AWSCIO BriefingsRetrospectives

CIO Brief: Owning Your Security Data — The OCSF Shift

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2022, written in 2026 with the benefit of hindsight.

The short version: In 2022, AWS introduced Security Lake, which stores your security logs in your own cloud account, in a standard format any security tool can read. The bigger idea: you shouldn't be locked into one vendor's tool to access your own security data.

Why owning your security data matters

Many organizations send all their security logs to a single SIEM vendor and pay based on volume. Switching vendors becomes costly, and keeping logs for years becomes expensive. A security data lake keeps logs in cheaper storage you control, in an open format (OCSF), and lets multiple tools use them.

The business impact

  • Lower long-term storage costs.
  • Flexibility to change or add security tools.
  • Better investigations with longer history available.

The trade-offs

  • Another system to manage.
  • Querying a data lake is slower than a SIEM for real-time detection.
  • Requires skills in data management.

Questions to ask your team

  • How much do we spend on security log storage each year?
  • How far back can we search during an investigation?
  • Could we switch SIEM vendors without losing historical data?

What good looks like

Recent, high-value data in your SIEM for fast detection; longer history in a lake you own; a standard format so tools can change without data migration.

The decision

At your next SIEM renewal, ask for an architecture that separates detection from long-term storage. It's often cheaper and more flexible.

amazon security lake impactre:Invent 2022 Security Lake2022

More on this story