SECURITY
SECURITY
SECURITY
Security and engineering teams can no longer operate in silos as software delivery accelerates and adversaries move faster with AI, requiring shared context from production data so both sides can prioritize risk and respond without friction.
At Black Hat USA 2026, this friction is a major focus. Historically, the separation of data creates delays. Security teams often lack production visibility while engineering teams struggle to understand the security context behind requested fixes, according to Emilio Escobar (pictured), chief information security officer of Datadog Inc.
“At Datadog we think of it, it has to be a unified context for both teams,” Escobar said. “If both people, both teams can see the same data, but from a different lens…they can solve the problems faster.”
Escobar spoke with Krista Case at Black Hat USA, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed how shared context can break down silos while helping teams prioritize risk and validate detections more effectively. (* Disclosure below.)
When both teams examine the same telemetry through different lenses, root-cause analysis accelerates. Security investigates a threat on a server while engineering troubleshoots sudden CPU saturation that is degrading a customer-facing function, Escobar noted. The underlying cause—a crypto miner—is identical, yet without shared data the teams pursue separate problems and lose critical time.
“Imagine that happening at a scale where both teams are now trying to solve what may seem as two separate problems but the root cause of it is one thing,” he said. “If they see the same data, they’re like, oh, we know exactly what happened, and within minutes you can just solve that problem in itself.”
Prioritization of risk depends on the same joint visibility. A vulnerability on an internet-exposed critical business function with a known exploit must rank higher than a similar finding buried deep in the infrastructure with no active exploit path, Escobar said. Without runtime and traffic context, both items appear equal on a backlog and create tension when engineering is asked to act.
“Every security team understands that not every vulnerability should be treated the same,” he said. “However, where I think security teams lack is the context and the visibility to be able to understand why is one more important than the other, rather than just the rating and severity of the vulnerability.”
Deep runtime and application-level information remains the biggest visibility gap for many security teams, Escobar noted. Traditional tooling often stays at the surface—attack surface, external scans or infrastructure posture—while actionable understanding requires insight into what is actually happening inside the running application and supporting systems.
“How can you do more with what you have?” Escobar said. “The right agents for the right use cases, really actually helping them close the loop — which is remediating problems rather than just telling you all the problems you have.”
Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of Black Hat USA:
(* Disclosure: Datadog sponsored this segment of theCUBE. Neither Datadog nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.