Dell Technologies Security Strategy Overview
This session will cover Dell’s overall strategy for cybersecurity including reducing the attack surface, detecting and respond to cyber threats, and recovering from a cyberattack.
In this presentation at Security Field Day 13, Dell Technologies provided a comprehensive overview of their cybersecurity strategy, emphasizing the concept of “advanced cybersecurity maturity.” The speakers explained that Dell aims to help customers progress in their cybersecurity posture by embedding security from the ground up—starting with the supply chain and extending through endpoints, infrastructure, and services. With the rise of AI, the attack surface has expanded, and bad actors have gained access to more sophisticated tools. In response, Dell focuses on three strategic pillars: reducing the attack surface, detecting and responding to threats, and ensuring rapid recovery. Their approach includes building secure hardware (claiming the most secure commercial and AI PCs), utilizing industry-vetted security partnerships, and providing services that align with the Zero Trust model.
Dell’s reduction of the attack surface involves enforcing strong cyber hygiene, emphasizing practices such as regular patching, encryption, multi-factor authentication, and network segmentation. The company views cybersecurity as not only technological but procedural, with detection strategies that incorporate AI/ML-enhanced XDR tools and, where possible, managed detection and response (MDR) services. Their hardware is designed with security baked in, including features like firmware verification and behavioral detection at the BIOS level. They also stress the importance of monitoring, both with built-in capabilities and via partner integrations. Dell aims to give customers not only preventative tools but also detection systems that assume eventual breach, shifting focus toward resilience.
Recovery, as Dell sees it, is the ultimate goal and involves both technology and process readiness. Their solutions include air-gapped cyber vaults and services that support incident response planning, communications, and business continuity. For Zero Trust, Dell supports two paths: an incremental uplift approach for customers with existing investments, and Fort Zero, a pre-certified private cloud solution aligned with the U.S. Department of Defense’s Zero Trust architecture. Fort Zero integrates hardware and software from vetted partners and is delivered as a turnkey system. Dell also supports brownfield environments through consulting services and maturity-based architecture planning. Overall, the presentation framed cybersecurity not as a static goal but as a continual process of improvement, which is rooted in practical frameworks, backed by technology, and supported by Dell’s ecosystem of services and partners.
Presented by Steve Kenniston, Portfolio Marketing Cybersecurity, Sameer Shah, Cybersecurity Consultant, and Adam Miller, Marketing Lead. Recorded live at Security Field Day 13 in Santa Clara, CA on May 29, 2025. Watch the entire presentation at https://techfieldday.com/appearance/dell-technologies-presents-at-security-field-day-13/ or visit https://techfieldday.com/event/xfd13/ or https://www.dell.com/en-us/lp/dt/security-solutions for more information.
Transcript
My name's Steve Kenton. I lead the, uh, the portfolio security practice at Dell. Um, this year we've, uh, or this e this episode, I guess we've decided to bring it to you a little bit differently.
Last year, I, we talk a little bit about how Dell's the largest security company you've never heard of, right? Um, but it's becoming more and more important. A lot of the analysts we talked to, we just got done our, our Dell technology world.
And even more of those folks are talking about how, you know, you never would've thought that your server was a security tool, but it actually is these days, right? And we're gonna go into a, into a lot of that. Um, this, this, uh, session, we wanted to break up a little bit, do it a little bit differently than we did last time.
Last time we talked about our three practice areas, which Samir is gonna get into, and then kind of what those are. I think you guys kind of get that right, and you gave us some great feedback last time. This, this session.
Um, Samir's gonna open it up and talk about how we think about security, but then we're gonna kind of talk about how each one of our portfolio organizations, so endpoint infrastructure and AI, kind of manifests those things that, how we feel and think about security. So with that, I'll be back to do the infrastructure piece, but I'm gonna turn it over to Samir who's gonna talk about the holistic, uh, strategy. And we'll go from there.
Great. Thanks Steve. I appreciate that intro.
So, as Steve, my role in this presentation is to set the strategic framework and talk about how we look at cybersecurity. And so I'll talk a little bit about products and services, but that's really something that the rest of the presenters will go into in more detail. So, um, this is a bit of an overview.
So, uh, stay tuned and never fear. We will be getting into much more detail about our products, services, and differentiators as we go on, uh, throughout the two hours. Uh, first and foremost, how we think about cybersecurity is summarized in this phrase, advanced cybersecurity maturity.
And what we mean by that is that we know that all organizations are on some path to cybersecurity. Um, it's not, certainly not a new topic, the threats are real, but based on the data and research that we see from what we do, in addition to, uh, what we see in the general marketplace, indicates that there are still significant gaps in the key areas. And so our job at Dell is to try to help our customers grow incrementally and take steps forward to improve their cybersecurity and try to achieve maturity relevant relative to that posture as well as achieving resilience, which I'll speak to in just a moment.
So, first and foremost, just to set the stage on, uh, where we are today with the cybersecurity landscape. I think it's no surprise to anyone, and we all know that the threat landscape is rapidly evolving. We have organizations adopting ai, uh, with rapid rate, um, and security is not always at the table in those early discussions and early implementations.
So that's a huge, uh, increase in the surface area or attack surface for cybersecurity. Now, at the same time, cybersecurity, or excuse me, AI is also creating tools that the bad actors are able to use. And we're seeing a democratization of cybersecurity where you can go online and buy a phishing pit for just a few dollars, and with very little IT knowledge, you can launch attacks.
So these are just a couple of the things we, we talk about, but the, the key point is that the attack landscape continues to evolve and organizations have to stay ahead of that. So what do you need? What does that require to be able to meet those challenges?
We believe that that is a partner that offers three key things. And the first is building in security from silicon to supply chain, as we say. So from the moment of manufacturer to the, to the time that the product is delivered, very strong security along with built-in security features in that hardware.
And we're gonna see a lot of detail about that. Secondly, security is a team sport, and that's a key theme that we're going to discuss throughout the day. And as a part of that, a strong partner needs to manage and implement and offer a d diverse eco scheme, ecosystem of partners that can address and augment capabilities that one provider, uh, can never, you know, address in entirety.
And then finally, services and guidance and support is kind of the third leg of that, uh, stool that is required to be able to provide, um, sec cybersecurity that meets the requirements and the needs of this ever evolving landscape. So, uh, we're going to illustrate as we go throughout the day of how we play a role in each of those areas in detail. But I'll start by talking a little bit about hardware.
And so if we start with our endpoints, our PCs, we have the legally vetted claim of saying that we have the most secure commercial PCs, as well as the most secure AI PCs. And those are actually two distinct claims that have been validated in the market and, um, by our legal team. And it's something that we can say, and that is the direct result of the built-in security features along with the partners that augment that.
So if you take our PCs, for example, um, they've got significant security from the supply chain to, uh, safe bios to, uh, protections around ensuring the components are exactly as they were designed in the machine. And then that's augmented potentially by services or software from absolute potentially, um, MDR from, uh, Dell, but including the CrowdStrike XDR capability. So it's a good illustration and all of that together, together we call Dell trusted work space.
Now, on the infrastructure side, servers and storage, uh, same concepts. So we have very strong built-in security features. We have zero trust enabling capabilities.
An example of that is a common MFA platform so that, uh, you don't have to implement different multifactor authentication on a server versus a storage device. And then, as you can see, there's a few names here of partners that are involved to augment that offering. Again, no one part, no one company can do it all by themselves.
So we have to ensure that partners, uh, are incorporated. So, Samir, Yes, Uh, thanks, uh, Jack Poller with Paradigm Technica. When you talk about, excuse me, and say world's most secure in commercial IPCs, and I know you say this was vetted by your legal team, what are you, when you say most secure, what is, how is it measured?
Like, what are your definitions of most secure? So I'm gonna, I'm gonna hand that to Justin to answer in more detail, but what I will say is that there's a checklist of 10 key capabilities that we measure ourselves against the major other manufacturers, and we're able to tick more of those boxes. And Justin, I think you might be able to shed light on kind of the specifics there.
Uh, yeah, specifically it would be our alignment to the full NIST cybersecurity framework, uh, in our implementation around PC security. So, um, rather than taking an approach that's, let's say like highly proprietary and like prevention based or taking an approach that is, um, maybe not necessarily interconnected between supply chain hardware and software, what we've done is we've built out controls of, uh, prevention, detection, response and recovery, uh, through the pc, and then integrated that through ecosystems of software partners that we've vetted and validated, uh, who also have like significant market share. So for example, uh, I'll speak more on this later, but to give you a tactical example, Dell's implemented, um, uh, firmware, uh, signing for, uh, bios updates and, uh, EFI drivers, uh, using our trusted certificate and Dell's embedded controller.
And theoretically, that should be all that you need, which means if we didn't write it, it can't run. But we've also gone forward and implemented, uh, behavioral detection and response of what is happening at the firmware level, as well as off host firmware verification. So you're not having to trust that preventative control of that cryptographic signing.
You've got some measure of validation that you can do as a client and a customer after assuming that that preventative control has failed. So that's kind of an example of, um, where we root this claim is, uh, building in, uh, not just, um, sound controls to manage risk in the technology, but providing you the data and the platforms that you're already using so that you can validate those for yourself and then detect when they fail. Okay.
And then the last piece are the services that I mentioned that wrap around these products. And ultimately all, all of what we're talking about, and I'm gonna get into this in more detail on the next couple of slides, but we break this down into three key areas, reducing the attack surface, detecting and responding to cyber threats, and then recovering from, uh, a cyber attack. So all of these are designed to progress along that goal, uh, around those goals.
And the services run the gamut from, um, advisory and consultative all the way to implementation and even, uh, recovering from cyber attacks. So before I get into the key three key areas, I want to talk about the distinction between security and resilience. Resilience is, in my view, the ultimate goal, but it requires security, very strong security and advanced posture to achieve resilience.
So security is everything we do to prevent an attack from occurring, to be able to detect it as quickly as possible and neutralize it, um, as quickly as possible. Then resilience is where we develop the toughness to know and the confidence to know that if an attack does occur, we can get through it, we can maintain performance to our SLAs, uh, we can operate as a minimum viable company, which is a concept we'll discuss in a minute. Uh, but that's really the true goal of security, is to achieve resilience.
And as we can see here in this middle circle, those are all the positive benefits that we achieve as we approach resilience. And really, the key point of all this is not to achieve strong cybersecurity or resilience as a goal in and of itself, but it's a foundation to be able to execute the core mission of the organization, which rarely, uh, is related to cybersecurity. So we want to help you build a better widget by knowing that all of the factors that go into that and the time and energy going into cybersecurity is manageable to free you to focus on, uh, building those better widgets.
Let's talk about our supply chain. This is an area of, of tremendous pride for Dell. It may be an area that doesn't get as much fanfare as it should, but we have one of the strongest, if not arguably, the strongest supply chain in the industry.
Not only do we work on perfecting our supply chain, but we also are involved in the industry organizations that define best practices in supply chain. So we're very much thought leaders in the supply chain arena. Now, without draining all the details of this slide, um, it really begins on the security side with things as simple as strong physical security around manufacturing sites.
Um, you know, video cameras, drug testing, personnel reviews, um, secure development lifecycle is something that's important. And when we talk about supply chain, we should understand that that's both hardware and software. So the secure development lifecycle ensures that from the design of products to the design of the software that runs those products, we have security and those processes have not been compromised.
So even processes around uploading code, um, are very secure. And we've seen in recent, uh, times with, uh, that vulnerability that the Microsoft developer found last year in open source code process, that these are very real, uh, risk points. Now, in addition, we ensure that we are holding suppliers accountable, uh, vetting when they first come on board, but then continual review to ensure that, uh, they're performing as needed.
And so it's almost like a never trust, always verify situation with our, uh, suppliers. From a quality, uh, standpoint, I'll, I'll address or, or kind of highlight one area, which is our security component verification. And that's where when we are building a product, all of the components that go into that product are inventory and then put into an encrypted, uh, file that's burned into that piece of hardware.
When the product shows up, the customer can then compare that to a secure validation, uh, software that they have to ensure that the exact inventory that was intended to go in is what has shown up, uh, at their door. And then of course, the more routine things like tracking freight, tamper resistant packaging, uh, there's a wide variety of options that customers can select depending upon their need. From a resilience standpoint.
On the technology side, silicon reader of trust, we burn the, uh, validation keys into the hardware so that when the system starts up, the bios is checked against that burned in key, um, that does make that key immutable by burning it in. And so we ensure that the bios is correct upon the start of the machine. And then from a non-technology standpoint, uh, supplier redundancy.
So no one or no, uh, group of suppliers can interrupt our production flow. Uh, simply, you know, on their own, we have plenty of redundancy built in to the supply chain. So if we are looking at now how do we actually bring this advanced cybersecurity maturity to life?
How do we address it with customers? And what areas, how do we divide kind of the, the focus points into key areas? We start with reducing the attack surface, and that is the most initial and fundamental step in prevention.
And the goal of that is to harden the organization as much as possible, minimize vulnerabilities, uh, make it as difficult as possible for an attack to get through. Then we look at detection and response, which is identifying potential threats as quickly as possible. Quarantining neutralizing them as quickly as possible and ensuring that they don't, uh, spread.
So I look at the first two of those, reduce and detect as being preventative in nature. Recovery is the third piece, and that's what is helping us move toward resilience, which is the ability here to recover as quickly as possible with minimal disruption to the organization, minimal financial risk, reputational damage, customer impact, um, et cetera. And as we'll see in a minute, recovery requires both strong technology component and a strong people and process component as well.
So, to talk a little bit more specifically about reducing the attack surface, much of reducing the attack surface focuses on developing good cyber hygiene practices. Um, our ciso, Adele likes to say that we should, it's better for organization to do 10 things really well in security than try to do a mediocre job at 60 things. And so we find that aligning to zero trust principles, implementing multifactor authentication, taking a never trust, always verify mindset, advances this goal of reducing the attack surface tremendously.
Um, it can also, cyber hygiene is also simple, yet difficult things like, um, ensuring regular patch management. So, uh, we've seen with hacks like WannaCry, what the impact can be, um, of being laid on a patch even by a couple of weeks. So it's, it's imperative that organizations do this.
Um, but it's difficult with everything, uh, going on with the, you know, billion security alerts taking place every day. And so many things that the security team is working on. Something as simple as regular patch management, uh, can fall through the cracks.
There's a sheer huge number of patches as well. Um, the supply chain plays an important role. Um, and I'm going backwards here a little bit on purpose, but it all begins with understanding where we are relative to the attack surface.
So the first step is evaluating, um, and assessing what the attack surface for that particular organization looks like. And that can be helpful, along with penetration testing and vulnerability, uh, management. And then finally, encryption, network segmentation, um, and air gapping.
These are all designed to prevent attacks from moving laterally and expanding through the organization. So again, reducing the, uh, attack surface. Moving on to detection, um, I think the cornerstone of our detection recommendation is implementing strong XDR and when possible MDR, which is adding a human element of oversight to what the software is doing.
Um, in the past, it was important to note that AI and ML should be incorporated into the XDR to intelligently scan the environment and know, uh, what normal behavior is versus abnormal behavior. But these days, uh, most if not all XDR capabilities do provide that. So it's, um, something we mentioned, but not, uh, not necessarily, um, earth shattering at this stage.
Now we do offer XDR from three, uh, partners, CrowdStrike, SecureWorks, and Microsoft. And then we can layer on top of that the human to, um, oversee and escalate and address issues should they, should they arise. So, um, monitoring also, we've got features built into our PCs and other hardware that can help and assist with the monitoring.
So I will not belabor that too far as I know the rest of the team, uh, will cover it. When it comes to recovering from an attack, there are really two pieces to this in my view. One is developing a strong incident response and recovery plan that's comprehensive.
This is more of the non-technology piece, so it's understanding who does what recovery runbooks, um, how this is going to, uh, impact the entirety of the organization because it will impact everyone from HR to CFO to customer service, et cetera. But it's also things like ensuring that we have communication templates, both externally and internally. Organizations are under a lot of pressure now to be transparent and report attacks, uh, within usually a couple of business days, sometimes even sooner.
So those last thing you wanna be doing is fumbling around figuring out that communication in the midst of an attack. So from the technology side, um, it's all about building an air gap cyber vault, and that's something that we do provide that Dell provides in a variety of ways on premise in the cloud. And it's something that we have deployed for a number of customers and have strong customer stories of recovery, but that recovery capability allows the organization to, uh, get back to find, you know, pull back good data and get back to operations, um, as quickly as possible.
So I won't belabor this too much in the interest of time, but, um, as we are moving along this path and implementing even some of the things that I've talked about, we see the threat funnel shrinking, less, getting in, and, uh, less impactful, um, even though things will get in, because we do have to operate with the mindset that an attack is imminent, uh, in spite of all the good work that we're doing with reduce and detect moving on to Zero trust. Um, this is an area that, uh, was a buzzword at one time, but now is an important operational layer to, um, any mature cybersecurity platform. So the first thing to understand here is that we want to shift the focus, uh, to identity and to a mindset of, uh, least privilege access.
Never trust, always verify. We believe that just by focusing on strong identity management, organizations can yield strong, um, incremental progress towards their cybersecurity goals. Um, and at the same time, aligning with zero trust principles is identity really is kind of the foundation in many ways when it comes to implementation.
We offer two paths. Uh, one is incremental uplift, where we're taking the existing environment, prioritizing workloads, and moving them into compliance with whatever zero trust activities are most relevant for that attack surface or that organization's need. And we have, we'll see how our hardware is designed to facilitate such an incremental uplift.
We also have an innovative project called Project Board Zero, uh, where we have a zero trust blueprint in a private cloud that directly aligns to the US Department of Defense, uh, zero Trust Blueprint. We're the only organization in the, uh, industry that is going to provide this. It's in the process of being productized, and when it's ready, you can essentially order this private cloud and have it delivered.
Um, and you'll have a, a, a strong zero trust compliant environment on day one, eliminating the need for prioritization and implementation and, uh, the road roadmap. Samir? Yeah.
Are these are, uh, I got confused here. These are all your recommendations for customers using Dell? Is that what we're going through here?
These are, so the first is the identity is basically just, um, understanding the importance of identity. But when it comes to the other two on the right uplift and private cloud, these are two mechanisms by which we can help customers align closer to, uh, zero trust architecture. All right.
Fernando, you from, I, I, I, I want to, uh, pick up a little bit just on, on what, um, I want that from a positioning perspective. I, I think I, to what extent can you clarify what is your opinion about where Zero Trust needs to be and, and where it fits versus what the implementation mechanisms are that you're offering, whether it is product oriented or services oriented? I think that, I'm not sure, Jack, I don't mean to speak to you.
No, absolutely. But it's, but it's kind of, kind of, uh, uh, clarifying that a little bit. How much of this is, is your opinion about where things fit, how much of this is, here's what we are offering to our customers?
Yeah, let me, um, let me hand that to Justin. I think he's got a thought there, um, thought process that I think will illuminate that. Yeah.
Um, I, so when we're engaging with clients, generally, the first step is to understand, um, a baseline of what they believe, zero trust to be. Mm-hmm. Uh, Dell's official alignment is around the Department of Defense's frameworks, and they're about 153 or so concepts.
Uh, but how we approach clients depends on the client that we're helping. So, like, for example, um, tactically the, uh, private cloud capability, um, what that is, is a solution that we refer to as Fort Zero, which is, um, Dell's gear free, integrated with a number of different, uh, solution providers and pre-configured where essentially a country or a specific Dell partner or a specific company can come to us and say, I need a data center that's gonna be implemented and aligned to these principles as defined by the Department of Defense. Uh, and we're able to produce that, uh, using basically a single bill of materials where everything is, uh, designed and implemented and, and just sort of works.
Now, the flip side of that is there are very few Greenfield implementations. So for our Brownfield customers, uh, how that generally manifests is around our services and consulting capabilities alongside our, uh, network and ecosystem of pre-vetted partners. So, like for example, um, if a client has adopted a large portion of, uh, the, uh, Microsoft Fabric, we have specific service capabilities and offerings around implementing zero trust in the context of Microsoft, if they've not settled on a specific fabric, um, we have capabilities, for example, around designing and implementing solutions, uh, that will combine and extend the capabilities of, uh, Okta, Zscaler, and CrowdStrike, and then integrate those with Dell PCs and, and Dell servers.
So hopefully that answers your question, which is tactically, uh, you know, Dell, first of all, we have to align to the customer's understanding, and we do educate them as far as, if you go to our chief Technology officer, uh, John Rose, what he'll tell you is our official alignment is to the Department of Defense's definition and framework. And then within that, we have basically two paths for a customer. We have a Greenfield path where we've done all the heavy work, heavy lifting, and had everything pre-built for you, and it's also pre validated by the Department of Defense.
So they've certified that implementation. If you're a Brownfield customer, that can be a little bit more nuanced because it typically starts out with some sort of assessment with an As is to be deliverable to create a roadmap. And then from there, uh, we start taking you down that roadmap rotating either around, uh, intra and Microsoft's interpretation of Zero Trust, or, uh, something a little bit more agnostic, leveraging, uh, capabilities from some of the partners that I mentioned previously, like Okta, Zscaler, uh, CrowdStrike, and what have you.
Uh, perfect. This is, uh, one follow up, if I may. Uh, is the scope of that, uh, services engagement is, is the scope of, uh, I, I love the name, by the way, the four zero.
I love that. Uh, um, is the scope of that, uh, within a particular customer subsystem a particular customer environment, or is it a wholesale transformation for a customer, uh, entire IT estate? Like, how, how do you find, uh, how do you define what the scope like, or what did you build it for in terms of what did you think the scope is for customers deploying this?
Um, so, so I have my answer to that, but, um, we have Arun who is part of the organization that actually built it. Um, so Arun, if you'd like to address that, I'd be happy to hand this over to you. No, thanks Justin.
So, great question. Uh, Justin, you actually hit really clear articulation on Brownfield versus Greenfield. I'll just add one more data point.
Uh, most of the time Brownfield comes up because our customers have made heavy investments on technology, right? They, they have an endpoint technology, they have networking technology, they have all kinds of technology, and really they're looking to leverage those existing investments. So it's really a tweak in architecture.
In many cases, it's consolidation. And I will tell you, there's not one C CSO that's come to us and say, give me zero trust. Zero trust is not a thing.
It is an architectural principle outside of DOD, right? At DOD, the definition is very precise, but outside of do OD and commercial Zero trust is really a maturity conversation, architecture conversation. Um, so, so we focus on, on those aspects.
The second question you asked is, what is the scope? It's the full stack. It is network, it's identity, it's applications, it's infrastructure, because everything has to participate in the zero trust policy management, right?
So if we have a uniform policy, uh, that policy has to apply to infrastructure, uh, where are users coming from? What are they accessing? What, what, uh, what RAs exist to give them access.
How do I do just in time access and not give everybody carte blanche? So it applies to the full staff. Thank you.
Hey, hey, everyone, just to kind of touch on, kind of extend thought on, I would say I, I think zero trust is more of a, a policy and a procedure than a technology, right? Because I think that's where a lot of this breaks down. But I wanna ask you specifically, you talked a lot about, we've heard a lot about the, the, the specific technology, but most oftentimes when we talked to most organizations, I would say 75% don't have the maturity to actually support this in day two and beyond.
How does your team address that? What, what things are you putting in place and what's your methodology look like for those organizations that want that zero trust, uh, outcome or lack the resources or the maturity to actually deliver on those outcomes for the business? Justin, you wanna take it?
Uh, yeah. So, uh, typically when we're working with clients who I, and I agree with you by the way. Um, to me, zero trust is like exercise.
It's something that you can never really complete. Like I have never achieved enough exercise in my lifetime. It's, it's like good self, good health.
Um, typically what we do when we're engaging with clients, usually clients will have a very specific tactical need, um, about a specific project or capability. Now, we'll evangelize and, uh, advocate for transformation, but ultimately we need to serve that client. And so what we do is we work on fulfilling that tactical need, uh, in a way that gives them the foundations to start maturing into a zero trust posture.
Um, so, you know, I'll take a, a very kind of specific example with like our servers and our client, our servers and our client have the ability to not just trust, uh, the Dell code that booted the operating system and any of the security tools on that compute device, but we have the ability to then, uh, do a continuous audit and attestation of that. And we have the ability to help a customer tie those into their identity sources and their network posture, uh, management controls, so that a customer can come to me with a very simple need, which is, I need a computer, or I need a server. And then I can step back and say, well, hey, um, the security architecture and Viewpoint has, uh, rotated to this position of, um, assuming breach or, um, uh, integrating identity, uh, network, uh, and apps to lease privilege, whatever you want to call it, in a simple way.
Uh, and here's how Dell is positioning you to solve that very specific tactical need while giving you a foundation that you can build upon as you start to mature. Another basic example might be a question as simple as, uh, what sort of endpoint protection can I use? And so rather than offering up a client, uh, uh, a point solution, uh, we've pre-validated and vetted our opinions on endpoint security solutions that have the ability to expand and incorporate, um, things like, uh, integrations with your network, control of choice or your identity, uh, management plan of choice.
So hopefully that answers your question, which is, um, ultimately we need to serve the customer. And I agree with you that, uh, not every customer is ready for, uh, a transformative experience. And that's fine because we've built our strategy, almost like the Lego block system, where we can help with a very tactical need and give them a way to strategically on ramp into that posture.
Justin, it's Karen Lopez from Info Advisors. Uh, my question to you is, what are you bringing? So it sounds like you're bringing professional services, experience consultancy.
What are there frameworks, templates, project management stuff, architecture tools? Like what are we talking about here? Yeah, um, so at a very high level, I'd say there's three things we're bringing, um, which, again, zero trust is a, a very broad concept.
So to get the official answer, I would probably recommend that you engage with our chief Technology Officer, John Rose. Uh, but at a very high level, the first piece that we're bringing is the infrastructure, right? What your infrastructure is, is made out of, and, uh, the components that go into it, the hardware bill of materials, supply chain, um, the software bill of materials, that's, that's one aspect of what we do, which is, if you wanted to do this, we're gonna help you do it.
And at the very least, we're not gonna inhibit you from doing it. We're not gonna be a barrier. So that's step one, is you can take our technology and build on this principle, and we're going to help it along, or at least stay out of the way.
Um, the next option, like I said, is for a Brownfield customer, it's largely services driven. It's largely consulting driven because you are creating an outcome. And a lot of times you're having to not just incorporate the way, the, the way you think the world should look, but the realities of their environment and their business processes.
And so it's a little bit like splinting a a broken leg. You need to set that bone kind of over time, uh, in order to, to heal the patient. Um, and then finally, that third capability, which is more productized and a little bit more tactical, is in cases where a customer needs a Greenfield implementation.
So they have nothing. It's a net new data center, uh, net new organization, um, whatever the use case is. Uh, and that's the, uh, Fort Zero solution, which, like I said, is a, uh, basically a, a hardware product that is multiple Dell products pre-integrated with, um, capabilities from, uh, software ISVs and Dell Partners, pre-integrated and pre-configured, and then tested and certified by the Department of Defense, uh, to provide basically a, a single part number on a bill of materials, uh, to implement this outcome.
So again, to take that back, what what we're providing is really three things. One is the building blocks for a customer to consume from us and then implement, uh, zero trust out of our building blocks. Uh, two is our services capabilities for the acknowledgement that customers might have some of our blocks, but they might have someone else's.
And then three is for that customer that, uh, needs to go from zero to hero. It's that Fort Zero implementation, uh, which is that private cloud, uh, built on our technology, uh, but then pre-integrated with, uh, technology from our partners, and then certified by the Department of Defense. Does that help?
Yes, it does. Thank you. Hi, Eric.
Just speaking, uh, just a question. When you say that these pre configurable, pre uh, integrated, you mean that all the technologies technology partner you mentioned, you mentioned such as CrowdStrike and netscope, are already configured to work together? So to reduce the, the day one activities?
Yes. The, uh, storage, compute, networking applications and security stack are, uh, included in the single B bill of materials, uh, as well as, uh, are, uh, pre-configured for the client. So they essentially order one part number from Dell, uh, and they get a cloud deployment with the security controls for that cloud deployment.
So again, it's a private cloud, so they get the, the hardware and the software, uh, all knitted together. And that architecture has been put through the certification process and achieved that, uh, from the US Department of Defense in alignment with their, uh, framework. Now as to the specific partners, uh, within that, um, we would, uh, I, I don't have that list in front of me.
It's, it's quite substantial. Uh, for example, I know there's, uh, some capabilities around network micro segmentation. Um, there's, uh, partners around network security, endpoint security, um, identity, uh, and secrets management.
Um, and that's also something that is part of our maintenance of this solution where what was certified, uh, previously, uh, about a, I believe a month or so ago, uh, that was, uh, rev one and we're already expanding, uh, and working on the certification process for rep two. Just picking up on that a little bit, like the, the, the, the, the challenge that the, help me understand the certification step a little bit better. Is it that the ar the architecture of four zero is certified, or is it that an implementation for a customer that has gone ahead with four zero if that is certified?
And, and if that's the case, how are you handling the, the changing nature of the software stack at, at, at each of your partners? Like, help me understand the certification step a little bit better. Does that make, does the question make sense?
It, it does. Okay, thank you. Um, where, where I would lean on that is the architecture and the implementation is largely static.
So that's what's been certified. Um, and the assumption is, you know, we're handing it over to a client who will then operate and maintain that within best practice. The flip side of that is, if a client had doubts of their ability to do that, what I would generally do is I would take that, uh, architecture or that baseline, and then I would incorporate or build out, uh, my services components to provide, you know, human beings, uh, to be able to manage and implement that for a customer.
So that's fully within the scope of Dell's four walls, which is, I've got this baseline and I'm gonna deploy this baseline in a way that has achieved and been validated by this external certification. Uh, and if you doubt your ability to maintain that baseline, I also have, uh, the team of individuals who will continue to drive and manage that baseline over time for you.