Dell Technologies Infrastructure Security with Steve Kenniston
Having a secure and resilient infrastructure gives organizations the confidence they need to innovate. Dell helps organizations stay safe and secure, today and into the future, by manifesting a comprehensive security strategy across three core pillars: modern workspace (PCs), modern data center (storage, servers, data protection, networking, HCI), and AI. This holistic approach, known as the Dell Technology Advantage (DTA), integrates security and sustainability across all three components. A dedicated development organization within Dell focuses on creating consistent security capabilities across their entire portfolio, aiming to reduce tool sprawl and provide a unified management experience for customers, including consistent operating systems across appliance solutions for predictable security implementation.
Dell’s infrastructure security strategy aligns with a “reduce attack surface, detect and respond, and recover” framework. To reduce the attack surface, Dell’s servers incorporate features like system lockdown, signed firmware updates, and dynamic USB control, while networking solutions leverage cryptography and secure authentication. For detection and response, features like iDRAC on servers and BIOS live scanning are used to continuously monitor for changes and send notifications upon physical chassis penetration. In terms of recovery, Dell ensures valid recovery points, scans data before recovery, and offers capabilities like scanning snapshots on primary storage for early threat detection and quicker recovery of business-critical data, complementing their data protection solutions with immutable vaults and isolation.
Dell also emphasizes a zero-trust approach, building capabilities into each solution set to support customers in creating zero-trust environments. While they clarified that “certification” by the Department of Defense is better termed “validation,” Dell’s Project Zero architecture adheres to the DOD’s zero-trust guidelines, having undergone testing and validation against their COA3 for on-prem infrastructure. This validation process involved implementing hardware that the DOD could pen-test and validate against various security controls. Additionally, Dell has partnered with CrowdStrike to enhance threat detection within backup environments, identifying over 70 types of attacks and sending actionable intelligence to SIEMs, thus shifting from reactive incident response to proactive detection and providing comprehensive recovery services through their integrated support and engineering teams.
Presented by Steve Kenniston, Portfolio Marketing, and Adam Miller, Marketing Lead. Recorded live at Security Field Day 13 in Santa Clara, CA on May 29, 2025. Watch the entire presentation at https://techfieldday.com/appearance/dell-technologies-presents-at-security-field-day-13/ or visit https://techfieldday.com/event/xfd13/ or https://www.dell.com/en-us/shop/scc/sc/artificial-intelligence for more information.
Transcript
You guys heard how we manifest those three things that, uh, um, Samir had set up into the, the PC side that Justin talked about, how it manifests itself in this, in the AI side. So that's the, you know, um, heavily Dell on the PC side. I'll talk about Dell on the infrastructure side, and then the, the, the big workload that everybody's talking about is the AI side.
That's why we wanted to talk about it. Um, I think there's a lot of components that you probably already know within the, uh, infrastructure side. When we talk infrastructure, we're talking storage servers, data protection, networking, HCI and AIOps.
I just wanted to give you the perspective of when Dell Dell's business, the, um, modern work workspace that Justin talked about. The workspace is the PC side, the modern, modern data center side is, is, is all of these things. And as the AI side, in fact, Dell has a strategy that we use to talk to our customers about.
It's called, um, it's called the, the DTA, the Dell Technology Advantage. And it's, it's those three components with security across all three and sustainability across all three. Um, so one of the important things that not a lot of folks know about when it comes to the infrastructure side of the house, um, is we actually have a separate organization, development organization on the infrastructure side of the house that focuses 100% solely on creating consistency.
So we've heard from a majority of our customers that there's just too much tool sprawl and, and all of that. So how can I get down to one set of capabilities that helps me manage everything that I own? Of course, hopefully if it's a Dell, uh, com component, but whether it be MFA single sign on or whatnot, you only have to go to one solution to implement to in order to get that across the entire Dell portfolio.
The other thing that is, um, brand new news, which was announced at Dell Tech World last week, was we have gone to this model where we're ensuring that in all of our appliance solutions, our service solutions, et cetera, we have a consistent o operating system. So that might sound like, eh, whatever, but I mean, from a security side, the, the, the customer knows that what they get on one is the same on, on, on everything. So what do they have to do is very consistent across their entire, their entire platform.
And I think that's, that's pretty great and something we've been striving to do for at least three years that, that I've been working on the security side of things here. Um, so what I'll talk about, and this gets back to a little bit of the zero trust stuff that you had asked about before. I don't, I'm, we're still thinking about how to answer the question on non Dell components, but what I've done here is talked about the consistent set of capabilities that we deliver on all of our solutions, including with our partners to, for example, reduce the attack service.
So our servers, you know, they have system lockdown, they have, uh, sign firmware updates, they have dynamic USB uh, components. These are all the things that we try to do to reduce the attack surface on the server server side. On the networking side, taking advantage of cryptography, taking advantage of secure authentication, like a lot of this stuff is, is kind of known, but, but we go above and beyond to think about if the strategy that Dell uses internally is this same, reduce its act, service, detect and response.
So it's catch and coming in, find the threats and then, and then get, get the business back to operational. We try to make sure that from a development standpoint, in each of our solutions in that we're, uh, selling to customers, we're making sure that they have the capabilities that they need to do to do all of them, and we're leveraging it both with our partners and with our services, right, to make sure it, it all goes according to plan on the infrastructure side, um, from the detection response side of things, right? Same kind of thing.
You heard, um, uh, Justin talking about irac, so irac on the server side, bios live scanning to make sure that what we were look constantly looking for for changes, anytime the chassis gets, gets, um, penetrated, we can actually send out notifications, let people know that something has happened. So not just, you know, the cybersecurity, but also the physical security of the devices and all that stuff. We're trying to take all of that into account to make sure that, that we're catching as much, as much as we can.
And the same thing on the, on the, um, recovery side, right? And especially in mainframe, sometimes it gets a little bit forgotten that Dell deals with, with mainframe a lot as well. So whether it's the checking, uh, and, and make, ensuring you've got valid recovery, uh, points to recover from, uh, like we do with index engines.
Rocket Soft is also scanning, scanning information and data before recovery as well as, uh, integrity who all does that on the mainframe side. So we try to, and, and in fact, on the index engine side, from a recovery standpoint, we've recently announced last week as well, not only during the scanning and the data protection side of things, so you, you, you've got your backup, we scan the backup, make sure it's clean, also leveraging index engine on the primary storage side, so scanning snapshots and that sort of thing. So if you, if you're trying to catch the threat early, doing it on the primary side and being able to recover quickly from those snaps on the primary side is definitely very beneficial.
And, and, and that's where we're, we're seeing the industry as well as some of the things that we're doing, Uh, Lars from Norway here. Yeah. Hey, Lars.
Uh, so that means that if you have a, a data protection system that is not on the list, which is only a few old ones, more or less, uh, I, I saw the list of supported systems, but now that you can scan the, uh, on the primary storage, you don't, uh, have to rely on the having one of those old systems. Yeah, it kind of, I think we have this conversation internally a lot, right? Because the customer we're sure is gonna ask, well, where should I do it?
Right? Or, or what's the smartest thing to do? And it's really trying to let the customer decide, right?
So if you're a belts and suspenders company, you probably might want to try both, right? But, um, you always want to catch it as early as possible, and doing it on the primary storage is definitely beneficial as well. That said, if you have a vault or you don't have a vault kind of situation with, with the Dell solution, you can then also leverage the fact that we do it.
We, we, we scan the data there too. And we've also come across a number of our customers who put, you know, all of their data in a cyber, in a cyber vault that gets a little unwieldy when you try to recover all your data. What does that mean?
Right? So now it's, it's up to maybe you've got some business critical data that you wanna recover, like near instant you can scan and be confident that that's gonna recover and you can maybe put your next tier down in the vault without putting everything in the vault, but it actually cleans up the scanning times and that sort of thing. And, and the manipulation you can do in the vault vis-a-vis on the primary storage side.
Yeah. Is that helpful? Yeah.
Uh, we, we'll use deport, um, more systems, uh, as time comes on. So right now it's on power store, our power store, uh, solution on our HCI solution and, um, UDS solutions. We use other, um, capabilities.
One is, uh, progress and flow. Mon, I forget who the other, the other one is we're doing, we're doing that across the primary storage side and the data protection side. I don't know how much further we're gonna expand that, uh, versus other security capabilities we're gonna build into the system.
Yeah, I, I was mainly thinking of, uh, data protection systems. There, there are some, uh, systems that are, uh, have gained a lot of traction the last, uh, 10 years that are not on the list. Oh, and I'm wondering many customers are migrated to them.
Yeah. Uh, I, I I'm sure we're in the process of testing a, a bunch of them. I'm just not quite sure kind of the order of progression that we might might do.
Thank you. Yeah, sure. So as a way, this is in the data protection space as a way to see it to, to come full circle is if you look at, um, our data protection solution, right?
When we talk to customers and we go and, and we're having conversations with 'em, we do put 'em in those three buckets, reduce the attack, surface, detect, and respond and recover. And you might say, well detect that's all about recovery. Well, we don't think of it that way, right?
We kind of turn the lens around and we say, from a deployment standpoint, you want to be able to secure your devices, um, properly. So what do you do from an MFA standpoint? What do you do from a rules-based access standpoint?
What do you do from a, uh, encryption standpoint? Making sure that all those things are in place as part of best practices. And then from a detection standpoint, we, we have obviously the detection with index engines to find the threats, uh, that, that are, that have come through.
But also as Adam just pointed out, um, we have done a relationship with CrowdStrike that we announced, uh, earlier in the year where they, we've found over 70 different types of attacks that can get through within your backup environment. And we can now send them to your SIM and kinda let you know what's happening, not only, not only in your regular storage or, or everything else that your CrowdStrike solution might look for. We can also do it in the backup and then leveraging the vault and immutability and the, um, isolation that we do, being, being able to recover securely.
So this is when we talk to customers, it's not about, about, um, what one solution are you gonna fulfill to, to solve each one of those three problems. It's about how does the solutions that you buy from Dell have the ability to solve all of the problems along the way? So we were talking about zero trust, again, Samir pointed out very well, right?
Zero trust's really all about the identity component and the two ways in which Dell can can bring that together is the project for zero and the incremental uplift on the uplift side. These are really the capabilities, and I think this answers your, your first question, which is, it's not just about what we believe, but these are the capabilities that we build into each one of our solution sets to make sure that as you're building a zero trust environment, especially in that brownfield environment where you have to say, Hey, I, I'm building zero trust, but I really only need to buy a server right today to, to fulfill my requirements. Well, you can look at the server side and, and I always, um, whenever I present this customers, they say, you're probably in this executive briefing not to hear about every single little thing that Dell does, but maybe you're here to buy servers, or you're here to buy storage.
Take a look at which one of the capabilities or the, the components that you're trying to buy and kind of zero in on the list. And then when the, uh, subject matter expert comes in to talk to you about that particular solution, whether it be storage or servers or networking, you can kind of drill down on some of the capabilities that are built into the system that allow you to continue to build out your zero trust environment or that perimeter list environment, uh, for you to keep it, to keep it secure. However, also, you know, if you are looking to ha build that enclave that keeps you secure, uh, and everything that you put behind it, the the way to do it is through our project four Zero, which just, just got certified through the, uh, the Department of Defense.
Actually, I have a question, uh, about that statement. Yep. Where is the certification process that the DOD uses certify Dell, their architecture processes, frameworks, everything is zero Trust.
Where is the process? Yeah, You guys said, we have been certified by the Department of Defense as Zero Trust, So there's no stamp or validation. I, I think, I think, uh, well Then why, why make the claim?
Because that's what the Department of Defense says. It's, it's not a, uh, maybe certification is the wrong word. Validation is the right word.
So what we did was the Department of Defense built a zero trust architecture mm-hmm. That you needed to follow if you're gonna be in any type of regulated business, if you're getting federal grants, if you're doing anything, if you're a critical infrastructure organization, they said, you must adhere to this. That's right.
So we built to that architecture and then we submitted it to them and said, okay, try to break it. Right. Okay.
But have they validated it? I guess? Yes, they have point.
Yes, they have. Okay. So what is that process that validates that I can't take?
Uh, We went, we went on site there, we built We, is there a document from, there is no DOD document. Yeah, that'd be great. Just because in the, in the first part of your presentation, uh, uh, I forget who was speaking, but it was mentioned, we've been certified by the DOD, department of Defense zero trust certification, and I'm searching and searching and I cannot find a single certification validation.
Okay. You know, that's subjective. There's a checklist.
Okay. But there is no certification. So I just, I needed clarity on that.
Yeah, yeah. It's driving me crazy understanding. Steve, if I might add just something quickly, um, part of this involved, you know, IM implementing hardware that they could then go work against from, you know, a pen test and various other security, you know, controls, validation checks.
But, um, the, these were built and they ran those tests against each of the COAs. So they had vendors they were looking at for co a two on cloud, uh, and co A three for on-prem infrastructure and CO A three is the one that we were validated against. Okay.
That, that's a good detail because I did find that reference. You were talking about the different COAs. Yeah, so I mean, holistically, again, what I said was, you know, Samir set it up.
The three, uh, strategies we, the strategy we use to talk to our customers about making sure that their environment is secure. We tried to bring it to life in each one of our infrastructure side, our endpoint side, and then, and then through our AI side. And I hope, I mean, we got out of it, I think a lot more questions than the last time we asked.
And some of you were here last time, some of you were not. But, um, it's very beneficial and we're looking forward to, to the next section.