AI Reopens The Security Build Versus Buy Debate And Moves The Value To Data
Arpan Maheshwari, Vice President of Product at CloudSEK, argues that AI is changing which parts of the security stack companies can realistically build themselves, while specialized data remains in vendors’ hands.

Make The Security Digest one of your go-to sources on Google
Companies may have 10 different security products in their stack. They’re now asking whether they can build their own layer to correlate them all.
AI has made it possible for security teams to do internally what would have required a dedicated engineering group a year or two ago. Teams can pull data from several vendors, correlate it, and stand up a working dashboard in a day. It’s a capability that reopened a build-versus-buy debate.
Arpan Maheshwari, Vice President, Product at CloudSEK, has spent his career moving from software engineering into product leadership, including at Ontic, a physical security software company serving Fortune 50 clients, before joining CloudSEK to work on external threat intelligence. That experience has repeatedly put him across the table from enterprise security buyers asking whether AI now allows them to build more themselves. "Companies may have 10 different security products in their stack. They’re now asking whether they can build their own layer to correlate them all," he says.
Specialized data remains a vendor advantage
Maheshwari argues that teams shouldn’t focus on building data collection. “There's a lot of investment in both the initial setup and ongoing maintenance. So get the data from security vendors.” Those vendors have spent years accumulating specialized datasets that would be prohibitively slow and expensive for an individual organization to recreate.
“If I talk about credential leaks, for example, that's something our company has been working on for the last 10 years. So we have a dataset covering roughly the last decade. Now, as an organization, if I wanted to build that myself, it would be next to impossible,” he says.
The barriers extend beyond engineering. "A lot of this kind of data contains PII," Maheshwari notes. "If you decide to get into the data business yourself, you're introducing significant legal risk into your organization."
Access can be equally difficult to replicate. Sourcing infostealer logs from dark web forums, for example, depends on relationships built over years inside those communities. AI cannot shortcut the trust required to gain that access. Data formats also change constantly, creating ongoing parsing and maintenance work.
The build opportunity lies in correlation
Getting the data from vendors only solves the first part of the problem. Since no single vendor supplies every category of data a security organization needs, companies have to bring different sources together. Historically, that required centralized engineering teams and lengthy integration projects. Maheshwari sees that changing.
“What people are asking in the industry now is, 'Do you have an MCP server through which I can access your data?'” he says. Because MCP servers can connect with other MCP servers, teams can build an internal layer that pulls from multiple vendors rather than relying on each vendor to produce the final analysis. Work that once demanded significant engineering resources can increasingly be handled in-house.
Risks still remain. Correlation can involve proprietary, sensitive, and regulated information, so organizations still need infrastructure that prevents data from leaving controlled environments. "When we look at companies like Anthropic and tools like Claude, they're also developing their own security layers," Maheshwari notes. Once those safeguards are in place, the case for building internally becomes much stronger.
Speed and specificity make the build case stronger
The strongest advantage of building the correlation layer is that internal teams can create what they need faster and tailor it more closely to their organization. "Business insights, dashboards, or reports that previously took months and months to build can now be built within a day and shared across the organization," Maheshwari notes.
Another advantage is specificity. Incident response procedures vary between organizations, and getting an external vendor to understand and encode those workflows can take considerable time. "Once I have the data and the insights, I can create those SOPs pretty quickly myself," Maheshwari says.
The tradeoff is financial. "AI gives you a lot of power, but there's an inherent cost associated with it," Maheshwari cautions. "The number of tokens companies are using is increasing, and it's becoming a substantial expense on the balance sheet of any technology company today."
So building internally doesn't shrink the security budget; it only changes where that budget goes. Organizations still need to pay vendors for specialized data because internal AI systems have little value without reliable inputs. But some of the money previously spent on vendor-built dashboards, analysis, and custom insights can now support internal experimentation and development instead.
The next frontier is cross-domain security intelligence
Maheshwari sees one of the untapped opportunities in connecting physical security and cybersecurity, two functions that sit inside the same enterprise but typically operate with separate teams, technology stacks, and reporting lines despite increasingly overlapping risks. "Until now, nobody has really thought about correlating both datasets because there isn't a company in the world doing it at scale," he argues. Groups like Scattered Spider have used physical-world social engineering as an entry point for cyber intrusion, yet signals from each stage often remain in separate systems and investigations.
As AI makes it easier to connect previously siloed cybersecurity tools, the same capability could eventually bridge physical and cyber security, revealing patterns and use cases that have so far been difficult to see. "If someone can crack that, it's a gold mine, in my opinion, at least in the security world," he concludes.






