Understanding the Role of Managed Security Service Providers with Sundhar Annamalai at QSC24
Sundhar Annamalai, President of LevelBlue, highlights the vital role of Managed Security Service Providers (MSSPs) for companies lacking cybersecurity resources. Customers struggle with complex security technologies, making MSSPs essential long-term partners. The services offered include 24/7 operations and specialized solutions. A partnership with Qualys for vulnerability management shows a commitment to evolving support, particularly for mid-market customers and larger enterprises needing security assistance.
Transcript
This is Textron tv. Hey everyone. We're back here.
Live in San Diego for Qualys, Q-S-C-Q-S-D, Qualys Security Conference. In case you don't know, our next guest is Mr. Sundar Anomaly.
Yes, he is the president of Blue Lava. What's Blue Lava? Well, I'm not gonna answer that.
You are? Well, level Blue is A level blue. Where did I get Blue Lava?
Well, you know, that's a different brand name, but Level Blue is the name of the Company, but Blue LA sounds like a good name. Good, okay. Yeah.
But, uh, yeah, so, you know, not a lot of folks know about Level Blue. We are formally at and t Cybersecurity. We've, we've created a standalone company to go focus completely on the managed security marketplace, and we're excited to be here at QSE today with, uh, SUM Ed and his team.
And yeah, excited to announce some of the MOC partnerships that we're, we're excited about launching with Qualys and, um, how we think that brings value to customers. So, Shar, if it's okay, we're gonna get into the AM Rock. We're gonna get into the Quala partnership.
I wanna talk a little bit about MSPs. So, as you said, level Blue's a spin out of at and t at t had acquired several, uh, technology cyber, uh, technology companies, including some MSSP and monitoring and stuff, and then spun it out. I always not question 'cause I thought it was a good thing that they spun it out, but, you know, as we were talking off camera, MSS ps in my mind, play such an important role because the fact of the matter is there's a handful of companies in the world that have resources to really do security well, A to Z mm-Hmm.
Everyone else should be using an MSSP in my mind, right? Because there's no way you could do A to Z mm-Hmm. You don't have the resources, you don't have the talent, you don't have the, you just don't have wherewithal.
I'm wondering your president, I assume you buy into that as well. Absolutely. But is, is the market buying into that is the MSSP market?
And I always thought it would be hockey stick. Yeah. Yeah.
And I think, I think, uh, it's a great question and great insight. Uh, I think some of that dynamic goes back to where customers are on their respective journeys. Some customers have the sophistication, they do have the resources to try to do it themselves.
You know, our, our play has let us help you drive towards the security outcomes that you're aspiring to and do that across the footprint of technologies that they're actively managing. Uh, I'd say that's one of the dynamics that we actively face is customers through a series of acquisitions or series of historical decisions, have a multitude of technologies that they've had to deploy and manage. And oftentimes is a trade off between DIY or use a partner like an MSSP to do it themselves.
And we're finding more and more customers are wanting to lean on MSPs to take that burden off of their resources, have the security personnel in mind to manage a complex set of policies, complex set of technologies that is changing every six months, and there's a new technology on the horizon they're being asked to consider. Sure. Um, and as we talked about in the room, uh, budgets aren't unlimited.
And so when they have a transformation journey in front of them, they're looking to us to help them on the migration from technology A to technology B, and that it's not as simple as rip and replace. You've got policy management, workflow management, who from the customer side is gonna do what and who, what, what do they want the MSSP to do as well? I agree with you a hundred percent, but I think another thing to note is the MSSP is not a transitionary partner.
No. Right? I don't think you say, oh, I'm gonna go out with an MSSP for six months or a year, and then we'll be able to take it in-house.
Yeah. Yeah. I, I think I, there are companies who have that mentality.
I think that's a, a losing mentality because you, you're just not. No. And yeah, I think, I think, uh, MSPs like ourselves, you know, we think about it as a partnership.
We wanna be considered as part of the team, on behalf of the customer to help jointly drive outcomes. And so our personnel are equally as excited about what does it take to achieve the goals the company's going after. We wanna be part of the team because the only way, you know, we will be successful is with the customer success.
Um, and so that means partnering with their technology teams, partnering with their risk and compliance teams, as well as our IT organizations to actually put all these practices into use and implement in terms of, uh, what they're looking to get done. Absolutely. Now, when you look at MSPs and, and we were talking, I, I have some experience with MSPs.
They, they have some things kind of in common, and then they have some things that separate one from the other. One of the things they all have in common is they basically do offer sort of a sock 24 7 operation where, look, you may not be 24 7, but we are, and we are, we where your eyes ears and watching it, some SSPs have developed their own proprietary software, you know, and it ranges like, you know, the spectrum of security services, if you will. Other SSPs are very specialized.
I'm not an a z security SSP, I'm an MSSP for email or for, uh, cloud, public cloud Yeah. Or, you know, whatever my specialization is. Then there are other MSPs who say, look, we're gonna offer you best of breed.
Mm-Hmm mm-Hmm. Right. Yeah.
We have some solutions, but if you think Quas vulnerability scanning is better than our in-house vulnerability scanning, we'll use Qualys. Yeah. Yeah.
Where do you guys Yeah. On that spectrum? Yeah.
So, uh, it's multifaceted as you know. And so the way that we thought about it and way we grew the business up is we have an advisory services team as one part of our offer set, which is to help customers on the decision making process for technology policies implementation. So that's one part of our organization.
We also have a network side network security side of our practice, our business, which is historically kind of where M MSSP has evolved out of. Um, and we do that for customers today. And we, we lean on best in breed strategic partnerships that we, we partner with today to implement these technologies, manage them, implement them, transition them over time.
And we also have our threat side of our portfolio, which also includes some proprietary IP that we've built over the years to, um, build out a threat platform and, and scale up, scale up what customers need. And what we're doing is putting all of that into a common platform that customers can use with level blue on a day in, day out basis from advisory services, network security and thread altogether. Got it.
Um, you mentioned you were up on the main stage. I, I happen to have, I interviewed Hamesh from the insurance company. Yeah, that's right.
Um, uh, Mayberry, uh, yeah, Mulberry, excuse me, Mulberry. And we, we spoke a little bit about what was set up there and it, and it really is about the, the cyber world today. And, and doing it right is such a multifaceted kind of thing that you need, you need your cyber insurance partner, you need your MSSP, you need maybe your direct security vendor like Aquas, right.
Because we do it, it's just, it's just too much. Right, Right, Right. Yeah.
For any one company that, to wrap around here. That's right. Um, and it, I mean, I'm, I don't wanna blow smoke up people's, you know, it's not getting easier.
No, no. Where do you see the role of MSSP evolving? Or do you think what we have today is sort of the modern MSSP?
I think, I think customers are gonna have to make choices over time. Uh, we continue to see customer environments to, to be multi-vendor. We don't see that going away anytime soon.
Um, and there's two sides of the coin. Um, you know, one side of it is what do you do on the pre-planning side to kind of assess where's my posture look like today? Um, what tools can I implement to understand what are my risk or risk exposure points?
How do you prioritize that? And that's what I think is interesting in terms of what was announced today around how do you plan for what's the right level of investment, right? Versus, uh, every, every nail standing up has to be nailed down.
And so that's not really a realistic outcome for a customer. And so how do you prioritize which ones will have the biggest bang for my buck? And then the flip side of that coin is just knowing where you have the risks is not sufficient.
You need to have arms and legs from an MSSP to partner with the company in terms of like, how do we make sure we're doing the patch management? What firewall policies have to be remediated? Where do I have the biggest risks in my business on the endpoint mobile endpoint?
And that's where we think the, the complimentary nature of exposure management and MSSP really are a good, nice synergistic, uh, value for customer drive security outcomes. We only have a few minutes left. I, I wanted, if you wouldn't mind, talk about your partnership with Qualys.
Yeah. So yeah, we've, we've been a partner with Qualys for a long time in the vulnerability management space, you know, in terms of what was announced today. It'll be an evolution of what we've been doing, uh, historically with them.
And, um, you know, how do we put that together in terms of our, our overarching MSSP, uh, go to market practice? Where can people get more information on, not only on the Qualys partnership put on level blue to begin with? Yeah.
com. Okay. Uh, and so, uh, you'll learn more about, you know, the comprehensive offers that we have in the marketplace from network security, endpoint management, and our threat detection capabilities, as well as our advisory services.
So we're a one-stop shop for customers. And, um, we're, we're happy to help where customers need us In that, in that regard. As I said before, there's such a wide spectrum of MSPs.
Any company too small, any company too big? What's the, what's your sweet Spot? Yeah.
So, uh, you know, we, we typically address the needs of mid-market customers and up and so, uh, where they, you know, those are the customers that really need, they, they, they don't have the resources on the, on the ready to kind of manage and deploy technologies from a security standpoint. And so those, those needs, uh, unfortunately, you know, are in the small business space, mid-market space, and all the way to the Fortune 500. It really depends on the sophistication level of the customer.
Got it. Hey, I know you have to get out of here. Absolutely.
I appreciate The time. Thank you so much. Yeah.
Keep up the great work. Thank you. com.
We're live in San Diego. We're gonna be back in just a minute with our next guest. You're watching Tech Drunk tv.