AI firewall proxy capability.
Was there a question I, there, There was, and, and, and I just, I'm, I'm looking at what you're saying and that you're not specifically saying it, but what you're saying is you have a relationship with a, with a partner and it sounds like you're getting into the space of DLP, should that be what I should interpret from the statement that you're making right there? That that is absolutely one of their core capabilities. Uh, we can operate their core technology as part of our managed services as well.
Um, this is, uh, a really interesting bit of technology because it takes into, um, you know, some of what they do, uh, in terms of, um, you know, firewalls, DLP, a lot of great work there and kind of marries that up with where we're going with AI and just really brings that all together. Yeah. Also web application firewall as well can be applicable I think, in this, uh, approach of inspection.
Mm-hmm. That's right. One thing that, Aaron, I'll just skip through this one, but so, uh, I did want to cover as part of this, I think even generally, something that we are seeing is that customers are, are really trying to, um, make sure that everything that they need around AI is kind of included in the solutions that they're purchasing.
So again, now that you've got this on board, how are you gonna protect it? And part of, uh, you know, what we're talking about here is not only from a data protection standpoint of how you're gonna do, you know, good backup and recovery around those, uh, whether it's the LLM itself or the vector databases that underlie that, but where we're coming at this from the managed detection and response standpoint, again, hopefully what you've heard today is that we can manage detection and response on diverse sets of endpoints, not just Dell, but anybody's. We can now manage detection and response around, uh, these ai, uh, you know, factories and, and, and implementations, and also go down into the data protection environment to very deeply inspect what's happening there.
We know threat actors are going there first. We know they're moving faster than ever, so why not move proactive detection into that space as quickly as possible? Um, generally what we've seen in the data protection and backup space thus far is this notion that if you can forward your logs to CrowdStrike, you're good to go.
But what we actually know from working with customers is that more often than not, their SecOps teams don't want more logs. They need real actionable intelligence. And again, in an environment where they traditionally have not had, uh, that level of visibility or the need to really inspect it that deeply, um, we have now built a very specific capability within our managed detection and response service to, uh, watch over power protect data, uh, manager and power protect data domain.
Um, which what it does is taking, uh, you know, proprietary threat indicators that we developed hand in hand with the engineering team at CrowdStrike in order to see what's happening on those and then correlate that to real security incidents. So instead of, you know, this, you know, sim being something that you're using as part of an incident response process of, hey, something has already blown up and now I'm going back to see how far the spread was, we're now using those same logs in a much more proactive manner, um, to get those, uh, detections to our managed detection response team who will very quickly see, um, uh, things that, uh, might constitute an ongoing attack. Like say, you know, an example might be somebody just logged in with administrative credentials from an IP address we've never seen before.
That's gonna require an investigation, an escalation to a level two analyst. So, um, instead of, you know, waiting for, you know, sim to be something that's very, uh, you know, kind of used after something has blown up, we're trying to really shift, uh, the point at which we can use those technologies because of what we're able to build on top of with CrowdStrike's, uh, next generation SIM platform here. Um, complimenting that of course is incident response and recovery hours, which are included, uh, you know, in that managed detection offer so that if we do see something we can very quickly task a team of experts, um, who not only can show up and help recover, uh, that data protection environment, but diverse sets of technologies as well.
The, um, I think that the inherent benefit there of course, is that as Dell, not only can we do that incident response work, but it's a single call to the, their support executive. It's a single call to our engineering teams if we need it. Really bringing together just an incredible set of capabilities from all across Dell in order to help our customers recover more quickly is our goal here.