The Company That Knows Your Data Now Wants to Protect It
On March 24, Databricks — a company most people associate with data engineering and AI model training — made an announcement that should have rattled every SIEM vendor on the planet: it's entering the cybersecurity market. The product is called Lakewatch. It's an agentic SIEM — Security Information and Event Management — built directly on top of Databricks' existing data lakehouse platform. And its pitch is devastatingly simple: if your security data already lives in our platform, why are you paying someone else to analyze it? [1] That's not just marketing. It's a genuine structural advantage that the traditional security industry has no clean answer for.
What Lakewatch Actually Does
Lakewatch unifies security data, IT telemetry, and business data into a single governed environment. That means your firewall logs, endpoint alerts, cloud access records, application traces, and identity events all land in one place — stored in open formats on the Databricks lakehouse, not locked inside a proprietary vendor's black box. [1]





