AWS, Splunk, IBM, CrowdStrike, Cloudflare, Okta, and 12 others announce the Open Cybersecurity Schema Framework to help monitor hacking attempts
Amazon's AWS, Splunk, IBM and others cooperate on format for cyber alerts — This feature is powered by text-to-speech technology.
Context & Ripple Effects
This announcement extends a pattern of competitors pooling security infrastructure rather than building alone: Microsoft, IBM, and Nvidia had already released an open framework for detecting threats against machine learning systems in 2020, and DHS formalized public-private coordination with the Joint Cyber Defense Collaborative alongside Amazon, Google, and Microsoft in 2021.
The Open Cybersecurity Schema Framework is the data-layer version of that cooperation — AWS, Splunk, IBM, CrowdStrike, Cloudflare, Okta, and 12 others agreeing on a common format for cyber alerts. It matters because alert data has historically been siloed in each vendor's own schema, making cross-tool monitoring expensive for the enterprises buying all of these products.
First-order effects
- Enterprise security teams running tools from multiple signatories — say CrowdStrike endpoint data feeding Splunk analytics on AWS — get a shared alert format, cutting the custom integration work that each vendor pairing previously required.
- The signatories themselves commit to interoperability at the data layer, which means AWS, IBM, and Splunk are standardizing away one form of differentiation in exchange for a larger addressable monitoring ecosystem.
Second-order effects
- Security vendors outside the founding group face pressure to adopt the schema or be the integration bottleneck, since customers will increasingly favor tools that speak the common format natively.
- Portable, standardized alert data weakens analytics lock-in: if logs flow freely between platforms, pricing power shifts toward whichever vendor's detection and response layer is best, not whoever holds the data.
Third-order effects
- If the framework becomes the default, the industry's structure shifts toward a shared data substrate under competing detection products — the same vendor-neutral-commons logic behind the 2020 ML-threat framework and DHS's collaborative, but embedded in commercial tooling.
- A de facto industry schema also gives regulators and government coalitions a ready-made reporting standard, which matters as later efforts like the public glossary of state-sponsored hacking groups show vendors standardizing shared security vocabulary more broadly.
The trend: Cybersecurity is consolidating around vendor-neutral open standards for shared threat data, with rival vendors cooperating on the plumbing while competing on detection and response built on top of it.