Skip to content
theCUBE

UPDATED 08:59 EDT / AUGUST 07 2026

Emilio Escobar, CISO at Datadog, talks to theCUBE about how shared context from production data helps security and engineering teams prioritize risk and respond faster, at Black Hat USA 2026. SECURITY

Shared context speeds risk response across security and engineering

Security and engineering teams can no longer operate in silos as software delivery accelerates and adversaries move faster with AI, requiring shared context from production data so both sides can prioritize risk and respond without friction.

At Black Hat USA 2026, this friction was a major focus. Historically, data separation creates delays. Security teams often lack production visibility while engineering teams struggle to understand the security context behind requested fixes, according to Emilio Escobar (pictured), chief information security officer of Datadog Inc.

“At Datadog … it has to be a unified context for both teams,” Escobar said. “If both people, both teams can see the same data, but from a different lens … they can solve the problems faster.”

Escobar spoke with theCUBE Research’s Krista Case at Black Hat USA, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed how shared context can break down silos while helping teams prioritize risk and validate detections more effectively. (* Disclosure below.)

Shared context turns friction into faster response

When both teams examine the same telemetry through different lenses, root-cause analysis accelerates. Security investigates a threat on a server while engineering troubleshoots sudden CPU saturation that is degrading a customer-facing function, Escobar noted. The underlying cause — a crypto miner — is identical, yet without shared data, the teams pursue separate problems and lose critical time.

“Imagine that happening at a scale where both teams are now trying to solve what may seem as two separate problems, but the root cause of it is one thing,” he said. “If they see the same data, they’re like, ‘Oh, we know exactly what happened,’ and within minutes, you can just solve that problem in itself.”

Risk prioritization depends on the same joint visibility. A vulnerability on an internet-exposed critical business function with a known exploit must rank higher than a similar finding buried deep in the infrastructure with no active exploit path, Escobar explained. Without runtime and traffic context, both items appear equal on a backlog and create tension when engineering is asked to act.

“Every security team understands that not every vulnerability should be treated the same,” he said. “However, where I think security teams lack is the context and the visibility to be able to understand why is one more important than the other, rather than just the rating and severity of the vulnerability.”

Deep runtime and application-level information remain the biggest visibility gap for many security teams, Escobar noted. Traditional tooling often stays at the surface — attack surface, external scans or infrastructure posture — while actionable understanding requires insight into what is actually happening inside the running application and supporting systems.

“How can you do more with what you have?” Escobar said. “The right agents for the right use cases, helping them actually close the loop — which is remediating problems rather than just telling you all the problems you have.”

Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of Black Hat USA:

(* Disclosure: Datadog sponsored this segment of theCUBE. Neither Datadog nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)

Photo: SiliconANGLE

Send us a news tip

Send us a News Tip

  • This field is for validation purposes and should be left unchanged.

Sign in or create an account

SIGN IN

OR

New User? SIGN UP

Join us

SIGN UP

Bio

Ethics statement

Extract the signal from the noise

Get SiliconANGLE updates and analysis.

Contact us

Partner with us

Contact us

Guest inquiry