Databricks enters cybersecurity with Lakewatch after acquiring Antimatter and SiftD.ai

2 Sources

Share

Databricks launched Lakewatch, a new AI security product that transforms traditional SIEM capabilities using AI agents powered by Anthropic's Claude. The move into cybersecurity follows two strategic acquisitions: Antimatter, acquired in May 2025, and SiftD.ai, which closed just days ago. With $5 billion in fresh funding, Databricks aims to help security teams respond faster to increasingly sophisticated cyber threats.

Databricks Unveils Lakewatch to Transform AI Security

Databricks announced Tuesday its formal entry into the cybersecurity market with Lakewatch, an agentic SIEM product that leverages the company's data platform and AI capabilities to detect and investigate threats

1

. The AI security product, currently in private preview, represents a major strategic investment for the cloud data analytics company, which closed a $5 billion funding round last month

1

. Unlike traditional SIEM tools, Lakewatch uses AI agents powered by Anthropic's Claude to automate threat detection and investigation at massive scale

1

.

Source: CRN

Source: CRN

Andrew Krioukov, general manager of Lakewatch, emphasized that "security is really a data problem, at the core of it," positioning Databricks' strengths in data and AI as the natural evolution of SIEM

2

. Prior to this launch, some customers were already running security workloads on the Databricks platform, loading security logs because it outperformed existing tools for threat analytics

2

.

Databricks Acquisitions Power New Security Offering

The launch of Lakewatch follows two strategic Databricks acquisitions that provide the technological foundation for the new product. The company acquired Antimatter in an undisclosed deal that closed in May 2025, bringing aboard security researcher Andrew Krioukov and his team

1

. Antimatter, which had raised $12 million led by New Enterprise Associates in 2022, was developing a data control plane tool that allowed enterprises to deploy AI agents securely while protecting sensitive data

1

.

Krioukov, who co-founded and led Antimatter, explained that his company's technology was originally built on the Databricks platform and provided the foundation for Lakewatch. "We were real partners before we were acquired," he noted, adding that the Antimatter team tripled in size within Databricks post-acquisition to develop the new offering in record time

2

.

In a second acquisition that closed just Monday, Databricks bought SiftD.ai in a deal that came together over the last couple of weeks

1

. The startup, founded by Steve Zhang, creator of Splunk's Search Processing Language, brings deep expertise in detection engineering and modern threat analytics

2

. SiftD.ai had only launched its product in November, an interactive notebook designed for human-agent collaboration

1

.

Advanced Threat Detection Through Agentic AI

Lakewatch is designed around three core pillars that address limitations in traditional cybersecurity tools. First, it unifies security, IT and business data into a single governed environment, enabling organizations to ingest and analyze huge volumes of multi-modal data including unstructured formats like text, audio and images that traditional SIEM tools struggle to process

2

. This provides security teams with complete visibility across an enterprise.

The second pillar focuses on automating security practices through AI-driven security solutions. "The attackers are moving faster and faster and so the time to respond is dropping," Krioukov explained. "We're applying AI to help the teams that are tasked with defending a company, to help automate their workflows, help them do their jobs faster, so that they can spot threats sooner and react to those threats faster"

2

. Using Databricks' Agent Bricks tools, customers can build and deploy custom security agents, while integration with Databricks' Genie AI assistant automates processes like alert triage

2

.

The third pillar emphasizes openness and flexibility, leveraging Databricks' ability to work with data from broad sources and connect to IT systems across its extensive technology partner ecosystem

2

.

Strategic Entry Into Cybersecurity Market

Databricks debuted Lakewatch at RSAC 2026 in San Francisco, where co-founder and CEO Ali Ghodsi delivered a keynote focused on how AI has replaced traditional SIEM approaches

2

. Krioukov emphasized that given the importance of data and AI within cybersecurity, Lakewatch is not just a side product but represents a major investment area backed by Ghodsi and the board

2

.

The company signaled its intention to continue pursuing acquisitions, with a spokesperson stating that Databricks continuously has its feelers out. "We're always looking to what's next -- our goal is to stay ahead of the market and close gaps in what our customers need," the spokesperson said

1

. For channel partners, Lakewatch opens opportunities around new security use cases such as leveraging business data for fraud detection

2

.

Today's Top Stories

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2026 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo