CrowdStrike Pre-Install on Dell PCs Shifts Ransomware Defense to Hardware Budgets
Dell now bundles CrowdStrike Falcon on business PCs and servers via Apex, letting enterprises move EDR spend into infrastructure lines and avoid standalone security purchases.
Dell Ties Ransomware Protection to Hardware Refresh Cycles
Dell expanded its OEM partnership with CrowdStrike so Falcon endpoint protection now ships directly with Dell business PCs and servers, available through Dell's Apex consumption model. Enterprises can now buy ransomware defense bundled with infrastructure on an OPEX basis, shifting security spend out of standalone software budgets and into hardware refresh cycles.
CrowdStrike reported $3.44 billion in ARR as of Q1 FY2026, up 33% year-over-year, with 70% of customers adopting five or more modules. Dell's Infrastructure Solutions Group generated $9.2 billion in revenue last quarter and called security attach rates a key upsell lever on earnings calls. The partnership creates a direct channel conflict with Microsoft Defender for Endpoint (bundled with E3/E5 licenses), SentinelOne, and legacy vendors including Trellix, Trend Micro, Sophos, and Broadcom.
For security buyers, the change matters in procurement, not just protection. Organizations standardizing on Dell can consolidate suppliers and use the pre-install as negotiating leverage against Microsoft or other EDR providers on price and module bundling. For companies still relying on legacy antivirus or native OS controls, the default availability of Falcon on new Dell fleets materially raises baseline protection against ransomware and living-off-the-land attacks without requiring separate procurement approval.
SailPoint Acquires Entro for $200M to Defend Service Accounts
Identity governance vendor SailPoint agreed to acquire Entro, an Israeli startup focused on non-human identity and credential security, for approximately $200 million. Entro discovers and monitors secrets across multicloud and SaaS environments and enforces least-privilege and rotation policies for service accounts, API keys, and application identities.
The acquisition addresses a specific ransomware vector: In 75% of ransomware incidents observed in 2024, attackers used remote access tools and abused credentials for ConnectWise ScreenConnect, TeamViewer, and LogMeIn rather than pure malware payloads, according to Huntress's 2025 Cyber Threat Report. Ransomware operators increasingly pivot through service accounts and API keys for lateral movement and data theft because these identities are over-provisioned, rarely rotated, and poorly monitored.
SailPoint now competes directly with CyberArk, Delinea, and BeyondTrust in privileged access management, and with 1Password (which just acquired Apono for just-in-time access governance for $250–$300 million). For ransomware defense, the deal strengthens SailPoint's pitch against Microsoft Entra, Okta, and Saviynt by extending governance beyond human identities into the service accounts attackers actually abuse.
Enterprises using SailPoint for identity governance can now consolidate secrets management and non-human identity controls into a single platform rather than buying point products or relying on CyberArk alongside SailPoint. The risk reduction is measurable: Organizations that enforce least-privilege and rotation on service accounts close the lateral movement path ransomware gangs depend on after initial access.
Tenet Security Raises $6M to Stop AI Agents from Data Exfiltration
Tenet Security emerged from stealth with a $6 million seed round led by Cota Capital, with participation from Felicis and Secure Octane. Tenet positions itself as a runtime control for AI agents and automations, detecting and stopping dangerous agentic behavior in real time—specifically preventing AI and automation from exfiltrating sensitive data or invoking dangerous actions that could lead to ransomware-like outcomes.
The company is pre-revenue but addresses a gap in ransomware defense as attackers increasingly automate discovery, lateral movement, and exfiltration using scripts and AI-assisted tooling. Tenet competes indirectly with HiddenLayer, Prompt Security, Protect AI, and Cranium AI on model and pipeline security, and with Symmetry Systems, Veza, and SailPoint on data access governance.
For security leaders piloting GenAI-driven workflows, the funding signals a new budget requirement: Controls that can halt high-risk automated actions in real time are becoming part of ransomware defense strategy rather than generic AI safety. Enterprises may need to carve out new budget lines for AI-specific runtime controls, potentially repurposing spend from legacy data loss prevention tools or insufficient robotic process automation governance.
The round also signals that AI-centric ransomware defenses—such as detecting abnormal automated access to file shares and backup systems—are becoming an investable niche. Expect incumbents in EDR, XDR, and identity security to respond with acquisitions or similar features within 12 to 18 months.
What to Watch
The CrowdStrike-Dell partnership sets a precedent for OEM-bundled security that bypasses standalone software procurement. If HP and Lenovo expand similar integrations with SentinelOne or Microsoft, the standalone EDR market will face margin pressure and consolidation. The SailPoint-Entro deal indicates that non-human identity is no longer a niche concern but a core ransomware control, meaning enterprises should audit service account privileges and rotation policies now rather than after the next breach. Tenet's emergence suggests that AI-driven automation is creating new attack paths faster than legacy controls can address them—organizations deploying GenAI workflows without runtime guardrails are expanding their ransomware exposure, not just their AI risk.
Technology decisions, clearly explained.
Weekly analysis of the tools, platforms, and strategies that matter to B2B technology buyers. No fluff, no vendor spin.
