— Lakehouse security consulting · Security data engineering
Lakehouse security consulting: cybersecurity is a data engineering problem.
Your analysts are not short of alerts. They are short of one conformed layer where every log means the same thing. Our lakehouse security consulting builds the security data lake on Databricks, normalises it to OCSF, and writes detections against data you can trust.
30+ years inside IBM · EY · J&J · McKesson
Lean Six Sigma Master Black Belt
AIMContext from $3,500
60-Day Ship Guarantee
— The pattern · What breaks
The tools are not the gap. The data is.
One user, five names.
Firewall, identity, endpoint and cloud logs each name the same user, host and action differently. Correlation becomes a join nobody wrote, so it never happens.
Symptom: an investigation starts with a spreadsheet of aliases.
Logs dropped to fit a budget.
When ingest is priced by volume, teams drop the logs they cannot afford to keep. That is a budget decision quietly turned into a detection decision.
Symptom: the log you need was never retained.
Rules that break on a format change.
A rule written against one vendor field breaks when that vendor changes a format. Without a conformed layer, detection engineering becomes maintenance.
Symptom: silent detections nobody notices are gone.
— The work · What we build
What our lakehouse security consulting actually delivers.
Security data lake design
Raw logs land in bronze with their source intact, on lakehouse storage priced like storage, not like search.
OCSF normalisation
Silver maps every source to the Open Cybersecurity Schema Framework, so a login is a login whichever product saw it.
SIEM consolidation
A clear split of which data needs hot search in your SIEM and which belongs on the lakehouse. That is how a Splunk alternative conversation starts on facts.
Detection engineering
Detections written as versioned code against the conformed layer, tested on real history before they page anyone.
Governed access
Unity Catalog grants by group, never by individual, with lineage on every table so an auditor can follow a finding back to its source.
Lakewatch readiness
Databricks announced Lakewatch, its agentic SIEM, on 24 March 2026 in Private Preview. We get your data ready for it or for any other SIEM you choose.
— The approach · Normalise first
Normalise once in silver. Detect everywhere after.
Most security stacks normalise inside each tool, so the same work is done five times and never agrees. We map every source to OCSF once, in the silver layer of the lakehouse, and let every detection, dashboard and SIEM read the same conformed events.
Gold then holds what your analysts actually query: sign-ins, network flows, endpoint events and cloud activity in one shape. Consolidation stops being a migration project and becomes a routing decision.
— The method · AIM-IT
Five phases. Every build, every time.
Assess, Innovate, Model, Implement, Track. Each phase ends with something you can inspect and sign off, not a slide.
01 · ASSESS
Assess
Log source inventory
Every log source, what it costs to keep, and which detections actually depend on it.
02 · INNOVATE
Innovate
OCSF and retention design
The OCSF mapping and the hot and cold split designed before a single pipeline is written.
03 · MODEL
Model
Two sources, one detection
Two high-value sources normalised end to end, with a detection proven on the conformed layer.
04 · IMPLEMENT
Implement
Onboarding in your workspace
The remaining sources onboarded in your workspace, with your security engineers in the room.
05 · TRACK
Track
Coverage scorecard
Coverage, freshness and cost per source measured on a schedule, with an owner for each.
— The deliverable · What you get
A security data lake your team can run without us.
AIMContext
Governed security data foundation, fixed scope.
AIMContext is the fixed-scope build for a governed security data foundation. You get:
- Priority security logs landed in a governed security data lake on the lakehouse.
- An OCSF mapping per source, documented and versioned.
- A clear split of which data needs hot search and which does not.
- Detections as tested, versioned code against the conformed layer.
- Your team able to run it. We are not trying to become permanent.
$3,500+
14 days
5 phases
60 days
60-Day
Ship Guarantee
On every Sprint engagement: if we do not deliver the agreed working artifact in 60 days, you do not pay the final invoice. That is what AIM-IT is for.
— Lakewatch · Any SIEM
Lakewatch or any SIEM: the conformed layer comes first.
Databricks launched Lakewatch in Private Preview on 24 March 2026, and no general availability date has been announced. Whether you adopt it, keep your current SIEM, or run both, the work that pays off is the same: a conformed security layer on the lakehouse.
We are not a Databricks partner and do not resell Lakewatch. Our own Lakewatch-style work is a prototype on dummy data, and we say so. What we sell is the data engineering underneath.
— Related reading · From the blog
Go deeper on lakehouse security.
Architecture
The bronze, silver and gold layout for security logs.
SIEM cost
Which data needs hot search and which does not.
Detections
Detections as tested code against a conformed layer.
Lakewatch
What the Private Preview changes, and what it does not.
OCSF
Mapping vendor fields to one open schema.
Consolidation
How tool sprawl collapses into one queryable layer.
— Straight answers · FAQ
Questions we get asked first.
Are you a Databricks partner or certified?
No, and we will not imply otherwise. Certification is in preparation, and we are not in the Databricks partner programme. What we bring is thirty years of delivering the enterprise systems this data comes out of, inside IBM, Ernst & Young, Johnson & Johnson and McKesson, plus Lean Six Sigma at Master Black Belt level. Ask us for the work, not the badge.
Is a security data lake a Splunk replacement?
Sometimes a replacement, more often a partner to it. Many teams keep a SIEM for hot search and alerting and move long retention, enrichment and heavy analytics onto the lakehouse. We will tell you which split fits your data, not which product we prefer.
What is OCSF and why does it matter?
The Open Cybersecurity Schema Framework is an open standard for how security events are described. Mapping to it once in silver means detections and dashboards stop caring which vendor produced the log.
When will Databricks Lakewatch be generally available?
Databricks launched it in Private Preview on 24 March 2026, and no general availability date has been announced. Build the conformed security layer now and it serves Lakewatch or any other SIEM later. We do not claim any Lakewatch partnership.
What does lakehouse security consulting cost?
AIMContext starts at $3,500 for a fixed-scope governed security data foundation, and a typical first build lands in 14 days. Larger security programmes are quoted after the assessment.
Start with the logs, not the licence.
One call, your real sources on the table, and a straight read on what a governed security data lake would change for your team. If we are not the right team, we will say so.
