Datadog CISO calls for shared production data in risk response
Datadog CISO Emilio Escobar said security and engineering need shared telemetry to rank risks by real exposure, though no outcome data was disclosed.
By Dominic Okoye · Staff Writer
· 3 min read
Datadog shared production data was the subject of a Black Hat USA 2026 interview with the company’s chief information security officer, Emilio Escobar. Escobar argued that security and engineering teams should work from the same production telemetry to connect incidents, exposure and business impact, but neither Datadog nor the report supplied measured response-time or remediation results.
The discussion, reported by SiliconANGLE from an interview on theCUBE, was an operating-model argument rather than a product launch. No funding, revenue, customer deployment, headcount or product implementation details were disclosed.
Escobar’s premise is that the two groups can investigate the same underlying event as unrelated work when they lack a common view of production systems. Security may identify suspicious activity but lack visibility into what is running and affected in production. Engineering may receive a request to fix a finding without the threat and exposure information that explains its urgency.
How can shared production data improve risk prioritization?
Shared context means giving security and engineering access to the relevant runtime, traffic and production information, while allowing each team to use it for its own work. Security can assess threat and exploitability; engineering can assess service behavior and the affected application. The intended result is a common explanation of an issue before separate investigations consume time.
Escobar illustrated the point with a hypothetical crypto miner. A security team could be investigating activity on a server while engineering is tracing CPU saturation that is degrading a customer-facing service. In his account, both symptoms have one cause, but the teams can treat them as separate problems if their data is divided.
The more consequential claim concerns vulnerability queues. Escobar said a known exploitable vulnerability on an internet-exposed, business-critical function should rank above a similar finding deeper in infrastructure that has no active exploit path. A list of findings without runtime or traffic context can make those items appear equally urgent, he said, increasing friction when security asks engineering to act.
That distinction fits the broader work of an enterprise security program, where monitoring, investigation and technical controls have to connect to the systems the business operates. It does not establish that any particular integration or dashboard will improve outcomes.
The evidence available here is limited to Escobar’s views and an illustrative scenario reported by SiliconANGLE. There is no independent benchmark, customer case study or breach-prevention data showing that Datadog’s approach shortens incident response or improves remediation quality. For operators, the practical test would be whether a shared view can answer a few questions during triage: what workload is affected, whether it is exposed, whether an exploit is known, and which customer or business function is at risk.
This story draws on original reporting from SiliconANGLE.