Executive Guide | Securing the AI Data Center & AI Factory | Check Point Software
Executive Guide
Securing the AI Data Center & AI Factory
Executive Summary
The enterprise adoption of private AI and LLM (Large Language Model) infrastructures introduces a new breed of risks. Unlike traditional IT workloads, AI factories and data centers manage sensitive training data, powerful GPU clusters, distributed inference services, and high-throughput pipelines. This new and much broader attack surface increases threats to data, intellectual property, proprietary AI models, and end-users. Another segment building their own AI factories are Neocloud providers, who deliver GPU-as-a-Service, building hyperscale AI factories powered by NVIDIA and other leading GPU platforms to give enterprises on-demand, high-performance compute for training and inference. Deploying AI capabilities and private LLMs (Large Language Models) without embedding additional security increases exposure to poisoning, data leakage, and governance failures. To ensure system resilience, AI data centers must be secured end-to-end — from the fabric and GPU clusters to Kubernetes workloads, along with API-driven inference workloads and services. Check Point enables organizations to confidently adopt and scale AI by addressing both traditional IT threats and new vulnerabilities introduced by AI-driven environments. Check Point delivers embedded cyber security by design to cover all sensitive blocks of AI data centers and private LLMs.
An AI Arms Race
The race to build AI is accelerating. Enterprises are investing billions in AI factories that power the creation and development of AI capabilities. More than half of enterprise networks now use AI tools, making them prime targets for cyber attacks. Check Point data shows that 1 in every 80 GenAI prompts exposes sensitive data. Meanwhile, a recent Gartner report found that 32% of organizations experienced an AI attack involving prompt manipulation, and 29% faced attacks on their GenAI infrastructure in the past year. While AI provides amazing productivity benefits, AI systems face unprecedented security challenges. Protecting the entire AI pipeline, from development to production, has become an urgent imperative. As organizations scale their AI infrastructure, they need comprehensive security solutions that won’t come at the cost of AI server performance.
AI Cyber Security Threats and Risks
AI security risks are compounded by the huge investment costs required by AI infrastructure and AI applications, which in turn amplifies and accelerates the threat landscape. The pace of change in attackers’ capabilities is reflected by industry establishments, such as OWASP, who recently published the Top 10 LLM threats. The list includes prompt injections, data leakage, model manipulation, and insecure outputs, along with previously unknown attack vectors that target the core behavior of modern AI applications and can cause incalculable business disruption. Others such as MITRE, and their ATLAS framework, further expand our understanding of this evolving landscape. It maps new real-world adversarial techniques against AI models and infrastructure, revealing how attackers exploit weaknesses across data pipelines, training processes, inference workflows, and GPU-driven environments.
The new AI threat landscape includes the following risks and attack methods:
- Prompt injection and jailbreaks: Manipulative inputs that bypass controls or trigger unintended behavior
- Model poisoning: Corrupted training data that degrades accuracy or embeds backdoors
- Data leakage: Model prompt responses reveal confidential or regulated information
- AI-driven cyber threats: AI infrastructure faces emerging threats like data poisoning, model theft, inference attacks, and AI-specific exploits that can manipulate the training process and output of models.
- Open ecosystems: AI developers pull code, containers, and models from public repositories. This open environment creates additional risks like model poisoning, data exfiltration, and malicious workloads hiding in downloaded models.
- Significant business losses: Training LLMs can involve processing massive volumes of sensitive data. One breach can wipe out investments and compromise intellectual property.
- AI Supply Chain failures: Private LLM models and AI systems introduce a hyperconnected environment, and therefore, a much broader threat surface than traditional IT data centers.
- AI applications require maximum GPU resources: AI workloads and language models can require AI Servers to run at maximum capacity for weeks or months. Every percentage point of CPU usage and microsecond of latency multiplies costs exponentially. Enterprises need security measures that do not impact AI performance.
- Compromised developers: whether through insider threat, credential theft, or coercion, a compromised user with privileged access represents a significant threat to AI factories and data centers.
Strategic Approach for Building Secure AI Systems
As organizations look to maximize the business value of AI and cyber teams develop their understanding of the attacker’s capability, a strategic risk-centric approach is required. To help communicate where key risks exist and how to mitigate them, Check Point developed an AI threat triangle.
The AI Threat Triangle is a simple model designed to help visualize three core AI domains for AI cyber security risk and business impact:
- AI Applications: External threats targeting AI models and applications mostly through prompt injection. This is the most valuable target since there is a significant cost in building elements in this layer.
- AI Responsible use and Governance: Ethical, transparent, and controlled operation of AI systems should ensure safe, reliable behavior, in line with organizational and regulatory requirements.
- AI Infrastructure: The most important foundational layer to secure. If an enterprise loses access to their AI systems, or if their infrastructure layer is compromised then all other layers will be directly impacted.
Check Point AI Data Center Security
Now that we understand the unique threats and risks to our AI Data Center, we can conceptualize what is required to protect enterprise from attacks.
Securing AI data centers after they are running (either training or inference) is prohibitively expensive. This is why ensuring security-by-design and extensive pre-deployment validation testing is critical. The Check Point approach to protect AI factories and data centers is unique and holistic, based on a layered AI Security ecosystem built on a defense-in-depth approach. The conceptual technologies stack includes:
- AI Native Application Protection (LLM): API based security of AI application and Agentic / LLM layer protection
- Perimeter Protection: External access control zone, entry point to the AI data center fabric, secured by zero-trust (ZTNA) enabled with Check Point Maestro Hyperscale Firewall and DDoS security
- Host Security: Check Point AI Factory Firewall running on the NVIDIA DPU, with security close to the AI workloads, segment servers (DGX) and protecting management traffic (Control Plane)
- AI-Hardware Protection: Monitor GPU and hosts memory behavior in real time, without negatively impacting GPU performance. Detects anomalous access patterns, enabling early identification of malicious activity, including data exfiltration, model theft, or compromised workloads
- Workload and Container Protection: Secure East-West traffic inside Kubernetes environments including cluster visibility and containers, with micro segmentation policy enforcement
Securing the AI Factory & Data Center
Multi Layer: Data Center, Servers, Containers and Application
AI Applications Protection: The following solutions are foundational to protecting AI applications. The unique nature of AI apps means that AI-native security is key to success:
- Check Point AI LLM Security and API Security
- AI-native runtime protection against prompt injection, data leakage, and model manipulation. With support for over 100 languages.
- WAF / AppSec – Prevent advanced threats including OWASP Top-10 and zero-day attacks without signature updates. Real-time API protection and auto-discovery
- Model Context Protocol (MCP) traffic visibility
AI Infrastructure Security: The term ‘AI infrastructure’ describes the components that support AI applications but have multiple roles and applications in a data center. These include the perimeter security capabilities and the developer environment.
AI Responsible Use and Governance
Without robust governance, organizations lack the visibility and control mechanisms to manage these unique risks. Therefore, applying a security-by-design approach assures that governance is a high priority for AI data center architects. The key governance and regulatory elements to consider are:
- External AI regulations and data residency laws (EU AI Act, GDPR, ISO/IEC 42001)
- International AI frameworks (e.g., NIST AI RMF, Gartner AITRISM) enforce data lineage, provenance, and quality to prevent LLM (model) bias, poisoning, and compliance failures
- Internal / in-house AI governance frameworks ensure least-privilege access to data and training infrastructure, reducing risks of data leakage, model theft, and operational disruption.