The Possibilities, Risks, and Rewards of Cyber Tech Convergence
RSA Conference 2024 · West Stage Keynote
Overview
In his RSA Conference 2024 presentation, "The Possibilities, Risks, and Rewards of Cyber Tech Convergence," Sundhar Annamalai, President of the newly formed Level Blue (formerly AT&T Cybersecurity), articulated a compelling vision for the future of cybersecurity. Annamalai introduced Level Blue as a significant player in the managed security space, emphasizing their recent launch as a joint venture with AT&T and their extensive experience in managed network security and MDR services. The core of his address revolved around the concept of achieving "security homeostasis" – a state of dynamic balance and resilience in the face of ever-evolving cyber threats, drawing a powerful analogy to the human body's ability to adapt and maintain internal stability.

Key moments
- 0:00 Introducing Level Blue, formerly AT&T Cybersecurity
- 1:00 Human body metaphor for resilient cyber systems
- 2:10 Relating human resilience to cyber leader challenges
- 3:20 Customer demand for integrated tech and collaboration
- 4:00 Emergence of security convergence and open platforms
- 4:45 Level Blue's deep integrations and custom applications
- 5:30 Centralized data and Gen AI for predictive intelligence
- 6:05 Real-world example: detecting supply chain attacks
The Possibilities, Risks, and Rewards of Cyber Tech Convergence
Speakers: Sundhar Annamalai, President, Level Blue
Conference: RSAC 2024
YouTube: https://www.youtube.com/watch?v=dOVpm1tEylQ
Overview
In his RSA Conference 2024 presentation, "The Possibilities, Risks, and Rewards of Cyber Tech Convergence," Sundhar Annamalai, President of the newly formed Level Blue (formerly AT&T Cybersecurity), articulated a compelling vision for the future of cybersecurity. Annamalai introduced Level Blue as a significant player in the managed security space, emphasizing their recent launch as a joint venture with AT&T and their extensive experience in managed network security and MDR services. The core of his address revolved around the concept of achieving "security homeostasis" – a state of dynamic balance and resilience in the face of ever-evolving cyber threats, drawing a powerful analogy to the human body's ability to adapt and maintain internal stability.
The talk underscored the critical need for cyber tech convergence as a fundamental strategy to build resilient and adaptable security systems. Annamalai highlighted that while the concept of convergence has been discussed for years within the cybersecurity community, it is now becoming a tangible reality, driven by customer demand for greater visibility, integrated technology, and shared best practices. Level Blue's perspective, as presented, centers on leveraging deep integrations across diverse security platforms, centralizing vast amounts of data, and employing advanced analytical capabilities, including Generative AI (Gen AI) and Machine Learning (ML), to empower Security Operations Center (SOC) analysts and deliver predictive intelligence.
This presentation is particularly relevant for security leaders, practitioners, and organizations grappling with the complexities of managing disparate security tools and an overwhelming volume of alerts. Annamalai's insights provide a roadmap for moving beyond siloed security operations towards a more unified, intelligent, and proactive defense posture. By demonstrating how a converged approach, especially through the lens of a global managed security provider, can dramatically enhance threat detection and response capabilities, the talk offers valuable perspectives on how to navigate the challenges and capitalize on the opportunities presented by the converging cybersecurity landscape.
Background
▶ Watch: Introducing Level Blue, formerly AT&T Cybersecurity (0:00)
The modern cybersecurity landscape is characterized by an unprecedented level of complexity and a relentless barrage of sophisticated threats. Organizations today are tasked with protecting critical business assets, ensuring operational continuity, and maintaining regulatory compliance against a backdrop of increasing attack frequency from highly skilled nation-state actors and advanced persistent threat (APT) groups. This challenge is often compounded by internal factors such as skill gaps, poorly defined processes, and an over-reliance or under-reliance on fragmented technologies.
Historically, the cybersecurity industry has seen a proliferation of point solutions, each designed to address a specific security challenge – be it endpoint protection, network security, vulnerability management, or cloud security. While these individual tools offer specialized capabilities, their independent deployment often creates a fragmented security ecosystem. This fragmentation leads to siloed data, limited visibility across the entire attack surface, and a significant burden on security teams to manually correlate alerts and incidents from disparate systems. The result is often alert fatigue, delayed detection, and an inability to respond effectively to complex, multi-stage attacks.
Annamalai explicitly pointed out that customers and organizations have been demanding better collaboration, more integrated technology, and shared practices for the past five years. This demand stems from the recognition that traditional, siloed approaches are no longer sufficient to combat the evolving threat landscape. The advent of Generative AI (Gen AI) and other advanced analytical capabilities further amplifies this need, as these technologies require vast, correlated datasets to deliver their full potential. The problem, therefore, is not a lack of security tools, but rather a lack of cohesive integration and intelligent orchestration among them, preventing organizations from achieving a state of "security homeostasis" – a stable, resilient, and adaptable defense posture. The talk positions cyber tech convergence as the necessary evolution to overcome these systemic challenges, transforming disparate components into a harmonious, adaptive security organism.
Key Findings
▶ Watch: Relating human resilience to cyber leader challenges (2:10)
The central finding presented by Sundhar Annamalai is that cyber tech convergence is no longer a theoretical aspiration but a present-day reality, fundamentally reshaping how organizations approach cybersecurity. This convergence is driven by two primary forces: pervasive customer demand for holistic visibility and integrated solutions, and the proactive efforts of hardware and software vendors to open their platforms. This shift enables adjacent technology partners and service providers, like Level Blue, to build deeper integrations and create more unified security ecosystems.
A significant contribution highlighted in the talk is the power of centralized data aggregation and anonymization across diverse customer environments. By ingesting data from a multitude of platforms – including legacy and modern technologies, multi-cloud deployments, multi-vendor environments, endpoints, security tools, and SaaS applications – Level Blue is able to normalize this vast "data exhaust." This centralized, normalized data provides an unprecedented level of insight into customer environments, moving beyond reactive alert management to proactive, predictive intelligence. Annamalai emphasized that this capability is not merely about collecting more data, but about transforming it into actionable intelligence through advanced analytics.
Furthermore, the talk underscored the critical advantage that managed security service providers (MSSPs) and Managed Detection and Response (MDR) providers bring to the table. By operating across a multi-customer base, these providers gain a unique, "outside-in" perspective on emerging threats. The example of a software-based supply chain attack vividly illustrated this point: while a single organization might mistakenly classify a suspicious but legitimate-looking software alert as a false positive, an MDR provider can correlate that same alert across hundreds of customers, cross-referencing it with global threat intelligence feeds from sources like OSINT (open-source intelligence), malware trackers, and platforms such as OTX (Open Threat Exchange). This multi-customer visibility allows for the rapid identification of malicious infrastructure and the accurate assessment of widespread threats, transforming a potential false positive into a confirmed, actionable threat that can be mitigated across the entire customer base. This collective intelligence and correlation capability represent a profound shift in defensive efficacy.
Technical Deep Dive
▶ Watch: Emergence of security convergence and open platforms (4:00)
The technical underpinnings of cyber tech convergence as described by Annamalai revolve around deep platform integrations, intelligent data processing, and the application of advanced AI/ML models. Level Blue, as an MDR provider, has developed a sophisticated architecture to achieve this convergence, addressing the challenge of fragmented security tools and siloed data.
At the heart of Level Blue's approach are its Level Blue apps. These are not merely integrations but a suite of over 700 distinct applications built on top of approximately 50 deep integrations with leading security platforms. These platforms include prominent vendors such as SentinelOne (S1), Qualys, Tenable, Fortinet, Check Point, and Palo Alto Networks, among others. The purpose of these applications is to facilitate the ingestion, analysis, and correlation of security data from a vast array of sources. This extensive integration capability ensures comprehensive visibility across diverse customer environments, encompassing multi-cloud infrastructures, multi-vendor security stacks, endpoints, and various SaaS applications.
Once data is ingested, it undergoes a crucial process of normalization and anonymization. This step is vital for creating a unified dataset from disparate formats and ensuring privacy while enabling broad analytical insights. The normalized data forms a rich "data exhaust" that becomes the foundation for advanced analytics. Level Blue employs sophisticated analytical capabilities, including large language models (LLMs), Machine Learning (ML) models, and Generative AI (Gen AI) models. These AI-driven tools are not intended to replace human analysts but rather to augment their capabilities, providing predictive intelligence, prioritizing alerts, and offering deeper context for faster and more accurate decision-making within the SOC. For instance, these models can help identify subtle patterns indicative of a nascent attack or predict potential vulnerabilities that might be exploited.
A key technical differentiator highlighted is the ability to leverage multi-customer data for enhanced threat intelligence. Level Blue integrates external threat intelligence feeds from various sources, including OSINT (open-source intelligence), proprietary malware trackers, and large-scale open threat intelligence platforms like OTX (Open Threat Exchange), which is described as one of the largest in the world. This continuous indexing and cataloging of evolving malicious infrastructure is then correlated with internal customer data. In the scenario of a software-based supply chain attack, this means that an alert flagged within a single customer's environment can be cross-referenced against global threat intelligence and similar events observed across Level Blue's entire customer base. This correlation engine can identify seemingly legitimate software sending traffic to known malicious infrastructure, a conflict that a single organization might overlook. This capability allows Level Blue's SOC operations teams, in conjunction with their dedicated threat intelligence team, to rapidly investigate, confirm, and mitigate threats that would otherwise be extremely difficult to detect in isolation. The synergy between extensive platform integrations, intelligent data processing, and AI-augmented human analysis across a broad customer base forms the technical backbone of this converged security paradigm.
Demo / Proof of Concept
▶ Watch: Level Blue's deep integrations and custom applications (4:45)
While Sundhar Annamalai did not present a live technical demonstration or a software-based proof of concept, he effectively utilized a conceptual scenario to illustrate the profound difference that cyber tech convergence and a multi-customer perspective can make in real-world threat detection. The example centered on a software-based supply chain attack, a notoriously difficult threat to identify due to its ability to mimic legitimate software behavior.
In the first part of the scenario, Annamalai described the experience of a SOC analyst within a single organization. When an alert surfaces, indicating potentially questionable software, the analyst faces a dilemma. The software might appear reputable and be in daily use within the organization. Lacking broader context or external intelligence, the analyst is prone to classifying the alert as a false positive, thereby inadvertently approving a malicious component. This decision, driven by limited visibility and context, ultimately leaves the organization vulnerable, with the realization of the breach often coming too late.
The contrast was then drawn with how a service provider like Level Blue, operating with a converged platform across a multi-customer environment, would handle the identical alert. When Level Blue's platform detects a similar suspicious software alert in a customer's environment, it immediately correlates this information with a vast index of evolving malicious infrastructure, compiled from sources like OSINT, malware trackers, and platforms such as OTX. This global threat intelligence perspective allows Level Blue to identify if the "legitimate" software is communicating with known malicious command-and-control servers or other threat infrastructure observed across the industry. The critical insight here is the ability to detect a "conflict" – where legitimate software is exhibiting behavior linked to malicious activities or infrastructure. This correlation transforms a potentially dismissed alert into a high-priority incident. Level Blue's SOC operations teams, supported by their dedicated threat intelligence team, would then proactively investigate this conflict, determine the true nature of the threat, and take immediate mitigating actions, such as blocking the malicious traffic or isolating affected systems. This conceptual demonstration powerfully illustrates how a converged approach, powered by collective intelligence and advanced correlation, significantly elevates an organization's ability to detect and respond to sophisticated, stealthy attacks that would otherwise bypass traditional, siloed defenses.
Defensive Implications
▶ Watch: Real-world example: detecting supply chain attacks (6:05)
The insights shared by Sundhar Annamalai carry significant defensive implications for organizations seeking to enhance their cybersecurity posture in an increasingly complex threat landscape. The overarching message is a call to move beyond fragmented security strategies towards a more integrated, intelligent, and collaborative approach.
Firstly, organizations should prioritize investing in diverse, open technology systems and vendors. The era of vendor lock-in and proprietary, closed platforms is detrimental to effective security. By embracing open architectures, organizations can foster a robust ecosystem of security tools that can seamlessly integrate and share data. This flexibility allows for the creation of a comprehensive threat detection and response fabric, rather than a collection of isolated point solutions. Defenders should actively seek out vendors committed to interoperability and API-driven integrations, enabling the kind of deep data aggregation that Level Blue exemplifies.
Secondly, the talk underscores the critical importance of centralizing and normalizing security data from across the entire enterprise. Data from endpoints, networks, cloud environments, SaaS applications, and various security tools must be brought together into a unified platform. This centralized data lake, when properly normalized, provides the foundational visibility required for advanced analytics, including AI/ML and Gen AI models, to deliver predictive intelligence. Without this unified data, even the most sophisticated analytical tools will operate in a vacuum, providing limited value. Organizations should focus on data ingestion strategies and platforms that can handle the volume and variety of security telemetry.
Thirdly, Annamalai strongly advocates for organizations to seek external partners that can provide an "outside-in" perspective. Relying solely on internal data and intelligence can create blind spots, especially for sophisticated, widespread attacks like supply chain compromises. Managed Security Service Providers (MSSPs) and Managed Detection and Response (MDR) providers, with their multi-customer visibility and global threat intelligence feeds (e.g., OSINT, OTX), offer a crucial advantage. These partners can correlate nascent threats observed across a broad client base, identifying patterns and malicious infrastructure that would be invisible to a single organization. Engaging such partners can significantly enhance an organization's ability to detect, analyze, and respond to emerging threats faster and more effectively.
Finally, the talk emphasizes the necessity of fostering collaboration and shared practices across the security community. The "security homeostasis" concept extends beyond technology to encompass people and processes. This means promoting intelligence sharing, participating in industry forums, and adopting community-driven best practices. The human element, particularly the expertise of SOC analysts augmented by AI, remains paramount. Training, process optimization, and a culture of continuous improvement are essential to ensure that integrated technologies are fully leveraged and that the organization can maintain its adaptable and resilient state in the face of persistent cyber challenges.
Key Takeaways
- Achieving Security Homeostasis: True cyber resilience requires a dynamic balance of integrated people, processes, and technology, constantly adapting to internal and external stimuli, much like the human body.
- Embrace Open, Diverse Tech Ecosystems: Organizations should invest in open security platforms and a variety of vendors that facilitate deep integrations, moving away from siloed tools to create a unified security fabric.
- Leverage External "Outside-In" Intelligence: Partnering with Managed Detection and Response (MDR) providers offers a crucial advantage by providing multi-customer visibility and correlating global threat intelligence (OSINT, OTX) to detect widespread and stealthy attacks like supply chain compromises.
- Centralize and Normalize Security Data: Aggregating and normalizing data from all security tools, endpoints, cloud, and SaaS applications is foundational for achieving comprehensive visibility and enabling advanced analytical capabilities.
- Augment Analysts with Advanced AI/ML: Utilize large language models, machine learning, and Generative AI to empower SOC analysts with predictive intelligence and enhanced context, improving threat detection and response efficiency.
- Prioritize Collaboration and Shared Practices: Effective cybersecurity extends beyond technology to include robust internal processes, continuous skill development, and active participation in the broader security community for intelligence sharing and best practices.
About the Speaker(s)
Sundhar Annamalai is the President of Level Blue, a newly formed company that was publicly announced at RSA Conference 2024. Level Blue is a joint venture with AT&T and was formerly known as AT&T Cybersecurity. As President, Annamalai leads a significant managed security provider globally, offering award-winning consulting services, managed network security, and Managed Detection and Response (MDR) services. His presentation at RSAC 2024 reflects Level Blue's strategic vision for the future of cybersecurity, emphasizing convergence, resilience, and adaptability.