IT Tech Pulse Exclusive Interview with Michael Cucchi Chief Product and Marketing Officer at Hydrolix

Stay updated with us

Michael Cucchi Chief Product and Marketing Officer Hydrolix
🕧 23 min

Michael Cucchi, Chief Product and Marketing Officer at Hydrolix, explores how unified telemetry, real-time analytics, and AI are transforming modern security operations.


Michael, you’ve spent two decades in product and marketing leadership across  companies like Sumo Logic, PagerDuty, Riverbed, and Akamai. How has that  path across observability, security, and CDN shaped how you think about the  problems Hydrolix is solving today? 

It has been a journey backed by the lifecycle of data and the value of telemetry. When I first began working in the space, there were many varied areas of “performance management,” which were places collecting information. However, we looked at it in a truly siloed fashion, mimicking our organization types. There was technology for network security and network performance management for networking teams. There was technology for application performance management and application security for app teams. There was technology for infrastructure monitoring for systems teams. Over time, those markets merged into what we called “observability,” which was the same set of data but unified and being used specifically for digital operations to optimize software, run software online, and keep it running really well and efficiently. At the same time, that same data was being merged with security telemetry and used by security teams for security operations, threat detection, identifying malicious actors and stopping them, and for building policies so they can’t do it again.

What we see now is those data sets merging into a single intelligence layer so that security and support teams can get their jobs done with a single source of truth. Even in the market today, you can see acquisitions playing out this trend. Security companies are buying observability companies because it’s now one problem – collect critical telemetry and root cause source-of-truth data so you can secure and maintain software responsibly. This data set has matured and is now the center of many of our businesses, as opposed to bespoke siloed technology applications. We now know how critical the data is. The data is gold. We can’t afford to lose data, and we can’t afford to miss a fact. That’s why being at Hydrolix at this time is amazing. Not many technology platforms can scale to ingest all that data, and if they can, they are extremely slow and expensive. Hydrolix is focused on ingesting all that data and making it immediately available for analytics so that you can do security operations or digital operations. 

Lastly, we are in this next chapter – the AI and agentic AI era. AI will generate new telemetry that’s critical to be captured. It needs to go in the same place and be correlated with the rest. The way we get security and digital operations done will be drastically enhanced and transitioned over to AI.  That’s where Hydrolix is unique. We are a data layer for security and agentic operations. That’s what this announcement was about.

Hydrolix just announced the Security Data Layer, designed to sit underneath  existing SIEMs like Splunk rather than replace them. What gap in security  operations pushed you to build it this way instead of positioning it as a SIEM  alternative? 

There are a couple of primary sacrifices that had been accepted that were handicapping security teams. Security teams have been forced for a long time to do security by budget. The common architecture for a security team would be to force themselves to prioritize the most critical data for threat detection and send that to the SIEM for real-time detection. Generally for an enterprise, that’s about 30% of their data. They had to make that decision and sacrifice because it’s hard to do threat detection and it’s expensive to send data to a SIEM. So, with that 70% of data, they had to make hard decisions.

In security, you can’t sample data because you must have the source of truth. If you sample, you may throw out critical evidence. So instead of sampling, you are forced to put something offline, archive it, or, worst case, decide what to throw out. The result is an incomplete view of what should be a full view of evidence. With what Hydrolix built, your threat detection and threat hunters are still in their native SIEM interface, inside Splunk, doing their job with the tool they know and love. But by federating to Hydrolix, those sacrifices can be erased. Instead of archived data that can take hours or sometimes days to be brought back online, all while you’re being hacked by malicious actors, now you have all data online, hot, immediately available, and you can get to it through Splunk. This extends the ability to find the root cause, perform root cause analysis, and accelerate incident response. It also opens long-term retention for compliance, trend analysis, and slow and low threat analysis that you may not have done before.

The launch referenced real-world testing with RAD and Monad using live Splunk  data, where broad correlation searches returned results in about 1.6 seconds.  What did that validation tell you about how security teams actually work during a  live investigation? 

It’s critical that security teams can maintain their native workflows during an incident. We don’t want them to have any type of change cost or learning curve, and so the ability to deliver this in the Splunk interface means there’s nothing new to learn and everything to gain. 

When a security incident occurs, every second counts. It was also critical to us that the security analyst didn’t feel a difference between the experience of querying data inside native Splunk or extending the query across the Hydrolix Security Data Layer. So we needed to return results near native Splunk performance. Most humans are willing to wait three to four seconds for a response, so we were excited to be within human expectations. It was even more exciting that these performance results were over such extended data sets. The key is that Hydrolix works seamlessly inside security teams’ workflow and operates in a way that’s transparent to them so they don’t know the data they are querying is on Hydrolix.

A recurring theme in your writing is that retention has quietly become a cost  decision rather than a security one. Why do you think shortened retention  windows became normalized across the industry, and what’s the real cost of that  trade-off? 

Retention is a huge problem in the industry. I will walk through a couple of areas where it was accepted that you couldn’t keep historical data. One is endpoint security telemetry – XDR and EDR traffic. It’s a ton of data, so most solutions allow you to only keep seven days’ worth of that data. So, you are looking at the security landscape through a periscope when you want to zoom back and see weeks and months worth of that type of data. 

In the bot management, bot intelligence, and DDOS prevention space, generally companies keep 30 days’ worth of traffic. In ecommerce, for example, where the world works seasonally, 30 days is not enough data to optimize content for humans and AI bots. It’s also not enough data to predict seasonal trends and changes. For many use cases across security and observability, companies put in retention limits, age out, and delete data from their analytic view. Adding Hydrolix into the reference architecture can have a huge impact on removing that barrier from businesses.

For teams weighing this today, how does a purpose-built data layer like Hydrolix  Search for Splunk change the economics of keeping months or years of high volume telemetry hot and queryable, without asking analysts to change how they  work? 

All telemetry data is critically important. It’s not just about network, application, enterprise, or CDN data; you need all data accessible. And then pile AI into there. So you need to manage this with a new economy, and that’s going to require a set of different point solutions purpose-built for the problem. But as you bring complexity into your architecture, your users, threat hunters, security analysts, and SREs can’t be asked to adopt that complexity. This has to fit into the existing stack. That’s why plugging into a powerful tool like Splunk is a critical part of this announcement. Once you plug into the existing stack, you don’t have to limit your investigations, analytics, application optimization, threat hunting and analysis, investigations, audits, or compliance use cases because you are putting it into a purpose-built data layer, where all data is always hot and always queryable. To top it off, you can keep 15 or 24 months of data, instead of seven or 30 days, but that all has to be natively plugged into your users. That is achieved through next-generation compression and our data architecture. That’s why our announcement is so exciting because it’s a low lift for the practitioner, but it’s a big return for the business.

Looking ahead to 2026 and 2027, how do you see agentic SecOps and AI-driven  detection reshaping the volume and role of security telemetry, and what will  separate teams that are ready from those that aren’t? 

Agentic AI will give us a lot more data to manage and do analytics across. But also, it changes the way we solve problems and the way digital and security operations are carried out. So it’s critical for Hydrolix that everything we deliver has an MCP-first approach because the agentic AI layer is going to be rapidly accelerated via MCP. Every capability we release is MCP-enabled and comes packaged with Claude skills so you can immediately leverage that technology. Agentic workloads and AI automation will transform security and AI operations, so making a data layer that’s AI-native was something we thought about from the first design.

Unfortunately, as we are seeing in the press now, what started as the first hack by an AI agent ever has now cascaded into what looks to be a new hack by an AI agent daily. We know agentic security operations will be paired with agentic malicious agents, and so now more than ever we need all this data and we need to act on it in a real-time fashion.

Before we wrap up this interview – what’s one piece of advice you’d give to  CISOs and SOC leaders who are currently having to choose between retention  depth and budget?

My piece of advice for CISOs and SOC leaders is that we are at the milestone where it’s time to consider a non-platform, non-homogeneous approach to securing your enterprise and to driving and innovating your security operations. When I look out at the technology space for identifying threats, stopping threats, autonomously defending your business, and arming your business against AI and agentic threats, I don’t see any single platform solving the problem today. To me, this is the time to define a new reference architecture where you select best-of-breed, purpose-built technologies and a mixture of agents from different vendors to solve security problems. My advice is to start thinking about that new reference architecture, and my bias is that it won’t be delivered by a single vendor. It will be a combination of innovative technology you want to pull together because while we are talking about this today, the adversaries and hackers are certainly pulling together theirs.

Thank you, Michael, for taking the time to share your insights with us.

Write to us [wasim.a@demandmediaagency.com] to learn more about our exclusive editorial packages and programmes.

About Michael Cucchi About Hydrolix

Michael Cucchi is Chief Product and Marketing Officer at Hydrolix, where he leads the company’s product, brand, growth strategy, and go-to-market initiatives as it redefines real-time analytics at internet scale.

With over 25 years of experience spanning systems engineering, product management, and marketing leadership, Michael has built a career helping high-growth B2B software companies scale and define categories. Most recently, he served as SVP of Product Marketing, Management, Design and Strategy at Sumo Logic, where he was central to the design and launch of Dojo AI, a premier agentic AI security operations platform.

Prior to Sumo Logic, Michael was VP of Product and Marketing at PagerDuty, where he scaled product, partner, and customer marketing functions while leading market intelligence, developer advocacy, and analyst relations. At Cognizant, he served as Global Vice President of Products and Marketing, establishing the company’s software innovation program and M&A strategy. He drove over $35 million in innovation funding, orchestrated multiple acquisitions across 15+ SaaS offerings, and scaled the business to over $250 million in ARR with $500 million in attached services. Earlier in his career, he held senior product marketing roles at Pivotal, Riverbed, and Akamai, launching pioneering technologies in analytics, network optimization, and cloud security.

Hydrolix is a Portland, Oregon-based real-time data platform for operational intelligence at internet scale. Founded in 2018, Hydrolix addresses the two scale barriers facing observability and security platforms: global scale and real-time performance. The platform delivers real-time analytics that get you insights in seconds across globally distributed data at internet scale—from servers and microservices to AI agents—while enabling years of retention through next-generation compression. Trusted by Fox, ABC, and Paramount for mission-critical live events, Hydrolix has grown to over 700 customers globally in just 24 months. For more information, visit www.hydrolix.io.

  • Kalpana Singh is an SEO Executive at IT Tech Pulse, where she optimizes digital content for maximum visibility and reach. Alongside her expertise in search engine strategies, she also contributes to interview preparation and supports editorial and publication workflows, ensuring content is both discoverable and impactful.