ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Why the data feeding your data lake could be your biggest security blind spot  

Danielle Kinsella at Gigamon explores the risks that organisations face when moving their data to data lakes

Linked InXFacebook
bookmark_borderSave to Library

We are starting to see a real shift in how organisations store and manage their data. After years of spreading it across tool-specific platforms and migrating everything into the cloud, business leaders are now asking harder questions about the return on that effort. Cloud costs have risen beyond expectations, with Gartner reporting that public cloud spending jumped 20.4% last year; performance has been uneven, and confidence in public cloud security has softened. In response, the centralised data lake is gaining momentum, which promises lower costs, greater flexibility, and a stronger foundation for AI models.  

 

Whilst it is a sensible evolution, the problem is that it’s happening without sufficient scrutiny of what data is being fed into these lakes, or how access to that data is being governed. Without this, organisations risk creating a new set of performance, efficiency and security risks, just in a different place. 

 

The economic reasons behind the migration 

To understand why data lakes are gaining such traction across sectors, you need to look at the factors behind the current architectures. For years, many organisations funnelled data into log management and analytics platforms because they offered powerful querying and analysis capabilities at a price tied directly to volume. As the amount of data being ingested has grown, so have storage and licensing costs, creating an economic tension that pushed many organisations to look for a cheaper, more flexible model.  

 

By adopting data lakes, organisations can substantially lower storage costs and have the flexibility and visibility needed to feed data to multiple tools without duplicating data or paying premium usage fees. Cloud dynamics have also accelerated the shift towards data lakes. According to the Gigamon 2026 Hybrid Cloud Security Survey of more than 1,000 security and IT leaders, 70 percent now regard public cloud as their riskiest environment. This shift in perception, combined with rising costs and uneven performance, has created real momentum for alternatives.  

 

Mind the data gap 

Moving data into a lake doesn’t automatically make it more useful or secure; that depends entirely on the quality, completeness, and integrity of what goes in. Traditional monitoring approaches generate metrics, events, logs and traces that describe what systems say they’re doing and log what was flagged and reported. It’s a valuable but partial view shaped by what those systems can record, rather than what is actually happening at the network level, which provides the complete picture of your risk profile. 

 

Instead of relying solely on tools reporting on themselves, organisations can capture immutable telemetry directly from network packets and feed it into the data lake. The result is a richer, more trustworthy dataset that reflects actual behaviour rather than reported behaviour.  

 

Organisations are realising that this difference matters. The same study of global security and IT leaders revealed that 92 percent believe network-derived telemetry is critical to making data lakes both more efficient and more secure. This finding reveals across-the-board recognition that without visibility into what data is actually flowing in and out, a data lake becomes an architecture built on an incomplete foundation.  

 

Monitoring access control is critical 

Once an organisation consolidates everything into a single golden source—  encompassing HR records, customer data, and intellectual property—the hardest challenge becomes control and performance. For example, how do you ensure a security analyst cannot reach personal HR data? And as these lakes scale across the enterprise, how do you prevent the queries running within the databases from creating performance issues or operational incidents across the network? 

 

A poorly governed lake can undermine the very investment it was meant to justify. Organisations are spending millions on building an AI capability, yet risk creating a system that either causes problems elsewhere or returns data so slowly that no one uses it. Network-level visibility changes the equation by feeding immutable telemetry that teams can trust and act upon directly into the lake, without waiting on the network team to investigate on their behalf. 

 

The compliance impact is just as significant. For organisations in regulated sectors, answering to bodies such as the Prudential Regulation Authority (PRA) or Financial Conduct Authority (FCA), the ability to produce evidence quickly is essential. Network telemetry accelerates this process and expands it beyond point-in-time responses. Continuous monitoring frees teams from scrambling to assemble evidence after the fact by maintaining an always-on view of what is happening across their environment, surfacing potential breaches or compliance incidents as they emerge. Enriching a data lake with network telemetry is what makes that shift possible, turning compliance from a reactive exercise into a proactive posture that teams can evidence at any moment. 

 

Building a strong foundation  

Getting value from a data lake demands a shift in mindset. For years, the focus has been on storage efficiency, while governance, data quality, and visibility were treated as secondary concerns. But a data lake is only as strong as the data flowing into it, and the controls governing access to it, and organisations that lead with those questions will be the ones that turn a repository into genuine advantage. 

 

Network-derived telemetry closes the gap. By feeding immutable, packet-level data into the lake alongside metrics, events, logs, and traces, organisations create a dataset that reflects their actual security posture rather than an assumed one. This shift enables security teams to move from reconstructing incidents after the fact to understanding it in near real-time and provides AI models with the accurate and complete data they need to operate effectively. 

 

The organisations that get this right will build data lakes that are both secure and efficient, and they’ll have the confidence to act. 

 


 

Danielle Kinsella is Technical Director EMEA at Gigamon

 

Main image courtesy of iStockPhoto.com and Floriana

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543