— Lakehouse security consulting · Security data engineering

Lakehouse security consulting: cybersecurity is a data engineering problem.

Your analysts are not short of alerts. They are short of one conformed layer where every log means the same thing. Our lakehouse security consulting builds the security data lake on Databricks, normalises it to OCSF, and writes detections against data you can trust.

Lakehouse Security Consulting: Security data lake on Databricks: OCSF-normalised logs, SIEM consolidation, detection engineering

30+ years inside IBM · EY · J&J · McKesson

Lean Six Sigma Master Black Belt

AIMContext from $3,500

60-Day Ship Guarantee

— The pattern · What breaks

The tools are not the gap. The data is.

One user, five names.

Firewall, identity, endpoint and cloud logs each name the same user, host and action differently. Correlation becomes a join nobody wrote, so it never happens.

Symptom: an investigation starts with a spreadsheet of aliases.

Logs dropped to fit a budget.

When ingest is priced by volume, teams drop the logs they cannot afford to keep. That is a budget decision quietly turned into a detection decision.

Symptom: the log you need was never retained.

Rules that break on a format change.

A rule written against one vendor field breaks when that vendor changes a format. Without a conformed layer, detection engineering becomes maintenance.

Symptom: silent detections nobody notices are gone.

— The work · What we build

What our lakehouse security consulting actually delivers.

Security data lake design

Raw logs land in bronze with their source intact, on lakehouse storage priced like storage, not like search.

OCSF normalisation

Silver maps every source to the Open Cybersecurity Schema Framework, so a login is a login whichever product saw it.

SIEM consolidation

A clear split of which data needs hot search in your SIEM and which belongs on the lakehouse. That is how a Splunk alternative conversation starts on facts.

Detection engineering

Detections written as versioned code against the conformed layer, tested on real history before they page anyone.

Governed access

Unity Catalog grants by group, never by individual, with lineage on every table so an auditor can follow a finding back to its source.

Lakewatch readiness

Databricks announced Lakewatch, its agentic SIEM, on 24 March 2026 in Private Preview. We get your data ready for it or for any other SIEM you choose.

Lakehouse Security Consulting: engineer mapping security log sources to a common schema on a whiteboard

— The approach · Normalise first

Normalise once in silver. Detect everywhere after.

Most security stacks normalise inside each tool, so the same work is done five times and never agrees. We map every source to OCSF once, in the silver layer of the lakehouse, and let every detection, dashboard and SIEM read the same conformed events.

Gold then holds what your analysts actually query: sign-ins, network flows, endpoint events and cloud activity in one shape. Consolidation stops being a migration project and becomes a routing decision.

— The method · AIM-IT

Five phases. Every build, every time.

Assess, Innovate, Model, Implement, Track. Each phase ends with something you can inspect and sign off, not a slide.

01 · ASSESS

Assess

Log source inventory

Every log source, what it costs to keep, and which detections actually depend on it.

02 · INNOVATE

Innovate

OCSF and retention design

The OCSF mapping and the hot and cold split designed before a single pipeline is written.

03 · MODEL

Model

Two sources, one detection

Two high-value sources normalised end to end, with a detection proven on the conformed layer.

04 · IMPLEMENT

Implement

Onboarding in your workspace

The remaining sources onboarded in your workspace, with your security engineers in the room.

05 · TRACK

Track

Coverage scorecard

Coverage, freshness and cost per source measured on a schedule, with an owner for each.

— The deliverable · What you get

A security data lake your team can run without us.

AIMContext

Governed security data foundation, fixed scope.

AIMContext is the fixed-scope build for a governed security data foundation. You get:

  • Priority security logs landed in a governed security data lake on the lakehouse.
  • An OCSF mapping per source, documented and versioned.
  • A clear split of which data needs hot search and which does not.
  • Detections as tested, versioned code against the conformed layer.
  • Your team able to run it. We are not trying to become permanent.
Entry: AIMContext · governed security data foundation, fixed scope. Starting at $3,500.

$3,500+

Starting price

14 days

Typical first build

5 phases

AIM-IT, end to end

60 days

Ship guarantee

60-Day
Ship Guarantee

On every Sprint engagement: if we do not deliver the agreed working artifact in 60 days, you do not pay the final invoice. That is what AIM-IT is for.

— Lakewatch · Any SIEM

Lakewatch or any SIEM: the conformed layer comes first.

Databricks launched Lakewatch in Private Preview on 24 March 2026, and no general availability date has been announced. Whether you adopt it, keep your current SIEM, or run both, the work that pays off is the same: a conformed security layer on the lakehouse.

We are not a Databricks partner and do not resell Lakewatch. Our own Lakewatch-style work is a prototype on dummy data, and we say so. What we sell is the data engineering underneath.

Lakehouse Security Consulting: security operations analyst at a desk with log analytics dashboards, calm modern SOC, daylight

— Related reading · From the blog

Go deeper on lakehouse security.

Architecture

The bronze, silver and gold layout for security logs.

SIEM cost

Which data needs hot search and which does not.

Detections

Detections as tested code against a conformed layer.

Lakewatch

What the Private Preview changes, and what it does not.

OCSF

Mapping vendor fields to one open schema.

Consolidation

How tool sprawl collapses into one queryable layer.

— Straight answers · FAQ

Questions we get asked first.

Are you a Databricks partner or certified?

No, and we will not imply otherwise. Certification is in preparation, and we are not in the Databricks partner programme. What we bring is thirty years of delivering the enterprise systems this data comes out of, inside IBM, Ernst & Young, Johnson & Johnson and McKesson, plus Lean Six Sigma at Master Black Belt level. Ask us for the work, not the badge.

Is a security data lake a Splunk replacement?

Sometimes a replacement, more often a partner to it. Many teams keep a SIEM for hot search and alerting and move long retention, enrichment and heavy analytics onto the lakehouse. We will tell you which split fits your data, not which product we prefer.

What is OCSF and why does it matter?

The Open Cybersecurity Schema Framework is an open standard for how security events are described. Mapping to it once in silver means detections and dashboards stop caring which vendor produced the log.

When will Databricks Lakewatch be generally available?

Databricks launched it in Private Preview on 24 March 2026, and no general availability date has been announced. Build the conformed security layer now and it serves Lakewatch or any other SIEM later. We do not claim any Lakewatch partnership.

What does lakehouse security consulting cost?

AIMContext starts at $3,500 for a fixed-scope governed security data foundation, and a typical first build lands in 14 days. Larger security programmes are quoted after the assessment.

Start with the logs, not the licence.

One call, your real sources on the table, and a straight read on what a governed security data lake would change for your team. If we are not the right team, we will say so.