Defending the Private Cloud in the Age of Frontier AI — Inside VMware vDefend
Alan Shimel sits down with Umesh Mahajan, VP & GM of the Application Networking and Security Division at Broadcom, for a candid conversation about what it really takes to secure the private cloud in the era of frontier AI.
Umesh explains why the classic perimeter-and-insurance security posture is collapsing now that attackers can spin up AI agents to carpet-bomb environments in parallel, compromising hosts in 30 minutes instead of six months. He makes the case that signature-based deep packet inspection, micro-segmentation and defense-in-depth — the “old faithfuls” of security — have become urgent again, but only when delivered as a single integrated stack rather than stitched together from five vendors.
He walks through VMware vDefend, Broadcom’s full lateral-security platform built directly into the ESXi hypervisor for VMware Cloud Foundation. Because vDefend’s data plane runs at the hypervisor level and plugs seamlessly into vSphere, customers get 100% east-west visibility, integrated distributed firewall, IDS/IPS, NDR, advanced threat protection and virtual patching — without bolting on appliances or sending traffic out for inspection. Umesh also explains how Broadcom is doubling firewall and load-balancing throughput every other year through a distributed, software-defined architecture that scales with workloads rather than against them.
The centerpiece of the conversation is the DFW 1-2-3-4 prescriptive model: step 1 — visibility and scoring on existing distributed firewall data; step 2 — infrastructure services hygiene (DNS, LDAP, NTP); step 3 — macro-segmentation and zoning; step 4 — true micro-segmentation. The result: a zero trust journey that used to take a year of services engagements can now be executed in weeks, and as little as three days with a top architect.
Umesh and Alan close with a sharp warning: with frontier AI accelerating the threat landscape, enterprises that wait until next year to modernize their lateral security will, with high probability, be attacked. The time to move is now.
Transcript
Hey everyone. Welcome back here to Techstrong TV. I'm really happy to have our next guest on here because we're living in such interesting times right now, and it's going to be good to get his view on things.
I want to introduce you to Umesh Mahajan. Umesh is the Vice President and General Manager for Application Networking in the Security Division over at Broadcom. Umesh, welcome.
Thank you for coming here on Techstrong TV with us. Thank you so much for having me here today. A pleasure.
Umesh, I always like to give the audience a sense of who they're listening to. So if you don't mind, let's start there. I gave them your title, but let's go beyond the title.
Give them a sense of your journey. Okay. I've been in the tech industry for 30, 35 years.
Me too. I'm a first-generation immigrant. I came here to graduate school to study, and then once I got my master's in computer science, I got to work as a software engineer.
Maybe that was the right time with AI. You never know what happens. Mm-hmm.
" We don't know. Seven, eight years later, there may be no software jobs around. But nevertheless- ...
it has been a fantastic career, and I've somehow always been in networking, security, load balancing, in somewhat those areas, wherever packets are flowing and networks happening and services along with that. So long story short, we got acquired by Broadcom three years ago. I've been at VMware Broadcom 10 years.
But we got acquired three years back, and then Hock Tan, the CEO, had this vision is we are going to have this private cloud. His whole focus was VMware Cloud Foundation, VCF. But then it was, okay, but I need security and load balancing products for that because everybody uses a load balancer and some kind of security product, firewall, advanced threat protection.
So Umesh, you are going to be responsible for those products and build the best advanced services or security load balancing products which fit in seamlessly and plug-and-play style, and scale appropriately for the private cloud, which VMware Broadcom will offer. Have been on that journey and we were chugging along well, AI, ML, everything, and then suddenly agentic AI, okay, change gears, move faster, and now the frontier AI model. So it's been an exciting journey and- It really has ...
having been from the technical background, I'm having a lot of fun maneuvering and changing and adjusting our roadmaps as the threat landscape is changing so rapidly. You just can't have three-year-old legacy security tools, because then they are almost useless. Our paths are somewhat similar.
I'm also in tech 30, 35 years, and I think back, and we were lucky to be born when we were born and live through what we've lived through. I don't think either one of us would've thought that at this stage of our career, we would be dealing with something like AI, such a game... I was up in Dallas yesterday at a conference talking with CEO there, also gentleman, probably contemporaries of ours, Umesh.
Who would've thought that our once-in-a-lifetime type of event would happen now? Not the dot com era when the internet became commercial or the start of the cloud and virtualization. We might have thought those were the pinnacles.
Those were the big events in our tech careers. But as your son said, this might very well be the big event in our career. Yes.
The big thing happening. It's interesting. But there is a lot of excitement around AI, but there's also a lot of concern.
It's like a double-edged sword. Mm-hmm. It's almost the technology people love to hate.
Yes. I don't know if you saw it. There was a thing at a college graduation last week.
Eric Schmidt, formerly of Google, every time he mentioned AI, they were booing him. Yeah, because jobs are harder for the new grads. Yeah.
Right. You can't blame them. So there's a lot of anxiety, a lot of angst, a lot of stress, as well as this exuberance and excitement.
Mm-hmm. A lot of it goes around the security question, right? Yeah.
How do we govern this? How do we secure it? The bad guys are going to use it, too.
How do you see security in this, if we can call it the age of AI? How do you see security playing in? I think, as soon as AI comes in, especially agentic AI, the third word is security.
Or frontier AI models, people are really, really concerned. Okay, of course, we, Broadcom, are using those models to make our products more robust, and we'll continue to do so as those models further evolve. But there's these customer workloads, too.
So the way to look at AI, like you said, it's a double-edged sword. We are using AI to obviously generate code, do our own patches, make our infrastructure better, use AI, ML-Somewhat aged now with all the agentic AI. Use that to come up with better security recommendations, behavioral analytics, because you cannot, in this day and age, when things are moving so fast, you have to use the tools and AI to do a lot of the work.
Humans can't just do that. " So you're forced to use AI, or else the tool is useless, at this day and age. So we have been investing heavily in that, whether you call it co-pilot, or you just call it behavioral analytics.
So we have been leveraging AI. But now, the bad side. This AI is also available to any kind of attacker.
You don't even have to be a very refined hacker. And if you ask us some smart questions, outcomes, like this is what you can do, and sophisticated things, and people can bypass the perimeter firewall and start compromising hosts, and that's where the real damage starts. Yeah.
Until recently, lo behold, enterprises like, "Yeah, I understand the challenge and the problem, but it's too hard, so I'll do nothing. " But when they get hacked, the tone changes, right? Mm-hmm.
I think people are getting smarter now with this recent frontier AI model. Now, from prime ministers to presidents to CEOs to CIOs, suddenly it's top of mind. So I think it's a good thing for security.
People are scared, so finally they will move in a systematic fashion, not some random thing. I did this one thing in security, and I'm okay. No, no, no.
You're not okay. You have to have a security architecture. You have to have multiple layers of defense, threat and defense, and you have to go implement it.
Just talking about it, talking more about it another six months is not good enough. You have to quickly decide, and then you have to find out which is the tool which works for you in your environment. If it's a private cloud, if it's VCF, Broadcom VCF, then why not look at Broadcom tools, because we are deeply integrated and can provide fantastic security over there, because we take all the advantages of the entire stack over there.
I'm hoping this whole new AI human tribe will finally get the inertia going and our customers going. Otherwise, they are in for a surprise. Because with AI, I like to use the word carpet bombing can happen in parallel.
It's not like you'll go one thing at a time. Okay. Hey, spin up three servers, and let's go in parallel, and let's attack everything.
And sooner or later, something is going to- Something's going to give ... find a vulnerability, get in there, and then move around, and before you know... There are studies which say you can be compromised in no time, in 30 minutes.
And all it used to be six months, nine months. Now it's so fast. Now it's minutes and hours, not days and months.
Yeah. So that's the danger. But now, I think the awareness is at an all-time high.
And that's, I think, the good thing. Hopefully, it'll get the enterprise customers finally moving. Okay, why do I want to do all this extra work and all that?
So they'll have to do that. So that's goodness in some ways. Absolutely.
Like you, I've also been in security now 25 years. Founded a few companies, co-founded. The issue that you brought up, the frontier models and their ability to find more vulnerabilities, more holes, more defects, more bugs than perhaps we've been able to find.
If we had enough people, we could probably find all those vulnerabilities and bugs, too, but we didn't have enough people doing this enough time. Mm-hmm. But with AI, you can do it all the time and at a scale that we haven't been able to match.
And that really is the problem, isn't it, Umesh? Because at the scale we're able to find vulnerabilities, we need the same scale to remediate those vulnerabilities, to defend against those vulnerabilities. Of course, one is remediated.
So everybody should be looking. The customers should be looking at their own workloads, how do they scan it and patch it. Mm-hmm.
The infrastructure and security providers need to do it for us. But at the same time, we can do all this and still be not up to snuff or, otherwise we'll never roll out any product or run anything if we are just- Well, you can't, right? You can't be paralyzed by it.
Yes. So there will be those windows. So you have to get much more disciplined on segmentation, micro-segmentation.
Yes. Okay, you got compromised. God forbid you got compromised someplace.
At least it doesn't spread out, and suddenly you are being ransomwared, and everything's down. Because when that happens, the downtime, people don't understand. First of all, you can get in the press if you are a bigger company.
You have to pay money, and then just the sheer... And then companies do too much analysis paralysis. Because now somebody has to be blamed, something has to happen, and all that.
So the best thing is, don't think about how will I recover if I got compromised. Okay, that is the final thing. I don't want to get compromised.
And if I get compromised, keep it as tiny as possible. Don't let it- Resilience. Resilience ...
be resilient and-So we- Agreed ... I mean, there are new ways, of course, in our product, since we have the full security stack, firewall, distributed firewall, IDS, IPS, NT, and DR, we can do virtual patching. We have a large library of signatures for IDS, IPS, but then we are watching out for the new vulnerabilities, and then we have a team which is going to crank, "Hey, this new heavy-duty vulnerability shows up.
Let's work around the clock at full night, come up with a signature," and then we'll make it available to our customers. Because they will probably can't upgrade their workload products that fast, right? So we'll be able to provide these virtual patching.
I don't want to call it patching of infrastructure. This is what signatures we roll out quickly that the customers can download to protect their workload. So we have all those elements, and of course, we are using AI to speed up all these things.
Right? Let's use AI where it helps. You have to use AI to defend AI.
Yeah. Exactly. So- Umesh, you know a thing about security people, when the going gets tough, we tend to rely back on our old faithfuls.
Yeah. Things like you're describing, defense in depth. Mm-hmm.
Right? Layered security, micro-segmentation, zero trust. Right?
These are the principles we've learned to live by in the face of security. Now, your group has rolled out some specific solutions and ideas, one of which is vDefend. Mm-hmm.
Yes? Yes. And it really helps rolling out zero trust.
Because a lot of people, getting zero trust right's not always so easy. Talk to us a little bit about how vDefend makes zero trust more practical. So, first of all, we have a full security stack, right?
It's just not a firewall. Of course, we have that segmentation, micro-segmentation, and layer seven firewall, layer four fire. That's a given.
That is the foundation. But then, what we've done over the last decade is, we built IDS, IPS, NT, and DR. Because you need all the layers.
Earlier, the firewalling was good enough, or segmentation, micro-segmentation, used to do 70% of the protection. Now, with frontier AI and otherwise AI and getting sophisticated, the more modern attacks, the signature-based thing, the deep packet inspection, that is where that area is evolving very fast. Because earlier it used to be very difficult, now it's not that.
" You need the full stack, and you need an integrated stack. You can't take products with five vendors, tries to stitch it together. Looks very good on a slide.
Security teams, by and large, you find out, "I spend money, now I can't look like an idiot, so I won't say I couldn't put it together" and da, da, da, da, da. But they haven't been able to put it together, most of them. Yes, there are always some groups which have very smart engineers, and they can.
But typically, that's a nightmare to put eight or nine security tools together. They don't talk well together. So we've done the work.
One integrated stack, one solution. We start at the hypervisor level, of course, ESXi. Sure.
Our data plane runs at that level when we crack open the packets. And then we completely plug and play with vSphere. So as you're bringing in workloads, you can configure the policies for the security.
So we work seamlessly. It's not like, send the traffic here, bring the traffic back. We auto-detect, we run at every level, and we auto plumb everything.
So that makes the whole execution very simple. And then we have, the most beautiful thing is we have complete 100% visibility. We can pull from the hypervisor level, right?
Virtual machine to virtual machine or container to container, in, out, whichever direction. And we don't need any Gigamons and any third-party tools to do all that. We have all the data.
We have all the policy from vCenter, VMware, all the products over there. And we can put all this together intelligently and then we can work on it, and the detection, prevention, scoring, and all the steps we can come out with. This is how you'd get zero trust.
And if you leave out any step, we give you a low score, right? Yeah. So this guides the customer.
It's almost game of fight. Yeah. Umesh, I want you to talk DFW1234.
Yes. Explain that to our audience. So, we've had DFW from quite some time, but our customers are challenged.
"Oh, it's brownfield. I can't do it. " And they were all mixed up, because DFW has visibility.
You can do a lot of simple things. " So what we decided is, we said let's come up with a prescriptive model. Let's put it in the product itself, so we'll show everything versus visibility.
We'll give a score. This is what you've done till now. Your score is 12 or 9 or 25, whatever it is.
And here are the reasons why your score is not higher and your attack surface is open, and your blast radius is so big. And we generate the whole report. After that, that'sDFW1.
DFW2 is you have infrastructure services, DNS, LD, LDAP, NTP. Every workload is talking to them. Make sure you're talking the well-known ones and not some masquerading ones, because that's how attacks happen.
So that's step two. We discover, we check off, yes, this is the right one. Or, s**t, I didn't know.
Who has these 50 extra NTP? Who left them on 10 years ago? They're still running.
Turn them off. And then the step three is zoning, which is like macro segmentation, and step four is micro segmentation. And we don't ask hardly any questions in the first two, three steps.
In the micro segmentation, we ask, download a file, which are parts of an application. Truly, truly simplified it. So what people used to take with services people a year to do, we were able to do it for a customer in a matter of a few weeks.
And if I send my top architect, we can do it in three days, right? Because that person knows the ins and out of the thing. And it's in the product, because I want our customers to get the value of our product quickly and not be worried, "Oh, this is very complicated.
" It just guides them. Step, step. And all they have to do is say yes.
And we don't make mistakes because we know the code inside, right? So I think we are getting very good traction with this tool as customers are embracing, get out of the inertia. And I hope the frontier model, all this hue and cry with like, "Okay, I need to do it fast.
" No. Of course, you have to know what you're doing, but then the tool guides you through, and we are here to help our largest customers get that done. And I don't mean to be a henny penny or something, but the fact of the matter is time is of the essence, because this- Yep ...
AI stuff is moving that fast. Very fast. You have three, four, five months.
Exactly. Honestly, I'm not saying if you didn't start now, it's already too late. Too late.
But I'm saying if you don't start really soon, it will be too late. It'll be too late. And that- If you think you're going to do it next year, I think there's- You're done ...
a high probability you're going to get attacked. Yeah. You've got big trouble.
You can't wait till next year for this stuff. Of course, the issue is how do I put this in without impacting performance? Right?
So, I think that's a very good point, right? The classical way of doing security load balancing was a services rack. You move the traffic there.
The appliances don't scale if you do advanced services and all that. So in our case, we are a completely distributed architecture. So we are running at every host level as close to the workload.
So it scales very nicely, and we have paid a lot of attention. Not only the distributed scale-out, but we've optimized the code so that we use the minimal number of cores with very high throughput, and every other year, we are doubling the throughput for the firewall and load balancing. And it's a distributed architecture, so it scales very well.
And then the policy model all is central. Because it's a software-defined architecture, so from one place, you can see everything, manage everything, control everything. It's like almost think of like 1,000 firewalls are running, but you are only going to one console because of the software-defined architecture.
And it's distributed. And when we can, we take advantage of what is available in the X86. Like Intel has a QA chip set for encryption.
We take advantage of that. So we scale really well. It's a simple declarative policy model, totally integrated with VCF when it needs to be integrated.
But we also give the security and the load balancing people that full privilege they want and not get tied with all the elements of compute and storage and everything, right? So they have the independence, and they can really, really scale properly. And we have very, very large customers who are in deployment and no problem.
Love it. Umesh, we only have 15 minutes. We're already way past that.
Okay. I'm sorry. But one last thing.
People hear this, they want to get more information. com, that's a big site. Where exactly should they go to get more information?
So, we have the ANS and the VMware websites where a lot of the links are available. We have been actively publishing a lot of blogs in the recent past. So those have the linkages, and we'll be happy to send you further links.
Yeah, we'll include some of these in the notes on this one. But I think it's important that people are able to go see for themselves and- Yeah ... you know, could- We have YouTube videos, too, that they can watch.
I don't know. Great. In this day's you need that.
That's how people learn today, right? It's a different- Yes ... it's a little bit different.
Umesh, thank you so much for coming here on Techstrong TV. We appreciate it. Keep up the great work.
It's going to be all hands on deck here for a little bit, right? Yes. Absolutely.
And we're going to need all of us doing everything we can, so. But it's a lot of fun. It's not boring.
It's exhilarating, right? Yeah. As I said in the beginning, wasn't on my bingo card, but- Yep ...
I'm glad I'm here for it. Thank you so much, Alan, and- Thank you ... wonderful talking to you today.
All right. Hey, we're going to take a break here on Techstrong TV. We'll be back in just a bit with more.