AT&T and WillJam Ventures officially launched LevelBlue on May 6, 2024, as a standalone managed cybersecurity joint venture. AT&T retained an ownership stake and board representation; the move did not mean it abandoned cybersecurity. Instead, selected AT&T security operations, software and consulting resources became part of LevelBlue while AT&T continued pursuing security embedded in its connectivity services.
What launched—and when
LevelBlue was not simply a new name for an AT&T product. It became the operating identity of a standalone cybersecurity-services business jointly formed by AT&T and WillJam Ventures. AT&T announced the planned arrangement on November 17, 2023; the company formally launched at RSA Conference on May 6, 2024. The distinction matters: the November announcement described the planned structure, while May was the public launch of LevelBlue. AT&T’s November 2023 announcement · LevelBlue’s launch announcement
- November 17, 2023: AT&T announced its plan to create a standalone managed cybersecurity business with WillJam Ventures.
- May 6, 2024: LevelBlue officially launched at RSA Conference.
- October 2024: LevelBlue announced services planned for its partner program, with availability described for Q1 2025.
- March 2025: The company announced an expanded three-tier partner program for MSPs, MSSPs and resellers.
The launch announcement described a company with more than 1,000 employees globally, four global security operations centers (SOCs) and three global network operations centers (NOCs). These are company-reported launch-era figures, not verified current headcount or a promise that every customer uses every facility. LevelBlue’s launch announcement
Who owns LevelBlue, and what stayed with AT&T?
WillJam Ventures is LevelBlue’s investor and strategic partner. AT&T is its former parent and continuing minority owner, with representation on LevelBlue’s board. The cited launch announcement does not disclose the ownership percentage or financial terms. LevelBlue is the standalone operating cybersecurity business; it is not wholly independent of AT&T in ownership or governance. LevelBlue’s launch announcement
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems#1 Best Overall
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 3 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
AT&T described the business as built from selected cybersecurity software, managed security operations and consulting resources. That wording does not establish that every AT&T cybersecurity product, customer contract or intellectual-property asset moved to LevelBlue. AT&T also said it would continue offering Managed Security Services while focusing on enhanced network-based security capabilities. AT&T’s announcement
Why separate the businesses?
The stated division was between a focused managed-security and consulting operation at LevelBlue and AT&T’s continuing work on security tied to its network and connectivity offerings, particularly for small and medium-sized businesses. A reasonable strategic interpretation is that a standalone company can concentrate its hiring, sales, partnerships and product roadmap on cybersecurity, while AT&T can emphasize connectivity-linked security. WillJam’s involvement also brings outside investment and cybersecurity-industry operating expertise; those are strategic implications, not a guarantee of better service or outcomes.
What LevelBlue offered at launch
The May 2024 launch grouped LevelBlue’s capabilities into managed security services, cybersecurity consulting, threat intelligence and continuous SOC support. These categories address different needs: outsourced operations for teams with limited coverage, expert advice for programs being built or modernized, and threat context to help security staff interpret activity.
Rank #2
- Enterprise-grade prevention, detection, correlation and response from the perimeter to the endpoint with our Total Security Suite.
- Gain critical insights about network security, from anywhere and at any time, with WatchGuard Cloud.
- Built-in compliance reports, including PCI and HIPAA, mean one-click access to the data you need to ensure compliance requirements are met.
- Up to 18 Gbps firewall throughput. Turn on all additional security services and still see up to 2.4 Gbps throughput.
| Capability | What it covers | Potential use |
|---|---|---|
| Managed security services | Security operations, monitoring, reporting and risk-management support as an extension of a customer’s internal team. | Organizations that need additional operational capacity or help scaling a security program. |
| Cybersecurity consulting | Priority assessments, secure architecture and environment design, network-security transformation, risk identification, preventive controls, remediation planning and program efficiency. | Businesses building, assessing or modernizing security processes and infrastructure. |
| Threat intelligence | Threat information supported by machine learning and the Open Threat Exchange (OTX). | Security teams seeking external indicators and context to inform detection and investigation. |
| SOC and service support | Company-reported operations through four global SOCs and three global NOCs, with monitoring described as 24/7/365. | Organizations needing continuous operational coverage or support across distributed environments. |
At launch, LevelBlue said OTX had more than 235,000 security professionals and received more than 20 million threat indicators daily. Those are figures stated in the May 2024 launch materials, not independently verified current metrics. Similarly, “24/7/365” describes the company’s stated monitoring and support coverage; it does not by itself establish immediate containment, identical coverage for every service or guaranteed response times. LevelBlue’s launch announcement
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Technology and legacy capabilities
LevelBlue’s launch drew on AT&T’s cybersecurity heritage, including AlienVault-related threat-intelligence capabilities and OTX. Later partner materials identify USM Anywhere as a central platform in the service ecosystem, integrating security monitoring and threat intelligence across on-premises, cloud and hybrid environments. The later description should not be read as proof that USM Anywhere or every related service was part of the May 2024 launch scope. LevelBlue’s partner-program announcement
How LevelBlue’s services expanded after launch
Later announcements broadened the public picture of LevelBlue’s portfolio and channel strategy. These are subsequent developments, not a list of everything announced on launch day.
Rank #3
- Entry-Level Privacy Gateway: Designed for users who want simple online privacy protection at an affordable level—ideal for basic home networking and daily internet use.
- Secure Browsing for Everyday Needs: Perfect for email, social media, online shopping, and standard streaming—protecting your connection while keeping setup and operation easy.
- Lightweight Protection Against Common Online Threats: Helps reduce exposure to unwanted ads, trackers, and risky websites, improving online safety for your household.
- Simple Setup, No Technical Skills Required: Plug it in, follow the quick steps, and start using—an excellent choice for beginners who don’t want complicated network configurations.
- Decentralized VPN (DPN) Included – No Monthly Payments: Get built-in decentralized VPN access with lifetime free usage, helping you stay private without paying recurring subscription fees
- October 2024: LevelBlue announced four services for its planned partner program: managed threat detection and response, incident-response retainers, vulnerability management and managed endpoint security. The announcement described availability for Q1 2025. LevelBlue’s October 2024 announcement
- March 2025: The company announced a three-tier partner program for MSPs, MSSPs and resellers. Its described portfolio included USM Anywhere, managed threat detection and response, managed vulnerability scanning, penetration testing, incident-response retainers, email security powered by Check Point and managed endpoint security powered by SentinelOne. The program also offered training and dedicated support. LevelBlue’s March 2025 announcement
- Current public services directory: LevelBlue lists MDR, MXDR, co-managed SOC, SASE, SSE, managed cloud and network security, endpoint security, DDoS defense, penetration testing, vulnerability management, incident readiness and response, cyber advisory, USM Anywhere and Fusion. A current listing is not evidence that each service was available at launch or is offered on identical terms in every market. LevelBlue services
The partner program makes the channel part of LevelBlue’s strategy: an MSP or reseller can use the company’s services to add security capabilities, rather than LevelBlue selling only to enterprise customers directly. For a prospective partner, the program’s existence does not settle commercial details such as margins, white-label rights or customer ownership; those need to be checked in the actual agreement.
What the change means for customers
Customers may encounter two related but distinct propositions. AT&T continues to center its offering on connectivity and network services, including security features embedded in that portfolio. LevelBlue focuses on standalone managed cybersecurity, consulting, threat intelligence, SOC operations and the broader detection-and-response services it later publicized. AT&T’s announcement said it would continue offering Managed Security Services, so the launch should not be read as an exit from managed security. AT&T’s announcement
Recommended Free Tools
The public launch materials do not establish that all existing AT&T cybersecurity customers were automatically transferred, that contracts were universally novated, or that support arrangements remained identical. Existing customers should use their own contract, account team and service documentation to confirm provider, responsibilities, escalation paths and any changes that apply to them.
Rank #4
- Single appliance with integrated firewalling, SD-WAN and Wi-Fi controller reduces complexity of WLAN management. Its zero-touch deployment helps optimize your onboarding experience.
- Built on a patented secure processor, this compact network firewall delivers the highest level of security and performance in its class – 800 Mbps IPS | 500 Mbps threat protection.
- User-friendly management console gives you centralized visibility and simplifies policy enforcement across your network. Its zero-touch deployment helps you optimize your onboarding experience.
- Compact and fanless design equipped with 4 GE RJ45 ports (1 WAN port and 3 internal ports) provide essential connectivity and flexibility for various network configurations in a small-scale environment.
- Including award-winning FortiGate hardware and 3-year FortiGuard AI-powered UTP security services. Services cover IPS, Advanced Malware Protection, Application Control, URL, DNS & Video Filtering, Antispam Service, and FortiCare Premium customer support.
Who might consider LevelBlue?
- Enterprises and commercial organizations seeking outsourced or co-managed security operations.
- Organizations that lack the staffing or expertise to monitor security signals continuously.
- Businesses with hybrid or multi-vendor environments that want managed services alongside consulting or response support.
- MSPs, MSSPs, resellers and systems integrators evaluating services to add to their own customer offerings.
LevelBlue’s breadth may help a buyer reduce the number of separate providers, but it can also bring integration and contract complexity. Buyers already invested in Microsoft, Cisco, endpoint security or another SIEM may need better operations and integration rather than a wholesale platform replacement. A network-centered security proposition may be less relevant when most assets are remote, cloud-hosted or SaaS-based.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What buyers should verify before signing
“Managed,” “24/7” and “response” can describe materially different service commitments. Ask for the service description and contract terms, not just a product summary.
- Define the environment in scope. List endpoints, identities, cloud accounts, networks, SaaS applications and any OT/IoT or unmanaged assets. Confirm which systems and data sources are covered.
- Establish response authority. Ask whether the provider only alerts and recommends actions or can isolate endpoints, block indicators, disable accounts or change controls. Identify actions requiring customer approval.
- Check integrations and platform dependencies. Confirm support for existing SIEM, endpoint, identity, firewall and cloud tools; ask whether the service is optimized for USM Anywhere, Fusion or another platform and what functionality differs across integrations.
- Document onboarding requirements. Get the required agents, sensors, log sources, access permissions, retention periods and data-transfer arrangements, along with expected deployment time and customer responsibilities.
- Separate monitoring from incident response. Clarify whether threat hunting, digital forensics and incident response (DFIR), containment, evidence handling, legal coordination and post-incident remediation are included, retained separately or priced as additional work.
- Confirm service levels. Request written targets for alert triage, escalation, response, availability and service credits. Distinguish a monitoring schedule from a guaranteed containment deadline.
- Review geography and compliance. Ask about data residency, SOC locations, subcontractors, relevant certifications and regulatory support, as well as contractual breach-notification and escalation obligations.
- Compare the full commercial model. Ask whether billing is based on users, endpoints, assets, log volume, cloud accounts, sites or service tiers. Review minimum commitments, overages, implementation charges, renewal increases and cancellation terms.
- For a partner arrangement, check channel terms. Clarify margins, white-label rights, customer ownership, escalation procedures and which party provides first-line support.
LevelBlue’s public services pages use “Request Pricing” rather than publishing standard list prices, so buyers should expect to request a proposal and compare its pricing unit, implementation costs and contract terms with competing bids. LevelBlue services
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchBest Value
How to judge the business beyond its launch claims
LevelBlue’s significance is structural: AT&T moved selected cybersecurity resources into a focused joint venture while keeping a separate network-security strategy. That structure could support greater cybersecurity focus and a wider partner channel, but the launch announcement alone cannot show whether customers receive better detection, faster response or lower costs.
For a buyer, the practical test is whether a proposed service fits the existing environment, provides the necessary response authority, meets compliance and data-location requirements, and offers contractually clear service levels at an acceptable total cost. A broad portfolio is useful only if its integrations and operational responsibilities are clear. Treat machine-learning and AI descriptions as claims about approach, not proof of superior accuracy; ask for detection coverage, analyst involvement, false-positive handling and response metrics relevant to the proposed service.
LevelBlue is therefore more than an AT&T rebrand, but its value to any organization depends on the specific service, contract and operating fit—not the corporate launch alone.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.




