October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

AT&T Cybersecurity Spin-Off: What LevelBlue Is—and Why It Is Not a Typical Startup

LevelBlue launched in May 2024 as a standalone managed-security joint venture backed by AT&T and WillJam Ventures. Here is what it inherited, how AT&T remains involved and how Trustwave, Cybereason and Alert Logic changed the company.
From TheFinanceBase Team6 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

LevelBlue launched on May 6, 2024, at the RSA Conference as a standalone managed-cybersecurity company created by AT&T and WillJam Ventures. It was formed from selected AT&T Cybersecurity software, security operations, personnel and consulting resources—not built from scratch as a conventional venture-backed startup. AT&T retained an ownership stake and board representation, while continuing to develop security embedded in its network and connectivity products.

That distinction matters. The launch story described a new corporate structure, but by August 2026 LevelBlue had expanded substantially through Trustwave, Cybereason and an Alert Logic-related transaction. It is best understood today as a large, sales-led managed security services provider (MSSP), not simply a renamed AT&T product line.

What exactly launched?

AT&T announced the planned standalone business on November 17, 2023, then publicly introduced the LevelBlue brand on May 6, 2024. The transaction was a joint venture between AT&T and WillJam Ventures. Its initial scope included selected managed-security operations, software, threat intelligence and consulting capabilities from AT&T Cybersecurity.

Calling LevelBlue an “AT&T Cybersecurity spin-off” is useful shorthand, but “spin-off” can imply that AT&T completely exited. That did not happen. AT&T kept an ownership interest and board representation, and the announcement did not disclose exact ownership percentages or financial terms. The arrangement was an asset separation and joint venture, not a clean divestiture.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

LevelBlue’s own launch description is available at LevelBlue’s May 6, 2024 announcement; AT&T described the transaction in its November 17, 2023 release.

Why AT&T created LevelBlue

AT&T gave the new company a focused operating model for the global managed-security market. AT&T itself said it would concentrate more heavily on security integrated directly into its network and connectivity products, including offerings associated with business connectivity and the network edge.

The logic is strategic rather than merely cosmetic. A standalone security company can sell managed services without being perceived only as a telecom add-on, while AT&T can prioritize network-embedded protection. WillJam brought cybersecurity investment and operating experience. It is reasonable to infer that the structure also preserves access to AT&T relationships and technology while reducing potential conflict between a broad MSSP strategy and AT&T-specific network products; those are analytical implications, not disclosed transaction terms.

What LevelBlue sells

LevelBlue launched with managed security, consulting, threat intelligence and continuous security-operations support. Its current portfolio is broader and includes both services and software.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
Category Examples Typical buyer need
Managed detection and response 24/7/365 detection, investigation and response Outsourced security operations for an under-resourced team
Managed XDR, SIEM and co-managed SOC Managed extended detection and response, SIEM and co-managed operations Support while retaining some internal control
Security platforms USM Anywhere and Fusion Centralized visibility, analytics and security workflows
Network and cloud security Managed cloud security, SASE and secure service edge Protection across distributed infrastructure
Advisory and testing Threat hunting, vulnerability management, penetration testing and cyber advisory Readiness, assessment and risk reduction
Incident response Incident readiness, response, forensics and related professional services Preparation for or recovery from a breach

See the LevelBlue service portfolio and its managed detection and response description for the vendor’s current scope. LevelBlue says MDR onboarding can take 10 days or less and describes 24/7/365 operations; both are vendor-stated service claims, not universal guarantees. Response permissions, telemetry coverage and escalation procedures depend on the contract and deployment.

The AlienVault and USM Anywhere connection

Former AlienVault and AT&T Cybersecurity customers will recognize the technology lineage. IDC describes LevelBlue’s USM Anywhere as descended from AlienVault’s USM Anywhere Open XDR product.

USM Anywhere combines centralized security visibility with SIEM functions, vulnerability scanning, threat intelligence and detection-and-response workflows. It integrates with LevelBlue threat intelligence and Open Threat Exchange telemetry. LevelBlue now markets it as an Open XDR platform for organizations and MSSPs seeking consolidated monitoring and automated workflows. It is therefore not a brand-new product created after the LevelBlue launch; its roots predate the brand.

Product lineage is documented in the IDC MarketScape report, while LevelBlue’s current product page is USM Anywhere XDR.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

How LevelBlue changed after launch

The company’s scale and portfolio changed quickly. The key public milestones are:

  1. Trustwave: LevelBlue announced an agreement in July 2025 and completed the acquisition on August 19, 2025. The combination added Trustwave’s MDR, offensive-security, advisory and government capabilities. LevelBlue called the resulting company the world’s largest managed security services provider; that is a corporate claim rather than an independently verified market ranking. Details appear in the acquisition announcement and completion release.
  2. Cybereason: The acquisition closed November 25, 2025, adding XDR, endpoint security, threat intelligence, and digital-forensics and incident-response capabilities. SoftBank Corp., SoftBank Vision Fund 2 and Liberty Strategic Capital also invested. See the completion announcement.
  3. Alert Logic: On January 27, 2026, LevelBlue and Fortra announced a strategic partnership that included acquiring Fortra’s Alert Logic MDR business. The announcement establishes the transaction, but not a complete timetable for technical integration.

These deals mean a May 2024 description is now historical context. Customers should not assume that every acquired service uses one portal, one contract or one SOC without confirming it.

Who buys LevelBlue?

LevelBlue targets enterprises needing 24-hour monitoring, organizations with heterogeneous security tools, Microsoft-focused environments, government and regulated-sector customers, and companies seeking threat hunting, vulnerability management, consulting or incident response. It also markets to MSPs, MSSPs, VARs and distributors through a partner program.

The commercial model is sales-led. LevelBlue’s pages direct prospects to request pricing or a sales conversation; no standard public list pricing is stated on its services page or contact page. A buyer looking for a simple, transparent endpoint-only subscription may find the portfolio more extensive than necessary.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What MDR does—and does not—promise

LevelBlue describes MDR as continuous detection, investigation and response using customer telemetry, behavioral analytics, threat intelligence and response actions, with a dedicated Cyber Success Team. “24/7 monitoring” does not mean every alert receives immediate human intervention, and MDR does not replace patching, identity hardening, asset inventories, backups or an internal incident-management process.

Before signing, establish:

  • Which endpoint, identity, cloud, network, SaaS and operational-technology data sources are supported and retained.
  • Whether LevelBlue may isolate endpoints, block accounts or change controls automatically, and who authorizes those actions.
  • What containment and forensic work is included, what is extra, and how after-hours escalation works.
  • Whether the service is fully managed, co-managed or advisory.
  • Service-level commitments, SOC locations, data residency and subcontractors.

Government and compliance qualifications

LevelBlue states that its MDR service has FedRAMP certification. That statement must be tied to the specific service, authorization boundary and current authorization status; it does not automatically make every LevelBlue product or acquired capability government-authorized. Regulated buyers should request the authorization documentation and verify data location, incident-notification deadlines, encryption, key management and audit rights.

Questions for an existing AT&T, AlienVault or acquired-customer account

Brand continuity does not by itself establish technical or contractual continuity. Ask the account team:

  • Is the existing contract being assigned, amended or replaced?
  • Will the current portal, SOC and escalation contacts remain?
  • Are service-level agreements and data-retention terms unchanged?
  • Which LevelBlue or legacy product will operate the service after any migration?
  • Will Trustwave, Cybereason or Alert Logic capabilities be integrated, optional or separately managed?
  • What data-export and termination procedures apply?

LevelBlue’s main trade-offs

Potential advantages

  • A broad portfolio spanning MDR, XDR, consulting, offensive security, threat intelligence and incident response.
  • Support for existing, heterogeneous security investments rather than a requirement to replace every tool.
  • Inherited AT&T and AlienVault operating experience, expanded by Trustwave and Cybereason capabilities.
  • Access to a large MSSP operating model for organizations that cannot staff a full SOC.

Potential risks

  • Acquisition breadth can create duplicated portals, contracts, tools and escalation paths.
  • Large-provider processes may be less customized than a specialist boutique.
  • Public pricing is unavailable, making early comparisons difficult.
  • Customers seeking a purely independent vendor may weigh AT&T’s continuing ownership.
  • A platform purchase without internal response ownership can produce little security improvement.

How to evaluate LevelBlue against alternatives

Compare the operating model, not just feature lists. Microsoft Defender Experts for XDR is a natural fit for organizations standardized on Microsoft security and cloud services (Microsoft details). CrowdStrike Falcon Complete emphasizes endpoint and identity protection (CrowdStrike details). Arctic Wolf focuses on managed detection and response across a broad ecosystem (Arctic Wolf details), while SentinelOne Vigilance MDR is most natural for SentinelOne-centered environments (SentinelOne details).

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For each provider, obtain a written coverage matrix, minimum telemetry commitments, response-authority rules, retention periods, data-residency terms, measurable service levels and exit procedures. Measure outcomes such as time to contain, remediation and recovery—not alert volume alone.

Bottom line

LevelBlue is best described as AT&T’s managed-security business reorganized into a standalone joint venture backed by AT&T and WillJam Ventures. It launched as a newly independent company, but inherited mature operations, customers, personnel and AlienVault-derived technology. AT&T remained involved and retained its own network-embedded security strategy. After the Trustwave and Cybereason acquisitions and the Alert Logic-related transaction, LevelBlue is no longer accurately portrayed as a small startup; it is a broad, enterprise-focused MSSP whose fit depends on service scope, integration requirements, compliance boundaries and the buyer’s willingness to navigate a consultative sales process.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.