
Without a doubt, security is critical — yet a tangle of tools leaves many businesses navigating blind.
In the first of this two-part feature, Datadog CEO Olivier Pomel discussed the company’s direction in agentic AI and the central role of observability in its strategy. This time, he shares his thoughts on security — including market differentiation, the challenges facing security operations centre (SOC) teams, and Datadog’s broader approach.
Security first
No organisation can afford to deploy a solution vulnerable to threats like phishing or ransomware. Regardless of strengths in scalability or observability, inadequate security undermines a system’s integrity. According to Pomel, the only way to build secure products is to make security a shared responsibility across development, operations, and security teams.
“You can’t just have the security team do it just because it’s too small. In any company, for every security engineer, there are 10 operations engineers, and for every operation engineer, there are 10 software engineers,” he said.
Pomel explained that Datadog’s security portfolio is designed for both security teams and those working in software development and operations.
“We have a product aimed at security teams, and the rest are geared more towards developers and operations. These are about understanding the vulnerabilities in your code and infrastructure, and how you address them. It’s less about identifying bad patterns or threats, and more about seeing what your code and infrastructure are doing, right or wrong,” he remarked.
He acknowledged that both SOC and application security teams are often overwhelmed with scanning alerts and incident response.
“The moment you turn on scanning, whatever product you’re using, you’ll get 20,000 vulnerabilities. What do you do next? You can’t possibly get to all of them, so how do you prioritise?” Pomel said.
One way to ease this burden is through AI, especially as attackers become more sophisticated in their use of the technology.
“If you have 10,000 vulnerabilities in your application, and 12 of those are really bad, those 12 can be identified much more easily today by AI agents than two years ago by human analysts. That means defenders have to respond faster, and they need AI to help do that,” he said.
Fragmented infrastructure
The fragmentation seen during the pandemic still persists; enterprises remain reliant on a patchwork of security tools, leading to complexity and inefficiency.
“As a customer, you might need 12, 15, or even 24 products to cover your entire security surface. The problem is that it’s hard to get full internal usage across all of them. There are gaps between tools, it’s difficult for teams to switch between them, and in the end, you’re buying more than you use, and missing out on the value,” Pomel explained.

To address this, he said Datadog has applied the same integrated platform approach to security that it used for observability.
“Because we already cover observability, we’re already deployed everywhere. We have the signals. We know what’s happening on the machines and networks, what users are doing, what the engine is doing, what the code is, and what’s happening to it. So we already have a lot of the data we need,” he said.
Pomel acknowledged the highly competitive nature of the security space, where many vendors offer point solutions for the same niche. Even so, he said Datadog remains focused on its platform-based approach.
“We’re working to build a complete security suite that matches what these other companies offer individually. Then, we can add value by ensuring there are no gaps across the entire stack. That’s what drives adoption,” he said.
Market segmentation
While large enterprises remain Datadog’s core market, Pomel said smaller players are also important, even if they represent less than 1% of revenue.
He described how market dynamics differ between SMBs and larger organisations: “The SMB, cloud-native side is much more cutthroat than the enterprise side. Developers are fickle. They have many options — they can build their own tools, use open source, or try new vendors. An individual developer isn’t just dealing with a shortlist of scaled companies; they’re looking at everything,” he said.
By contrast, he said the enterprise space tends to revolve around a familiar group of vendors.
“It’s not as dynamic, but we’ve decided not to abandon either end of the market. We want to cover everything, from the very low end and emerging technologies to the largest enterprises,” he noted.
In the long run, Pomel believes these smaller customers will become increasingly valuable.
“That low end gives us a window into what’s coming for the rest of the market in one, two, or three years. They’re the first to integrate with new technologies. Some will grow into future leaders, and become key drivers of our growth over time,” he said.













