What Databricks completed
Databricks announced on August 3 that it has officially completed its acquisition of Panther, an AI SOC (security operations center) platform. The deal combines Panther's detection engineering workflows with Lakewatch, the agentic SIEM Databricks launched in March as its first entry into cybersecurity. The company frames the combination as accelerating a security lakehouse vision: an open, governed lakehouse that unifies security, IT, and business data so SOC teams can run detection, investigation, and response directly against that data instead of a separate, siloed system. The post carries four named authors from the Databricks security team, a signal the company is staffing this as a durable product line rather than a one-off integration project.
The core argument is that cybersecurity has become fundamentally a data management and AI problem. Attackers now use automation to hide inside large volumes of complex telemetry and to launch multi-stage attacks across cloud, identity, and SaaS environments simultaneously. Databricks argues that defending against that requires an architecture built to process petabytes of telemetry with continuous context, and that legacy SIEMs, designed more than a decade ago around limited ingestion and manual triage, cannot scale to match it.
The problem this is meant to fix
Traditional SIEM economics force security teams into an uncomfortable trade-off: ingest everything and absorb escalating licensing costs and noisy alert volume, or ingest selectively and accept coverage gaps. When an alert does trigger, analysts often have to manually stitch together logs pulled from separate cloud services, endpoint tools, identity providers, and SaaS applications, which is slow and burns analysts out over time. Databricks is explicit that this is the specific failure mode Lakewatch and Panther together are designed to eliminate.
Lakewatch supplies the open data foundation: petabyte-scale retention without the sampling trade-offs legacy SIEM pricing forces, built on open standards including OCSF, Spark, Unity Catalog, Delta, and Parquet rather than a proprietary storage format. Panther supplies the operational layer on top of it, including detections written and version-controlled as code through standard CI/CD pipelines, more than 100 prebuilt integrations across major clouds and identity providers, and AI-native triage that enriches alerts with context before an analyst opens a ticket. Databricks describes this as replacing manual, UI-centric SIEM rule management with software-engineering discipline applied directly to threat detection.
Why unifying security and business data changes the triage math
The most consequential design choice here is treating security telemetry as one more dataset inside the same governed lakehouse that already holds HR records, asset inventories, and other business context, rather than isolating it in a dedicated security data store. Databricks argues that correlating a security event directly against that broader business context is what lets an automated triage agent produce a genuinely useful incident summary instead of a raw alert that still requires manual investigation to interpret correctly.
That only works if the underlying data platform already has strong governance and access controls, which is the part of this deal that should interest CTOs beyond the security team. Databricks is effectively arguing that its existing customers, who already run governed data and AI workloads on the lakehouse, get security operations as a natural extension of infrastructure they have already invested in, rather than as a new platform requiring separate integration and governance work. That is a meaningfully different pitch than most security vendors can make, since most of them are starting from a security-only data model rather than an existing enterprise-wide one.
The build versus buy question this creates
For enterprises already standardized on Databricks for data and AI, the Panther acquisition makes an internal case for extending that platform into security operations instead of running a separate best-of-breed SIEM alongside it. For enterprises standardized elsewhere, it is a reminder that the SIEM market is no longer competing only against other SIEMs. It is being pulled into the same data platform consolidation battle already playing out across analytics, governance, and AI infrastructure more broadly.
The open standards commitment, spanning OCSF, Delta, and Parquet among others, is Databricks' answer to the obvious objection that this locks security data into one vendor's ecosystem. Whether that commitment holds up under real customer usage, particularly for enterprises wanting to run best-of-breed detection tools against Databricks-hosted telemetry, is the detail worth pressure-testing before treating this as a finished architecture rather than a roadmap still being built out in public.
What this means for the CTO's roadmap
Security leaders evaluating SIEM replacements should now treat the underlying data platform question as inseparable from the SIEM vendor question. Asking whether a security tool can ingest everything without punitive costs is no longer sufficient on its own. The more useful question is whether security telemetry can live inside the same governed data platform already running the rest of the business, and what that buys in terms of context-rich, automated triage that a standalone SIEM cannot easily replicate.
The acquisition also reinforces a broader pattern worth tracking across the data platform market this year: vendors that started in analytics are moving into adjacent operational domains, security here, by arguing that their core lakehouse architecture generalizes better than a purpose-built point solution. CTOs should expect more of these moves and should evaluate each one on whether the underlying data architecture argument actually holds up under load, not just on the new capability being bundled in alongside it.



