CyberWire Daily

Eviction notice for Media Land.

Nov 20, 2025
Cliff Crosland, CEO and co-founder of Scanner.dev, dives into the benefits of security data lakes for AI in the Security Operations Center (SOC). He explains how these lakes, built on object storage, enhance AI workflows with fast query performance. Cliff highlights the power of human-AI collaboration in reducing false negatives and improving investigations. He also discusses the evolving roles of SOC analysts and the importance of managing unstructured logs, advocating for a flexible approach to data management in modern cybersecurity.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Data Lakes Power Agentic SOC Workflows

  • Security data lakes on object storage enable rich context for AI agents to accelerate investigations.
  • Fast access to large historical logs makes agentic workflows effective for SecOps.
ADVICE

Automate Tasks But Keep Humans In The Loop

  • Design agentic workflows that fetch alerts, query the data lake, and auto-create human-reviewable artifacts.
  • Let agents open pull requests and add ticket comments while humans review and approve changes.
INSIGHT

Query Speed Is The Limiting Factor

  • Query speed is the gating factor for practical AI agents on data lakes.
  • Improvements like Iceberg, Parquet, and full-text indexes will remove the 'data lake too slow' barrier.
Get the Snipd Podcast app to discover more snips from this episode
Get the app