Databricks to acquire Panther, pushing deeper into cybersecurity
What's the deal? Databricks has agreed to acquire Panther, a cloud-native security analytics platform, as it moves to establish what it calls the "security lakehouse" category. The deal will bring Panther's security information and event management (SIEM) capabilities directly into the Databricks platform, giving security teams the ability to detect, investigate, and respond to threats using the same data infrastructure their organisations already run.
Financial terms of the acquisition were not disclosed. Panther is the third security acquisition announced by Databricks, following its purchases of Antimatter and SiftD.ai.
Why now? Traditional SIEM tools have struggled to keep up with the sheer volume of security data modern organisations generate. Many security teams already store their logs in data lakehouses but lack native tools to act on them. By acquiring Panther, Databricks can offer a tightly integrated security solution — eliminating the need for separate, costly security platforms and reducing the lag between data collection and threat response.
The deal also comes as Databricks continues its aggressive acquisition spree ahead of a widely anticipated IPO. Adding a security layer strengthens its pitch to enterprise buyers who want fewer vendors handling more of their data stack.
What could go wrong? Integrating a security-focused product into a broad data platform is no small task. Security teams have specialised workflows and compliance requirements that differ sharply from those of data engineers and analysts — Databricks' core users. If the integration feels bolted-on rather than seamless, enterprise security buyers may stick with established SIEM vendors like Splunk (now part of Cisco) or CrowdStrike.
There's also the question of whether bundling security into a data platform creates concentration risk. Organisations may hesitate to rely on one vendor for both their data infrastructure and their security operations.
The signal: This acquisition reflects a broader convergence between data platforms and cybersecurity. As companies centralise massive volumes of data in lakehouses and cloud warehouses, the logic of running security analytics on the same infrastructure becomes hard to ignore. Snowflake has made similar moves, and the trend suggests that standalone SIEM may eventually give way to security built into the data layer.
For Databricks, the Panther deal is a bet that the future of security operations lives inside the data platform — not alongside it.
Read more: Databricks · Reuters