
Sameer Shah, Cyber Security Portfolio Marketing at Dell Technologies, and Justin Vogt, Field CTO, Dell Trusted Workspace and Ransomware Resilience, dig into what it really takes to put AI to work during an active incident. They start with a challenge many defenders hit at the worst possible moment: cloud-hosted AI models often refuse to analyze malicious forensic data, like keystrokes or payloads, right when you need those answers most. Sameer and Justin offer a practical path forward: run open-weight, locally hosted models on sovereign infrastructure so you can set your own boundaries, bypass restrictive guardrails, and keep your most sensitive data in-house. They bring it to life with real-world examples, including Dell GB10 systems built for mobile incident response "go bags" and GB300 systems for frontier-level analysis, deployed together in a hub-and-spoke model for local pre-processing and deep investigation. The key takeaway is clear: decide before a crisis where your vetted incident response AI will run, what data it can touch, and how you’ll control it, rather than scrambling to stand up infrastructure under pressure.
For more information, please visit Dell.com/CyberSecurityMonth
00:00 Introduction
00:10 Rogue AI and Incident Response Strategy
00:31 Why Hosted Models Fall Short
01:55 Sovereign AI and Data Privacy
03:03 Controlling Your Own Guardrails
04:00 Dell Deployment Models for AI Response
05:19 Pre-Incident Playbook Planning
05:48 Closing Thoughts and Resources











