As the data handled by corporations soars, cybersecurity is shifting from system defense to the real-time management of massive data. Databricks, a U.S.-based global data and artificial intelligence (AI) company, unveiled the security information and event management (SIEM) platform Lakeview in March and has been expanding into cybersecurity by acquiring three security companies over the past year.

Omar Khawaja, Databricks field chief information security officer (CISO) and vice president for security, whom we met on the 25th in Samseong-dong, Gangnam-gu, Seoul, at the Databricks Korea office, said, "Within corporations, demand is surging for cybersecurity organizations to leverage data and AI, so we determined it was time to build cybersecurity capabilities inside Databricks." Databricks is used as the enterprise-standard data platform at about 20,000 corporations worldwide, but security teams, which handle the most data in companies, were using separate systems, causing data to be siloed and harder to use, in his view. He added that legacy security solutions have clear limits in throughput and expense, making it difficult to handle the explosion of security data.

Omar Khawaja, Databricks field CISO and vice president of security, speaks during an interview at the Databricks Korea office in Samseong-dong, Gangnam-gu, Seoul, on the 25th of last month. /Courtesy of Databricks

Khawaja said, "One customer collects 7 petabytes (PB, 1,000 times a terabyte) of data every day solely for cybersecurity, and among existing SIEM platforms, not even 1/100 of that scale can be processed." He went on to say that for AI-era security, "Corporations should not defend every system the same way; they should first understand what risks they are actually exposed to and then decide on controls."

Khawaja advises CISOs at corporations around the world on AI security strategy. The following is a Q&A with him.

—You meet security leaders at many corporations. What are they struggling with in security in the AI era?

"What they say in public forums and what they confide in one-on-one conversations are different. In front of many people, they complain that 'the business unit is moving too fast.' They say nothing is decided yet on what to do, they want to use AI, and they keep changing models and data. In private, they admit there is too much they don't know and they aren't prepared. They feel they still have a lot to learn to become an expert group that properly understands and manages security and risk in the AI era."

—Why did Databricks make a full-fledged entry into the security market with the launch of Lakeview?

"Even before launching Lakeview, more than 100 customers were using Databricks for cybersecurity. Databricks is used as the enterprise-standard data platform at about 20,000 corporations worldwide. The organization that handles the most data in a company is the security team, so it was odd that the security team wasn't using the enterprise data platform. Customers first asked us to 'make it much easier for the security team to use Databricks.' We determined it was time to build cybersecurity capabilities inside Databricks."

—How is Lakeview different from existing SIEMs?

"First, scalability and cost. Traditional SIEMs can process up to 10 terabytes (TB) a day but cannot handle 100 TB a day. In contrast, among customers using the Databricks platform, some collect hundreds of TB daily, and one customer collects 7 PB per day solely for cybersecurity. Also, by adopting a cost structure that separates storage and compute, it costs about 30% to 70% less in expense than traditional SIEMs. Second, no SIEM is an enterprise-wide data platform for corporations. If you use a traditional SIEM, your data ultimately becomes separated from other data."

—You acquired three security companies in one year: Antimatter, SiftD.ai, and Panther.

"Every acquisition starts with customer needs. Customers asked to more easily build data pipelines to collect from security data sources, to more easily write security detection logic, and to further automate security response by integrating with SOAR (security orchestration, automation and response) platforms."

Omar Khawaja, Databricks field CISO and vice president of security. /Courtesy of Databricks

—Where should security go in the AI era?

"Traditional security starts by thinking about which controls to apply, which techniques to use, and which technologies to deploy to make systems safe. In the AI era, you should not take that approach. You should start from the risks corporations face and then decide which security controls to apply to manage those risks. For example, if a doctor didn't ask 'Where does it hurt?' and instead said, 'I've seen hundreds of patients, and I'll give you 10 medicines—take them all,' wouldn't that seem absurd? Yet most security programs today operate that way. If you understand what's happening, one medicine may be enough. You should focus on and respond to the specific problems that actually affect corporations."

—Korea's large corporations have traditionally preferred on-premises (self-hosted) infrastructure and are conservative about cloud security.

"This is not unique to Korea. Europe and the United States are the same. It has already been 20 years since Amazon Web Services (AWS) introduced early cloud services like S3 and EC2 in 2006, yet I still often meet corporations that think of the cloud as an emerging technology. But over the past five years, I've watched numerous corporations that had said, 'We will never adopt the cloud,' move to the cloud. Almost all corporations had no major issues after moving. It appears to be more a psychological issue—'the data is not inside my establishment'—than a technical one; ultimately, there must be confidence that cloud providers are trustworthy. Our customers include the world's largest banks and government agencies that handle the most sensitive information."

—Anthropic's Mythos demonstrated world-class offensive capabilities. Lakeview's defense engine also runs on the same Anthropic model; can defense stay ahead of offense?

"We always run security programs looking six months to a year ahead. Even before Mythos appeared, we were 100% sure that a model with that capability would emerge someday. We just didn't know which company, when, or under what name. So we've prepared for a long time. That's why we've invested much effort over the past several years in largely automating response controls. Rather than Mythos creating new risks, the urgency to address already known risks has greatly increased. Fortunately, we have a strong partnership with Anthropic, so we can access Mythos and use it internally to strengthen Databricks' security. I also think that models less capable than Mythos can still be effectively used by defenders to proactively find weaknesses and gaps in current security postures."

—What do you expect from this visit to Korea?

"I look forward to conversations directly with the executives, chief technology officers (CTOs), chief information officers (CIOs), and chief security officers (CSOs) of Korean corporations. I know there are many fields in which Korean corporations and Korean technology hold dominant positions not only in Korea but also in the global market. So I want to see how these corporations are using AI to develop next-generation strategies, new businesses, and future success. Korea is a very important and strategic market for Databricks, and revenue in Korea grew 100% over the past year."

※ This article has been translated by AI. Share your feedback here.