CrowdStrike and CoreWeave have linked security expertise with specialized cloud infrastructure to build defense that operates at machine speed. The partnership was discussed by Bartley Richardson, chief of AI at CrowdStrike, and Jim Higgins, chief information security officer at CoreWeave, at the Fully Connected event in a broadcast on theCUBE. CrowdStrike's fastest observed eCrime attacker breakout time in 2025 was 27 seconds. For enterprises that train and run models continuously, that interval makes manual response insufficient.

CrowdStrike and CoreWeave pair security data with AI cloud for faster defense

How SafeMind training and joint lab work

CoreWeave supplies training and inference capacity for SafeMind and acts as a design partner for CrowdStrike's Cyber Superintelligence Lab. The arrangement combines CrowdStrike's security data and adversary expertise with CoreWeave's infrastructure capabilities. Richardson and Higgins spoke with theCUBE Research's Dave Vellante and John Furrier about machine-speed defense, infrastructure-level security and operational trust. TheCUBE is a paid media partner for the event, without editorial control by sponsors.

Richardson described the development method as adversarial co-evolution, meaning the team trains offensive capabilities to attack and find ways around defensive operations. Defensive models are then trained on large-scale infrastructure to learn from those attacks. Meeting that cycle requires computing capacity for both training and inference. In his words, humans cannot combat such attacks alone, and machine-speed defense relies on critical infrastructure.

CoreWeave faces a parallel task of strengthening protection while production systems keep running. Higgins called the approach the aikido of the security problem, using the running machine's own energy to advance security needs. That includes using AI to support and scan code and placing automation in the continuous integration and continuous delivery pipeline to fix misconfigurations. Attackers work within budgets and time limits, so several ordinary weaknesses combined can create an opening.

What machine-speed defense means for business

For companies operating AI workloads, the model points to security embedded in training and deployment rather than added afterward. Continuous scanning, automated correction of misconfigurations, and monitoring of the inference layer become part of normal operations. Large organizations with nonstop model pipelines feel the effect first, because a 27-second breakout leaves no room for ticket queues. Smaller firms gain indirectly if such controls arrive as built-in platform functions.

The limits are basic hygiene and trust in automation. Higgins urged patching, repeated testing and continual monitoring, since the easiest route into an environment remains attractive to attackers. Richardson said investment goes into AI that is always on, with trust built into the system, adding that technology counts as AI until it is trusted and then is treated as automation. Buyers should ask how models were trained, what data was used, and how automated fixes are verified.

The marker to watch is progress from the Cyber Superintelligence Lab and SafeMind workloads running on CoreWeave. New details on training scale, detection speed and customer adoption will show whether adversarial training shortens response below attacker breakout times. If joint testing produces documented gains, infrastructure-level security will become a standard criterion in AI cloud selection.