San Mateo, CA, USA
2007
  |  By Grant Hutchons
Australia is my home now. Safeguarding it is no longer a job. It is a mission. I am on a flight heading north from Melbourne to Sydney as I write this. The significance of that journey is not lost on me. In a few hours, I will stand in front of the Security Operations Centre that our team has built. It represents something far larger than infrastructure or technology. It represents a choice. LevelBlue's choice. Our choice. Australia's choice. For years, Australian organizations faced a narrow choice.
  |  By Brandy Wityak, Vinodpal Minhas
Organizations spend considerable time preparing for the technical realities of a cyber incident. Detection capabilities, containment procedures, recovery plans and governance structures are all essential. Yet many of the factors that shape the success of a response have little to do with technology. The most effective incident response programs recognize that cyber resilience is shaped as much by people as technology.
  |  By Bread Fyan
When organizations experience a cyberattack, executives often focus on recovery timelines, business impact, and regulatory obligations. Yet the outcome of those conversations is often determined long before recovery begins.
  |  By Aaron Cookstra
Digital risk has expanded far beyond the traditional security perimeter. Brands now operate across social platforms, advertising ecosystems, messaging applications, collaboration tools, marketplaces, and dozens of other digital channels. Each represents an opportunity to connect with customers. Each also creates opportunities for abuse. A fraudulent advertisement can direct users to a spoofed login page. A fake social media account can support an executive impersonation campaign.
  |  By LevelBlue
Organizations with mature security programs still get breached. Teams that pass audits still find themselves responding to ransomware, Business Email Compromise (BEC), and credential theft. The controls that satisfy an audit requirement and the controls that significantly reduce the likelihood, impact, and cost of an intrusion are often not the same.
  |  By Sean Shirley
Originally published on Cybersecurity Insiders. Phishing remains one of the most reliable entry points for attackers, serving as the initial intrusion vector in 58% of incidents analyzed in LevelBlue’s Q1 2026 TTP Briefing. But today’s campaigns are becoming increasingly targeted and technically sophisticated, evolving from simply convincing a user to click to establishing long-term access to enterprise environments.
  |  By LevelBlue
Established by the Canadian nonprofit Women Cybersecurity Society, Women in Cyber Day celebrates the contributions of women across the cybersecurity community and encourages the continued advancement of the profession. Observed annually on September 1, the day also provides an opportunity to spotlight the expertise and perspectives shaping what comes next in cybersecurity, especially as the industry rapidly transforms. Cybersecurity has never had more frameworks, controls, benchmarks, metrics, or tools.
  |  By LevelBlue
LevelBlue is making a multi-million-dollar investment in a new local Security Operations Center (SOC) in Sydney, going live August 25, 2026. The Sydney SOC gives Australian organizations, with a particular focus on critical infrastructure owners and operators, access to onshore analysts and local escalation pathways, backed by the scale, threat intelligence, and 24/7 coverage of LevelBlue's global security operations.
  |  By Bindu Sundaresan
Healthcare has always run on two currencies: information and trust. Patients hand over their most sensitive data, diagnoses, genetic profiles, mental health histories, on the assumption that it will be protected and that the people (or systems) handling it will treat them with care. Artificial intelligence is now reshaping both sides of that bargain at once.
  |  By Brandy Wityak
Originally published by Cybersecurity Insider. Over the past decade, cybersecurity threats have evolved from a technical issue into a key driver of business and operational risk. Artificial intelligence is accelerating that shift even further, changing the game once again. In 2026, AI in cybersecurity is multifaceted: a tool for defense and incident response, but also a powerful accelerator for attackers. AI-enabled incidents rarely stay contained within the security function.
  |  By LevelBlue
Many companies have an incident response retainer...but it doesn't actually make them risk ready. That's because too many retainers are built on outdated, hour-based "use it or lose it" models that don't actually reduce risk, improve resilience, or focus on outcomes. A modern retainer should drive preparedness, align with today's insurance realities, and actively lower exposure before an incident happens.
  |  By LevelBlue
Some of the biggest delays in incident response aren’t caused by the attacker… they’re caused by the first steps taken after discovery. A few examples of well-intentioned actions that can unintentionally slow investigations and extend recovery timelines: Resilience isn’t built during an incident. It’s built before one ever happens.
  |  By LevelBlue
LevelBlue. Built for what’s next. AI-powered security that stays ahead of threats, not reacts to them. From cloud to network to hybrid, we deliver total visibility, total control, and protection at scale, so enterprises can move faster with confidence.
  |  By LevelBlue
Originally recorded in 2025, we look back at how cybercriminals perfected deception during the first half of the year. Now available as an archive recording, the session highlights the second edition of the LevelBlue Threat Trends Report and explores real-world incident data, fast-moving attack chains, and the social engineering techniques that shaped the threat landscape at the time. While the data reflects early 2025, many of the lessons remain relevant for understanding how today’s threat environment evolved.
  |  By LevelBlue
Originally recorded in 2025, we look back at the key threat trends and attack techniques shaping the security landscape at the time. Now available as an archive recording, the session explores emerging threats, evolving attacker tactics, and early indicators of risks that still influence cybersecurity strategies today. While the data reflects 2025, many of the insights remain relevant for understanding how the modern threat landscape has evolved.
  |  By LevelBlue
LevelBlue and the PGA of America share a commitment to excellence under pressure. As the Official Cybersecurity Advisor of the PGA of America, LevelBlue brings championship standards of protection, continuity, and trust to the organizations that keep the game - and business - moving forward. From fairways to firewalls, LevelBlue safeguards mission-critical operations, member data, and high-profile events with always-on defense, accelerated response, and expert-led security operations powered by AI-driven threat intelligence.
  |  By LevelBlue
Cyberattacks are evolving fast; powered by AI, deepfakes, ransomware, phishing, and growing software supply chain risk. So how prepared is your organization? In this webcast, we breakdown key findings from the 2025 LevelBlue Futures Report (in partnership with FT Longitude). The report is based on a global survey of 1,500 C-suite and senior executives across 16 countries and seven industries, including healthcare, financial services, energy, and manufacturing.
  |  By LevelBlue
Discover how LevelBlue and Tenable are transforming cybersecurity in this exclusive fireside chat featuring Michael Vaughn, Director of Product Management at LevelBlue, and Greg Goetz, VP of Global Strategic Partners at Tenable.
  |  By LevelBlue
As email-based cyberattacks surge, security teams are struggling to stay ahead of increasingly sophisticated phishing, Business Email Compromise (BEC), and AI-driven social engineering. With attackers exploiting platforms like Microsoft 365, Google Workspace, OneDrive, and SharePoint, organizations face growing pressure to strengthen protection, visibility, and compliance.
  |  By LevelBlue
As global cybersecurity regulations tighten, security leaders are under increasing pressure to demonstrate strong Incident Readiness and Response (IRR). New requirements like the SEC cybersecurity disclosure rules, the EU’s NIS 2 Directive, and the forthcoming CIRCIA mandate faster reporting, stronger governance, and greater accountability. In this session, LevelBlue experts share insights from a survey of 500 security leaders on how organizations are adapting their IRR strategies for today’s regulatory climate.
  |  By LevelBlue
Phenomenal security. Phenomenal partnership. At AlienVault, we understand that customers rely on your expertise to deliver world-class security solutions specifically designed to protect their unique business. We also know that vetting partnerships opportunities with security vendors is a critical component to delivering those outcomes.
  |  By LevelBlue
The Insider's Guide to Incident Response gives you an in-depth look at the fundamental strategies of efficient and effective incident response for security teams that need to do more with less in today's rapidly changing threat landscape.
  |  By LevelBlue
As organizations around the world shift their workloads to Amazon Web Services (AWS) and other popular cloud infrastructure-as-a-service (IaaS) providers, concerns about cloud security continue to rise. According to a 2018 Cloud Security Report from Cybersecurity Insiders, 91% of respondents are concerned about cloud security, an increase of 11% over last year's report.
  |  By LevelBlue
Get All 5 Chapters of AlienVault's How to Build a Security Operations Center (On a Budget) in 1 eBook! You'll get an in-depth look at how organizations with limited resources can set up a successful operations center for monitoring, detecting, containing, and remediating IT threats across applications, devices, systems, networks, and locations.
  |  By LevelBlue
Criminal organizations and hackers increasingly perceive regional banks and credit unions as attractive targets. That's why we've created this primer-to help IT managers and executives at financial organizations understand not just the top threats they're facing, but also what they can do to fend them off.
  |  By LevelBlue
This whitepaper provides an overview of Open Source IDS and the various IDS tools available today. Whether you need to monitor hosts or the networks connecting them to identify the latest threats, these are some of the best open source intrusion detection (IDS) tools available to you.
  |  By LevelBlue
With so many open source tools available to help with network security, it can be tricky to figure out where to start, especially if you are an IT generalist who has been tasked with security.

LevelBlue has simplified the way organizations detect and respond to today’s ever evolving threat landscape. Our unique and award-winning approach, trusted by thousands of customers, combines the essential security controls of our all-in-one platform, AlienVault Unified Security Management, with the power of AlienVault’s Open Threat Exchange, the world’s largest crowd-sourced threat intelligence community, making effective and affordable threat detection attainable for resource-constrained IT teams.

AlienVault® USM Anywhere™ accelerates and centralizes threat detection, incident response, and compliance management for your cloud, on-premises, and hybrid environments. USM Anywhere includes purpose-built cloud sensors that natively monitor your Amazon Web Services (AWS) and Microsoft Azure cloud environments, and cloud applications like Office 365. On premises, lightweight virtual sensors run on Microsoft Hyper-V and VMware ESXi to monitor your virtual private cloud and physical IT infrastructure.

With USM Anywhere, you can rapidly deploy sensors into your cloud and on-premises environments while centrally managing data collection, security analysis, and threat detection from the AlienVault Secure Cloud.