Databricks launches Lakewatch, a security information and event management service currently used by Adobe, and acquires security startups Antimatter and SiftD
Databricks has grown from startup into major software company, generating billions by processing data and running generative artificial intelligence models for clients.
Context & Ripple Effects
Databricks’ product arc has moved from data analytics and AI workloads toward user-facing tools: LakehouseIQ added natural-language access to company data, followed by AI/BI’s conversational chart-building workflow. Lakewatch extends that platform logic into security operations, where event data is itself a core workload.
The paired acquisitions make the launch more than a standalone feature announcement: Databricks is adding security capability while attempting to make its data platform more central to customers’ operational stack.
First-order effects
- Databricks gains a SIEM offering and the teams and technology of Antimatter and SiftD; Adobe is identified as an early Lakewatch user.
- Existing Databricks customers can evaluate security-event management within the same vendor relationship used for data and AI workloads, rather than treating security analytics as wholly separate.
Second-order effects
- SIEM vendors and data-platform rivals face a more credible platform-level competitor, particularly where buyers want security telemetry close to their analytics and AI data.
- The acquisitions raise the importance of integration quality: Lakewatch’s appeal will depend on whether acquired capabilities become a coherent security workflow rather than separate products.
Third-order effects
- If Databricks continues adding security assets—as its later agreement to acquire Panther Labs suggests—security operations could become another workload consolidated onto large data-and-AI platforms.
- That consolidation would shift competition from individual security tools toward control of the data layer, integrations, and AI-assisted workflows that surround them.
The trend: This is one data point in AI infrastructure platformization, as data-platform providers broaden into adjacent operational software to capture more of the enterprise workflow.