BlueVoyant
Cyber Defense Platform with MDR and TPRM Scale, but Private-Market Opacity
BlueVoyant is a credible late-stage cybersecurity platform with real MDR and TPRM scale, differentiated regulated-industry positioning, and strong Microsoft ecosystem leverage, but its private-company opacity and unresolved valuation/revenue conflicts justify a track posture rather than a conviction buy.
Cover facts
Company profile
BlueVoyant was founded in 2017 and is headquartered in New York City. Public company materials position the business as a unified cyber defense platform spanning MDR, third-party risk management, digital risk protection, and professional services, with especially deep alignment to Microsoft security tooling and a meaningful footprint in government and other regulated sectors. The company has credible commercial scale — over 1,000 customers in 45 countries, 600+ employees, and a publicly announced 2023 Series E above $140M following the 2022 $250M Series D that pushed it above the $1B unicorn threshold. However, current valuation, ARR quality, margin profile, and ownership structure remain only partially visible in public data, leaving underwriting confidence constrained.
- Website
- www.bluevoyant.com
- Founders
- Jim Rosenthal, Tom Glocer
- Founding location
- New York, New York, USA
- Headquarters
- New York, New York, USA (6 East 45th Street, Floor 17)
- Product
- BlueVoyant sells a cyber defense platform spanning managed detection and response, third-party risk management / supply chain defense, digital risk protection, and professional services. The current roadmap emphasizes AI-native SecOps, Microsoft-native deployment, and continuous supplier-risk remediation rather than point-in-time assessments.
- Customers
- Large enterprises, financial services firms, government agencies, defense-industrial-base entities, and other regulated organizations that need managed SOC coverage, Microsoft security optimization, and third-party cyber risk management across vendors and suppliers.
- Business model
- Recurring managed security and software revenue tied to MDR, TPRM, DRP, and consulting / response services, with cross-sell through Microsoft ecosystem work, public-sector programs, and channel partners.
- Stage
- Series E (private unicorn)
- Funding status
- Public capital history includes a $250M Series D in February 2022 led by Liberty Strategic Capital and a more-than-$140M Series E announced in November 2023 alongside the Conquest Cyber acquisition. Third-party datasets place total funding around $665.5M to $696M.
Executive summary
Top strengths
- BlueVoyant spans MDR, TPRM, DRP, and services in one platform, letting it sell unified cyber defense rather than a single control point.
- The company has credible enterprise scale, with over 1,000 customers in 45 countries, more than 600 employees, and meaningful public-sector and regulated-industry traction.
- BlueVoyant's Microsoft specialization is a durable go-to-market advantage, reinforced by large deployment counts, verified partner status, and customer ROI studies.
- Funding support from Liberty Strategic Capital, ISTARI, Temasek-linked capital, and other investors gives the company strategic credibility despite a difficult private-market backdrop.
Top risks
- Public financial visibility is poor: audited ARR, growth, gross margin, burn, NRR, and cap-table terms are not disclosed, while public revenue estimates conflict sharply.
- The last clear unicorn valuation anchor is stale, and private-market data does not provide a clean, high-confidence read on current enterprise value or liquidation preferences.
- BlueVoyant competes in crowded MDR and cyber-risk markets against larger platforms such as Palo Alto Networks, CrowdStrike, Rapid7, Arctic Wolf, and risk specialists like BitSight and SecurityScorecard.
- The business model still depends materially on services delivery and Microsoft ecosystem execution, which can pressure margin scalability and increase platform-dependence risk.
- AI-led product repositioning in 2026 raises execution risk because the company must prove differentiation beyond marketing while maintaining service quality across a growing platform.
Open gaps
- Audited ARR, revenue growth, gross margin, NRR, burn, and cash balance.
- Fully diluted cap table, preferred terms, liquidation preferences, and any secondary-market transaction details.
- Precise current valuation for the November 2023 Series E and whether 2026 secondary clears validate or discount the unicorn mark.
- Revenue mix across MDR, TPRM, DRP, professional services, and government programs.
- Customer concentration and retention by vertical, especially government and financial services.
- Independent proof of AI product adoption, pricing, and conversion impact following the June 2026 BlueVoyant AI launch.
Contents
01Company Overview
1.1 Identity, Headquarters, and Business Model
BlueVoyant presents itself as a cyber-defense platform company founded in 2017 and headquartered in New York. Its official company and contact pages anchor the present footprint in Manhattan while also showing a wider multinational operating base. The company says it has over 600 employees and more than 1,000 customers across 45 countries, which places it beyond startup incubation stage and into scaled private-company territory even before considering third-party estimates. Product-wise, BlueVoyant does not describe itself as a single-point tool vendor. Its platform combines managed detection and response, third-party risk management, digital risk protection, and professional services, with revenue implied to come from both recurring software modules and analyst-led managed operations. The reviewed materials consistently position BlueVoyant around enterprise, government, and critical-infrastructure use cases rather than a narrow SME or consumer motion. That mix matters for later diligence because it suggests longer sales cycles, service-heavy onboarding, and differentiated exposure to regulated or mission-critical buyers.[CO001, CO002, CO003, CO004, CO005, CO006]
| Metric | Value / status | Date | Confidence | Gap / note |
|---|---|---|---|---|
| Founded | 2017 | 2017 | High | Corroborated by official and independent sources |
| Headquarters | 6 East 45th Street, Floor 17, New York, NY 10017 | 2026-06-29 | High | Official leadership/contact pages |
| Official employee disclosure | 600+ employees | 2026-06-29 | Medium | Company-claimed; third-party estimates are higher |
| Customer disclosure | 1,000+ customers in 45 countries | 2026-06-29 | Medium | Company-claimed on contact page |
| Core platform | MDR + TPRM + DRP + professional services | 2026-06-29 | High | Official suite pages |
| Last publicly identified financing | > $140M Series E with Conquest Cyber acquisition | 2023-11-29 | High | Public record reviewed does not show a later named round |
| Third-party total funding estimate | ~$665.5M | 2025-11-28 | Medium | Private-market database estimate, not audited |
| Third-party valuation estimate | ~$1B | 2025-11-28 | Medium | No official current valuation disclosed |
| Current CEO | John Hernandez | 2026-05-05 | High | Succeeded co-founder Jim Rosenthal |
| Recent product launch | BlueVoyant AI | 2026-06-09 | High | AI-native / agentic SecOps positioning |
| Microsoft recognition | 2024 Worldwide + U.S. + Canada Security Partner of the Year honors | 2024 | High | Historical award signal, not a current financial metric |
Funding, valuation, and external headcount figures mix official disclosure with private-market or monitoring estimates; treat non-official numeric rows as directional rather than audited.
[CO001, CO002, CO003, CO004, CO005, CO016]BlueVoyant links a founder-shaped governance layer to an integrated cyber platform, Microsoft ecosystem leverage, a global customer footprint, and a private-capital base with still-private economics.
[CO005, CO017, CO028, CO032, CO035, CO043]The clearest public signals point to a scaled private cybersecurity platform with strong ecosystem recognition but still-private economics.
Funding and valuation are third-party private-market estimates; customer and employee figures use the company’s own minimum disclosed thresholds rather than a precise audited count.
[CO003, CO004, CO015, CO028]1.2 Leadership, Governance, and Key-Person Risk
BlueVoyant’s current public leadership picture is shaped by a recent transition. John Hernandez is now CEO, while co-founder Jim Rosenthal moved into the chairman role and co-founder Thomas Glocer remains vice chairman. The current operating bench is broad enough to cover finance, product, technology, information security, HR, government solutions, regional sales, and partnerships, which reduces dependence on any single functional lieutenant. Even so, founder influence is still material because Rosenthal and Glocer remain central governance figures and the public company narrative still leans heavily on founder identity. That mix suggests a meaningful but manageable key-person risk: BlueVoyant has completed a top-of-house handoff, but its public credibility, investor continuity, and strategic storytelling still run through the founders. A prior public COO appointment for Michael Montoya also shows that BlueVoyant has been willing to refresh the operating layer below the board during its scale-up period.[CO009, CO010, CO011, CO012, CO013, CO014]
| Person | Role | Background / public context | Functional coverage / founder-market fit | Key-person dependency |
|---|---|---|---|---|
| John Hernandez | Chief Executive Officer | Named CEO in May 2026 to scale an AI-driven cybersecurity platform globally | Current operating leader and transition point after founder-led phase | Medium |
| James Rosenthal | Co-founder; Chairman of the Board | Co-founder and former CEO; remains governance anchor after CEO handoff | High founder-market fit across strategy, investor continuity, and board influence | High |
| Thomas Glocer | Co-founder; Vice Chairman of the Board | Co-founder and former Thomson Reuters chief executive | Adds enterprise operating and board credibility beyond pure cyber pedigree | Medium |
| Ravi Subramanian | Chief Financial Officer | Publicly listed finance leader on current leadership page | Covers planning, finance, and investor-readiness functions | Medium |
| Sebastian Sobolev | Chief Product Officer | Current product leader on leadership page | Owns roadmap and packaging of platform / AI evolution | Medium-High |
| Jim Bieda | Global Chief Technology Officer | Current technology leader on leadership page | Covers technical architecture and platform credibility | Medium-High |
| John Harbaugh | Chief Information Security Officer | Current security leader on leadership page | Supports trust, security posture, and enterprise credibility | Medium |
| Lonny Anderson | President, BlueVoyant Government Solutions | Public leader for government-focused business line | Important for public-sector and regulated-environment GTM | Medium |
Table reflects only leaders publicly surfaced on BlueVoyant pages and corroborating CEO-transition coverage; private-company committee structure and full board roster remain incomplete.
[CO009, CO010, CO011, CO012, CO013, CO042]1.3 Funding History, Investors, and Ownership Visibility
BlueVoyant’s publicly visible capital story has two major inflection points. First, the company closed a $250 million Series D in February 2022 led by Liberty Strategic Capital, with participation from ISTARI, Eden Global Partners, and 8VC. Second, in November 2023 it paired the Conquest Cyber acquisition with more than $140 million in Series E funding led by existing investors Liberty Strategic Capital and ISTARI. Third-party market-data platforms now cluster around roughly $665.5 million of total capital raised and an estimated $1 billion valuation, but those figures are database estimates rather than company-certified financial disclosure. The evidence therefore supports a strong capital base and credible institutional sponsorship, yet not an exact present-day mark. Public materials are also thin on board committees, protective provisions, debt, secondaries, and cap-table concentration, so investor map rows below should be treated as a diligence scaffold rather than a fully verified control chart.[CO020, CO021, CO023, CO026, CO027, CO028]
| Stakeholder | Role | Control / economic importance | Public support | Diligence ask |
|---|---|---|---|---|
| Liberty Strategic Capital | Lead investor in 2022 Series D; co-led 2023 Series E | Anchor institutional sponsor; official sources tie the fund to both major recent financings | $125M investment disclosed by Liberty in 2022; present again in 2023 funding | Confirm board seat, protective provisions, and any step-up rights |
| ISTARI (Temasek-founded cyber investor / advisor) | Series D participant; Series E co-lead | Strategic cyber investor with likely information-rights relevance | Named in 2022 and 2023 company-linked financing coverage | Confirm ownership stake, board observer rights, and strategic-commercial links |
| Eden Global Partners / Eden Global Capital Partners | Series D participant and strategic advisor; affiliate advised on 2023 transaction | Growth-equity and placement support rather than clearly disclosed control | Named in 2022 official release and 2023 transaction coverage | Clarify whether advisory role carries any continuing governance rights |
| 8VC | Series D participant | Signals venture participation in the 2022 scale-up round | Named in official 2022 financing coverage | Confirm follow-on participation and present ownership percentage |
| James Rosenthal | Co-founder; chairman | Likely meaningful insider ownership plus governance continuity after CEO handoff | Public materials show continuing board role but not share count | Request current cap table and voting-control summary |
| Thomas Glocer | Co-founder; vice chairman | Board-level strategic influence and reputational capital | Publicly identified as co-founder and vice chairman | Confirm equity stake and any reserved consent rights |
| Conquest Cyber assets / team | Acquired strategic platform extension | Important for regulated, government, and DIB product expansion rather than pure ownership control | Acquisition announced with Series E in Nov. 2023 | Review integration milestones, earnouts, and customer-retention assumptions |
Public sources identify round leaders and strategic roles but do not disclose ownership percentages, liquidation stack, debt, or observer rights; rows therefore emphasize diligence asks over inferred control.
[CO020, CO023, CO025, CO026, CO028, CO042]1.4 Platform Evolution, Ecosystem, and Commercial Positioning
BlueVoyant’s positioning is not just about detecting threats; it is about wrapping multiple cyber workflows into a managed platform narrative. Its Microsoft page and awards history show unusually strong ecosystem alignment, including repeated security-partner recognition and service packaging around Sentinel, Defender, Purview, and Copilot-era security operations. The partner program also indicates a channel-led route to market rather than purely direct sales. On the product side, the company has expanded its story from managed cyber defense into a broader AI-native or agentic SecOps message, capped by the June 2026 BlueVoyant AI launch. The November 2023 Conquest Cyber acquisition sits in the middle of that evolution by adding SaaS-heavy capabilities for regulated and government-sensitive environments. The Auto-ISAC partnership then extends the third-party-risk narrative into a named vertical. Together, these moves imply a company trying to deepen wallet share inside complex accounts rather than merely add logos.[CO015, CO016, CO017, CO018, CO019, CO023]
1.5 Milestones, Scale Signals, and Adverse Considerations
The public milestone pattern shows BlueVoyant moving from a 2017 founding story to a capital-intensive scaling phase, then into platform broadening and management transition. By 2026, the company is describing itself as global, Microsoft-aligned, and AI-forward, with more than 1,000 customers and more than 600 employees according to official pages. At the same time, diligence should resist over-precision. Third-party headcount signals range meaningfully above the official disclosure, while valuation and revenue numbers mostly come from private-market databases rather than audited reporting. The strongest public adverse signal in the retained source set is UpGuard’s June 2026 external risk report, which flags specific website-security hardening issues such as CSP weaknesses and unsafe-eval usage. That is not a thesis-breaking event, but it is notable because BlueVoyant sells security outcomes. Combined with sparse public governance and financial disclosure, it argues for a diligence posture that separates clear operating momentum from still-private economic quality.[CO021, CO028, CO029, CO030, CO031, CO032]
| Date | Event | Type | Amount / valuation / status | Participants | Implication |
|---|---|---|---|---|---|
| 2017 | BlueVoyant founded in New York | founding | Company launch | Founders including James Rosenthal and Thomas Glocer | Establishes the company as a post-2016 cyber-defense entrant with founder-led governance roots |
| 2022-02-23 | Series D closes | financing | $250M | Liberty Strategic Capital, ISTARI, Eden Global Partners, 8VC, others | Major scale-up round for technical capability and global expansion |
| 2022-02 | BlueVoyant publicly described as a cybersecurity unicorn | scale | > $1B valuation; $525M total raised to date | SecurityWeek / TechCrunch public coverage | External market validation of the 2022 financing inflection point |
| 2023-11-29 | Conquest Cyber acquisition announced with Series E financing | product | > $140M Series E | BlueVoyant, Conquest Cyber, Liberty Strategic Capital, ISTARI | Broadens platform depth and adds regulated-environment SaaS capability |
| 2023-11-29 | Acquisition positioned for highly regulated and government environments | regulatory | Strategic expansion | BlueVoyant, Conquest Cyber | Shows deliberate move toward defense-industrial-base and regulated buyer relevance |
| 2024 | Microsoft security partner awards highlighted on awards page | partnership | Worldwide + U.S. + Canada honors | BlueVoyant, Microsoft | Strengthens ecosystem credibility and channel positioning |
| 2025-09-24 | Auto-ISAC strategic engagement announced | partnership | TPRM collaboration | BlueVoyant, Auto-ISAC | Adds named automotive vertical wedge for supply-chain cyber products |
| 2026-05-05 | John Hernandez succeeds Jim Rosenthal as CEO | governance | Leadership transition | John Hernandez, Jim Rosenthal, BlueVoyant board | Marks shift from founder-led operations to hired-CEO scaling phase |
| 2026-06-09 | BlueVoyant AI launched | product | AI-native / agentic SecOps platform | BlueVoyant | Repositions company around AI-led SOC workflows |
| 2026-06-29 | UpGuard vendor risk report flags website-security hardening issues | adverse | CSP / unsafe-eval findings | UpGuard | Creates the clearest adverse public signal in the retained source set |
Timeline blends official company announcements with high-signal third-party corroboration; later financing and governance details remain incomplete because BlueVoyant is private.
[CO001, CO016, CO020, CO021, CO023, CO025]The public record shows BlueVoyant moving from 2017 founding to 2022 financing scale-up, 2023 platform broadening, and 2026 management plus AI-product repositioning.
[CO016, CO020, CO021, CO023, CO032, CO036]1.6 Exhibits
02Market Analysis
2.1 Market Boundary and Adjacent Spend
BlueVoyant should be framed as operating in the overlap between managed detection and response and cyber-focused third-party risk management, not as a generic cybersecurity vendor and not as a broad GRC suite. The MDR pages emphasize augmentation of existing EDR, SIEM, cloud, and Microsoft security stacks with 24x7 monitoring, incident response, and automation. The TPRM pages emphasize continuous monitoring, analyst-directed remediation, questionnaire workflows, zero-day alerting, and fourth-party mapping. That boundary matters because it defines what spend belongs in the core opportunity. Included spend is the part of security operations and vendor-risk budgets that buys continuous detection, validation, remediation, and external dependency visibility. Adjacent spend sits in GRC, board reporting, and broader resilience workflows, while the main substitutes remain in-house SOC buildouts, periodic questionnaires, spreadsheet-led vendor reviews, and point products that only solve one layer of the problem.[CM001, CM002, CM003, CM004, CM005, CM006]
| Segment / category | Included spend | Excluded spend | Buyer / payer | Relevance |
|---|---|---|---|---|
| MDR overlay / managed SecOps | 24x7 monitoring, threat triage, incident response, tuning of existing EDR, SIEM, cloud, and Microsoft security tools | Standalone endpoint licenses, firewalls, or generic network hardware | CISO, SOC leader, security operations budget | Core BlueVoyant MDR boundary |
| Cyber-focused TPRM | Continuous monitoring, vendor cyber findings, analyst-led remediation, questionnaire workflows, zero-day alerting | Generic vendor master data and non-cyber procurement administration | CISO, third-party risk leader, compliance, procurement | Core BlueVoyant TPRM boundary |
| Fourth-party and concentration analytics | Dependency mapping, nth-party visibility, what-if analysis, concentration exposure management | Pure one-time assessments with no dependency mapping | Enterprise risk, resilience, security, procurement | Important expansion wedge inside supply-chain cyber risk |
| AI-assisted cyber triage | Attack-surface monitoring, threat intelligence enrichment, vulnerability prioritization, automated triage support | General-purpose AI tooling without security workflow integration | Security operations and cyber defense teams | Supports MDR and digital-risk adjacencies |
| GRC / board reporting adjacency | Controls reporting, governance workflows, board-ready cyber risk summaries, policy evidence management | Broad legal, audit, HR, and non-cyber governance suites | Compliance, audit, board, enterprise risk | Adjacent spend that should not be counted as pure BlueVoyant core TAM |
| Status quo and substitute motion | In-house SOCs, spreadsheet-led vendor reviews, annual questionnaires, narrow point tools, manual remediation emails | N/A | Existing process owners | Explains why conversion is gradual and multi-step |
Boundary is the overlap of managed SecOps and cyber-focused vendor-risk monitoring. Generic GRC and stand-alone security controls are adjacent, not direct core TAM.
[CM001, CM002, CM003, CM004, CM005, CM006]2.2 Sizing Lens — TAM, SAM, and Contradictory Published Estimates
BlueVoyant's market can be sized, but only with layered logic rather than a single headline TAM. MDR estimates span from $3.92B in 2026 according to Precedence Research to $5.09B according to Mordor, with The Business Research Company at $4.16B. TPRM is even more definition-sensitive: TBRC gives a direct 2026 value of $8.09B, while NextMSC's 2025 baseline and Grand View Research's 2023 baseline imply normalized 2026 values near $11B. Those contradictions are not noise; they reflect differing treatment of software versus services, compliance workflows versus cyber monitoring, and adjacent GRC scope. For BlueVoyant, a reasonable gross 2026 core-market ceiling is roughly $12–16B when MDR and TPRM published baselines are combined before overlap. A more practical SAM narrows to about $5–8B after applying large-enterprise, regulated-buyer, and western-market filters. Public data does not support a precise dollar SOM because BlueVoyant does not disclose segment revenue or win-rate by module, so SOM should be treated as evidence-constrained rather than invented.[CM009, CM010, CM011, CM012, CM013, CM014]
| Lens | Publisher | Year / period | Geography | Value | CAGR / share | Methodology | Confidence | Limitation |
|---|---|---|---|---|---|---|---|---|
| MDR published baseline | Precedence Research | 2026 to 2035 | Global | USD 3.92B in 2026 -> USD 13.90B by 2035 | 15.12% | Category forecast for MDR market | medium | Long horizon and publisher-specific category definition |
| MDR alternate published baseline | Mordor Intelligence | 2026 to 2031 | Global | USD 5.09B in 2026 -> USD 13.45B by 2031 | 21.45% | Current-category market sizing with segment shares | medium | Broader service scope than some peers |
| MDR third published baseline | The Business Research Company | 2026 to 2030 | Global | USD 4.16B in 2026 -> USD 8.57B by 2030 | 19.8% | Headline MDR market forecast | medium | Different time window and scope from Precedence and Mordor |
| TPRM direct 2026 baseline | The Business Research Company | 2026 to 2030 | Global | USD 8.09B in 2026 -> USD 15.45B by 2030 | 17.6% | Headline TPRM market forecast | medium | May include solution and service layers beyond BlueVoyant's cyber-specific wedge |
| TPRM 2026 proxy from 2025 base | NextMSC | 2025 to 2030 | Global | USD 9.71B in 2025; ~USD 11.02B normalized to 2026; USD 18.28B by 2030 | 13.48% | 2025 base projected forward one year for 2026 comparability | low | 2026 figure is transformed from a 2025 baseline |
| TPRM 2026 proxy from 2023 base | Grand View Research | 2023 to 2030 | Global | USD 7.42B in 2023; ~USD 11.49B normalized to 2026; USD 20.59B by 2030 | 15.7% | 2023 base compounded forward for 2026 comparability | low | 2026 figure is transformed from a 2023 baseline |
| Adjacent GRC context | Mordor Intelligence | 2026 to 2031 | Global | USD 23.32B in 2026 -> USD 39.01B by 2031 | 10.84% | Broader governance, risk, and compliance software market | medium | Useful adjacency, but too broad to count as direct BlueVoyant core TAM |
| BlueVoyant gross 2026 core ceiling | Analyst synthesis from MDR + TPRM baselines | 2026 proxy | Global | Roughly USD 12.0B to USD 16.6B | n/a | Low and high ends sum published MDR and normalized TPRM baselines before overlap | low | Double-counts some overlapping budgets and excludes pricing/module mix detail |
| BlueVoyant practical SAM | Analyst synthesis from category filters | 2026 proxy | Regulated large enterprise; North America / Europe weighted | Roughly USD 5B to USD 8B | n/a | Applies large-enterprise, regulated-buyer, and western-market filters to the core ceiling | low | Needs management data on region, segment, and module mix to validate |
| BlueVoyant public SOM | Public-data lens | 2026 | BlueVoyant target accounts | Not supportable from public data | n/a | No public segment revenue or module share disclosure | low | Requires management disclosure on revenue mix, win rates, and customer concentration |
Contradictory analyst estimates are preserved intentionally. TPRM 2026 proxy rows transform older baselines to a common 2026 view; SAM and SOM rows are analyst-derived lenses, not disclosed company numbers.
[CM009, CM010, CM011, CM012, CM013, CM014]Three-layer view from adjacent governance context to BlueVoyant's narrower practical SAM.
The top layer uses Mordor's 2026 GRC estimate. The middle layer is the midpoint of published MDR and normalized TPRM baselines before overlap. The bottom layer is a low-confidence SAM midpoint after large-enterprise, regulated-buyer, and western-market filters; it is not a disclosed company number.
[CM017, CM018, CM019]Low/high ranges in USD billions showing how much published 2026 market baselines diverge before company-specific filtering.
MDR low/high come directly from Precedence and Mordor 2026 baselines. TPRM high converts Grand View's 2023 base to a 2026 proxy using its stated CAGR, while TPRM low uses TBRC's direct 2026 value. The core-ceiling row sums published category ranges before overlap; SAM is a filtered estimate, not a reported company figure.
[CM012, CM016, CM018, CM019]2.3 Buyer, Budget Owner, and Adoption Path
The buyer map is cross-functional. On the MDR side, the economic buyer is usually the CISO or security leader who already owns SIEM, EDR, and Microsoft security budgets but needs better response coverage, better tuning, or more 24x7 capacity. On the TPRM side, the day-to-day operator is often a vendor-risk or compliance team, but payer authority can sit with security, procurement, enterprise risk, or a regulated business-line owner depending on where supplier exposure is measured. The adoption trigger is usually not abstract 'cyber maturity.' It is a recent incident, a regulatory deadline, repeated questionnaire fatigue, a zero-day exposure across vendors, or an internal realization that fourth-party risk is largely invisible. BlueVoyant's official surfaces suggest an adoption path that starts with MDR overlay or TPRM monitoring inside an existing workflow, then expands into remediation, fourth-party analytics, and broader resilience reporting once leadership decides manual processes are too slow.[CM021, CM022, CM023, CM024, CM025, CM026]
| Segment | Buyer | User | Payer | Workflow | Budget owner | Adoption trigger |
|---|---|---|---|---|---|---|
| Large-enterprise SOC modernization | CISO or VP Security | SOC analysts, detection engineers, IR teams | Security operations budget | Overlay existing EDR/SIEM/Microsoft stack with 24x7 monitoring and response | CISO with CIO/CFO visibility | Alert fatigue, tool sprawl, staffing shortage, recent incident |
| Public-company third-party cyber program | CISO, third-party risk lead, audit sponsor | Vendor-risk analysts, compliance teams, remediation coordinators | Security or GRC budget | Collect evidence, monitor vendors continuously, escalate material findings, support board reporting | CISO / CRO / chief compliance officer | SEC governance pressure, recurring questionnaire burden, supplier incident |
| EU or regulated financial-resilience program | Operational resilience or security leader | Risk teams, resilience office, procurement, security operations | Risk, compliance, or regulated business-line budget | Map critical suppliers, validate cyber posture, support resilience testing and remediation | CRO, CISO, regulated-entity executive | NIS2-style deadlines, critical-vendor dependency mapping |
| Microsoft-heavy security environment | Security platform owner or CISO | Sentinel, Defender, M365, and cloud-security administrators | Existing Microsoft and security platform budget | Tune alerts, expand automation, add managed coverage without stack replacement | CISO / platform owner | Under-used Microsoft security spend, need for faster response, limited internal tuning capacity |
| Procurement and vendor-onboarding program | Procurement or vendor-management leader with security co-sponsorship | Vendor-onboarding analysts, business owners, risk reviewers | Procurement / operations budget with security input | Questionnaire management, vendor tiering, remediation follow-up, exception tracking | Procurement head with security sign-off | Supplier onboarding backlog, contract clause enforcement, zero-day exposure across vendors |
Rows blend MDR and TPRM buying centers because BlueVoyant sells across both motions. Budget ownership is inferred from product fit plus survey evidence, not disclosed BlueVoyant pipeline data.
[CM021, CM022, CM023, CM024, CM027, CM029]Qualitative map of how authority, budget, and trigger logic change by buyer archetype across BlueVoyant's MDR and TPRM motions.
Cells are qualitative and synthesized from BlueVoyant's product surfaces plus survey evidence on who feels the pain and who controls the budget. This is a decision-map exhibit, not a company-disclosed segmentation table.
[CM024, CM025, CM026, CM029, CM030]Typical path from an initial cyber pain point to wider BlueVoyant adoption across MDR and TPRM workflows.
This flow is qualitative. It synthesizes survey evidence on trigger events and BlueVoyant's module structure; it is not a disclosed funnel conversion chart.
[CM027, CM029, CM037, CM047, CM048, CM049]2.4 Growth Drivers, Regulation, and Category Expansion
The strongest demand drivers in 2026 are regulation, demonstrated third-party incident pain, and the rising cost of operating fragmented security programs without enough skilled people. SEC disclosure rules put cyber governance and incident materiality into board processes for U.S. public companies. NIS2 broadens EU cyber obligations across 18 critical sectors. CISA and NIST frame supply-chain cyber risk as a formal resilience problem spanning hardware, software, and managed services. That policy stack meets real operating pain: Marsh reports that 70% of organizations experienced a material third-party cyber incident in the past year and that 66% plan to increase cyber investment, while Panorays shows that most CISOs still lack full supply-chain visibility and formal breach-response playbooks. BlueVoyant's positioning aligns with those pressures because it combines monitoring, validation, remediation, and AI-assisted triage across both internal defense and external vendor exposure.[CM025, CM026, CM027, CM028, CM031, CM032]
| Driver / constraint | Direction | Timing | Implication for BlueVoyant | Diligence ask |
|---|---|---|---|---|
| SEC cyber disclosure governance | Driver | Current | Expands buyer set from SOC teams to audit, legal, and board stakeholders who need evidence-backed cyber workflows | Ask management which share of pipeline is tied to public-company governance requirements |
| NIS2 and broader EU cyber obligations | Driver | Current through 2026 enforcement cycles | Makes supplier cyber posture and resilience reporting more urgent for covered sectors | Quantify BlueVoyant's exposure to NIS2-covered industries and EU-headquartered accounts |
| CISA / NIST supply-chain formalization | Driver | Structural | Validates cyber supply-chain risk as a resilience discipline spanning hardware, software, and managed services | Test whether BlueVoyant wins when buyers frame SCRM as resilience rather than procurement compliance |
| Third-party incident frequency | Driver | Immediate | Real incidents create emergency budgets for continuous monitoring, remediation, and dependency mapping | Ask for case studies where supplier incidents accelerated purchase timing |
| Fourth-party blind spots and concentration risk | Driver | Immediate and expanding | Strengthens demand for dependency mapping and what-if analysis beyond direct vendors | Verify how often fourth-party analytics expands existing TPRM deals |
| AI-assisted triage and Microsoft optimization | Driver | Near-term | Supports MDR upsell into Microsoft-heavy environments and lowers cost-to-serve narrative | Request independent proof of alert-volume reduction and remediation-time improvement |
| Tool sprawl and weak integration | Constraint | Persistent | Disconnected buyer workflows slow cross-sell and standardization across MDR and TPRM modules | Request win/loss data on deals blocked by platform overlap or internal integration issues |
| MDR label confusion and crowded evaluations | Constraint | Current | Buyer confusion raises proof burden and favors vendors with clearer category ownership or bundling power | Ask how BlueVoyant differentiates against managed EDR and larger XDR platforms |
| Insurance softening and budget scrutiny | Constraint | Current | Falling insurance pricing can reduce one urgency lever even while claims severity stays high | Test whether pipeline quality changes when cyber-insurance pricing softens |
| No public SOM disclosure | Constraint | Current | Makes market-share underwriting imprecise and limits valuation confidence from public evidence alone | Request module-level revenue mix, ACV bands, and renewal/cross-sell metrics |
Timing and strategic implications are synthesized from regulation, market surveys, and BlueVoyant product positioning. Constraint rows are as important as driver rows for valuation relevance.
[CM027, CM031, CM032, CM033, CM034, CM035]2.5 Constraints, Adverse Signals, and Valuation Relevance
The market case is good, but it is not frictionless. KPMG shows that most programs are still only partly integrated with enterprise risk and that end-to-end managed-service adoption remains low, which means buyers often approach TPRM and MDR through disconnected tools, partial pilots, or narrow use cases. CyberProof warns that some providers misuse the MDR label by offering managed EDR or tool-centric monitoring without full human response leadership, which creates buyer confusion and slows category conversion. PeerSpot's crowded MDR category and CRC's evidence of softer cyber-insurance pricing both reinforce the idea that budget urgency can ebb even when claims severity keeps rising. For valuation, the right takeaway is that BlueVoyant participates in markets large enough and painful enough to matter, but multiple compression remains sensitive to how effectively the company can turn its cross-category story into measurable module penetration, lower buyer confusion, and a publicly supportable SOM.[CM036, CM039, CM040, CM041, CM042, CM043]
2.6 Exhibits
03Competitors
3.1 Competitive Landscape and Buyer Alternatives
BlueVoyant does not sit in a single clean market box. Gartner's 2026 MDR market definition treats managed detection and response as a turnkey, provider-operated SOC capability with active containment rather than alerting-only monitoring, while BlueVoyant's own homepage markets four adjacent offers at once: MDR, third-party risk management, digital risk protection, and professional services. That creates a broader competitive field than a normal MDR shortlist. On one side, BlueVoyant faces direct MDR rivals such as CrowdStrike, Palo Alto Networks, Arctic Wolf, Rapid7, ReliaQuest, and eSentire. On the other, it faces TPRM and cyber-ratings platforms such as SecurityScorecard and BitSight, plus workflow-oriented alternatives such as OneTrust- or ProcessUnity-style vendor-risk programs and the internal-SOC status quo. The practical implication is that BlueVoyant can win when the buyer wants one partner across SOC operations and supplier cyber defense, but it can be displaced when the budget owner narrows the problem to either platform-native MDR or procurement-centered vendor-risk automation.[CP001, CP002, CP005, CP027, CP029, CP033]
| Competitor | Category | Scale / Funding Signal | Buyer Sweet Spot | Key Differentiation | Primary Limitation vs. BlueVoyant |
|---|---|---|---|---|---|
| BlueVoyant | Hybrid MDR + TPRM / C-SCRM | 600+ employees; 1,200+ Sentinel deployments; private funding not refreshed in retained 2026 sources | Microsoft-heavy enterprise, regulated buyers, government supply chains | Combines MDR, TPRM, DRP, and services with strong Microsoft delivery depth | Lower MDR visibility than the biggest platform-native rivals; public funding/pricing detail is thin |
| Palo Alto Networks Unit 42 / Cortex XSIAM | Platform-native MDR / SOC | 16K+ employees; 70K+ customers globally | Large enterprise standardized on Palo Alto | Unified AI SOC platform plus Unit 42 services and deep first-party telemetry | Best economics and outcomes are tied to the Palo Alto stack; limited TPRM overlap |
| CrowdStrike Falcon Complete | Platform-native MDR | Public-company scale; 2.7M detections remediated monthly; 1-minute median time-to-contain | Enterprise and security-mature mid-market willing to standardize on Falcon | Native endpoint, identity, cloud, and SIEM telemetry with autonomous and human response | Higher platform lock-in and less open-stack flexibility than BlueVoyant or ReliaQuest |
| Arctic Wolf | Open-XDR MDR | 10K+ customers; 1,000+ security engineers; $60M Series D and ~$4.3B valuation reported historically | Mid-enterprise to enterprise buyers wanting co-managed outcomes | Concierge delivery, open XDR, warranty, and security-journey model | TPRM and supply-chain cyber defense are not core buying motions |
| Rapid7 | Platform-led managed operations | 11,500+ customers worldwide; public-company scale | Large SMB, mid-market, and enterprise buyers wanting unified exposure plus detection | Command Platform connects exposure management, telemetry, and managed operations | Less differentiated service identity than BlueVoyant; TPRM overlap is limited |
| ReliaQuest | Open-platform enterprise SecOps | 50K+ alerts processed daily; 255+ technology partners; customer count not disclosed on retained pages | Fortune 1000 and heterogeneous-tool enterprises | Any-source normalization, agentic AI teammates, and broad integration depth | Public scale and pricing disclosure are limited; no TPRM-specific data-network moat |
| eSentire | Vendor-independent MDR | 2,000+ customers across 35+ industries; 300+ integrations | Regulated mid-market, private-equity portfolios, and upper-mid-enterprise teams | Human-led containment plus multi-signal XDR and unlimited hunting/incident handling messaging | Brand scale is below the largest public suites and TPRM is not core |
| SecurityScorecard | Threat-informed TPRM / supply-chain detection | 3,300+ customer organizations; 12M+ monitored and rated organizations | Vendor-risk, cyber insurance, procurement, and board-reporting programs | Continuous ratings plus AI assessment automation, nth-party visibility, and remediation workflows | Managed SOC depth is lighter than BlueVoyant MDR; outside-in methods do not replace internal telemetry |
| BitSight | Cyber risk intelligence / TPRM | 3,500+ customers; 68K+ active organizations; 75K+ mapped vendor profiles | Ratings-centric enterprise risk and supply-chain programs | Large mapped supply-chain dataset, independently validated ratings claims, and strong analyst recognition | MDR is not core and customers may still need separate workflow or service layers |
| Internal SOC / workflow-only program | Status quo / substitute | Buyer-funded people, tools, or GRC-suite budget | Very large enterprises or compliance-led procurement teams | Maximum control or lowest incremental spend if a workflow suite already exists | Highest staffing burden or weaker threat-response outcomes than full MDR |
Scale signals mix employees, deployments, customer counts, vendor profiles, and historical private-market funding markers; they are directional rather than like-for-like revenue measures.
[CP002, CP005, CP011, CP012, CP014, CP017]Evidence-backed ordinal view of competitor openness and budget breadth; higher y-values indicate broader overlap across SOC, procurement, insurance, or supply-chain workflows.
Axes are ordinal scores derived from retained product pages and market guides rather than audited market-share data. X = stack openness/tool neutrality from 1 (closed suite) to 5 (open ecosystem). Y = budget breadth from 1 (SOC-only) to 5 (SOC plus supply-chain/procurement/insurance relevance).
[CP001, CP002, CP014, CP021, CP027, CP032]3.2 MDR Head-to-Head: Platform Suites vs Open-Stack Providers
The MDR field around BlueVoyant splits into two economically different competitor classes. Palo Alto Networks and CrowdStrike sell managed response as an extension of broader proprietary platforms; their pitch is automation depth, native telemetry, and bundle economics. Palo Alto layers Unit 42 services on top of Cortex XSIAM's unified SIEM, SOAR, EDR, NDR, and CDR stack, while CrowdStrike's Falcon Complete emphasizes one-minute median time-to-contain, millions of monthly remediations, and deep endpoint, identity, cloud, and third-party telemetry from the Falcon ecosystem. Arctic Wolf, ReliaQuest, Rapid7, and eSentire attack from the opposite direction: they position themselves as more open, service-intensive partners that work across an existing tool estate. Arctic Wolf leads with concierge delivery and open XDR; ReliaQuest with any-source normalization and broad integrations; Rapid7 with integrated exposure plus detection; and eSentire with vendor-independent XDR and human-led containment. BlueVoyant belongs closer to this second camp operationally, but with a stronger Microsoft-specific services identity than most of those rivals.[CP003, CP004, CP009, CP010, CP011, CP012]
| Buying Criterion | BlueVoyant | Palo Alto | CrowdStrike | Arctic Wolf | Rapid7 | ReliaQuest | eSentire | SecurityScorecard | BitSight |
|---|---|---|---|---|---|---|---|---|---|
| Hands-on managed response authority | High | High | High | High | Medium | High | High | Low | Low |
| Proprietary platform lock-in pressure | Medium | High | High | Low | Medium | Low | Low | Low | Low |
| Microsoft ecosystem depth | High | Medium | Medium | Medium | Medium | Medium | Medium | Low | Low |
| EDR / SIEM openness | Medium | Low | Low | High | Medium | High | High | Low | Low |
| Third-party / supply-chain cyber monitoring | High | Low | Low | Low | Low | Low | Low | High | High |
| Board / procurement / insurance reporting utility | Medium | Medium | Medium | Medium | Medium | Medium | Medium | High | High |
| Publicly signaled AI / agentic roadmap | High | High | High | High | High | High | High | High | High |
| Best fit for mixed-tool enterprises | Medium | Low | Low | High | Medium | High | High | Low | Low |
High/Medium/Low values are author assessments derived from retained public product pages and independent buyer guides; they indicate publicly stated capability and operating model, not audited benchmark performance.
[CP003, CP009, CP012, CP014, CP016, CP020]Condensed capability map showing where BlueVoyant overlaps with MDR suite vendors versus TPRM platforms.
High/Medium/Low values are author assessments from retained public documentation and buyer-guide sources; they show the public capability narrative, not audited feature parity.
[CP003, CP006, CP013, CP023, CP025, CP028]3.3 Supply-Chain and TPRM Competition
BlueVoyant's supply-chain defense introduces a separate buyer alternative set from its MDR competitors. SecurityScorecard and BitSight are the clearest overlaps because both frame cyber risk as a continuous, outside-in view of vendor exposure, then connect that data to board reporting, procurement oversight, insurance workflows, and remediation programs. SecurityScorecard goes further in presenting itself as supply-chain detection and response with questionnaire automation, nth-party visibility, and AI-assisted remediation. BitSight pairs a large mapped vendor network with Forrester-recognized ratings credibility and a cyber-risk intelligence dataset measured in tens of millions of monitored companies. Independent market guides also point out that many buyers do not stop at ratings tools; they pair them with workflow-centric platforms such as ProcessUnity, OneTrust, Venminder, or internal questionnaire programs. That matters for BlueVoyant because its outside-in C-SCRM proposition competes not only with rival data networks, but also with workflow software that can make standalone intelligence layers look interchangeable unless BlueVoyant proves faster remediation and stronger analyst involvement.[CP006, CP007, CP021, CP022, CP023, CP024]
3.4 BlueVoyant Differentiation, Packaging, and Likely Win Zones
BlueVoyant's most distinctive public story is the combination of Microsoft-heavy MDR, outside-in supplier defense, and adjacent digital-risk services rather than a claim to be the single best endpoint or ratings vendor. Its retained pages emphasize 1,200-plus Microsoft Sentinel deployments, 24x7 regional SOC coverage, 50-plus certified Microsoft delivery and SOC engineers, and a government product that can map tens of thousands of suppliers using 70,000-plus data feeds without requiring proprietary supplier data. The June 2026 BlueVoyant AI launch adds a second important angle: management is trying to move from pure services into an agentic SecOps platform that can be consumed either as a managed service or self-service SaaS. That gives BlueVoyant a plausible win zone in regulated, Microsoft-heavy environments where the buyer wants one provider across managed SOC operations and third-party cyber defense. It is a weaker fit for buyers who want the lowest investigation burden inside one proprietary security suite, or for procurement-led TPRM programs that already prefer a ratings vendor plus workflow software.[CP003, CP004, CP006, CP007, CP008, CP027]
| Vendor | Public Pricing Visibility | Contract / Packaging Signal | What Is Publicly Emphasized | Competitive Implication |
|---|---|---|---|---|
| BlueVoyant | No public list pricing on retained pages | Quote-based platform and managed-service bundles | MDR, TPRM, DRP, and professional services sold together | Cross-sell flexibility is a strength, but outside buyers cannot benchmark list ACV from public pages |
| CrowdStrike Falcon Complete | No public list pricing on retained pages | Quote-based MDR on the Falcon platform | Agentic MDR, deterministic automation, and broad native telemetry | Customers already on Falcon can rationalize spend inside a broader platform contract |
| Palo Alto Networks | No public list pricing on retained pages | Quote-based XSIAM plus Unit 42 managed services | Unified SOC stack and managed services | Bundle economics can undercut service-led challengers in large-suite accounts |
| Arctic Wolf | No public list pricing on retained pages | Security operations bundles with concierge delivery and warranty | Outcome-led managed service rather than tool purchase | Appeals to buyers seeking outsourced outcomes, but public comparability is still low |
| Rapid7 | No public list pricing on retained pages | Platform subscription plus managed operations | Exposure management + SIEM + managed operations | Natural expansion path for Rapid7 customers, but opaque public pricing remains a diligence item |
| ReliaQuest | No public list pricing on retained pages | Enterprise platform with integration-heavy deployment | Any-source GreyMatter operations and integrations | Best fit for complex enterprises, but procurement likely remains custom and services-heavy |
| eSentire | No public list pricing on retained pages | Managed MDR / XDR service contract | Unlimited hunting and incident handling messaging | Good for outcome buyers, but less transparent for early shortlist cost screens |
| SecurityScorecard / BitSight | No public list pricing on retained pages | Quote-based ratings / TPRM programs | Continuous monitoring, questionnaires, AI summaries, vendor-network intelligence | Budget path often runs through procurement, risk, or insurance rather than the SOC |
This table compares pricing visibility and packaging signals only. Retained official pages generally omit enterprise list pricing, so contract values and realized discounts remain a diligence gap.
[CP041, CP042, CP043, CP044]Six public indicators that summarize BlueVoyant’s competitive position as of June 2026, combining strengths and adverse signals.
[CP003, CP005, CP007, CP008, CP034, CP040]3.5 Weaknesses, Adverse Evidence, and Moat Durability
The most important disconfirming evidence is not that BlueVoyant lacks product breadth, but that larger competitors can frame the same job with stronger market visibility or lower operational friction. PeerSpot's June 2026 review page puts BlueVoyant at just 0.9% MDR mindshare, down from 1.2% a year earlier, and its direct comparison page ranks BlueVoyant #34 versus CrowdStrike #2 while noting weaker reporting customization and potentially heavier configuration. Daylight's 2026 buyer guide is blunter: it classifies BlueVoyant among MSSP-style MDR providers chosen for broad security partnership, but with more analyst-hours-intensive workflows than AI-native or XDR-extended alternatives. On the TPRM side, BlueVoyant must also defend against much larger external data networks from SecurityScorecard and BitSight. Public pricing opacity across nearly every retained competitor page compounds the challenge because it makes incumbent suite bundling and multi-product discounts harder to benchmark from the outside. BlueVoyant therefore has a real moat in cross-budget service breadth, but not an obviously durable moat in category visibility, data-network scale, or platform lock-in.[CP017, CP018, CP034, CP035, CP036, CP037]
| Moat or Risk Claim | Primary Threat | Severity | Current Mitigation Signal | Diligence Ask |
|---|---|---|---|---|
| Microsoft-specialist MDR depth | CrowdStrike, Palo Alto, and Microsoft-native alternatives can offer more native automation or bundle economics | High | BlueVoyant AI launch and 1,200+ Sentinel deployments strengthen the specialist story | Break out revenue mix from Microsoft-heavy accounts vs. non-Microsoft accounts |
| Cross-budget MDR + TPRM + DRP positioning | Buyers may still split SOC and vendor-risk budgets and select separate best-of-breed tools | High | BlueVoyant markets all four motions together and government C-SCRM broadens the story | Measure multi-product attach rate and expansion from MDR into TPRM |
| Outside-in supplier illumination | SecurityScorecard and BitSight operate much larger public data networks and stronger ratings brands | High | BlueVoyant adds analyst-led remediation and government mission framing rather than ratings alone | Benchmark supplier coverage, false positives, and remediation speed against ratings vendors |
| Services-led delivery model | AI-native and platform-native MDR can shift more investigation burden into software and automation | High | BlueVoyant AI moves the model toward agentic SecOps and self-service SaaS | Test analyst-to-customer leverage and escalation load before and after BlueVoyant AI deployment |
| Public pricing opacity | Suite vendors can hide discounts inside broader contracts and make standalone comparison harder | Medium | BlueVoyant can package MDR and TPRM together when buyers want one partner | Obtain apples-to-apples ACV, ramp, and renewal benchmarks in diligence |
| Lower MDR market visibility | PeerSpot mindshare and ranking suggest weaker shortlist gravity than CrowdStrike or category leaders | Medium | BlueVoyant can target regulated or Microsoft-led use cases instead of generic MDR bake-offs | Validate enterprise brand awareness and RFP inclusion rates by vertical |
Severity reflects author judgment based on retained public evidence. Diligence asks identify the private data needed to test whether the observed moat or risk is durable.
[CP017, CP018, CP034, CP035, CP036, CP037]04Financials
4.1 Revenue model and monetization visibility
BlueVoyant's public commercial surface looks like a recurring cybersecurity platform wrapped around MDR, TPRM, DRP, and professional services rather than a one-off project business. The homepage and product materials emphasize ongoing monitoring, response, remediation, and takedown work, while customer proofs and TEI studies reinforce a subscription-or-retainer style value proposition. That said, the public record is much stronger on outcomes than on monetization detail. BlueVoyant discloses deployment counts, ROI claims, and marketplace procurement routes, but it does not publish standard list prices for its core offers, nor does it expose realized pricing, discounting, or revenue mix between recurring managed services and project-based work. The result is a clear top-line revenue mechanism but an incomplete view of revenue quality and contribution margin by stream.[CI001, CI002, CI003, CI004, CI005, CI006]
| Stream | Mechanism | Public evidence | Monetization visibility | Quality / caveat | Diligence ask |
|---|---|---|---|---|---|
| Managed Detection & Response | Recurring managed monitoring and response | 1,200+ Sentinel deployments; 24x7 SOC coverage | Contracted / recurring, but list pricing not public | Strong demand proxy; weak pricing transparency | Request contract terms, seat/device basis, and gross margin by customer segment |
| Third-Party Risk Management | Recurring monitoring, validation, and remediation support | 18x faster remediation; 98% accuracy; GCP marketplace route | Recurring / enterprise procurement eligible | Outcome data strong; revenue realization opaque | Request per-vendor pricing, remediation fees, and attach rates |
| Digital Risk Protection | Ongoing monitoring and takedown services | 50,000 domain takedowns over two years; social and website takedown success rates | Likely recurring service bundle | High activity signal; no price disclosure | Request pricing by protected brand/account and takedown economics |
| Professional Services / DFIR | Project, retainer, and advisory revenue | Homepage and case studies position incident response and strategic services alongside MDR | Project / retainer mix not disclosed | Most likely lumpy compared with MDR/TPRM | Request retainer attach rate and services utilization data |
Official pages show the revenue mechanisms clearly, but they do not reconcile stream mix, realized pricing, or stream-level margin.
[CI001, CI002, CI004, CI005, CI006, CI007]| Offer / channel | Public pricing signal | Realized pricing visibility | Procurement path | Revenue implication |
|---|---|---|---|---|
| MDR / SOC outsourcing | Build-vs-buy page frames >$1.2M self-build cost and <25% MSSP alternative | No public contract price or per-endpoint rate | Direct sales and partners | Value proposition is explicit, but realized ASP and gross margin are unknown |
| TPRM on GCP Marketplace | Marketplace availability public; no numeric list price disclosed | No public net price, discount, or minimum commit | Cloud marketplace / enterprise agreement | Should reduce procurement friction and channel cycle time |
| Microsoft optimization services | Blog says internal optimization can cost up to $750k annually | No BlueVoyant service price card disclosed | Direct enterprise sale, likely consultative | Supports advisory upsell logic, not actual BlueVoyant pricing realization |
| Partner-assisted deals | Partner contribution hit 50% of new business in 2021 | Channel discounts and rev-share not disclosed | Resellers, consultancies, and technology partners | Could improve top-of-funnel efficiency while compressing realized price |
| Customer case-study expansions | Odeon and Snappi show multi-product land-and-expand motion | No disclosed contract values | Direct / partner blend | Supports wallet-share story without supplying ARR per account |
This table separates public procurement routes from missing realized-price data; the public record shows how buyers can buy, not what they actually pay.
[CI012, CI013, CI017, CI034, CI035, CI038]BlueVoyant converts direct demand, partner demand, and marketplace access into recurring managed-security revenue plus a smaller professional-services layer, but public materials stop before realized gross profit can be quantified.
This bridge is qualitative because public materials expose route-to-market and outcomes but not realized revenue mix or gross margin by stream.
[CI001, CI011, CI017, CI034, CI038, CI060]4.2 GTM motion and sales-efficiency proxies
BlueVoyant appears to scale through a hybrid of direct enterprise selling, partner-led demand, and lower-friction cloud-marketplace procurement. The company explicitly says partners contributed half of all new business in 2021, and its channel pages show that reseller and consulting relationships are central rather than incidental. That matters because partner leverage can offset the staffing intensity that usually accompanies 24x7 managed services. BlueVoyant also markets hard savings arguments against the in-house SOC alternative, claiming both that self-build can exceed $1.2 million annually and that an MSSP can cost under one quarter of that level. Customer-value studies add more evidence, though they are company-sponsored: the Forrester TEI materials, ODEON outcomes, and Sentinel case-study guide all point to meaningful operational savings, but they still stop short of giving true CAC, payback, or realized gross-margin data.[CI011, CI012, CI013, CI017, CI029, CI030]
| Proxy | Public value / status | Confidence | Why it matters | Diligence ask |
|---|---|---|---|---|
| ARR growth since 2018 | 117% average growth claim | medium | Signals strong top-line momentum if still directionally true | Request audited bookings/ARR bridge by year |
| Partner-sourced new business | 50% of 2021 new business | medium | Suggests distribution leverage beyond direct sales headcount | Request partner-sourced pipeline, win-rate, and margin split |
| Build-vs-buy alternative cost | >$1.2M self-build annual SOC cost | medium | Frames customer ROI and willingness-to-pay ceiling | Request ROI model assumptions and actual competitive win-loss data |
| Outsourced SOC savings claim | <25% of internal SOC cost | medium | Supports payback narrative but not realized price | Request contract examples and customer payback models |
| MDR TEI value proxy | 210% ROI; 90% fewer escalated alerts; 70% faster MTTR | medium | Supports retention and expansion thesis if representative | Request customer cohort methodology and non-sponsored references |
| Supply-chain-defense value proxy | ~300% ROI; 62% faster critical-risk remediation | medium | Suggests higher-value TPRM economics than pure compliance tooling | Request customer retention and expansion metrics for TPRM accounts |
These are sales-efficiency and value proxies, not closed-loop unit economics; public evidence is directional and mostly company-sponsored.
[CI017, CI018, CI029, CI030, CI031, CI032]BlueVoyant presents strong customer-value proxies and outsourcing economics, but the public trail breaks before CAC, payback, and margin can be measured directly.
Nodes summarize evidence quality, not hidden internal telemetry; downstream economic outputs remain intentionally unresolved.
[CI012, CI013, CI017, CI029, CI030, CI031]4.3 Public scale signals and operating leverage proxies
BlueVoyant's official scale narrative is directionally strong and internally consistent on growth, but not consistent enough on exact current size to underwrite without caveat. Official press releases progress from more than 700 customers in 30 countries in early 2022, to more than 900 global customers in mid-2024, to more than 1,000 customers in over 45 countries by March 2025. Headcount signals are more uneven: BlueVoyant says it has over 600 employees, GetLatka estimates about 650, Dialectica lists 653, and an accessible historical PitchBook snapshot showed only 363 employees. That spread is too wide to ignore, especially because revenue-per-employee and sales-efficiency proxies change meaningfully depending on which denominator is used. The prudent read is that BlueVoyant has real enterprise scale and international delivery reach, but public databases remain stale or inconsistent on the exact operating baseline.[CI010, CI014, CI015, CI016, CI020, CI025]
| Metric | 2022 signal | 2024 signal | 2025 / database signal | Caveat |
|---|---|---|---|---|
| Customer count | >700 customers in 30 countries | >900 global customers | >1,000 customers in >45 countries | Progression is directionally strong, but exact current count is still company-claimed |
| Headcount | >560 employees at Series D | >600 employees on company page | 650 (GetLatka); 653 (Dialectica); 363 (historical PitchBook) | Private databases disagree and some snapshots are stale |
| Partner leverage | Partners contributed 50% of new business | Channel roster broadened on official site | Marketplace route added for TPRM | Good GTM signal, weak disclosed economics |
| Delivery scale | 1,200+ Sentinel deployments; 24x7 SOC | ODEON across 8 countries and 280+ cinemas | Hundreds of deployments / 16 case studies in guide | Proof of scale exists, but not all deployments translate to comparable ARR |
| EMEA investment | Expanded into >10 countries in 2021 | Finance function and acquisition buildout in 2024 | Cork launch, local revenue +70% in 2024 | Scale signals support growth, not profitability |
These proxies mix official disclosures and private-database snapshots; they are useful for trend direction, not as a clean single-period operating baseline.
[CI010, CI015, CI016, CI017, CI020, CI021]4.4 Capital base, investor syndicate, and conflicting private-company signals
BlueVoyant's capital history clearly includes two large late-stage rounds: a $250 million Series D in 2022 and a more-than-$140 million Series E tied to the Conquest Cyber acquisition in 2023. Liberty Strategic Capital and ISTARI are recurring anchors in that investor base, with Eden Global Partners recurring as adviser or participant. Beyond that, third-party databases start to diverge. CB Insights and Clay both report roughly $665.5 million of cumulative funding, while Tracxn reports $696 million; investor counts vary from 9 on a historical PitchBook snapshot to 11 on Clay and 15 on CB Insights. Revenue signals diverge even more sharply, with GetLatka showing a $213.5 million 2025 estimate while CB Insights shows $750 million for 2024. Those contradictions do not prove any single source is wrong, but they do make plain that the public/private data exhaust is insufficiently reconciled for investment underwriting without management confirmation.[CI019, CI021, CI022, CI023, CI024, CI041]
| Dimension | Public signal | Source-backed value / status | Underwriting implication | Diligence ask |
|---|---|---|---|---|
| Series D equity capital | Large late-stage round | 2022 Series D, $250M, Liberty Strategic Capital lead | Material balance-sheet support for scale-up and hiring | Request post-money cash bridge and uses of proceeds |
| Series E + acquisition capital | Acquisition-linked growth funding | > $140M Series E alongside Conquest acquisition in 2023 | Shows continued investor support and M&A appetite | Request integration budget and revenue contribution from Conquest |
| Investor base depth | Repeat strategic sponsors | Liberty, ISTARI/Temasek, Eden, 8VC, plus varying database investor counts | Syndicate quality looks strong, but exact breadth is inconsistent | Request current cap table and ownership by round |
| Debt / leverage signal | Only historical public debt trace retained | PitchBook snapshot shows 2020 Debt-PPP entry; no retained current debt facility | Current leverage may be zero, modest, or simply undisclosed | Request debt schedule, lender names, and covenant package |
| Cash / burn / runway | Not publicly disclosed | No retained public source verified them as of run date | This is the largest underwriting blocker | Request latest cash balance, burn, and runway model |
| Regional expansion commitments | EMEA buildout and SOC expansion visible | Cork opening tied to multi-million-euro investment and 70% local revenue growth | Expansion suggests ongoing spend even without cash disclosure | Request EMEA hiring plan, opex, and expected payback |
Historical funding chronology belongs in Company Overview; this table focuses on forward adequacy and current blind spots needed for underwriting.
[CI019, CI022, CI023, CI026, CI028, CI041]| Metric | Source A | Source B | Source C | Why it conflicts / how to use |
|---|---|---|---|---|
| Total raised | CB Insights: $665.5M over 9 rounds | Clay: $665.5M total raised | Tracxn: $696M over 6 rounds | Consensus is roughly mid-$600Ms, but round counting and treatment differ; management should provide the cap table |
| Revenue / ARR | GetLatka: $213.5M in 2025 | CB Insights: $750M in 2024 | No official revenue disclosure | These figures are not directly reconcilable and could reflect ARR vs broader revenue vs stale estimates |
| Employees | Company page: >600 | GetLatka: 650; Dialectica: 653 | PitchBook snapshot: 363 | Later sources cluster around 600+, while the accessible PitchBook snapshot looks stale or partial |
| Investor count | Clay: 11 investors | CB Insights: 15 investors | PitchBook snapshot: 9 investors | Database coverage varies; use public round announcements plus cap table request instead of any single count |
| Latest deal history | Series E $140M in 2023 appears in official/news sources | PitchBook accessible snapshot shows latest deal amount of $30M | PitchBook also shows historical Debt-PPP entry | A stale or archived profile can materially distort current financing and leverage assumptions |
The point is not to choose a favorite database; it is to preserve contradictory estimates until management reconciles them.
[CI042, CI043, CI044, CI045, CI046, CI047]Publicly surfaced funding, revenue, customer, and employee figures span wide ranges because the company is private and database snapshots are inconsistent.
Ranges intentionally preserve contradictory years and source methodologies instead of collapsing them into a false point estimate.
[CI042, CI044, CI045, CI046, CI047, CI049]4.5 Financial verdict and diligence blockers
The retained evidence supports a company with real recurring demand, substantial private-capital backing, and enough customer breadth to matter in enterprise cybersecurity. It does not, however, support a clean financial underwriting case. Cash, burn, runway, debt obligations, realized pricing, gross margin, retention, CAC, and payback remain outside the public record. A historical PPP debt signal and UK filing trail show corporate-document activity, but they do not answer current leverage or liquidity questions. The adverse workforce review does not overturn the growth narrative, yet it does warn that resource constraints may coexist with acquisitive expansion and executive buildout. The right financial conclusion is therefore constructive but not investable on public evidence alone: BlueVoyant looks commercially relevant, but management data is still required to judge revenue quality, operating leverage, and next-round dependency.[CI026, CI028, CI053, CI054, CI055, CI056]
| Missing metric | Why it matters | Current proxy | Specific diligence path |
|---|---|---|---|
| Cash on hand / runway | Determines financing dependency and next-round urgency | Large past raises and ongoing expansion only | Request current balance sheet, cash forecast, and board runway scenario deck |
| Monthly burn and hiring plan | Shows whether growth is self-funded or cash-consuming | Cork expansion, CFO buildout, and customer growth are indirect proxies | Request monthly burn bridge, hiring plan, and variance to budget |
| Gross margin by product line | Needed to separate software-like recurring economics from staffing-heavy service economics | TEI and case studies show outcomes, not margin | Request gross margin and utilization by MDR, TPRM, DRP, and services |
| Realized pricing / discounts | Needed to judge price discipline and renewal quality | Marketplace route and build-vs-buy framing only | Request price books, discount approvals, and recent contract samples |
| Debt schedule and covenants | Needed to understand leverage, restrictions, and refinancing risk | Only a historical 2020 Debt-PPP trace surfaced directly | Request lender agreements, covenant package, and any acquisition-related borrowing |
Nulls here are intentional diligence blockers rather than formatting omissions; they mark the minimum dataset required for underwriting.
[CI052, CI058, CI059, CI060, CI061, CI062]4.6 Exhibits
05Product & Technology
5.1 Platform definition and converged architecture
BlueVoyant now markets the company less as a stand-alone MDR provider and more as a unified cyber-defense operating system. The homepage, the Cyber Defense Platform page, and the 2024 launch materials consistently describe one cloud-native platform spanning internal defense, third-party risk, and external digital-risk monitoring. That matters because the product definition is customer-workflow specific: a security team can run internal SOC triage, supplier remediation, and brand or credential takedown work from the same operating model instead of stitching together separate point tools. The company’s newer AI layer reinforces that convergence thesis rather than replacing it; BlueVoyant AI is framed as a control plane that decides when to route work to deterministic automation, when to call a human analyst, and when to let agents act. The diligence-positive takeaway is that the portfolio is coherently packaged. The diligence caveat is that the public architecture remains marketing-layer deep outside a few Microsoft-specific documents.[CE001, CE003, CE004, CE005, CE006, CE007]
| Module / asset | Primary buyer or user | Current public maturity | Differentiation signal | Diligence gap |
|---|---|---|---|---|
| Cyber Defense Platform | CISO, SOC leader, security operations team | Current umbrella product | Converges MDR, TPRM, DRP, and services on one cloud-native surface | No public architecture document that shows shared schemas, tenancy, or data-routing details |
| BlueVoyant AI | BlueVoyant SOC or customer SOC | New 2026 launch / active go-to-market | Agentic model pairs human judgment, deterministic automation, and AI agents with managed or self-service deployment | No public benchmark pack for false-positive reduction, MTTR change, or model-governance details |
| MDR for Microsoft | Microsoft-native security teams | Core and deeply evidenced | Most concrete technical proof in the portfolio, including tenant-resident data handling and specific Microsoft stack coverage | Breadth outside Microsoft tools is still described only at a higher level |
| Continuous Optimization for Microsoft Solutions | Security engineering, compliance, and platform-ops teams | Current module / advisory-plus-software layer | Extends beyond monitoring into Sentinel, Defender, M365, and Purview optimization | Commercial packaging, repeatability, and automation depth are not publicly broken out |
| Third-Party Risk Management / Supply Chain Defense | Vendor-risk, procurement, and cyber-risk teams | Current and feature-complete in public materials | Combines continuous monitoring, remediation, questionnaires, and advisory work instead of only passive scoring | Software versus analyst-labor contribution is not publicly quantified |
| Digital Risk Protection | Brand-protection, fraud, and external-risk teams | Current and modular | Covers web, social, app, dark-web, and executive-protection workflows with published takedown metrics | Outcome quality depends on external platforms and partner responsiveness |
| Conquest-enhanced compliance and posture layer | Defense, government, and regulated buyers | Integration-stage capability expansion | Adds risk-maturity, posture, and compliance mapping useful for CMMC-heavy environments | Public sources do not show how completely Conquest workflows are now embedded in core BlueVoyant UX |
Rows separate currently marketed modules from the acquisition-expanded posture/compliance layer that is still best evidenced through release materials.
[CE001, CE003, CE007, CE011, CE019, CE025]The public product story resolves into a five-layer stack from signal collection through AI orchestration and analyst-driven outcomes.
This figure is synthesized from current product pages, launch releases, trust-center metadata, and Microsoft collateral rather than copied from a vendor-published system diagram.
[CE004, CE005, CE006, CE007, CE016, CE030]5.2 Microsoft-centric MDR and agentic SOC operations
The most concrete technical depth is in BlueVoyant’s Microsoft ecosystem story. The MDR suite explicitly nests MDR for Microsoft and Continuous Optimization for Microsoft Solutions, and the Microsoft-specific pages are more precise than the generic platform prose. BlueVoyant publicly claims 24/7 coverage across the Microsoft security stack, multiple partner designations and specializations, a large engagement base around Sentinel and Defender, and a delivery model that can keep customer security data in the customer tenant instead of exporting it to an MSSP-controlled data lake. The 2026 BlueVoyant AI launch expands that position by describing automated containment actions, a managed or self-service deployment choice, and models trained on years of Microsoft-native operating history. In practice, this suggests BlueVoyant’s strongest technical moat is not a broad open integration catalog; it is process depth, tuning, automation, and analyst workflows around Microsoft environments.[CE002, CE006, CE007, CE008, CE009, CE010]
| User job | Current workflow problem | BlueVoyant solution | Published benefit or operating signal | Limitation |
|---|---|---|---|---|
| Microsoft SOC triage and containment | Too many alerts across Sentinel, Defender, identity, endpoint, and cloud surfaces | MDR for Microsoft plus BlueVoyant AI | 24/7 monitoring, automated response actions, and high-fidelity alerting are explicitly marketed | Public proof is strongest for claims, not for independent measured outcomes |
| Microsoft cost and posture optimization | Customers overpay or under-configure Sentinel, Defender, M365, and Purview | Continuous Optimization for Microsoft Solutions | BlueVoyant cites 1,000+ engagements and cost-control guidance for licensing and Sentinel consumption | Savings methodology and realized customer distributions are not public |
| Third-party critical finding remediation | Vendor-risk teams discover issues but struggle to drive closure | Continuous Monitoring & Remediation | ROC analysts validate findings and contact third parties directly | No public disclosure of closure-rate distributions by customer segment |
| Supplier assessment operations | Questionnaires are manual, slow, and hard to verify | Questionnaire Management platform and managed service | Automation plus validation of supplier claims is presented as the differentiator | Public material does not show integrations into customer GRC stacks |
| Brand impersonation takedowns | Phishing sites, fake pages, and rogue apps move quickly across many platforms | Brand Protection | Unlimited takedowns and 300+ app-store coverage are marketed, with public success metrics on the homepage | Takedown success still depends on registrar, social, or app-store cooperation |
| Credential, fraud, and leak monitoring | Security teams lack visibility into underground communities and leaked data | Dark Web Watcher | Continuous monitoring of underground sources plus account-takeover and leakage workflows are described | Public evidence does not show signal-to-noise ratios or time-to-detect distributions |
| Executive-targeted attack prevention | VIPs face personal-data exposure and account-takeover risk outside core IT controls | Executive Cyber Guard | Real-time alerts and tools to stop attacks are part of the marketed workflow | Public materials do not quantify adoption or measured executive-risk reduction |
This table focuses on user jobs and operational workflows, not on contractual SKUs or internal package names.
[CE007, CE008, CE012, CE015, CE021, CE023]BlueVoyant’s Microsoft-heavy workflow starts with telemetry and identity signals, then moves through AI-assisted triage, human validation, and containment or optimization action.
The flow emphasizes the Microsoft-centric MDR path because that is where the public evidence is most specific.
[CE007, CE008, CE012, CE015, CE016, CE018]5.3 Third-party risk and supply-chain workflows
BlueVoyant’s supply-chain defense materials are specific enough to treat TPRM as a productized workflow, not just a consulting wrapper around external ratings. The current TPRM overview, the continuous-monitoring page, and the 2023 expansion release align on the same operating model: vendor monitoring is tiered by risk, BlueVoyant analysts validate findings inside a Risk Operations Center, and remediation is driven directly with suppliers instead of being left entirely to the customer. Questionnaire management is also described as both software and managed service, which fits the overall BlueVoyant pattern of combining automation with labor-intensive execution where the workflow is messy. Publicly, the best substantiated differentiators are analyst-directed remediation, zero-day alerting, AI/ML-based business-risk monitoring, and the ability to combine continuous monitoring with periodic due-diligence assessments. The remaining diligence question is how much of this is repeatable software leverage versus scale achieved through expert staffing and service process discipline.[CE019, CE020, CE021, CE022, CE023, CE024]
| Layer / component | Role | Key dependency | Main risk |
|---|---|---|---|
| Customer telemetry and asset surfaces | Supply internal, external, and supplier signals into the platform | Customer tenancy, cloud workloads, endpoints, suppliers, and dark-web monitoring access | Public materials do not explain normalization, retention, or cross-domain schema design |
| Microsoft-native data plane | Provides Sentinel, Defender, identity, and compliance context for MDR workflows | Microsoft ecosystem depth and continued API / feature access | A heavy Microsoft concentration raises concentration risk if buyers want broader heterogeneous-stack transparency |
| AI and deterministic automation layer | Enriches, triages, and can trigger automated containment actions at machine speed | Model tuning, playbooks, approval logic, and data quality | Public evidence does not expose model-governance, evaluation, or rollback controls |
| Human analyst layer | SOC and ROC experts validate alerts, tune logic, and communicate with customers or vendors | Skilled labor availability and repeatable processes | Service quality can become people-intensive as volume scales |
| Third-party risk analytics layer | Monitors vendors, risk events, questionnaires, and remediation workflows | Large external data-source coverage plus customer vendor inventories | No public documentation of customer-side integrations into procurement or GRC systems |
| External takedown and monitoring network | Executes brand, app, social, and credential-remediation outcomes | Registrars, social platforms, app stores, and underground-source access | Outcome quality can vary with external platform responsiveness |
| Conquest posture and compliance layer | Extends the platform into posture, maturity, and government-oriented compliance workflows | Successful post-acquisition product integration | Public sources do not show whether the UX is fully unified or still portfolio-level |
The architecture is synthesized from reviewed product pages, releases, and Microsoft collateral rather than from a vendor-published engineering diagram.
[CE004, CE006, CE015, CE016, CE021, CE022]5.4 Digital risk protection and external dependency chain
The external-risk side of the platform is organized into a clean three-module structure: Brand Protection, Dark Web Watcher, and Executive Cyber Guard. Those modules map to concrete user jobs rather than abstract threat-intelligence buzzwords. BlueVoyant claims brand takedowns across web, social, and rogue-app channels; dark-web monitoring for fraud, leaked credentials, and exposed data; and executive monitoring for high-value account compromise or personal-data exposure. The company also publishes at least some measurable DRP performance signals, including website and social-media takedown success rates and a median server-level takedown time. Operationally, however, this product line is the most obviously dependent on outside platforms and counterparties: registrars, social networks, app stores, underground monitoring access, and customer response playbooks all sit in the outcome chain. That makes DRP strategically important but also dependency-heavy, which is why the Gartner review headline about occasional takedown challenges deserves attention.[CE025, CE026, CE027, CE028, CE029, CE030]
BlueVoyant’s product outcomes depend on a chain of technology and ecosystem counterparties, especially Microsoft plus external takedown and supplier-response channels.
The dependency map focuses on counterparties visible in fetched sources; undisclosed internal infrastructure vendors are intentionally omitted.
[CE021, CE027, CE028, CE030, CE033, CE035]5.5 Trust controls, capability expansion, and product risks
BlueVoyant has enough public trust and roadmap proof to support enterprise diligence, but not enough to eliminate buyer follow-up. The Trust Center confirms that the company wants to be seen as a cloud-native, AI-plus-human platform with more than 1,000 clients, while the Microsoft and Conquest materials show explicit alignment to compliance-heavy environments. Conquest is particularly important because it expands BlueVoyant from detection and risk visibility into risk-maturity mapping, posture management, and government-oriented compliance workflows such as CMMC and FedRAMP-adjacent environments. At the same time, the public developer surface is thin: GitHub shows only one visible public repository, and that repository is branded as content for Copilot for Security rather than core platform code or reusable integrations. Independent review and community sources also surface real caution signals—occasional DRP takedown friction, long-running questions about proprietary depth, and limited public evidence for non-Microsoft integrations, SLAs, or independently audited product performance.[CE016, CE031, CE032, CE033, CE034, CE035]
| Control / signal | Status | Scope | Gap |
|---|---|---|---|
| Trust Center presence | Verified | Vanta-hosted public Trust Center states BlueVoyant is cloud-native and AI-plus-human with 1,000+ clients | Fetched public surface does not expose the full certificate and report inventory in readable text |
| Tenant-resident Microsoft data handling | Verified in collateral | MDR for Microsoft PDF says customers can keep security data in their own environment | This proof is in partner collateral, not a public architecture or data-processing white paper |
| Microsoft partner recognitions and specializations | Verified company claim | MDR for Microsoft page lists partner awards, designations, and security specializations | Awards signal delivery credibility more than platform control maturity |
| CMMC / FedRAMP / defense-environment relevance | Verified through Conquest acquisition | Release materials tie Conquest and BlueVoyant to CMMC RPO accreditation, DIB use cases, and ARMED ATK on the FedRAMP marketplace | Public sources still do not map those controls to the main commercial platform in detail |
| Independent review signal on DRP execution | Mixed | Gartner surface shows a favorable DRP review headline that still flags occasional takedown challenges | A single public review headline is not enough to underwrite broad reliability |
| Public developer transparency | Low | GitHub shows one visible public repository focused on Copilot for Security content | Open-source evidence is too thin to evaluate connector depth, release cadence, or engineering reuse at scale |
This table separates trust signals that are directly visible in fetched sources from the larger control inventory that still requires private diligence.
[CE016, CE017, CE031, CE032, CE035, CE036]| Date / stage | Feature / milestone | Status | Implication | Source |
|---|---|---|---|---|
| 2023-03 partner training | BlueVoyant Shadow Hunter Microsoft Security Immersion Workshop | Historical / partner-enabled | Shows Microsoft practitioner engagement before the broader platform convergence story was fully public | SE032 |
| 2023-09 product expansion | Comprehensive third-party cyber risk management expansion | Launched | Added questionnaire management, multi-tier monitoring, zero-day alerting, and advisory workflows to Supply Chain Defense | SE015/SE023 |
| 2023-11 acquisition | Conquest Cyber acquisition | Closed / integration underway | Expanded posture, compliance, and government-defense capabilities with a risk-maturity lens | SE016/SE024 |
| 2024-07 platform launch | BlueVoyant Cyber Defense Platform | Launched | Established one cloud-native umbrella across internal, external, and supply-chain defense | SE021/SE026/SE027 |
| 2025-09 developer signal | BV-Security-Copilot repo updated publicly on GitHub | Visible but narrow | Indicates some practitioner-facing artifact creation, but not broad open engineering transparency | SE018/SE019/SE020 |
| 2026 current go-to-market | MDR for Microsoft and Continuous Optimization are live modules inside the platform | Current | Confirms the product is sold both as operations coverage and as optimization around Microsoft security spend and controls | SE005/SE006/SE007 |
| 2026 AI launch | BlueVoyant AI agentic SecOps platform | Launched | Moves the roadmap from converged surfaces to an AI-native orchestration layer for managed and self-service SOCs | SE022 |
Because BlueVoyant does not publish a public changelog, roadmap evidence is reconstructed from releases, collateral, GitHub activity, and current solution pages.
[CE004, CE007, CE015, CE024, CE033, CE034]Public proof is strongest for Microsoft delivery depth and module breadth, weaker for open engineering transparency, non-Microsoft integrations, and hard operational benchmarks.
[CE015, CE022, CE035, CE036, CE037, CE039]5.6 Exhibits
06Customers
6.1 Customer Segmentation and Buyer Structure
BlueVoyant’s public customer file points to enterprise and government buyers with complicated security operations, meaningful regulatory exposure, or large third-party ecosystems rather than a broad SMB base. The buyer is usually a CISO, Office of Information Security, security architecture lead, or infrastructure owner; the daily user is the SOC or IT operations team; and the payer is typically an agency procurement budget, a regulated enterprise security budget, or a partner-enabled contract vehicle. The strongest visible segments are public sector and financial services: California’s OIS, NAVSEA and Carahsoft-backed government routes on one side, and Snappi, Beeks, ClearBank, and financial-services-oriented Microsoft content on the other. ODEON broadens the file into multi-country consumer operations, but the pattern is still complex, high-stakes environments. Energy and legal are clearly targeted verticals, yet the reviewed corpus does not show equally strong named production references there.[CU001, CU002, CU003, CU004, CU030, CU031]
| Segment / cohort | Buyer / user / payer | Representative public proof | What the evidence proves | Main gap |
|---|---|---|---|---|
| State and local government | Buyer: OIS/CISO; user: SOC and IT teams; payer: agency or statewide cybersecurity budget | California OIS SOCaaS and CDT SOCaaS pages | BlueVoyant can support shared-service monitoring in resource-constrained public entities | Public proof is concentrated in California and does not disclose contract economics |
| Federal defense and acquisition | Buyer: program/procurement leadership; user: supply-chain and security analysts; payer: federal contract vehicle | NAVSEA / 202 Group Phase III work and SCRIPTS BPA availability | BlueVoyant has real federal procurement traction in supply-chain risk use cases | Program and supplier-coverage proof is stronger than end-user adoption detail |
| Digital banking and regulated finance | Buyer: CISO / board / security leadership; user: SOC and compliance teams; payer: enterprise security budget | Snappi and ClearBank public materials | BlueVoyant resonates where resilience, reporting, and Microsoft operations matter | Named bank roster remains thin in public materials |
| Capital-markets infrastructure | Buyer: CISO / IT leadership; user: SOC analysts; payer: platform operator budget | Beeks Group customer statements | BlueVoyant can support customer-facing financial infrastructure and reassure downstream clients | Little public evidence on expansion beyond the initial deployment |
| Multi-site commercial operators | Buyer: central InfoSec / cloud services; user: regional security teams; payer: corporate security budget | ODEON case study and independent coverage | BlueVoyant can unify noisy multi-country environments and add third-party risk visibility | Public commercial proof is led by one flagship entertainment reference |
| Energy and legal go-to-market motions | Buyer: sector CISO or IT/security lead; user: security teams; payer: enterprise security budget | Energy webinar and law-firm solution spotlight | BlueVoyant actively targets other regulated segments beyond banking and government | Reviewed sources do not name comparable production customers in these verticals |
Rows separate segments with named proof from sectors that are currently supported mainly by solution marketing or thought leadership.
[CU001, CU002, CU003, CU004, CU030, CU031]The visible buyer journey usually starts with compliance or alert-fatigue pain, moves through partner- or Microsoft-led onboarding, and expands into always-on operations plus third-party risk visibility.
[CU001, CU002, CU026, CU027, CU030, CU042]6.2 Named Production Proof and Buyer Outcomes
BlueVoyant’s strongest public customer evidence comes from a small set of named references with concrete operational outcomes. California OIS provides the clearest state-government proof, showing a Microsoft-centered SOCaaS deployment with faster detection and response plus budget savings. ODEON adds a multinational commercial reference with a quantified alert-noise reduction, third-party vulnerability resolution, and a more detailed technical narrative about moving from fragmented tooling to Sentinel plus MDR. Snappi is weaker on numerical ROI but strong on regulated-banking readiness: 24/7 SOC coverage, board reporting, tabletop-tested response, and DORA preparedness within months of launch. Beeks is the best financial-markets proof because the customer itself says BlueVoyant reduced alert fatigue, lowered data-ingestion costs, and went live in under three months. NAVSEA and the BlueVoyant Government Solutions material prove real federal deployment relevance, although the proof is programmatic and contract-led rather than seat-count or renewal-led.[CU005, CU006, CU007, CU008, CU009, CU010]
| Date / signal | Public metric or proof point | Source | Interpretation | Caveat |
|---|---|---|---|---|
| May 2025 | Trusted by more than 1,000 clients globally | BlueVoyant Microsoft awards press release | Shows the company is comfortable making a four-digit client-count claim in recent public materials | Company-wide claim is not segmented by product, geography, or revenue scale |
| June 2025 | California SOCaaS protects 112 public sector organizations with more than $54 million of combined savings | California Department of Technology newsroom | Shows a production public-sector program at meaningful statewide scale | CDT does not break out how much of the current program is attributable specifically to BlueVoyant |
| April 2025 | SCD-G currently identifies critical risks for more than 4 million suppliers | BlueVoyant Government Solutions SCRIPTS BPA press release | Demonstrates large monitored ecosystem scale in government supply-chain defense | Supplier coverage is platform scope, not a customer-count metric |
| 2026 review surfaces | FeaturedCustomers shows a 4.7/5 reference rating across 133 total customer references | FeaturedCustomers testimonials page | Third-party review surface suggests a material stock of customer references exists | Reference platforms are not audited retention or usage disclosures |
| 2026 marketplace visibility | Reviewed AWS Marketplace and Slashdot pages show zero customer reviews or ratings | AWS Marketplace and Slashdot comparison page | Independent public review density is still shallow on some buyer-facing surfaces | No reviews does not prove low adoption; it mainly shows low visible feedback volume |
This table mixes company-claimed scale, program scale, and third-party visibility proxies because BlueVoyant does not publish a full public customer cohort series.
[CU009, CU025, CU036, CU037, CU039]| Customer / program | Segment | Deployment status | Publicly reported outcome | What it proves | Limitation |
|---|---|---|---|---|---|
| California OIS SOCaaS | State government | Production shared-service program | 70% lower MTTD, 60% lower MTTR, $2.1M annual personnel savings per participating entity | BlueVoyant can support a large, Microsoft-based public-sector operating model | Reviewed corpus does not show contract value or renewal mechanics |
| ODEON Cinemas Group | Entertainment / multi-site operations | Production multinational deployment | 98% fewer alerts requiring review, 30 critical/high third-party vulnerabilities resolved | BlueVoyant can cut noise and add supplier-risk visibility in a distributed environment | Most proof is still vendor or partner authored rather than audited by ODEON |
| Snappi | Digital banking / neobank | Production launch-phase deployment | 24/7 SOC, DORA readiness, board-level KPI reporting, tabletop-validated incident response | BlueVoyant can help a regulated bank launch security operations quickly | Proof emphasizes resilience readiness more than commercial or user-volume outcomes |
| Beeks Group | Capital markets infrastructure | Production customer deployment | Go-live in less than three months with lower alert fatigue and lower data-ingestion costs | BlueVoyant can strengthen a customer-facing financial platform where cyber trust affects client acquisition | Public proof does not quantify renewal, expansion, or contract scale |
| NAVSEA / BlueVoyant Government Solutions | Federal defense supply chain | Production government program | Phase III contract, delivery orders, and current platform claim covering more than 4M suppliers | BlueVoyant has real federal supply-chain adoption and procurement relevance | Programmatic proof is stronger than conventional SaaS account metrics |
Rows focus on the deepest named proofs in the reviewed corpus and separate operational milestones from traditional SaaS retention metrics.
[CU005, CU006, CU007, CU008, CU011, CU013]Proof quality is strongest for a handful of named references, but retention visibility remains weak even where quantified outcomes are strong.
[CU005, CU011, CU018, CU020, CU023, CU039]6.3 Government and Financial Services Depth
Government and financial services are the most defensible parts of BlueVoyant’s public customer story. On the government side, the company can point to California’s statewide SOCaaS model, NAVSEA supply-chain work inherited through 202 Group, and a widening procurement footprint through Carahsoft, SEWP, ITES-SW2, NASPO, CMAS, and the SCRIPTS BPA. That is more than logo evidence: it shows real contract pathways and operating use cases. On the financial-services side, the proof is narrower but still credible. Beeks offers capital-markets infrastructure proof with a direct customer statement. Snappi shows a new regulated bank using BlueVoyant to stand up cyber operations from day one, and ClearBank indicates BlueVoyant can speak publicly with an established UK bank customer on Microsoft optimization. The caution is that public depth is strongest around Microsoft-centric managed security and resilience themes, not around a broad roster of named banks or insurers.[CU003, CU004, CU017, CU018, CU020, CU021]
6.4 Channel and Procurement Routes
BlueVoyant’s route to market appears deliberately partner-heavy. The company advertises a formal partner program with co-selling, enablement, account planning, and OEM/tech-alliance support. Carahsoft is the clearest channel amplifier for public sector demand, because it gives BlueVoyant access to existing reseller networks and contract vehicles rather than forcing direct procurement one agency at a time. BlueVoyant Government Solutions then adds a more specialized federal path through SCRIPTS and supply-chain-defense motions. AWS Marketplace contributes another procurement path, though the reviewed listing is private-offer oriented and thin on external feedback. The practical implication is that expansion may come through partner and platform ecosystems as much as through net-new direct sales. That can be efficient, especially for Microsoft-centric buyers, but it also means customer visibility can lag behind route-to-market breadth because some wins surface through distributors, webinars, or partner pages rather than through detailed standalone case studies.[CU024, CU025, CU026, CU027, CU028, CU029]
| Route | Buyer or user type | Public proof | What it enables | Limitation |
|---|---|---|---|---|
| Direct Microsoft-centered enterprise sale | CISO / SOC / cloud-security teams | ODEON, Snappi, Beeks, ClearBank, California OIS | Supports fast onboarding into Sentinel, Defender, MDR, and reporting workflows | Public proof is strongest where Microsoft is already strategic |
| Carahsoft public-sector distribution | Federal, state, local, tribal, education, healthcare buyers | Carahsoft partnership and contract pages | Gives agencies access through existing reseller channels and contract vehicles | Indirect route can reduce visibility into end-customer economics |
| SCRIPTS BPA / BlueVoyant Government Solutions | DoD and FCEB supply-chain-risk buyers | BlueVoyantGov SCRIPTS BPA press release | Streamlines access to SCD-G and analyst support for federal programs | Program scale does not automatically translate into commercial-style retention data |
| AWS Marketplace private offer | Cloud-first security buyers | AWS Marketplace MDR listing | Provides procurement through AWS billing and marketplace workflows | Reviewed listing still shows no customer reviews and requires private offers |
| Partner-led external advocacy | Partner, distributor, and customer reference ecosystems | Partners page, Carahsoft reseller page, Beeks and Veracloud external stories | Extends reach and credibility beyond BlueVoyant-owned channels | Route breadth exceeds the depth of independently visible renewal evidence |
This extra table separates procurement mechanics from customer outcomes so partner and contract routes are not mistaken for proof of retention.
[CU026, CU027, CU028, CU029, CU030, CU031]BlueVoyant’s public deployments tend to follow a route from procurement access into Microsoft-centered onboarding, then into continuous operations and partner-visible expansion.
[CU013, CU018, CU021, CU026, CU029, CU042]6.5 Retention, Concentration, and Visibility Risks
The biggest gap in BlueVoyant’s customer file is not absence of reference accounts; it is absence of durability disclosure. None of the reviewed sources provide NRR, GRR, churn, logo-retention, cohort renewal curves, or revenue concentration by customer. PeerSpot hints that annual or multi-year agreements are common, but that is still generic third-party commentary rather than company-verified cohort evidence. Independent review surfaces help only partially. FeaturedCustomers shows a meaningful stock of references and a positive rating, yet AWS Marketplace and Slashdot pages still show zero public ratings on the reviewed listings. Most quantified proof is vendor-authored or partner-authored, which is useful for seeing deployment outcomes but weak for underwriting concentration and renewal risk. The diligence conclusion is therefore mixed: BlueVoyant has credible marquee proofs and regulated-sector relevance, but a buyer still needs private data on top-customer exposure, expansion rates, renewal rates, and segment economics before treating the public customer story as fully underwritten.[CU037, CU038, CU039, CU040, CU041, CU042]
| Metric / proxy | Public value | Segment | Confidence | Diligence ask |
|---|---|---|---|---|
| Net revenue retention (NRR) | Overall customer base | Low | Request NRR by product line and customer segment for the last eight quarters | |
| Gross retention / logo retention | Overall customer base | Low | Request logo-retention and gross-dollar-retention cohorts | |
| Churn rate | Overall customer base | Low | Request gross and net churn with top-20 customer contribution | |
| Contract duration / renewal structure | Annual or multi-year agreements mentioned on PeerSpot | Mixed enterprise segments | Low | Obtain sample order forms, renewal dates, and termination rights by segment |
| Public satisfaction / visibility proxy | FeaturedCustomers 4.7/5 with 133 references, but 0 AWS reviews and 0 Slashdot ratings on reviewed pages | Public proof surface | Medium | Reconcile public review density with actual renewal and support KPIs |
Null means the metric was not publicly disclosed in the reviewed corpus; the visible review and contract signals are proxies, not substitutes for retention data.
[CU037, CU038, CU039, CU040]| Expansion driver or concentration risk | What public evidence shows | Impact on the thesis | Diligence path |
|---|---|---|---|
| Microsoft-centric cross-sell | California, ODEON, Snappi, Beeks, and ClearBank all tie BlueVoyant closely to Microsoft-centric security operations | Strong expansion logic inside Microsoft-heavy accounts, but product breadth outside that stack is less visible | Request product-by-product ARR, attach rates, and win rates outside Microsoft-led deployments |
| Public-sector contract route dependence | Carahsoft, SEWP, ITES-SW2, CMAS, and SCRIPTS create meaningful government access | Helps scale distribution, but procurement timing and channel execution could shape revenue concentration | Request bookings split by direct vs channel and by contract vehicle |
| Financial-services compliance pull | Snappi, Beeks, and financial-services content suggest compliance-led demand and operational-resilience value | Good sector fit, but named-bank depth is still limited | Request top financial-services accounts, pipeline conversion, and referenceability by subsegment |
| Marquee-reference concentration | The public proof set is led by a small number of deep stories rather than a broad set of equally detailed references | A few flagship accounts may overstate overall deployment depth if the long tail is shallower | Request top-10 customer revenue share and number of customers above material ARR thresholds |
| Durability visibility gap | No public NRR, GRR, churn, renewal, or top-customer concentration disclosures were found | This is the largest remaining diligence blocker for underwriting customer quality | Obtain cohort tables, renewal dashboards, and concentration schedules under NDA |
This exhibit mixes upside and risk because BlueVoyant’s public file is strongest on why accounts buy and weakest on how durable those accounts are over time.
[CU026, CU028, CU030, CU031, CU039, CU040]07Risks
7.1 Regulatory, Privacy, and Adverse Signals
BlueVoyant does not present as a company under broad public enforcement today, but its visible operating surfaces still create real regulatory and legal exposure. The company’s privacy and legal notice says BlueVoyant LLC is the controller for website personal data and may share personal information with affiliates unless prohibited by law, which is not unusual but still matters for buyers that scrutinize controller boundaries, affiliate access, and global data handling. The bigger external constraint comes from the company’s government- and defense-adjacent motion. BlueVoyant Government Solutions explicitly sells supply-chain defense, CMMC support, and NIST 800-171 compliance management into federal and defense contexts, and the DoD’s CMMC rollout is now active in live contracts. That means the risk is not abstract regulation; it is execution against procurement-linked cyber controls that can delay or disqualify wins if BlueVoyant or its customers cannot evidence readiness. The clearest adverse company-specific signal in the current public file is the Steward Health adversary complaint against Bluevoyant LLC in Texas bankruptcy court. Public docket text alone does not quantify exposure, merit, or expected outcome, but it is still the one live adverse item that warrants direct diligence on factual background, insurance, reserve treatment, and whether it reflects a billing, delivery, or vendor-management dispute. Separately, SAM.gov and USAspending make federal award data publicly traceable, which is useful because BlueVoyant’s contract-vehicle breadth is visible while actual agency-level concentration and renewal dependence are not. Overall, legal and regulatory risk is manageable only if the company can show privacy governance discipline, current public-sector compliance readiness, and a contained explanation of the Steward matter.[CR015, CR016, CR017, CR018, CR019, CR020]
| Rule / case / control | Jurisdiction | Status | Likelihood | Severity | Mitigation | Residual exposure | Diligence path |
|---|---|---|---|---|---|---|---|
| DoD CMMC rollout for defense-linked work | United States / DoD | Phase 1 active from 2025-11-10 with Level 1 and Level 2 self-assessments | High | High | Use existing CMMC and NIST support positioning to evidence readiness | High — missing or weak certification evidence can slow awards or exclude bids | Obtain internal CMMC level mapping, latest SPRS affirmations, and customer references tied to CMMC work |
| NIST SP 800-171 obligations in contract execution | United States / federal procurement | Persistent baseline control framework for nonfederal systems handling CUI | High | High | Map delivery processes to 800-171 control coverage | Medium-High — control gaps become procurement, audit, or remediation burdens | Request formal control matrix, inheritance model, and any third-party assessments |
| Steward Health adversary complaint | Texas Southern Bankruptcy Court | Active public docket as of 2026-06-26 | Medium | Medium-High | Legal defense, insurance, and negotiated resolution if exposure is limited | Medium — factual and dollar exposure remain unclear from the public docket alone | Review complaint, answer, claimed amount, payment history, and any insurer correspondence |
| Website privacy governance and affiliate sharing | Website / cross-border data governance | Privacy notice states BlueVoyant LLC is controller and may share with affiliates unless prohibited | Medium | Medium | Clarify controller boundaries, affiliate access, and retention limits in deal-specific DPAs | Medium — buyer diligence burden rises if data flows are not crisply bounded | Request product-level DPA, subprocessors, and regional data-flow maps |
| Federal award transparency and agency scrutiny | United States / procurement data | SAM.gov and USAspending make contract-award diligence feasible but company mix is undisclosed | Medium | Medium | Pre-build agency and vehicle analytics before underwriting concentration | Medium — hidden concentration can surface late in diligence | Pull agency-level awards by legal business name and reconcile to management revenue segmentation |
Rows are ordered by residual severity using public evidence only; they are not a substitute for counsel review or contract-by-contract compliance testing.
[CR015, CR016, CR017, CR018, CR019, CR020]7.2 Microsoft Ecosystem and Competitive Platform Risk
BlueVoyant’s strongest public advantage is also one of its largest strategic dependencies. The company markets itself as a Microsoft security specialist across Sentinel, Defender, Purview, Copilot readiness, and adjacent cost-of-adoption assessments; Microsoft and BlueVoyant materials both reinforce that BlueVoyant helps shape Sentinel use cases, analytics, and Security Copilot content. Awards and ecosystem recognition confirm real channel credibility, and the partner stack is clearly not superficial. But that also means BlueVoyant’s differentiation is exposed to Microsoft roadmap choices, pricing changes, packaging shifts, and native-feature expansion. If Microsoft makes more workflows turnkey inside its own stack, BlueVoyant has to keep proving that its expert services, content, and operational judgment justify the extra spend rather than becoming optional wraparound labor. Competitive intensity is high because BlueVoyant is not defending a narrow wedge. Public materials and review directories place it across MDR, Microsoft-managed security, digital risk, supply-chain defense, and third-party risk management. That gives the company multiple shots on goal, but it also means buyers can compare BlueVoyant against more specialized vendors in each category. The company’s own Sentinel case-study eBook and Gartner-market-guide blog suggest that BlueVoyant wins by reducing complexity and helping customers operationalize risk, not by owning a unique underlying platform. That is valuable, but it is harder to defend if Microsoft partners proliferate, if focused MDR vendors outperform on service depth, or if best-of-breed TPRM vendors out-execute on a single workflow. In short, Microsoft channel strength de-risks demand generation while increasing commoditization and concentration risk at the same time.[CR001, CR002, CR003, CR004, CR005, CR006]
| Dependency | Counterparty / ecosystem | Role | Concentration | Failure scenario | Severity | Mitigation | Residual exposure |
|---|---|---|---|---|---|---|---|
| Microsoft security stack | Microsoft | Core telemetry, workflow, and services substrate for major BlueVoyant offers | High | Native Microsoft improvements compress the value of BlueVoyant overlay services | High | Keep proving differentiated deployment, content, and managed-operations value | High |
| Microsoft channel credibility and awards | Microsoft / MISA ecosystem | Demand generation and trust signal for Microsoft-centered buyers | High | Roadmap, co-sell, or partner-program shifts weaken pipeline efficiency | High | Diversify proof points beyond awards and Microsoft-only success stories | Medium-High |
| Sentinel partner ecosystem build-out | Microsoft Sentinel ecosystem | BlueVoyant creates analytics, playbooks, queries, and Copilot agents on top of Sentinel | High | APIs, platform economics, or store distribution rules change materially | High | Stay close to product teams and maintain delivery assets customers cannot easily replicate | High |
| Public-sector procurement vehicles | Carahsoft and government contracting channels | Access route into agencies and defense-adjacent buyers | Medium | Vehicle access exists but underlying award mix is concentrated in a few agencies or programs | Medium-High | Use SAM.gov and USAspending to measure real concentration before underwriting | Medium-High |
| Crowded cyber-risk categories | MDR / TPRM / supply-chain and digital-risk market | Sets the benchmark buyers use to price and compare BlueVoyant | High | Focused vendors out-execute on one workflow while BlueVoyant carries platform sprawl | Medium-High | Clarify where BlueVoyant wins on operating outcomes rather than breadth alone | Medium-High |
Dependency risk is led by Microsoft concentration, but procurement-channel and category-breadth dependence also matter because they shape conversion, renewal, and pricing power.
[CR001, CR002, CR003, CR004, CR005, CR006]BlueVoyant depends on Microsoft, human SOC talent, procurement channels, and compliance proof more than on any single proprietary public metric.
[CR001, CR002, CR003, CR007, CR021, CR022]7.3 Human Services Delivery and AI Execution Risk
BlueVoyant is trying to extend a human-led managed-security franchise into an AI-native product story without giving up the promise of expert oversight. The June 2026 BlueVoyant AI launch says customers can buy either a fully managed service backed by BlueVoyant’s elite SOC team or a SaaS platform that puts the same capabilities in customer hands. That is attractive commercially, but it raises a real operating challenge: the company now has to deliver high-quality analyst-driven service, credible autonomous workflows, and coherent pricing and packaging across both modes. Public claims about machine-speed containment, false-positive reduction, and deterministic response are ambitious. If those claims are not supported by strong guardrails, human override processes, and measurable quality outcomes, BlueVoyant could create more scrutiny rather than less—especially in regulated or high-consequence customer environments. The operating model also remains labor intensive. BlueVoyant still emphasizes 24x7 expert monitoring, global SOC coverage, and regional expansion such as the Cork center for Irish and EU clients. Those are meaningful mitigants, but they imply ongoing recruiting, training, localization, and quality-control requirements even as the company pitches automation. Leadership changes add another layer of execution risk. John Hernandez took over as CEO in 2026 with an AI-growth mandate, while the 2023 CPO hire was explicitly about unifying product direction after product-line expansion. The risk is not that BlueVoyant lacks ambition; it is that the company may have to manage service consistency, model trust, analyst workflows, and product integration all at once. Public review and directory sources acknowledge broad capability, but they do not give the SLA, MTTR, staffing-ratio, or alert-tuning evidence that would fully de-risk execution.[CR008, CR009, CR010, CR011, CR012, CR013]
| Failure mode | Likelihood | Severity | Mitigation maturity | Residual exposure | Unresolved gap |
|---|---|---|---|---|---|
| Agentic-AI response misfire or weak human override | Medium-High | High | Medium — human-centered workflow language exists, but hard quality metrics are not public | High | No public false-positive, false-negative, or intervention-rate data for BlueVoyant AI |
| Managed-service and SaaS coexistence complexity | High | High | Medium — one platform/two deployment modes is clear, but packaging and support boundaries are unproven publicly | High | No public pricing architecture or migration path between managed and self-service modes |
| 24x7 SOC staffing or analyst-quality drift | High | Medium-High | Medium — regional SOC expansion is visible, but staffing ratios and SLAs are not | High | No public MTTR, staffing, or escalation-quality metrics |
| Regional compliance and service localization burden | Medium | Medium-High | Medium — Cork expansion adds in-region coverage for EU clients | Medium-High | No public evidence on multilingual support depth, local data-boundary design, or audit cadence |
| Feature sprawl across MDR, TPRM, and supply-chain products | Medium | Medium-High | Low-Medium — product breadth is a sales asset but also a coordination burden | Medium-High | No public roadmap on how product, service, and AI layers are sequenced or simplified |
Operational risk is elevated by the need to sustain human delivery quality while simultaneously expanding platform breadth and AI automation claims.
[CR008, CR009, CR010, CR011, CR012, CR013]7.4 Public-Sector Exposure, Leadership, and Financing Opacity
BlueVoyant’s public-sector posture creates both resilience and concentration risk. On the positive side, the company is visible on multiple contract vehicles through Carahsoft and presents a government-specific value proposition around supply-chain defense, cybersecurity, and compliance support. That can create durable demand because the work maps to real procurement and mission needs rather than discretionary experimentation. The downside is that government-linked revenue tends to be slower-moving, more compliance-gated, and more sensitive to certification evidence and contract execution than generic commercial SaaS. BlueVoyant’s public materials do not disclose what share of revenue comes from government or defense customers, which agencies matter most, or how renewals are distributed across programs. So the public record can establish exposure, but not diversification. Financing visibility is similarly incomplete. The clearest capital fact in the current file is the 2023 announcement that BlueVoyant raised more than $140 million in Series E financing to support the Conquest Cyber acquisition. PM Insights shows that there is at least some secondary-market and valuation monitoring around the company, but the public-facing preview is intentionally thin and does not provide underwritable current metrics. There is no cited public disclosure here on ARR, burn, runway, leverage, liquidation preferences, or current valuation. That does not prove stress, but it does mean late-stage private-market risk is real: if growth, Microsoft economics, or public-sector win rates soften, outside investors would be asked to price a business whose most important operating metrics are still largely private.[CR011, CR012, CR013, CR014, CR023, CR024]
| Role / function | Dependency or gap | Likelihood | Severity | Mitigation | Diligence path |
|---|---|---|---|---|---|
| Chief executive leadership | Founder-to-operator transition to John Hernandez while AI story and global scale are being pushed simultaneously | Medium | High | Experienced incoming CEO with enterprise-platform background | Review first-year operating priorities, sales productivity, and leadership-team stability |
| Product leadership and integration | CPO mandate implies ongoing product unification across acquired and legacy lines | Medium | Medium-High | Dedicated product leader with large-vendor and portfolio experience | Request current product map, deprecation policy, and integration milestone tracking |
| MDR analyst bench | 24x7 expert monitoring remains central even after AI launch | High | High | Regional SOC footprint and managed-service history | Obtain analyst-to-customer ratios, attrition, certification coverage, and escalation protocols |
| Regional support and localization | Cork expansion and EU servicing add staffing, compliance, and time-zone complexity | Medium | Medium-High | In-region SOC investment and local hiring | Validate staffing ramp, language coverage, and customer-support boundaries by geography |
| Government and compliance specialists | Public-sector motion depends on scarce cyber/compliance talent that can speak CMMC, NIST, procurement, and remediation | Medium | Medium-High | Dedicated government business and partner channels | Review bid support, compliance specialists, and renewal ownership for public-sector accounts |
Execution risk is driven less by founder credibility than by the need to coordinate service labor, product integration, regional support, and public-sector specialization at the same time.
[CR011, CR012, CR013, CR014, CR023, CR024]7.5 Monitoring Triggers, Mitigation Maturity, and Data Gaps
The mitigation picture is credible but incomplete. BlueVoyant has genuine strengths: Microsoft recognition across multiple years, visible public-sector contract access, a growing EMEA SOC footprint, and a product set that spans managed detection, third-party risk, and supply-chain defense. Those are not cosmetic signals. But the company’s most important residual risks are only partially mitigated by public evidence. Microsoft dependency is softened by channel strength, not removed. BlueVoyant AI may improve unit economics and service quality, but the same launch also broadens execution scope. Government exposure can create durable demand, but it also raises the bar for compliance evidence and procurement discipline. Financing risk is still hard to score because public disclosures stop well short of the metrics needed to size dilution or exit risk. The right way to treat BlueVoyant is therefore as a business with real strategic assets but a narrow margin for execution error. The most actionable kill criteria are observable: Microsoft feature commoditization that compresses service differentiation; weak AI quality or human-override evidence; inability to evidence CMMC/NIST readiness in public-sector pursuits; adverse movement in the Steward matter; or a new financing event that implies stress rather than optionality. The public file also leaves material diligence gaps around concentration, service quality, and capital structure. Those omissions do not negate the business, but they do keep residual-risk scoring elevated. Until management can produce hard metrics on customer mix, renewal durability, SOC quality, and capital terms, the prudent underwriting stance is to treat BlueVoyant as strategically interesting but execution-sensitive.[CR004, CR005, CR008, CR010, CR017, CR021]
| Risk | Monitorable trigger | Threshold / event | Action implication |
|---|---|---|---|
| Microsoft ecosystem dependence | Evidence that Microsoft-native features subsume BlueVoyant service content or economics | Renewal objections rise around paying for partner overlay on top of Microsoft spend | Re-rate differentiation and gross-margin durability downward |
| AI execution quality | Human override, false-positive, and containment-quality evidence for BlueVoyant AI | Management cannot provide credible quality metrics or customer references for autonomous workflows | Treat AI launch as risk-increasing rather than de-risking |
| Public-sector compliance readiness | CMMC, NIST, and award-level diligence outputs | Missing SPRS affirmations, weak control mapping, or stalled agency pursuits tied to compliance readiness | Assume slower government growth and higher cost-to-win |
| Legal / adverse signal containment | Direct facts on Steward litigation, insurance, and reserve posture | Complaint expands materially, damages look meaningful, or management cannot narrate the dispute cleanly | Escalate legal risk rating and revisit counterparty/process diligence |
| Financing opacity | Current ARR, burn, cash runway, and any new capital event | Next round implies stress, punitive preferences, or heavy dilution without clear operating acceleration | Lower conviction on entry price and require stronger downside protection |
These kill criteria convert soft public signals into explicit diligence tests so that channel strength and press releases are not mistaken for closed risk.
[CR017, CR021, CR030, CR032, CR036, CR037]Highest-impact residual risks cluster around Microsoft dependence, financing opacity, public-sector compliance, and the quality of the managed-plus-AI operating model.
[CR046, CR047, CR048, CR049, CR050, CR051]Platform, compliance, or execution failures would likely hit customer trust before they show up as financing or valuation pressure.
[CR046, CR047, CR048, CR049, CR052, CR053]08Valuation
8.1 Investment Thesis and Anti-Thesis
BlueVoyant has enough scale and category breadth to make the company investable at the right price. Official company materials describe a unified platform spanning MDR, TPRM, digital risk protection, and professional services, not a single-point tool. That breadth matters because it supports a comp set wider than pure MDR and gives BlueVoyant multiple product wedges into enterprise and public-sector budgets. The 2023 growth release also suggests meaningful commercial proof: more than 900 clients, presence in 40-plus countries, and historical triple-digit recurring-revenue expansion since 2018. If the third-party 2025 ARR proxy of $213.5 million is directionally right, BlueVoyant is already a scaled cybersecurity vendor rather than a speculative pre-revenue unicorn. The anti-thesis is valuation quality, not company existence. Public secondary evidence is the key disconfirming signal in this chapter: Notice shows a 39% discount to the last round, Forge calls market activity limited, and Hiive exposes no visible price history on the public listing page. Those signals imply that the private market is either illiquid, cautious, or both. Meanwhile, the company still lacks public disclosure of current gross margin, retention, services mix, diluted share count, and any post-2023 financing terms. That combination keeps the right call at research-more rather than buy, even though the core business appears credible. [CV012, CV013, CV015, CV016, CV017, CV018]
| Dimension | Value | Rationale |
|---|---|---|
| Recommendation | research-more | Public evidence supports a plausible but not clearly mispriced $1B mark; missing private metrics still matter. |
| Confidence | medium | Multiple cross-checks are coherent, but the main ARR and liquidity inputs come from third-party data vendors. |
| Risk Rating | high | Secondary discount, thin visible liquidity, and undisclosed share-count and margin data create real downside sensitivity. |
| Valuation Stance | fair | The implied ~4.7x ARR proxy is within hybrid cyber peer ranges, but not cheap enough to offset disclosure gaps. |
| Decision Implication | Diligence before price-taking | Upgrade only if management proves software mix, margin quality, and recent clearing prices. |
Public-only view as of 2026-06-29; valuation uses third-party ARR and secondary-market previews rather than audited financial disclosure.
[CV041, CV044, CV045, CV046, CV047, CV048]| Side | Argument | What Would Change the View |
|---|---|---|
| Thesis | BlueVoyant spans MDR, TPRM, DRP, and professional services, which broadens wallet share and comp relevance. | Proof that platform modules are becoming a larger share of revenue would strengthen the case. |
| Thesis | Official sources show meaningful commercial scale: >900 clients, 40-plus countries, and historical triple-digit recurring-revenue growth. | A credible 2026 update on client count, ARR quality, and retention would make the scale argument more durable. |
| Thesis | If the $213.5M ARR proxy is directionally right, $1B equates to only about 4.7x ARR—well below premium cyber leaders. | Disclosure of gross margin and software mix could justify moving toward higher-quality platform multiples. |
| Anti-thesis | Notice shows a 39% discount to the last round, implying secondary buyers may clear materially below the headline mark. | A recent broker sheet or executed transaction near or above $1B would directly rebut the discount signal. |
| Anti-thesis | Forge shows limited activity and no visible Forge Price, which weakens confidence in current liquidity. | Visible bid-ask depth or matched secondary prints would reduce the liquidity discount. |
| Anti-thesis | Public sources disagree on total capital raised and do not expose current dilution, margins, or post-2023 financing terms. | A clean cap table, share count, preference stack, and current financial pack would convert the case from narrative to underwritten. |
Arguments are intentionally price-sensitive: the positive case is real, but the anti-thesis is rooted in observable secondary and disclosure gaps.
[CV007, CV008, CV012, CV013, CV015, CV018]Decision flow from scale and comparable support through secondary-market caution and disclosure gaps to the final research-more call.
Logical decision architecture only; it summarizes the weighting of public evidence rather than a formal scoring model.
[CV034, CV037, CV038, CV044, CV045, CV048]8.2 Financing History, Disclosure Quality, and Secondary Signals
BlueVoyant's public funding history is clear at the headline level but fuzzy in the details that matter for pricing discipline. The retained sources confirm a $250 million Series D in February 2022 and more than $140 million of new funding in November 2023, but the public filing trail is incomplete. The SEC browse result surfaces Form D notices only for 2017, 2019, and 2020; it does not surface later financing terms. Caplight, CB Insights, and GetLatka converge on $665.5 million of total funding, while Tracxn reports $696 million across six rounds and SiliconANGLE quotes Tracxn at about $646 million after the 2023 round. This is not fatal, but it means investors are using vendor summaries instead of a crisp public ledger. The secondary-market platforms deepen that caution. Caplight still anchors BlueVoyant at an estimated $1 billion and shows the last round as Series E on November 29, 2023. Forge still shows the last known valuation as $1 billion from February 2022, calls current market activity limited, and does not publish a Forge Price. PM Insights and Hiive both confirm that secondary infrastructure exists, yet the public previews do not offer enough live depth to underwrite a precise clearing price. Put differently: the market offers directionally useful signals, but not enough transparent liquidity to turn those signals into conviction without direct broker data. [CV001, CV002, CV003, CV004, CV005, CV006]
8.3 Public Comparable and Multiple Analysis
The right public comp set for BlueVoyant is mixed by design. On the higher-growth end, CrowdStrike, Palo Alto Networks, and Fortinet represent scaled security platforms with strong security-operations franchises and materially higher software quality. On the more moderate end, SentinelOne, Qualys, Tenable, and Rapid7 are the better reference points for a hybrid model that still sits closer to operational security and risk management than to a pure cloud-security winner-take-all story. Windsor Drake's 2026 sector framing is the key macro anchor: public cyber trades around 6.0x to 6.5x NTM revenue, while managed security services sit lower at about 3x to 5x. BlueVoyant's implied 4.7x multiple on the 2025 ARR proxy lands near the lower-middle of that landscape. It is far below CrowdStrike's 34.3x and Palo Alto's 23.28x, below Fortinet's 15.2x, and much closer to SentinelOne at 4.61x, Qualys at 5.73x, and Tenable at 3.32x. That is directionally sensible if BlueVoyant's revenue mix includes a meaningful services component and if the platform's automation advantages have not yet translated into disclosed software-like margins. The comp conclusion is therefore nuanced: $1 billion is not obviously too high on a revenue-multiple basis, but it is not the kind of discount that creates a clear public-evidence entry opportunity. [CV015, CV016, CV022, CV023, CV024, CV025]
| Comparable | Segment Lens | Market Cap | Revenue (ttm) | EV/Revenue | Relevance to BlueVoyant | Key Limitation |
|---|---|---|---|---|---|---|
| CrowdStrike | Security operations / XDR leader | $178.47B | $5.09B | 34.30x | Upper-bound software/security-operations reference. | Too software-pure and too premium to be a direct base-case anchor. |
| Palo Alto Networks | Broad security platform incl. operations | $247.92B | $10.61B | 23.28x | Shows what scaled platform breadth can command. | Far more mature and profitable than BlueVoyant. |
| Fortinet | Security platform with operations exposure | $110.88B | $7.11B | 15.20x | Useful premium benchmark below PANW/CRWD. | Still materially higher quality and more hardware/subscription diversified. |
| SentinelOne | MDR / endpoint platform | $5.45B | $1.05B | 4.61x | Closest public multiple check for a growth-but-not-premium security platform. | Pure endpoint/software mix is still cleaner than BlueVoyant's. |
| Qualys | Risk / compliance / vulnerability | $4.34B | $684.86M | 5.73x | Good reference for risk and compliance adjacency. | Not a services-heavy MDR business. |
| Tenable | Exposure management / vulnerability | $3.33B | $1.02B | 3.32x | Useful lower-band reference for risk-oriented cyber. | Product mix and GTM differ from MDR plus services. |
| Rapid7 | XDR / SIEM / exposure management | $0.51B | $859.23M | 0.93x | Shows the floor when public markets discount quality and growth. | Likely too punitive for BlueVoyant unless margins or growth disappoint badly. |
Market cap and revenue figures come from Yahoo Finance and CompaniesMarketCap snapshots accessed on 2026-06-29; EV/revenue is taken from Yahoo Finance. Values are directional public-market references, not private-market clearing prices.
[CV022, CV023, CV024, CV025, CV026, CV027]Illustrative enterprise value in USD millions at different ARR multiples applied to the $213.5M 2025 ARR proxy.
Values are calculated from the third-party $213.5M ARR proxy and rounded to the nearest USD million; they are not broker marks.
[CV022, CV023, CV034, CV035, CV041, CV042]8.4 Bull, Base, and Bear Valuation Scenarios
The scenario framework starts with what is actually observable. In the base case, BlueVoyant deserves a multiple around 4.0x to 5.0x on the $213.5 million ARR proxy, which yields roughly $0.85 billion to $1.1 billion. That range is consistent with the company's real scale and product breadth, but also with hybrid-margin caution and limited liquidity. In the bull case, BlueVoyant can stretch into roughly $1.2 billion to $1.5 billion if management proves that recent growth is durable, that the software and platform layer is expanding faster than services, and that recent secondary or primary price discovery supports a higher-quality cyber multiple. The bull case is therefore an execution-and-disclosure case, not just a market-multiple case. The bear case is visible already. Notice's 39% discount to the last round and Forge's absent price signal point to a downside band around $0.6 billion to $0.8 billion if the next real clearing event comes below the headline mark or if investors decide BlueVoyant belongs in the 3x to 4x managed-security range instead of a platform premium bucket. The skew is important: the public evidence does not scream overvaluation, but it does show that downside is already partially discoverable while upside still depends on private facts the market has not shared. [CV018, CV019, CV022, CV023, CV034, CV035]
| Scenario | Key Assumptions | Implied Multiple | Valuation Range (USD B) | Probability Signal | Key Risk |
|---|---|---|---|---|---|
| Bull | Growth remains strong, software mix expands, and diligence supports a higher-quality platform profile. | 5.5x–7.0x ARR | 1.2–1.5 | Requires private evidence to overpower secondary discounts. | No margin proof or weak clearing prices would break the case. |
| Base | ARR proxy is directionally right and BlueVoyant clears as a hybrid cyber platform with moderate services discount. | 4.0x–5.0x ARR | 0.85–1.10 | Most consistent with retained public evidence. | If ARR quality is weaker than the proxy, even base compresses. |
| Bear | The next real clearing event validates secondary discounts and pushes BlueVoyant toward managed-security or services ranges. | 3.0x–3.8x ARR | 0.60–0.80 | Consistent with Notice discount and thin visible liquidity. | New capital at a lower mark or poor margins would accelerate the downside. |
Scenario ranges are analytical estimates in USD billions using the public ARR proxy; they are not management guidance or broker marks.
[CV018, CV023, CV034, CV041, CV042, CV043]| Trigger | Threshold / Event | Transmission to Thesis | Action Implication |
|---|---|---|---|
| Secondary discount widens | Observable discount to the last round moves beyond ~50% or a new round prices below $0.8B. | Would imply the market sees materially weaker quality or liquidity than the base case assumes. | Pause and re-underwrite around bear-case levels. |
| Services-heavy economics confirmed | Gross margin or revenue mix shows the business is materially more services-heavy than implied. | Would cap the justified multiple closer to the managed-security range. | Move stance from fair toward stretched. |
| No real price discovery | No broker-backed secondary clears, bids, or cap-table evidence emerge over the next diligence cycle. | Liquidity discount remains unresolved, so the market cannot validate the headline mark. | Keep recommendation at research-more or downgrade. |
| Opaque post-2023 financing | Management cannot document any post-2023 financing terms, share count, or preference stack. | Without dilution mechanics, return math is unreliable even if enterprise value looks reasonable. | Do not commit capital without a cap-table package. |
| Growth quality weakens | ARR proxy proves overstated, or retention / expansion metrics fall below software-like thresholds. | Breaks the base-case assumption that BlueVoyant merits at least a hybrid platform multiple. | Re-rate toward the bear band immediately. |
Thresholds are diligence triggers rather than contractual covenants; they translate public-market evidence into concrete kill criteria.
[CV018, CV019, CV023, CV036, CV038, CV041]Scenario valuation ranges in USD millions versus the current headline $1B mark.
Ranges are analyst estimates based on retained public evidence, secondary previews, and comparable multiple brackets.
[CV041, CV042, CV043, CV048]8.5 Recommendation, Exit Discipline, and Final Diligence Asks
The recommendation from public evidence alone is research-more. BlueVoyant looks like a legitimate scaled cybersecurity platform, and the current $1 billion headline mark is not obviously detached from the retained ARR proxy. But that is not the same as calling the valuation attractive. The public market offers only preview-level secondary signals, and the strongest one available is negative. In addition, none of the retained sources disclose the current diluted share count, margin profile, retention metrics, or the terms of any financing after November 2023. Without those facts, a buyer can explain why $1 billion is plausible, but cannot yet explain why it is clearly mispriced in their favor. Exit readiness is also limited in public evidence. Hiive states that BlueVoyant remains privately held and accessible pre-IPO only through secondary marketplaces for accredited investors, and no retained source indicates an IPO process, a strategic sale process, or a fresh valuation reset. The actionable path is straightforward: obtain current ARR composition, gross margin, NRR or customer retention, the cap table and preference stack, and actual recent secondary clears from brokers or management. If those data confirm software-like economics and stable or improving secondary pricing, the call could upgrade. If they instead confirm services-heavy revenue and continued discount trading, the fair label would slide toward stretched. [CV021, CV033, CV041, CV042, CV043, CV044]
| Topic | Missing Evidence | Why It Matters | Owner / Diligence Path |
|---|---|---|---|
| 2026 ARR quality | Current ARR, recurring vs. services mix, and ARR bridge from 2023 to 2026. | Determines whether the 2025 ARR proxy is real and whether a 4.7x multiple is fair or too high. | Request current board deck or CFO operating pack. |
| Margin and retention profile | Gross margin, adjusted EBITDA, gross retention, and NRR by major product line. | Needed to know whether BlueVoyant deserves hybrid-services or software-platform multiples. | Management diligence session plus cohort-level retention exhibits. |
| Cap table and diluted share count | Latest fully diluted share count, preference stack, option pool, and liquidation waterfall. | Per-share return can diverge sharply from enterprise-value math when dilution is opaque. | Data room cap-table export or counsel-prepared summary. |
| Actual secondary-clearing prices | Recent broker sheets, matched trades, and bid-ask history from cap-table administrators or marketplaces. | The best public secondary signal is negative; true clears can validate or refute that discount. | Direct broker diligence and admin records from Forge / Notice / company. |
| Any post-2023 financing terms | Evidence of debt, structured financing, or side letters after the Series E round. | Later capital structure changes can alter downside protection, seniority, and valuation interpretation. | CFO/legal confirmation plus financing documents. |
Each ask is tied to a current blocker in the public record rather than a generic diligence wishlist.
[CV011, CV021, CV044, CV046, CV047, CV048]IC-style scoring across six dimensions that matter most to BlueVoyant's current valuation decision.
Scores are analytical and relative, intended for IC discussion rather than as mechanically derived model outputs.
[CV037, CV038, CV044, CV046, CV047, CV048]Disclaimer
This report is provided for diligence and informational purposes only and does not constitute investment, legal, accounting, or tax advice. BlueVoyant is a private company and multiple figures in the public record remain estimated, conflicting, or stale. Any investment decision should be based on direct management diligence, customer references, audited financials, and definitive legal documentation rather than public-source synthesis alone.
Evidence index
| ID | Statement | Confidence | Sources |
|---|---|---|---|
| CO001 | BlueVoyant was founded in 2017. | High | SO001, SO020, SO021 |
| CO002 | BlueVoyant's current headquarters is 6 East 45th Street, Floor 17, New York, NY 10017. | High | SO002, SO003 |
| CO003 | BlueVoyant officially says it has over 600 employees. | Medium | SO001 |
| CO004 | BlueVoyant officially says it has more than 1,000 customers in 45 countries. | Medium | SO003 |
| CO005 | BlueVoyant's core platform spans managed detection and response, third-party risk management, digital risk protection, and professional services. | High | SO004, SO005, SO006 |
| CO006 | BlueVoyant's MDR offering covers internal networks, cloud instances, containers, and endpoints and advertises 500+ Microsoft Sentinel deployments. | Medium | SO005 |
| CO007 | BlueVoyant describes its TPRM product as a fully managed service in which ROC experts review, validate, and help remediate third-party findings. | Medium | SO006 |
| CO008 | BlueVoyant presents itself as an AI-driven provider of internal, external, and supply-chain cyber defense. | Medium | SO012, SO029 |
| CO009 | John Hernandez is BlueVoyant's current chief executive officer. | High | SO002, SO016, SO027 |
| CO010 | James Rosenthal is a co-founder and now serves as chairman of BlueVoyant's board. | High | SO002, SO016, SO027 |
| CO011 | Thomas Glocer is a co-founder and vice chairman of BlueVoyant's board. | High | SO002, SO001 |
| CO012 | BlueVoyant's public executive bench includes Ravi Subramanian (CFO), Sebastian Sobolev (CPO), Jim Bieda (Global CTO), John Harbaugh (CISO), and Sangya Sharma (CHRO). | Medium | SO002 |
| CO013 | BlueVoyant's leadership page also lists solution and regional leaders including Ron Feler, Austin Berglas, Chris Teekema, Michael Spencer, Robert Hannigan, Lonny Anderson, Justin Staffel, Holly Steele, and Patrick Shea. | Medium | SO002 |
| CO014 | BlueVoyant published a COO appointment for Michael Montoya, stating that he would oversee technology, product, and operations. | Medium | SO015 |
| CO015 | BlueVoyant says it has received more than 60 awards and nominations since 2019. | High | SO009, SO001 |
| CO016 | BlueVoyant's awards materials say it won Microsoft's 2024 Worldwide Security Partner of the Year and 2024 U.S. and Canada Security Partner of the Year honors. | High | SO009, SO008 |
| CO017 | BlueVoyant markets itself as a Microsoft security expert with 10x recognition and dedicated service packaging around Sentinel, Defender, Purview, and Copilot-era security operations. | High | SO008, SO009 |
| CO018 | BlueVoyant's partner program emphasizes end-to-end platform resale and 24x7 access to sales, marketing, training, and certification resources. | Medium | SO007 |
| CO019 | BlueVoyant says it is a member of the ISTARI Collective. | Medium | SO007 |
| CO020 | On 2022-02-23 BlueVoyant closed a $250 million Series D led by Liberty Strategic Capital with participation from ISTARI, Eden Global Partners, and 8VC. | High | SO013, SO017, SO021 |
| CO021 | Independent 2022 coverage said BlueVoyant's Series D valued the company at over $1 billion and brought total funding to $525 million at that time. | High | SO021, SO020 |
| CO022 | TechCrunch described BlueVoyant's pre-Series-D offering as a mix of proprietary technology, third-party best-in-class tools, and professional services for internal and external cyber risk. | Medium | SO020 |
| CO023 | BlueVoyant announced on 2023-11-29 that it acquired Conquest Cyber and paired the transaction with more than $140 million in Series E funding. | Medium | SO018, SO023, SO033 |
| CO024 | CRN reported that the combined BlueVoyant-Conquest proposition was aimed at customers securing Microsoft environments across both commercial and government sectors. | Medium | SO022, SO024 |
| CO025 | GovConWire and BankInfoSecurity framed the Conquest acquisition as expanding BlueVoyant's reach into highly regulated, U.S. government, and defense-industrial-base environments. | Medium | SO023, SO024, SO018 |
| CO026 | Caplight lists BlueVoyant's last round as a Series E on 2023-11-29, with an estimated $1 billion valuation and $665.5 million of total funding raised. | Medium | SO030 |
| CO027 | GetLatka lists a 2025 revenue estimate of $213.5 million, $665.5 million of total funding, a $1 billion valuation, and a team size near 650 for BlueVoyant. | Low | SO029 |
| CO028 | Third-party private-market datasets in the reviewed set cluster around roughly $665.5 million of total funding and a $1 billion valuation, but those figures remain unaudited estimates rather than company disclosure. | Medium | SO029, SO030 |
| CO029 | The reviewed official company sources do not publish current ARR, GAAP revenue, gross margin, or profitability. | Medium | SO001, SO013, SO018 |
| CO030 | Public headcount signals diverge: BlueVoyant officially says it has over 600 employees, while third-party datasets in the retained set range from about 649-650 to 750. | Medium | SO001, SO029, SO030, SO031 |
| CO031 | UpGuard's June 29, 2026 vendor risk report lists BlueVoyant with 750 employees and says its assessment is based on continuous external monitoring across five risk categories. | Medium | SO031 |
| CO032 | UpGuard flags CSP allowing insecure active sources and use of unsafe-eval on BlueVoyant's web estate, creating the clearest adverse public signal in the retained source set. | Medium | SO031 |
| CO033 | BlueVoyant's contact page lists offices in New York, Leeds, London, Tel Aviv, Makati, and Bogotá plus SOC locations in Riverdale and Cork. | Medium | SO003 |
| CO034 | BlueVoyant's company overview page separately describes offices or support presence in College Park, Washington, D.C., London, Leeds, Cork, Toronto, Tel Aviv, Bogota, Manila, and Singapore across five continents. | Medium | SO001 |
| CO035 | Taken together, BlueVoyant's official pages support a globally distributed operating footprint rather than a single-office New York vendor. | High | SO001, SO003 |
| CO036 | BlueVoyant launched BlueVoyant AI on 2026-06-09 as an AI-native or agentic SecOps platform for both managed and self-service SOCs. | High | SO012, SO025, SO026 |
| CO037 | The 2026 AI launch extends BlueVoyant's existing Microsoft and SOC positioning rather than creating a wholly new category. | Medium | SO012, SO008, SO011 |
| CO038 | On 2025-09-24 BlueVoyant and Auto-ISAC announced a strategic engagement to elevate third-party cyber risk management across the automotive industry. | High | SO014, SO019 |
| CO039 | BlueVoyant's careers page emphasizes mission-driven culture, a large proprietary dataset, automation playbooks, and continual training as part of its employment brand. | Medium | SO010 |
| CO040 | BlueVoyant explicitly markets to companies, government entities, and critical-infrastructure organizations rather than to a narrow single vertical. | Medium | SO001, SO018 |
| CO041 | Cyber Insurance News summarized BlueVoyant's 2025 State of Supply Chain Defense report as showing 97% of surveyed organizations suffered negative impact from at least one supply-chain cyber breach, reinforcing the demand case behind its TPRM positioning. | Medium | SO032, SO014 |
| CO042 | PRNewswire and Enterprise IT World show a May 2026 CEO transition from co-founder Jim Rosenthal to John Hernandez while Rosenthal remained chairman. | High | SO016, SO027, SO002 |
| CO043 | The CEO handoff reduces single-person operating dependence, but founder-linked governance and brand concentration remain meaningful because Rosenthal and Glocer continue in chair and vice-chair roles. | Medium | SO002, SO016, SO027 |
| CO044 | BlueVoyant's public leadership materials foreground founders in governance or advisory roles rather than as the day-to-day executive bench. | Medium | SO002 |
| CO045 | Caplight characterizes BlueVoyant's customer profile as a B2B mix of subscription SaaS, services and consulting, and government contracts. | Medium | SO030 |
| CO046 | Caplight tags BlueVoyant around threat intelligence, incident response, vulnerability management, cloud security, and compliance or risk workflows. | Medium | SO030 |
| CO047 | The combination of MDR, TPRM, and professional-services pages indicates BlueVoyant monetizes both recurring software modules and analyst-led managed services. | Medium | SO005, SO006, SO030 |
| CO048 | In the reviewed public source set, the last specifically dated financing event is the more-than-$140 million Series E announced on 2023-11-29 alongside the Conquest acquisition. | Medium | SO018, SO023, SO030, SO033 |
| CM001 | BlueVoyant markets MDR as protection for internal networks, cloud instances, containers, and endpoints that augments existing EDR, SIEM, and cloud security tools. | Medium | SM001 |
| CM002 | BlueVoyant markets TPRM as a fully managed solution that identifies, validates, and resolves critical cybersecurity issues in a third-party ecosystem. | High | SM002, SM003 |
| CM003 | BlueVoyant's TPRM module set includes continuous monitoring and remediation, questionnaire management, point-in-time risk assessments, and program consulting. | Medium | SM002 |
| CM004 | BlueVoyant's continuous-monitoring workflow includes analyst-directed remediation, business risk monitoring, tiered vendor analysis, zero-day alerting, fourth-party analytics, and APIs/integrations. | Medium | SM003 |
| CM005 | BlueVoyant's fourth-party analytics motion goes beyond direct-vendor questionnaires into fourth- and nth-party dependency mapping and what-if analysis. | Medium | SM005 |
| CM006 | BlueVoyant's AI positioning emphasizes augmenting human judgment in attack-surface monitoring, threat detection, and vulnerability analysis instead of promising a fully autonomous cyber workflow. | Medium | SM001, SM004 |
| CM007 | BlueVoyant's direct market boundary is the overlap between managed SecOps and cyber-focused third-party risk management rather than generic GRC or stand-alone security controls. | High | SM001, SM002, SM003, SM005 |
| CM008 | The most relevant adjacent budget pools are GRC, board reporting, and resilience workflows, but those categories should remain outside BlueVoyant's direct core TAM. | Medium | SM015, SM020, SM023 |
| CM009 | Precedence Research sizes the MDR market at USD 3.92B in 2026 and USD 13.90B by 2035, implying 15.12% CAGR from 2026 to 2035. | Medium | SM006 |
| CM010 | Mordor Intelligence sizes the MDR market at USD 5.09B in 2026 and USD 13.45B by 2031, implying 21.45% CAGR. | Medium | SM007 |
| CM011 | The Business Research Company sizes the MDR market at USD 4.16B in 2026 and USD 8.57B by 2030, implying 19.8% CAGR. | Medium | SM008 |
| CM012 | Published MDR baselines conflict materially, with 2026 starting values ranging from USD 3.92B to USD 5.09B and growth assumptions ranging from 15.12% to 21.45% CAGR. | Medium | SM006, SM007, SM008 |
| CM013 | Grand View Research sizes TPRM at USD 7.42B in 2023 and USD 20.59B by 2030 at 15.7% CAGR, with North America holding more than 38% of revenue in 2023. | Medium | SM009 |
| CM014 | NextMSC says the TPRM market reached USD 9.71B by end-2025 and will reach USD 18.28B by 2030 at 13.48% CAGR, with large enterprises expected to dominate demand. | Medium | SM010 |
| CM015 | The Business Research Company says the TPRM market will grow from USD 8.09B in 2026 to USD 15.45B by 2030 at 17.6% CAGR. | Medium | SM011 |
| CM016 | Published TPRM baselines also conflict materially, with direct and normalized 2026 values ranging from roughly USD 8.09B to USD 11.49B depending on methodology and category scope. | Medium | SM009, SM010, SM011 |
| CM017 | The broader adjacent GRC software market is much larger than BlueVoyant's direct wedge, at an estimated USD 23.32B in 2026 growing to USD 39.01B by 2031. | Medium | SM020 |
| CM018 | Combining MDR and TPRM published baselines suggests a gross 2026 core-market ceiling for BlueVoyant of roughly USD 12.0B to USD 16.6B before removing overlap. | Low | SM006, SM007, SM008, SM009, SM010, SM011 |
| CM019 | Applying large-enterprise, regulated-buyer, and western-market filters to the gross ceiling yields a practical BlueVoyant SAM of roughly USD 5B to USD 8B. | Low | SM007, SM009, SM010, SM011 |
| CM020 | Public data does not support a precise dollar SOM for BlueVoyant because the company does not disclose module-level revenue or the split between MDR, TPRM, Microsoft-managed services, and adjacent offerings. | Low | SM001, SM002, SM003, SM004, SM005 |
| CM021 | MDR spending is enterprise-skewed: Mordor says large enterprises accounted for 57.65% of 2025 MDR spend, while TBRC lists major adopters across BFSI, IT, government, and energy verticals. | Medium | SM007, SM008 |
| CM022 | BlueVoyant's practical SAM is likely western-market skewed because Mordor assigns North America 45.78% of MDR revenue in 2025 and Grand View gives North America more than 38% of TPRM revenue. | Low | SM007, SM009 |
| CM023 | Large enterprises dominate public TPRM demand because they manage extensive vendor ecosystems, global supply chains, and complex regulatory requirements. | Medium | SM010 |
| CM024 | BlueVoyant's TPRM workflow implies a buying committee that spans security, vendor-risk operations, compliance, procurement, and resilience owners rather than a single budget line. | Medium | SM002, SM003, SM005 |
| CM025 | Panorays says 85% of CISOs lack full supply-chain visibility and only 41% monitor fourth parties, validating a core buyer pain point for BlueVoyant's dependency-mapping and monitoring wedge. | Medium | SM014, SM005 |
| CM026 | Panorays says 62% of CISOs saw regulatory pressure increase and only 22% feel fully prepared, showing that buyer urgency is rising even where operating readiness remains low. | Medium | SM014 |
| CM027 | Marsh says 70% of organizations experienced at least one material third-party cyber incident in the past year and 66% plan to increase cybersecurity investment in the coming year. | Medium | SM013 |
| CM028 | KPMG says regulatory compliance and cyber risk are now the primary drivers shaping TPRM strategy globally. | Medium | SM012 |
| CM029 | BlueVoyant's MDR positioning is an overlay and optimization motion for existing security tooling, not a pure rip-and-replace platform sale. | Medium | SM001, SM004 |
| CM030 | BlueVoyant's TPRM positioning suggests payer logic often extends from security into procurement and enterprise-risk owners because remediation and onboarding workflows sit outside the SOC. | Medium | SM002, SM003 |
| CM031 | SEC cybersecurity disclosure rules require public companies to disclose material cyber incidents within four business days and to describe cybersecurity risk management, strategy, and governance. | Medium | SM016 |
| CM032 | NIS2 creates a unified EU cybersecurity framework across 18 critical sectors, expanding the set of organizations that must take supplier and operational cyber risk seriously. | Medium | SM017 |
| CM033 | CISA defines ICT supply-chain cyber risk as spanning hardware, software, and managed services from third-party vendors, suppliers, service providers, and contractors. | High | SM023, SM024 |
| CM034 | NIST CSF 2.0 and CISA's SCRM materials show that cyber supply-chain risk is now treated as a formal management and resilience discipline rather than a narrow procurement checklist. | High | SM015, SM023, SM024 |
| CM035 | Gartner says AI, geopolitical tension, regulatory volatility, and an accelerating threat landscape are the forces shaping cybersecurity buying priorities in 2026. | Medium | SM018 |
| CM036 | KPMG says only about one in five organizations have achieved full TPRM integration with ERM and only 5% have adopted end-to-end managed-service models. | Medium | SM012 |
| CM037 | Black Kite says that in 2025 each vendor breach compromised an average of 5.28 downstream companies, which makes fourth-party and concentration analysis commercially relevant. | Medium | SM021 |
| CM038 | BlueVoyant claims its TPRM monitoring uses AI/ML across more than 50,000 data sources and can issue zero-day alerts in as little as 90 minutes, aligning the product with continuous-risk rather than periodic-review buying criteria. | Medium | SM003, SM005 |
| CM039 | CyberProof says Gartner has warned that some providers misuse the MDR label by offering managed EDR or other tool-centric monitoring without full human-led incident-response leadership. | Medium | SM019 |
| CM040 | CyberProof says MDR has moved toward mainstream adoption, citing projections that half of organizations would use MDR services for 24x7 monitoring, detection, and containment. | Low | SM019 |
| CM041 | KPMG says most organizations still rely on a patchwork of disconnected tools, which constrains category standardization and slows end-to-end TPRM adoption. | Medium | SM012 |
| CM042 | Panorays' data implies that many buyers still operate with major blind spots beyond direct vendors, so category adoption is limited as much by process maturity as by software availability. | Medium | SM014 |
| CM043 | CRC says global cyber-insurance pricing fell about 7% in Q4 2025 as market capacity improved, which can soften one urgency lever for cyber-spend escalation. | Medium | SM022 |
| CM044 | CRC says ransomware remained the primary driver of business interruption claims and that supply-chain and vendor risk stayed a central underwriting focus in 2026. | Medium | SM022 |
| CM045 | PeerSpot's MDR category page shows that buyers actively compare many vendors and still ask what differentiates MDR from a traditional SOC, reinforcing category crowding and education friction. | Medium | SM025 |
| CM046 | BlueVoyant's market should not be equated with generic GRC because BlueVoyant sells cyber monitoring, validation, remediation, and dependency visibility rather than broad policy-and-audit software alone. | Medium | SM002, SM003, SM020 |
| CM047 | BlueVoyant's strongest valuation support comes from cross-sell between independently growing MDR and TPRM categories that are both being pulled forward by regulation and operating pain. | Medium | SM006, SM007, SM011, SM013, SM018 |
| CM048 | The main market risk is not whether the categories exist, but whether BlueVoyant can win inside crowded, definition-sensitive categories where buyer confusion, tool sprawl, and budget scrutiny can slow conversion. | Medium | SM012, SM019, SM022, SM025 |
| CM049 | BlueVoyant's differentiated TPRM wedge appears to be analyst-led remediation plus fourth-party mapping, not just questionnaire automation. | Medium | SM002, SM003, SM005, SM014 |
| CM050 | BlueVoyant's differentiated MDR wedge appears to be overlaying and optimizing existing Microsoft, EDR, and SIEM environments with 24x7 monitoring and automation rather than selling a stand-alone security control. | Medium | SM001, SM004 |
| CP001 | Gartner defines MDR as a provider-operated, outcome-driven SOC service that includes active disruption and containment rather than alerting alone. | Medium | SP027 |
| CP002 | BlueVoyant publicly positions itself across MDR, TPRM, digital risk protection, and professional services rather than as a single-product MDR vendor. | Medium | SP001 |
| CP003 | BlueVoyant highlights 1,200+ Microsoft Sentinel deployments, 10 Microsoft security awards, and 24x7 in-regional SOC monitoring across Europe and the US. | Medium | SP001 |
| CP004 | BlueVoyant’s MDR page advertises 50+ certified Microsoft Delivery and SOC engineers plus unlimited remote incident-response lifecycle support. | Medium | SP003 |
| CP005 | BlueVoyant says it was founded in 2017 and has over 600 employees across offices on five continents. | Medium | SP002 |
| CP006 | BlueVoyant Government’s C-SCRM product says it uses more than 70,000 unique proprietary, open-source, and commercial data feeds without requiring agency or vendor proprietary data. | Medium | SP005 |
| CP007 | BlueVoyant Government says it can map, monitor, and mitigate risk for tens of thousands of suppliers at once and validate 100% of supplier risk events. | Medium | SP005 |
| CP008 | BlueVoyant’s June 2026 launch of BlueVoyant AI signals a strategic move toward agentic SecOps that can be consumed either as a fully managed SOC or a self-service SaaS platform. | Medium | SP006 |
| CP009 | Palo Alto positions Cortex XSIAM as a unified AI-driven SOC platform spanning SIEM, SOAR, EDR, NDR, and CDR. | Medium | SP007 |
| CP010 | Palo Alto advertises 10,000+ detections, 2,600+ analytics models, and Unit 42-managed services on top of XSIAM. | Medium | SP007 |
| CP011 | Palo Alto says it has 16K+ employees and 70K+ customers globally, giving it distribution scale that BlueVoyant cannot match publicly. | Medium | SP008 |
| CP012 | CrowdStrike Falcon Complete advertises a one-minute median time-to-contain and 2.7 million detections remediated monthly. | Medium | SP009 |
| CP013 | CrowdStrike frames Falcon Complete as agentic MDR that combines deterministic automation, adaptive AI agents, human-in-the-loop experts, and native visibility across endpoint, identity, cloud, and third-party data. | Medium | SP009 |
| CP014 | Arctic Wolf positions around a fully managed agentic SOC with 10,000+ customers, 1,000+ security engineers, and 200+ integrations. | Medium | SP010, SP011 |
| CP015 | Arctic Wolf says its proactive MDR can reduce attack frequency and impact by up to 90% and completed more than 74,000 security posture reviews in 2025. | Low | SP010 |
| CP016 | Arctic Wolf’s value proposition centers on concierge delivery, open XDR, security-journey guidance, and warranty coverage rather than a single endpoint platform. | Medium | SP010, SP012 |
| CP017 | CRN reported that Arctic Wolf raised $60 million in Series D to help the company prepare for IPO-related thresholds. | Medium | SP032 |
| CP018 | SC Media reported that Arctic Wolf was valued at roughly $4.3 billion while management avoided committing to an IPO timeline. | Medium | SP033 |
| CP019 | Rapid7 says it serves more than 11,500 customers worldwide and positions itself as a leader in AI-powered managed cybersecurity operations. | Medium | SP013 |
| CP020 | Rapid7’s Incident Command platform ties exposure management, endpoint and cloud telemetry, third-party sources, Rapid7 Labs intelligence, and 20 years of data into one detection-and-response workflow. | Medium | SP014 |
| CP021 | ReliaQuest describes GreyMatter as an agentic AI security operations platform that detects, contains, investigates, and responds regardless of data source. | Medium | SP015 |
| CP022 | ReliaQuest’s homepage says GreyMatter processes 50K+ alerts daily with 255+ technology partners and 99.4% AI investigation accuracy. | Medium | SP016 |
| CP023 | ReliaQuest’s integrations posture supports enterprises that want to keep existing SIEM, EDR, and cloud tools rather than replace them with one vendor stack. | Medium | SP017 |
| CP024 | eSentire says it protects 2,000+ customers across 35+ industries and pairs Atlas AI with 24/7 expert human SOC coverage. | Medium | SP018 |
| CP025 | eSentire’s XDR platform and third-party coverage claim a vendor-independent model with broad integrations and human-controlled AI response. | Medium | SP019, SP034 |
| CP026 | eSentire’s competitive messaging explicitly emphasizes unlimited threat hunting, unlimited incident handling, and any-signal integration breadth. | Medium | SP020 |
| CP027 | SecurityScorecard says 70% of the Fortune 100 trust its data, 3,300+ organizations use the platform, and 12M+ organizations are monitored and rated. | Medium | SP022 |
| CP028 | SecurityScorecard’s TPRM pitch combines questionnaire review, technical-ground-truth validation, continuous monitoring, nth-party visibility, remediation blueprints, and risk quantification. | Medium | SP021, SP023 |
| CP029 | SecurityScorecard publicly frames itself as supply-chain detection and response rather than only a passive cyber-ratings tool. | Medium | SP021, SP022 |
| CP030 | BitSight says its TPRM product includes 75K+ mapped vendor profiles and claims a 75% reduction in third-party breach probability for customers. | Low | SP025 |
| CP031 | BitSight says it continuously monitors 40M+ companies and 250M+ digital assets and exposes cyber risk through APIs, integrations, and data feeds. | Medium | SP024, SP025 |
| CP032 | Bitsight’s April 2026 press release says it was named a Forrester Leader and had more than 3,500 customers plus over 68,000 organizations active on platform. | Medium | SP026 |
| CP033 | Gartner’s 2026 MDR market page lists 173 products and reiterates that immediate remote mitigative response is a mandatory MDR feature. | Medium | SP027 |
| CP034 | PeerSpot says BlueVoyant CORE held 0.9% MDR mindshare in June 2026, down from 1.2% the year before. | Medium | SP028 |
| CP035 | PeerSpot’s BlueVoyant-versus-CrowdStrike comparison ranks BlueVoyant #34 in MDR while CrowdStrike is ranked #2 and holds 5.4% mindshare versus BlueVoyant’s 0.9%. | Medium | SP029 |
| CP036 | PeerSpot says reviewers occasionally note limited reporting customization for BlueVoyant and characterize CrowdStrike as broader and faster to deploy. | Medium | SP029 |
| CP037 | Daylight’s 2026 buyer guide classifies BlueVoyant among MSSPs offering MDR that are chosen for broad security partnership but use more analyst-hours-intensive investigation workflows than AI-native or XDR-extended alternatives. | Medium | SP031 |
| CP038 | Ciphers Security says the TPRM market splits between outside-in security-ratings platforms and workflow-oriented lifecycle tools such as ProcessUnity, OneTrust, Venminder, and Prevalent. | Medium | SP030 |
| CP039 | The same Ciphers Security guide says ratings tools assess vendors from the outside in, while workflow platforms manage questionnaires and lifecycle tasks from the inside, so many buyers blend the two approaches. | Medium | SP030 |
| CP040 | BlueVoyant’s public combination of MDR, TPRM, digital-risk protection, and government C-SCRM gives it a cross-budget story that most MDR-only or ratings-only competitors do not present on one surface. | Medium | SP001, SP004, SP021, SP024 |
| CP041 | The retained official pages for BlueVoyant, CrowdStrike, Arctic Wolf, Rapid7, ReliaQuest, eSentire, SecurityScorecard, and BitSight do not disclose enterprise list pricing for their full offerings, implying quote-based sales motions and limited public comparability. | Medium | SP001, SP009, SP010, SP013, SP015, SP018, SP021, SP024 |
| CP042 | Platform-native competitors create bundling pressure because Palo Alto, CrowdStrike, and Rapid7 tie managed response to broader SOC, XDR, or SIEM suites with unified telemetry and automation. | Medium | SP007, SP009, SP014 |
| CP043 | Arctic Wolf, ReliaQuest, and eSentire represent a separate open-stack threat because all three publicly stress preserving the customer’s existing security tools while adding 24x7 expert operations. | Medium | SP010, SP017, SP019 |
| CP044 | BlueVoyant’s supply-chain defense competes against much larger publicly described data networks because SecurityScorecard and BitSight cite millions of monitored organizations or tens of thousands of mapped vendor profiles. | Medium | SP022, SP025, SP026 |
| CP045 | BlueVoyant is best aligned to Microsoft-heavy or regulated buyers that want managed SOC operations plus outside-in supplier defense rather than a single-vendor endpoint suite or a pure ratings tool. | Medium | SP001, SP003, SP005, SP006, SP021, SP024 |
| CP046 | Internal SOC build remains a substitute, but Gartner and Decryption Digest both frame outsourced MDR as a way to avoid the staffing and response burden of self-running security operations. | Medium | SP027, SP031 |
| CI001 | BlueVoyant publicly packages MDR, TPRM, DRP, and professional services as four core commercial solution families. | Medium | SI001 |
| CI002 | BlueVoyant claims more than 1,200 successful Microsoft Sentinel deployments. | Medium | SI001 |
| CI003 | BlueVoyant claims customers can reduce Sentinel costs by 40% without sacrificing coverage. | Medium | SI001 |
| CI004 | BlueVoyant claims it provides 24x7 in-regional SOC monitoring across Europe and the United States. | Medium | SI001 |
| CI005 | BlueVoyant claims its TPRM offer drives 18x faster remediation of critical issues. | Medium | SI001 |
| CI006 | BlueVoyant claims 98% accuracy for critical vulnerabilities identified in its TPRM motion. | Medium | SI001 |
| CI007 | BlueVoyant claims an average response time of 3.5 hours for recently disclosed zero-day vulnerabilities. | Medium | SI001 |
| CI008 | BlueVoyant claims it remediated more than 1,600 vulnerabilities on behalf of clients in the last 30 days. | Medium | SI001 |
| CI009 | BlueVoyant claims it completed 50,000 successful domain takedowns over the prior two years. | Medium | SI001 |
| CI010 | BlueVoyant says it has over 600 employees across offices spanning five continents. | Medium | SI002 |
| CI011 | BlueVoyant publicly positions channel partners such as GuidePoint Security and CDW as part of its distribution model. | Medium | SI003 |
| CI012 | BlueVoyant's build-versus-buy marketing says a self-built 24/7 SOC can cost more than $1.2 million annually. | Medium | SI004 |
| CI013 | The same BlueVoyant page says a partnered MSSP can cost less than 25% of the annual cost of building an internal SOC. | Medium | SI004 |
| CI014 | BlueVoyant said it added 299 new customers during 2021. | Medium | SI005 |
| CI015 | BlueVoyant said customer count exceeded 700 across 30 countries by early 2022. | High | SI005, SI006 |
| CI016 | BlueVoyant said its employee count increased by 130% during 2021. | Medium | SI005 |
| CI017 | BlueVoyant said partners contributed 50% of all new business in 2021. | Medium | SI005 |
| CI018 | BlueVoyant said annual recurring revenue had grown 117% on average since 2018. | High | SI005, SI006 |
| CI019 | BlueVoyant closed a $250 million Series D round led by Liberty Strategic Capital with participation from ISTARI, Eden Global Partners, and 8VC. | High | SI006, SI022 |
| CI020 | BlueVoyant said it had grown to more than 560 employees and more than 700 customers by the Series D announcement. | Medium | SI006 |
| CI021 | BlueVoyant said it expanded into more than 10 countries during 2021. | Medium | SI006 |
| CI022 | BlueVoyant acquired Conquest Cyber and raised more than $140 million of Series E funding alongside the deal. | High | SI007, SI018, SI019, SI020, SI021 |
| CI023 | The Series E funding was led by Liberty Strategic Capital and ISTARI, with Eden Global Capital Partners acting as strategic adviser. | High | SI007, SI018, SI019, SI020, SI021 |
| CI024 | BlueVoyant said Conquest Cyber added SaaS technology and FedRAMP Marketplace credentials for defense and government use cases. | Medium | SI007, SI020 |
| CI025 | BlueVoyant said it had more than 900 global customers when Timothy Yost joined as CFO in June 2024. | Medium | SI008 |
| CI026 | BlueVoyant framed the Timothy Yost hire as scaling the company's financial and strategic planning capability. | Medium | SI008 |
| CI027 | BlueVoyant said it served over 1,000 customers in more than 45 countries by March 2025. | High | SI009, SI026 |
| CI028 | BlueVoyant said local EMEA revenue grew 70% in 2024 and described Cork as part of a multi-million-euro regional investment program. | Medium | SI009 |
| CI029 | BlueVoyant's commissioned Forrester MDR study claims 210% ROI over three years. | Medium | SI010 |
| CI030 | The same MDR study claims a 90% reduction in total escalated alerts per month. | Medium | SI010 |
| CI031 | The same MDR study claims a 70% acceleration in mean time to resolve. | Medium | SI010 |
| CI032 | BlueVoyant's commissioned Supply Chain Defense study claims nearly 300% return on investment. | Medium | SI011 |
| CI033 | The same Supply Chain Defense study claims a 62% reduction in time to remediate critical risks. | Medium | SI011 |
| CI034 | BlueVoyant's Snappi case study says the customer achieved 24x7 SOC coverage within months instead of hiring across multiple vendors. | Medium | SI012 |
| CI035 | BlueVoyant's ODEON case study says the deployment spans 8 countries and more than 280 cinemas. | Medium | SI013 |
| CI036 | BlueVoyant's ODEON case study says the program cut alerts requiring InfoSec or regional IT review by 98%. | Medium | SI013 |
| CI037 | BlueVoyant's ODEON case study says the program resolved 30 critical or high third-party vulnerabilities. | Medium | SI013 |
| CI038 | BlueVoyant said Google Cloud Marketplace availability removes procurement friction for its TPRM offer. | Medium | SI014 |
| CI039 | BlueVoyant's Microsoft-security ROI blog says an enterprise can spend up to $750,000 annually to optimize the stack internally. | Medium | SI015 |
| CI040 | BlueVoyant's Sentinel deployment guide says its examples are drawn from hundreds of deployments and 16 anonymized case studies. | Medium | SI016 |
| CI041 | Private Equity Insights reported that BlueVoyant intended to use Series D proceeds for product development and international expansion. | Medium | SI022 |
| CI042 | CB Insights reported that BlueVoyant had raised $665.5 million over 9 rounds. | Medium | SI023 |
| CI043 | CB Insights reported a $1.0 billion valuation in February 2022. | Medium | SI023 |
| CI044 | CB Insights estimated BlueVoyant's 2024 revenue at $750 million, which conflicts with lower recurring-revenue estimates in other databases. | Low | SI023 |
| CI045 | GetLatka estimated BlueVoyant's 2025 revenue at $213.5 million. | Low | SI024 |
| CI046 | GetLatka estimated BlueVoyant employed about 650 people in 2025. | Low | SI024 |
| CI047 | Clay reported $665.5 million of total funding and a latest funding date of 2023-11-01. | Medium | SI026 |
| CI048 | Clay reported 11 investors and over 1,000 customers across 45 countries. | Medium | SI026 |
| CI049 | Dialectica listed BlueVoyant at 653 employees and named Liberty Strategic Capital as an investor. | Medium | SI025 |
| CI050 | Tracxn reported $696 million of total funding across 6 rounds, conflicting with the $665.5 million totals cited by CB Insights and Clay. | Low | SI027 |
| CI051 | PitchBook's accessible snapshot showed 363 employees and a $30 million latest deal amount, conflicting with the 600-plus employee signals from later sources. | Low | SI028 |
| CI052 | PitchBook's accessible snapshot included a historical Debt - PPP financing entry dated 2020-04-27. | Medium | SI028 |
| CI053 | Companies House shows BlueVoyant UK Limited filed full accounts for the year ended 2024 on 2025-09-30. | Medium | SI029 |
| CI054 | Companies House shows a compulsory strike-off action against BlueVoyant UK Limited was discontinued in March 2025. | Medium | SI029 |
| CI055 | Companies House shows BlueVoyant Ltd also filed full accounts for the year ended 2024 on 2025-09-30. | Medium | SI030 |
| CI056 | An archived Indeed review described BlueVoyant as extremely top heavy with management. | Low | SI031 |
| CI057 | The same archived review alleged consistent bi-yearly layoffs and resource cuts across some business units. | Low | SI031 |
| CI058 | No retained public source verified current cash on hand, monthly burn, or runway as of 2026-06-29. | Medium | SI001, SI002, SI006, SI007, SI008, SI009, SI023, SI024, SI026, SI027, SI028 |
| CI059 | No retained public source disclosed realized contract pricing, discounting, gross margin, NRR, or CAC payback for BlueVoyant. | Medium | SI001, SI004, SI010, SI011, SI014, SI015, SI023, SI024, SI026 |
| CI060 | The public record supports a recurring managed-services model but does not reconcile the mix between software-like recurring revenue and project-based services. | Medium | SI001, SI005, SI006, SI007, SI010, SI011, SI012, SI013 |
| CI061 | Using GetLatka's $213.5 million revenue estimate and Dialectica's 653-employee estimate implies roughly $327,000 of revenue per employee. | Low | SI024, SI025 |
| CI062 | Using the $665.5 million consensus total raised and GetLatka's $213.5 million revenue estimate implies cumulative funding of roughly 3.1x estimated annual revenue. | Low | SI024, SI026 |
| CI063 | BlueVoyant's current public financial signal set is too contradictory to underwrite revenue quality or runway without management data. | Medium | SI023, SI024, SI025, SI026, SI027, SI028, SI029, SI030, SI031 |
| CE001 | BlueVoyant currently defines its customer-facing offer as Agentic SecOps, MDR, and TPRM that protect the full attack surface. | Medium | SE001 |
| CE002 | BlueVoyant publicly advertises Microsoft-focused scale signals including 1,200-plus Sentinel deployments, 24x7 in-regional SOC monitoring, and named cost savings. | Medium | SE001 |
| CE003 | The Cyber Defense Platform page organizes the portfolio into MDR, TPRM, DRP, and professional-services suites. | Medium | SE002 |
| CE004 | BlueVoyant’s 2024 platform launch describes a single cloud-native platform integrating internal, external, and supply-chain defense. | High | SE002, SE021 |
| CE005 | The platform is described as processing signals and alerts from internal networks, supply chains, and the clear, deep, and dark web. | High | SE021, SE027 |
| CE006 | BlueVoyant AI says the company matches human expertise, deterministic automation, and AI agents to the mission rather than treating AI as a universal substitute. | High | SE003, SE022 |
| CE007 | BlueVoyant AI is offered both as a fully managed service and as a SaaS platform for internal security teams. | High | SE003, SE022 |
| CE008 | BlueVoyant AI publicly claims automated response actions including device isolation, credential revocation, and malicious-email eradication. | Medium | SE022 |
| CE009 | BlueVoyant AI attributes its Microsoft advantage to almost ten years of operating experience and more than 2,500 Microsoft-native customer deployments. | Medium | SE022 |
| CE010 | BlueVoyant MDR is marketed as protecting internal networks, cloud instances, containers, and endpoints while strengthening existing EDR, SIEM, and cloud-security tools. | Medium | SE004 |
| CE011 | MDR for Microsoft and Continuous Optimization for Microsoft Solutions are first-class modules inside the MDR suite. | High | SE004, SE006 |
| CE012 | BlueVoyant promises 24/7 detection and response across the full Microsoft security stack. | High | SE005, SE031 |
| CE013 | The MDR for Microsoft page lists 2026 Data Security and Compliance Trailblazer recognition, 2024 Worldwide Security Partner of the Year, three-time US Security Partner of the Year, and MISA membership. | Medium | SE005 |
| CE014 | BlueVoyant claims Microsoft Solutions Partner designations in Security, Infrastructure (Azure), and Modern Work plus security specializations in Cloud Security, Identity and Access Management, and Threat Protection. | Medium | SE005 |
| CE015 | Continuous Optimization for Microsoft Solutions extends the offer into Sentinel, Defender, M365, and Purview configuration and optimization based on 1,000-plus engagements. | High | SE006, SE007 |
| CE016 | BlueVoyant’s MDR for Microsoft collateral says customers can keep security data in their own environment instead of sending it to MSSP-owned infrastructure. | Medium | SE031 |
| CE017 | The Microsoft collateral frames the service around Microsoft Sentinel and Microsoft 365 Defender as the core security stack. | Medium | SE031 |
| CE018 | The MDR for Microsoft deployment playbook explicitly includes infrastructure setup, log-source ingestion, alert and SOAR configuration, knowledge transfer, and initial alert tuning. | Medium | SE031 |
| CE019 | BlueVoyant describes TPRM as a fully managed solution that identifies, validates, and resolves critical cybersecurity issues in a third-party ecosystem. | Medium | SE008 |
| CE020 | BlueVoyant’s TPRM suite includes continuous monitoring and remediation, questionnaire management, point-in-time risk assessments, and vendor consulting. | High | SE008, SE015 |
| CE021 | The continuous-monitoring workflow says Risk Operations Center analysts validate findings and work directly with third parties on remediation. | Medium | SE009 |
| CE022 | BlueVoyant says its business-risk monitoring uses AI and machine learning across more than 50,000 data sources and eight risk categories. | Medium | SE009 |
| CE023 | The questionnaire-management module automates assessment creation and distribution while validating supplier statements against observed performance. | Medium | SE010 |
| CE024 | BlueVoyant’s 2023 supply-chain expansion added multi-tier continuous monitoring, questionnaire workflows, point-in-time assessments, rapid zero-day alerting, and advisory workshops. | High | SE015, SE023 |
| CE025 | BlueVoyant positions DRP as protection against threats emerging from the clear, deep, and dark web before they affect the business or customers. | Medium | SE011 |
| CE026 | BlueVoyant’s DRP modules are Brand Protection, Dark Web Watcher, and Executive Cyber Guard. | Medium | SE011 |
| CE027 | Brand Protection covers web, social-media, and app impersonation with unlimited takedowns and monitoring across more than 300 official and unofficial app stores. | Medium | SE012 |
| CE028 | Dark Web Watcher monitors underground communities for fraud campaigns, sold credentials, and data leakage. | Medium | SE013 |
| CE029 | Executive Cyber Guard focuses on executive-data exposure, stolen credentials, and account-takeover prevention for high-value individuals. | Medium | SE014 |
| CE030 | BlueVoyant’s differentiated product story is convergence: Microsoft-centric MDR on the inside, TPRM across the supply chain, and DRP on the external attack surface under one operating model. | Medium | SE002, SE004, SE008, SE011 |
| CE031 | The Trust Center describes BlueVoyant as a cloud-native security-operations platform combining advanced AI with expert human insight across networks, endpoints, supply chains, and web or dark-web monitoring. | Medium | SE017 |
| CE032 | The Trust Center says BlueVoyant is trusted by more than 1,000 clients globally. | Medium | SE017 |
| CE033 | Conquest Cyber adds SaaS technology that unifies security posture, compliance, detection, and response through a risk-maturity lens. | High | SE016, SE024 |
| CE034 | BlueVoyant planned to integrate Conquest technology into existing products and services to create internal and external cyber defense mapped to risk maturity. | High | SE016, SE024 |
| CE035 | Conquest brought DIB and government credentials, CMMC RPO accreditation, FedRAMP-marketplace presence for ARMED ATK, and additional Microsoft security capabilities into BlueVoyant’s platform story. | High | SE016, SE024 |
| CE036 | Public GitHub evidence shows only one visible BlueVoyant repository, BV-Security-Copilot, with the public pages pointing to a September 22, 2025 update. | High | SE018, SE019, SE020 |
| CE037 | The visible BlueVoyant GitHub repo is framed as public content for Copilot for Security, implying limited open-source transparency relative to the breadth of the marketed platform. | Medium | SE020 |
| CE038 | Microsoft Learn records a BlueVoyant Shadow Hunter Microsoft Security Immersion Workshop, showing practitioner-facing Microsoft training activity beyond static marketing pages. | Medium | SE032 |
| CE039 | Gartner’s DRP page surfaces a favorable review headline that still notes occasional takedown challenges, signaling that takedown execution remains a real operational risk area. | Medium | SE029 |
| CE040 | A 2019 Spiceworks thread shows buyer skepticism that BlueVoyant was a startup relying on established tools such as Splunk, highlighting a long-running diligence question about proprietary depth versus service orchestration. | Low | SE030 |
| CE041 | PeerSpot describes BlueVoyant CORE as a combined MDR, digital-risk-protection, and supply-chain-defense suite backed by 24/7 monitoring and machine learning. | Medium | SE025 |
| CE042 | Cyber Magazine independently described the 2024 launch as a cloud-native platform specifically aimed at the supplier-driven attack surface. | Medium | SE026 |
| CE043 | BlueVoyant publicly reports a 99 percent website-takedown success rate, a 95 percent social-media-takedown success rate, and a 23-hour median server-level takedown time for DRP. | Medium | SE001 |
| CU001 | BlueVoyant’s visible customer base skews toward regulated or operationally complex organizations rather than broad SMB self-serve buyers. | Low | SU001, SU002, SU003, SU005, SU014, SU019 |
| CU002 | The deepest named public proofs span state government, federal defense supply chains, digital banking, capital-markets infrastructure, and multinational entertainment operations. | Low | SU001, SU002, SU003, SU005, SU019 |
| CU003 | Public financial-services proof is concentrated in Snappi, Beeks, ClearBank, and sector-specific Microsoft content rather than a long named roster of banks or insurers. | Low | SU003, SU005, SU006, SU014, SU026 |
| CU004 | Public-sector proof is concentrated in California OIS, NAVSEA, and Carahsoft-enabled procurement routes rather than a broad public list of named agencies. | Low | SU001, SU013, SU019, SU024, SU030, SU031 |
| CU005 | California OIS launched a cloud-based SOCaaS that integrated Microsoft Security with BlueVoyant’s MDR for Microsoft. | Medium | SU001 |
| CU006 | BlueVoyant’s California case study says the program reduced mean time to detect by 70 percent. | Medium | SU001 |
| CU007 | BlueVoyant’s California case study says the program reduced mean time to respond by 60 percent. | Medium | SU001 |
| CU008 | BlueVoyant’s California case study says participating entities saved about $2.1 million in annual personnel costs. | Medium | SU001 |
| CU009 | California’s Department of Technology said in June 2025 that SOCaaS protected 112 public-sector organizations and had produced more than $54 million of combined savings. | Medium | SU037 |
| CU010 | California CDT describes SOCaaS as a 24/7 continuous-monitoring service used to satisfy statewide monitoring requirements. | Medium | SU036, SU037 |
| CU011 | ODEON Cinemas Group runs more than 280 cinemas across eight countries. | Medium | SU002, SU033 |
| CU012 | ODEON’s public materials describe nearly 50 log sources and a previously fragmented, noisy security setup before BlueVoyant’s engagement. | Medium | SU002, SU033 |
| CU013 | BlueVoyant migrated ODEON to Microsoft Sentinel, onboarded MDR for Microsoft, and added DFIR plus third-party risk management. | Medium | SU002, SU033 |
| CU014 | ODEON’s case-study materials report a 98 percent reduction in alerts requiring review. | Medium | SU002, SU033 |
| CU015 | ODEON’s BlueVoyant case study reports 30 critical or high third-party vulnerabilities resolved. | Medium | SU002 |
| CU016 | Independent coverage quotes ODEON saying monthly alerts fell from hundreds to roughly 6 to 12 tickets. | Medium | SU033 |
| CU017 | Snappi is described in multiple public sources as Greece’s first ECB-licensed neobank. | Medium | SU003, SU034, SU035 |
| CU018 | Snappi used BlueVoyant and Veracloud to implement 24/7 SOC coverage, MDR, dark-web monitoring, and incident-response readiness within months of launch. | Medium | SU003, SU034, SU035 |
| CU019 | Snappi’s public proof emphasizes board visibility, monthly SOC KPI reporting, tabletop exercises, and DORA readiness rather than conventional revenue or usage metrics. | Medium | SU003, SU034 |
| CU020 | Beeks says BlueVoyant now supports a 24x7 end-to-end SOC for a platform serving capital-markets and financial-services customers. | Medium | SU005, SU026 |
| CU021 | Beeks says BlueVoyant lowered alert fatigue, reduced data-ingestion costs, and was operational in less than three months. | Medium | SU005, SU026 |
| CU022 | Beeks positions the partnership as a customer-acquisition differentiator because its own clients ask about cyber resilience. | Medium | SU005, SU026 |
| CU023 | NAVSEA awarded a three-year Phase III contract and delivery orders to BlueVoyant Government Solutions for industrial-base resilience and supply-chain illumination work. | Medium | SU019, SU020 |
| CU024 | BlueVoyant Government Solutions said in April 2025 that its SCD-G platform had been added to Carahsoft’s SCRIPTS BPA vehicle. | Medium | SU031 |
| CU025 | BlueVoyant Government Solutions said its platform currently identifies critical risks for more than 4 million suppliers. | Medium | SU031 |
| CU026 | Carahsoft distributes BlueVoyant through SEWP V, ITES-SW2, NASPO ValuePoint, and California CMAS procurement routes. | Medium | SU024, SU030 |
| CU027 | BlueVoyant’s partner program offers co-selling, training, account support, and marketing tooling across channel, tech-alliance, and OEM relationships. | Medium | SU004 |
| CU028 | Carahsoft says its reseller ecosystem includes more than 10,000 government contractors, VARs, solution providers, integrators, and MSPs. | Medium | SU032 |
| CU029 | AWS Marketplace shows BlueVoyant selling a private-offer MDR service with 24x7 SOC support. | Medium | SU025 |
| CU030 | BlueVoyant’s public financial-services evidence includes named work with Snappi, Beeks, and ClearBank plus sector materials featuring Fiserv and JP Morgan participants. | Low | SU003, SU005, SU006, SU008, SU014, SU026 |
| CU031 | BlueVoyant’s public government evidence includes California SOCaaS, NAVSEA supply-chain work, Carahsoft distribution, and contract-vehicle access. | Low | SU001, SU019, SU024, SU030, SU031, SU037 |
| CU032 | BlueVoyant actively markets to energy and legal buyers, but the reviewed corpus does not show equally deep named production proofs for those sectors. | Low | SU015, SU016 |
| CU033 | BlueVoyant’s 2024 MDR TEI summary claims 210 percent three-year ROI, 90 percent fewer escalated alerts per month, and 70 percent faster mean time to resolve for a composite customer. | Medium | SU017 |
| CU034 | BlueVoyant’s supply-chain-defense TEI summary claims nearly 300 percent ROI, 65 percent better monitoring efficiency, 70 percent fewer suppliers above risk threshold, and 60 percent faster remediation of critical risks. | Medium | SU011 |
| CU035 | BlueVoyant’s 2025 supply-chain survey says it captured 1,800 executives across financial services, healthcare, pharma, utilities, energy, retail, manufacturing, and defense. | Medium | SU012 |
| CU036 | BlueVoyant said in May 2025 that it was trusted by more than 1,000 clients globally and had guided thousands of clients on Microsoft Security. | Medium | SU018 |
| CU037 | FeaturedCustomers shows BlueVoyant with 9 reviews, 5 case studies, and a 4.7 out of 5 reference rating across 133 total customer references. | Medium | SU021, SU022 |
| CU038 | PeerSpot describes BlueVoyant deployments across finance, healthcare, and manufacturing and says licensing typically includes annual or multi-year agreements. | Medium | SU023 |
| CU039 | The reviewed AWS Marketplace and Slashdot pages both show zero visible customer ratings or reviews for BlueVoyant. | Medium | SU025, SU029 |
| CU040 | None of the reviewed public customer sources disclose NRR, GRR, churn, or cohort renewal performance. | Low | SU001, SU002, SU003, SU005, SU014, SU021, SU022, SU023 |
| CU041 | None of the reviewed public customer sources break out top-customer concentration or contract-duration exposure by revenue. | Low | SU001, SU002, SU003, SU005, SU014, SU019, SU021, SU023 |
| CU042 | The strongest public outcomes cluster around Microsoft-centered operations, managed detection and response, and supply-chain risk use cases rather than broad attach-rate disclosure across all product lines. | Low | SU001, SU002, SU003, SU005, SU014, SU017, SU031 |
| CU043 | Most quantified customer proof is vendor-authored or partner-authored rather than independently audited, so deployment outcomes are visible but durability evidence remains thin. | Low | SU001, SU002, SU003, SU005, SU022, SU028, SU029, SU033, SU034 |
| CR001 | BlueVoyant markets itself as a Microsoft security specialist across Sentinel, Defender, Purview, and Copilot-readiness work. | Medium | SR002, SR003 |
| CR002 | BlueVoyant says its MDR for Microsoft offer combines BlueVoyant AI with an elite 24x7 SOC and security operations team. | Medium | SR003, SR018 |
| CR003 | BlueVoyant says it works with Microsoft product teams on Sentinel scenarios, operations feedback, API extensibility, and Security Copilot agents. | Medium | SR013, SR028 |
| CR004 | BlueVoyant says it won the 2024 Microsoft Worldwide Security Partner of the Year Award and additional U.S. and Canada security partner awards. | High | SR010, SR014 |
| CR005 | BlueVoyant and Micah Heaton were recognized in the 2025 Microsoft Security Excellence Awards as Security Trailblazer and Security Changemaker winners. | High | SR009, SR017, SR027 |
| CR006 | BlueVoyant’s Sentinel eBook says it summarizes 16 anonymized case studies drawn from hundreds of hands-on Microsoft Sentinel deployments. | Medium | SR033 |
| CR007 | Protiviti describes BlueVoyant’s Microsoft offering as combining advanced AI with expert human insight in a joint services stack. | Medium | SR018 |
| CR008 | BlueVoyant launched BlueVoyant AI on 2026-06-09 as an AI-native Agentic SecOps platform. | High | SR004, SR032 |
| CR009 | BlueVoyant AI is offered in both fully managed and enterprise SaaS deployment models. | High | SR004, SR032 |
| CR010 | BlueVoyant says its AI workflows keep humans at the center of the strategy even when automated response actions occur at machine speed. | Medium | SR004, SR032 |
| CR011 | BlueVoyant’s Cork SOC announcement says the site provides 24x7 monitoring for Irish and EU clients. | Medium | SR008, SR015 |
| CR012 | BlueVoyant links its Cork expansion to NIS2 and DORA-driven customer demand and says local revenue grew 70% in 2024. | Medium | SR008, SR015 |
| CR013 | BlueVoyant changed CEOs in May 2026 when John Hernandez succeeded co-founder Jim Rosenthal. | Medium | SR006 |
| CR014 | BlueVoyant’s 2023 CPO appointment was framed as a move to unify product lines and expand share in cybersecurity. | Medium | SR007 |
| CR015 | BlueVoyant’s privacy notice says BlueVoyant LLC is the controller of personal data collected through its website. | Medium | SR001 |
| CR016 | BlueVoyant’s privacy notice says personal information may be shared with affiliate companies unless prohibited by law or other regulatory requirements. | Medium | SR001 |
| CR017 | PacerMonitor shows Steward Health filed an adversary complaint against Bluevoyant LLC in July 2025. | Medium | SR020 |
| CR018 | The public Steward docket describes avoidance and recovery claims under bankruptcy preference and fraudulent-transfer theories. | Medium | SR020 |
| CR019 | The DoD CIO CMMC page says Phase 1 implementation runs from 2025-11-10 to 2026-11-09 and focuses on Level 1 and Level 2 self-assessments. | High | SR022, SR023 |
| CR020 | The DoD CIO CMMC page reminds contractors to submit affirmations with CMMC assessments in SPRS. | Medium | SR022 |
| CR021 | The DoD CMMC 2.0 page says contracting officers now include the new CMMC requirements in new solicitations and contracts. | Medium | SR023 |
| CR022 | NIST SP 800-171 says its security requirements are intended for use in contractual vehicles and agreements between federal agencies and nonfederal organizations handling CUI. | Medium | SR021 |
| CR023 | BlueVoyant Government Solutions markets supply-chain visibility and expert-led threat remediation at scale for mission assurance. | Medium | SR011 |
| CR024 | BlueVoyant’s government customer page targets intelligence, federal civilian, acquisition, cybersecurity, and supply-chain risk-management use cases. | Medium | SR012 |
| CR025 | Carahsoft lists BlueVoyant on NASA SEWP V through 2026-09-30. | Medium | SR019 |
| CR026 | Carahsoft also lists ITES-SW2 through 2030-08-30 and SCRIPTS BPA through 2030-03-30 for BlueVoyant. | Medium | SR019 |
| CR027 | Pavilion says BlueVoyant Government Solutions includes CMMC and NIST 800-171 compliance management. | Medium | SR029 |
| CR028 | SAM.gov says contract-award search now supports filtering by keyword, agency, and legal business name. | Medium | SR030 |
| CR029 | USAspending says it is the official open data source for federal awards, including contracts, grants, and loans. | Medium | SR031 |
| CR030 | BlueVoyant said it raised more than $140 million in Series E funding to support the Conquest Cyber acquisition. | Medium | SR005 |
| CR031 | BlueVoyant said Conquest Cyber had traction in the U.S. Defense Industrial Base and government organizations. | Medium | SR005 |
| CR032 | PM Insights exposes only delayed preview data and gated institutional datasets for BlueVoyant valuation, secondary activity, and cap-table details. | Medium | SR024 |
| CR033 | SourceForge presents BlueVoyant alongside many alternative cyber platforms in 2026, underscoring a crowded competitive set. | Medium | SR025 |
| CR034 | PeerSpot describes BlueVoyant as spanning MDR, digital risk protection, and supply-chain defense with advanced analytics and a 24x7 SOC. | Medium | SR026 |
| CR035 | Microsoft’s 2021 security blog framed customer need around tech sprawl and positioned BlueVoyant as an optimizer of Microsoft security services. | Medium | SR016 |
| CR036 | Finance Yahoo and PR Newswire say BlueVoyant is building analytics, playbooks, hunting queries, notebooks, and Security Copilot agents on top of Sentinel. | Medium | SR013, SR028 |
| CR037 | BlueVoyant’s Microsoft page markets cost-of-adoption assessments for Sentinel, Defender for Cloud, Microsoft 365 E5, data security, and Copilot readiness. | Medium | SR002 |
| CR038 | BlueVoyant’s Sentinel eBook says customers use the company to optimize costs and migrate from other SIEMs. | Medium | SR033 |
| CR039 | BlueVoyant’s Gartner-market-guide blog cites rising third-party breach pressure and presents AI-driven assessment plus expert remediation as its TPRM answer. | Medium | SR034 |
| CR040 | Independent coverage of the BlueVoyant AI launch repeats the company’s claim that the platform delivers autonomous speed, precision, and control at scale. | Medium | SR032 |
| CR041 | BlueVoyant’s 2024 Microsoft award release says the company’s Microsoft customer base has grown over the past three years. | Medium | SR010, SR014 |
| CR042 | Microsoft’s 2025 awards page independently confirms BlueVoyant was among recognized security-ecosystem winners. | Medium | SR017 |
| CR043 | Protiviti says it and BlueVoyant jointly deliver Microsoft security, compliance, and identity solutions. | Medium | SR018 |
| CR044 | The PR Newswire UK Cork release says BlueVoyant’s EMEA build-out reflects a multi-million-Euro investment since 2017. | Medium | SR015 |
| CR045 | BlueVoyant’s Cork release says the company had local employees in Ireland before opening the permanent office. | Medium | SR008 |
| CR046 | BlueVoyant’s go-to-market and product differentiation are tightly coupled to Microsoft roadmap, pricing, and channel behavior. | Medium | SR002, SR003, SR013, SR028 |
| CR047 | The shift from managed MDR into agentic SOC software increases execution complexity around packaging, pricing, support, and quality control. | Medium | SR004, SR006, SR007, SR032 |
| CR048 | BlueVoyant’s public-sector motion is compliance-gated because the company markets CMMC and NIST support while DoD rules are now flowing into contracts. | Medium | SR021, SR022, SR023, SR027, SR029 |
| CR049 | Public-sector concentration is material but still unquantified because contract vehicles are visible while agency-level award mix and renewal concentration are not publicly disclosed. | Medium | SR019, SR030, SR031 |
| CR050 | The Steward complaint is the clearest company-specific adverse signal in the public record and should be diligenced for amount, defenses, and insurance coverage. | Medium | SR020 |
| CR051 | Competitive risk is elevated because BlueVoyant competes at once in Microsoft services, MDR, TPRM, and supply-chain defense against more specialized vendors. | Medium | SR025, SR026, SR034 |
| CR052 | Financing risk remains material because the public file shows a 2023 private raise and gated secondary-market previews, but not current ARR, runway, or valuation terms. | Medium | SR005, SR024 |
| CR053 | The highest-likelihood near-term risks are Microsoft-feature dependence and managed-service staffing drift because both sit inside BlueVoyant’s daily delivery loop. | Medium | SR003, SR008, SR013, SR018 |
| CR054 | The highest-impact downside risks are compliance slippage, financing opacity, and any legal escalation because those could impair growth or capital access quickly. | Medium | SR020, SR022, SR023, SR024 |
| CR055 | If Microsoft economics worsen or BlueVoyant AI underdelivers, BlueVoyant would likely feel the damage first in customer ROI and renewal confidence before financing flexibility changes. | Medium | SR003, SR004, SR013, SR024 |
| CR056 | Missing public metrics on SLA attainment, MTTR, analyst-to-customer ratios, agency concentration, and capital structure reduce confidence in residual-risk scoring. | Medium | SR024, SR030, SR031 |
| CV001 | BlueVoyant announced on November 29, 2023 that it raised more than $140 million to accompany its acquisition of Conquest Cyber. | High | SV002, SV032 |
| CV002 | BlueVoyant said Liberty Strategic Capital and ISTARI led the November 2023 funding round. | High | SV002, SV032 |
| CV003 | BlueVoyant's February 23, 2022 Series D raised $250 million. | High | SV003, SV011 |
| CV004 | BlueVoyant named Liberty Strategic Capital, ISTARI, Eden Global Partners, and 8VC as participants in the Series D round. | High | SV003, SV011, SV008 |
| CV005 | Caplight currently shows BlueVoyant's last round as Series E on November 29, 2023 with an estimated valuation of $1 billion. | Medium | SV004 |
| CV006 | Forge shows BlueVoyant's last known valuation as $1 billion dated February 23, 2022. | Medium | SV006 |
| CV007 | Caplight, CB Insights, and GetLatka each report BlueVoyant total funding at $665.5 million. | High | SV004, SV009, SV027 |
| CV008 | Tracxn reports BlueVoyant total funding at $696 million across six rounds. | Medium | SV008 |
| CV009 | CB Insights classifies BlueVoyant as Series E | Alive and lists the last raise as $140 million. | Medium | SV027 |
| CV010 | The SEC browse result for BlueVoyant shows Form D notices dated 2017-08-04, 2019-04-25, and 2020-07-08. | Medium | SV012 |
| CV011 | The retained SEC browse result does not surface later BlueVoyant financing filings, leaving the 2022 and 2023 round terms undisclosed in public filing search results. | Medium | SV012 |
| CV012 | BlueVoyant's February 2023 growth release said the company had more than 900 clients in 40-plus countries and nearly 1,000 clients globally. | Medium | SV001 |
| CV013 | BlueVoyant's February 2023 growth release said recurring revenue grew 80% in 2022 and 108% on average since 2018. | Medium | SV001 |
| CV014 | GetLatka estimates BlueVoyant's 2025 revenue at $213.5 million and employee count at about 650. | Medium | SV009 |
| CV015 | BlueVoyant's public materials position the company around MDR, TPRM, digital risk protection, and professional services on one platform. | High | SV001, SV010 |
| CV016 | Caplight tags BlueVoyant with MDR, third-party risk management, SOC-as-a-Service, supply chain risk management, and digital risk protection keywords. | Medium | SV004 |
| CV017 | Notice titles BlueVoyant at $1.36 per share. | Medium | SV005 |
| CV018 | Notice's page markup shows the current Notice Price at a 39% discount to the last round. | Medium | SV005 |
| CV019 | Forge labels BlueVoyant market activity as limited and shows no Forge Price. | Medium | SV006 |
| CV020 | Hiive's page data shows no daily price history and sets displayChart to false for BlueVoyant. | Medium | SV007 |
| CV021 | PM Insights' public preview exposes sections for secondary-market ROI, bid-ask ratios, mutual-fund NAV, and cap-table details, but not the underlying numbers. | Medium | SV026 |
| CV022 | Windsor Drake says the public cybersecurity median trades at roughly 6.0x to 6.5x NTM revenue in Q2 2026. | Medium | SV018 |
| CV023 | Windsor Drake says managed security services compress to roughly 3x to 5x revenue in 2026. | Medium | SV018 |
| CV024 | Tablestat shows median enterprise cybersecurity EV/revenue at 8.4x for 2025E and 6.8x for 2026E. | Medium | SV020 |
| CV025 | CrowdStrike trades at 34.30x EV/revenue on 5.09B of trailing revenue and about 178.47B of market cap. | Medium | SV013, SV021 |
| CV026 | Palo Alto Networks trades at 23.28x EV/revenue on 10.61B of trailing revenue and about 247.92B of market cap. | Medium | SV028, SV030 |
| CV027 | Fortinet trades at 15.20x EV/revenue on 7.11B of trailing revenue and about 110.88B of market cap. | Medium | SV029, SV031 |
| CV028 | SentinelOne trades at 4.61x EV/revenue on 1.05B of trailing revenue and about 5.45B of market cap. | Medium | SV014, SV022 |
| CV029 | Qualys trades at 5.73x EV/revenue on 684.86M of trailing revenue and about 4.34B of market cap. | Medium | SV017, SV025 |
| CV030 | Tenable trades at 3.32x EV/revenue on 1.02B of trailing revenue and about 3.33B of market cap. | Medium | SV016, SV024 |
| CV031 | Rapid7 trades at 0.93x EV/revenue on 859.23M of trailing revenue and about 508.58M of market cap. | Medium | SV015, SV023 |
| CV032 | multiples.vc describes CrowdStrike and SentinelOne as security-operations platforms and Rapid7, Qualys, and Tenable as exposure, XDR/SIEM, and compliance platforms, supporting their use as BlueVoyant comparables. | Medium | SV019 |
| CV033 | BlueVoyant's homepage advertises 24x7 in-region SOC monitoring, 1,200-plus Microsoft Sentinel deployments, and 1,600-plus vulnerabilities remediated in the last 30 days. | Medium | SV010 |
| CV034 | A $1 billion valuation on the $213.5 million ARR proxy implies roughly 4.7x ARR. | Medium | SV004, SV009 |
| CV035 | A 4.7x ARR multiple sits below the 2026 public cyber median and near SentinelOne, Qualys, and Tenable. | Medium | SV018, SV022, SV024, SV025 |
| CV036 | Because BlueVoyant mixes software with managed services and professional services, it should not command CrowdStrike-, Palo Alto-, or Fortinet-level software multiples without disclosed margin proof. | Medium | SV010, SV018, SV020 |
| CV037 | The bull thesis rests on real scale, broad cyber-risk product breadth, and historical triple-digit recurring-revenue growth. | Medium | SV001, SV010, SV032 |
| CV038 | The clearest anti-thesis is that public secondary data show a 39% discount, limited visible liquidity, and no obvious public valuation step-up after 2022. | Medium | SV004, SV005, SV006 |
| CV039 | Caplight still showing a $1 billion estimate and Forge still showing a $1 billion last-known mark suggest no public upward valuation reset despite the 2023 Series E. | Medium | SV004, SV006 |
| CV040 | Public sources disagree on exact capital raised, ranging from $665.5 million to $696 million, which signals data-room opacity rather than a clean public funding ledger. | Medium | SV004, SV008, SV027 |
| CV041 | A base-case valuation band of roughly $0.85 billion to $1.1 billion is supportable by applying 4.0x to 5.0x to the $213.5 million ARR proxy. | Medium | SV009, SV018, SV022 |
| CV042 | An upside range of roughly $1.2 billion to $1.5 billion requires sustained growth and a mix shift toward higher-margin platform revenue that would justify 5.5x to 7.0x multiples. | Medium | SV018, SV020, SV028, SV029 |
| CV043 | A downside range of roughly $0.6 billion to $0.8 billion is consistent with the Notice discount to the last round and the managed-security/services range. | Medium | SV005, SV018 |
| CV044 | The public evidence does not support a buy call because downside is observable in secondary signals while the upside case still depends on undisclosed margin, retention, and share-count data. | Medium | SV005, SV006, SV012, SV026 |
| CV045 | BlueVoyant is large enough and strategically relevant enough that the correct recommendation is research-more rather than avoid. | Medium | SV001, SV010, SV032 |
| CV046 | Confidence should be medium because the multiple work is directionally coherent, but the core ARR and liquidity inputs come from third-party datasets rather than audited disclosure. | Medium | SV009, SV026, SV027 |
| CV047 | Risk rating should remain high because private-market liquidity appears thin and the current mark could compress if growth or margin quality undershoots. | Medium | SV005, SV006, SV007 |
| CV048 | Valuation stance is fair rather than attractive because the $1 billion mark can be justified on the ARR proxy but leaves limited margin of safety against secondary discounts. | Medium | SV005, SV009, SV018, SV022 |
| CV049 | Hiive states that BlueVoyant remains privately held and pre-IPO access is limited to accredited investors via secondary marketplaces. | Medium | SV007 |
| CV050 | The highest-value diligence asks are current ARR and gross-margin mix, cap table and share count, actual secondary-clearing prices, and confirmation of any post-2023 financing terms. | Medium | SV007, SV012, SV026, SV027 |
| ID | Publisher | Title | Quote |
|---|---|---|---|
| SO001 | BlueVoyant | Company | Founded in 2017... Headquartered in New York City, the company has over 600 employees... spanning five continents. |
| SO002 | BlueVoyant | Leadership | |
| SO003 | BlueVoyant | Contact Us | More Than 1,000 Customers in 45 Countries |
| SO004 | BlueVoyant | BlueVoyant Cyber Defense Platform | |
| SO005 | BlueVoyant | Managed Detection & Response | |
| SO006 | BlueVoyant | Third-Party Risk Management (TPRM) | |
| SO007 | BlueVoyant | Partners | |
| SO008 | BlueVoyant | BlueVoyant & Microsoft | |
| SO009 | BlueVoyant | Awards | |
| SO010 | BlueVoyant | Careers | |
| SO011 | BlueVoyant | Born in the SOC, Not in a Lab | Webinar | |
| SO012 | BlueVoyant | Next Era of Cyber Defense with BlueVoyant AI | BlueVoyant today announced BlueVoyant AI, an innovative Agentic SecOps platform that fundamentally redefines how modern enterprises prevent, detect, investigate, and stop cyber threats. |
| SO013 | BlueVoyant | BlueVoyant Raises $250 Million Series D Led by Liberty Strategic Capital | Liberty Strategic Capital... led the $250-million round with participation from... ISTARI... Eden Global Partners... and 8VC. |
| SO014 | BlueVoyant | BlueVoyant and Auto-ISAC Partner to Elevate TPRM in Automotive | |
| SO015 | BlueVoyant | BlueVoyant Welcomes Michael Montoya as COO | Michael Montoya has joined the company as Chief Operating Officer (COO)... overseeing the technology, product, and operations organizations. |
| SO016 | PR Newswire | John Hernandez Joins BlueVoyant as CEO to Accelerate AI-Driven Cybersecurity Platform and Global Growth | John Hernandez will succeed Jim Rosenthal as Chief Executive Officer (CEO). |
| SO017 | PR Newswire | Liberty Strategic Capital Leads Investment Round in BlueVoyant, an Industry-Leading Cyber Defense Platform | |
| SO018 | PR Newswire | BlueVoyant Acquires Conquest Cyber to Meet Market Need for Comprehensive Managed Detection and Response and Cyber Risk Posture Solutions | |
| SO019 | PR Newswire | BlueVoyant and Auto-ISAC Partner to Elevate Third-Party Cyber Risk Management Across the Automotive Industry | |
| SO020 | TechCrunch | BlueVoyant nabs $250M to help enterprises nab malicious hackers and stop security breaches | |
| SO021 | SecurityWeek | BlueVoyant Raises $250 Million to Boost Technical Capabilities, Global Expansion | |
| SO022 | CRN | BlueVoyant Acquires Conquest Cyber In Deal That Reshapes Microsoft Security Landscape | |
| SO023 | GovCon Wire | BlueVoyant Purchases Conquest Cyber, Raises Over $140M in Series E Funding Round | |
| SO024 | BankInfoSecurity | BlueVoyant Raises $140M, Buys Resilience Firm Conquest Cyber | |
| SO025 | iTWire | BlueVoyant Ignites the Next Era of Cyber Defence with Launch of BlueVoyant AI | |
| SO026 | UK Tech News | BlueVoyant Ignites the Next Era of Cyber Defence with Launch of BlueVoyant AI | |
| SO027 | Enterprise IT World | BlueVoyant Appoints John Hernandez as CEO to Drive AI-Led Cybersecurity Growth | |
| SO028 | Unify | Employee Data and Trends for Bluevoyant | |
| SO029 | GetLatka | BlueVoyant Revenue 2025: $213.5M ARR, $1B Valuation | |
| SO030 | Caplight | BlueVoyant | Valuation, Funding Rounds & Stock Price | |
| SO031 | UpGuard | BlueVoyant Security Rating, Vendor Risk Report, and Data Breaches | The Content Security Policy is implemented with unsafe-eval, reducing protection against XSS attacks. |
| SO032 | Cyber Insurance News | BlueVoyant Warns Supply Chain Breaches Soar as Cyber Liability Insurance Requirements Shape Risk Strategy | |
| SO033 | The SaaS News | BlueVoyant Raises $140 Million in Series E | |
| SM001 | BlueVoyant | Managed Detection & Response | Protect your internal network, cloud instances, containers, and endpoints from unknown threat actors, and strengthen your utilization of existing EDR, SIEM, and cloud security tools. |
| SM002 | BlueVoyant | Third-Party Risk Management (TPRM) | BlueVoyant Third-Party Risk Management (TPRM) is a fully managed solution that identifies, validates, and resolves critical cybersecurity issues in your third-party ecosystem. |
| SM003 | BlueVoyant | Continuous Monitoring & Remediation | |
| SM004 | BlueVoyant | AI-Driven Cyber Defense | |
| SM005 | BlueVoyant | Fourth-Party Identification and Analytics | |
| SM006 | Precedence Research | Managed Detection and Response (MDR) Market Size to Hit USD 13.90 Bn by 2035 | |
| SM007 | Mordor Intelligence | Managed Detection and Response Market Size & Trends, 2031 | |
| SM008 | The Business Research Company | Managed Detection And Response Market Insights 2026 to 2035 | |
| SM009 | Grand View Research | Third-party Risk Management Market Size Report, 2030 | |
| SM010 | Next Move Strategy Consulting | Third-Party Risk Management Market Analysis | 2025-2030 | |
| SM011 | The Business Research Company | Third-party Risk Management Market Growth Report 2026 | |
| SM012 | KPMG | The 2026 KPMG Global Third-Party Risk Management Survey | This is not the time for incremental improvements or fragmented approaches. |
| SM013 | Marsh | Rising third-party risks and persistent ransomware threats drive increased cybersecurity investments in 2026 | Marsh | 70% of organizations experienced at least one material third-party cyber incident in the past year. |
| SM014 | Panorays | 200 CISOs Reveal the Truth About Third-Party Cyber Risk | 85% of CISOs surveyed admitted they do not have full visibility across their entire supply chain. |
| SM015 | National Institute of Standards and Technology | Cybersecurity Framework | |
| SM016 | Securities and Exchange Commission | Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure | For domestic registrants, this disclosure must be filed on Form 8-K within four business days of determining that a cybersecurity incident is material. |
| SM017 | European Commission | NIS2 Directive: securing network and information systems | The NIS2 Directive establishes a unified legal framework to uphold cybersecurity in 18 critical sectors across the EU. |
| SM018 | Gartner | Gartner Identifies the Top Cybersecurity Trends for 2026 | The chaotic rise of AI, geopolitical tensions, regulatory volatility and an accelerating threat landscape are the driving forces behind the top cybersecurity trends for 2026. |
| SM019 | CyberProof | Mapping the Managed Detection and Response (MDR) Market for 2026 | Gartner has cautioned that many providers misusing the “MDR” label offer only tool-centric monitoring (e.g. managed EDR) without the critical human analysis and incident response leadership. |
| SM020 | Mordor Intelligence | GRC Software Market Size, Share & 2031 Growth Trends Report | |
| SM021 | Black Kite | 2026 Third-Party Breach Report | Black Kite Supply Chain Risk Data | For every single vendor breached, an average of 5.28 downstream companies were publicly compromised. |
| SM022 | CRC Group | 2026 Cyber + Technology State of the Market at a Glance | |
| SM023 | Cybersecurity and Infrastructure Security Agency | Information and Communications Technology Supply Chain Risk Management | CISA | If vulnerabilities in the ICT supply chain—composed of hardware, software, and managed services from third-party vendors, suppliers, service providers, and contractors—are exploited, the consequences can affect all users of that technology or service. |
| SM024 | Cybersecurity and Infrastructure Security Agency | ICT Supply Chain Risk Management Task Force | CISA | The ICT SCRM Task Force—a public-private partnership charged with identifying challenges and developing actionable solutions to enhance global ICT supply chain resilience. |
| SM025 | PeerSpot | Top Rated Managed Detection and Response (MDR) Vendors | |
| SP001 | BlueVoyant | MDR, TPRM, Digital Risk Protection | BlueVoyant | Agentic SecOps, MDR, and TPRM to protect your entire attack surface. |
| SP002 | BlueVoyant | Company | Founded in 2017... the company has over 600 employees across offices... spanning five continents. |
| SP003 | BlueVoyant | Managed Detection & Response | 50+ certified Microsoft Delivery & SOC Engineers |
| SP004 | BlueVoyant Government Solutions | BlueVoyant Government Solutions | Supply Chain Defense | BlueVoyant Government Solutions operationalizes mission assurance with deep supply chain risk visibility and expert-led threat remediation at scale. |
| SP005 | BlueVoyant Government Solutions | Products | More than 70,000 unique proprietary, open-source, and commercially-available data feeds |
| SP006 | PR Newswire | BlueVoyant Ignites the Next Era of Cyber Defense with Launch of BlueVoyant AI | BlueVoyant AI provides both with its fully managed service... or as an enterprise-grade SaaS platform. |
| SP007 | Palo Alto Networks | Explore Cortex XSIAM Security Analytics | Every SOC capability on one platform. |
| SP008 | Palo Alto Networks | About Us | 16K+ Employees | 70K+ Customers Globally | ~$100B Market Cap |
| SP009 | CrowdStrike | 24/7 Expert Protection | CrowdStrike Falcon® Complete Next-Gen MDR | 1min Median time-to-contain (MTTC) |
| SP010 | Arctic Wolf | Managed Detection and Response (MDR) | Arctic Wolf | The SOC uses trusted datasets drawn from 14+ years of security operations and insights from 10,000+ global customers, and 1,000+ security engineers. |
| SP011 | Arctic Wolf | A Higher Standard of Security Operations | Arctic Wolf | Trusted by over 10,000 customers worldwide |
| SP012 | Arctic Wolf | Why Arctic Wolf? | As the pioneer of the first open XDR platform that makes security work, the Aurora® Superintelligence Platform leverages AI to enable cyber defense at an unprecedented capacity and scale. |
| SP013 | Rapid7 | About Rapid7 - Cybersecurity Company | Rapid7 unifies exposure and detection to transform the cybersecurity operations of more than 11,500 customers worldwide. |
| SP014 | Rapid7 | Incident Command: AI Powered Next-Gen SIEM | Rapid7 | Incident Command delivers a new standard for detection and response built for scale, speed, and clarity across your entire threat landscape. |
| SP015 | ReliaQuest | About Us | ReliaQuest exists to Make Security Possible, allowing enterprise security teams to detect, contain and respond to threats within minutes—anytime, anywhere—using the GreyMatter agentic AI security operations platform. |
| SP016 | ReliaQuest | Home | ReliaQuest GreyMatter: The Agentic AI Security Operations Platform for Agentic Defense | 50K+ alerts processed daily; 255+ Technology Partners with security technologies; 99.4% accuracy of AI investigations. |
| SP017 | ReliaQuest | ReliaQuest GreyMatter Integrations: Your Environment + Agentic AI Powered Security Operations | Your environment + agentic AI powered security operations |
| SP018 | eSentire | Managed Detection and Response Services & Security Operations Platform | Protecting 2,000+ Customers Across 35+ Industries |
| SP019 | eSentire | XDR Extended Detection & Response Solutions | Our distributed platform easily integrates with your existing security investments. |
| SP020 | eSentire | eSentire MDR vs the Competition | The Atlas Platform connects to ANY SIGNAL, whether that's Endpoint, Network, Logs, Cloud, Vulnerability scanner, Browser, or Identity provider. |
| SP021 | SecurityScorecard | SecurityScorecard | Supply Chain & Third-Party Risk Platform | The world’s first AI-powered platform for continuous, threat-informed third-party risk management |
| SP022 | SecurityScorecard | Company - SecurityScorecard | 3,300+ global organizations... 12M+ organizations monitored and rated |
| SP023 | SecurityScorecard | Third-Party Risk Management (TPRM) | SecurityScorecard | Validate Questionnaires with Technical Ground Truth |
| SP024 | Bitsight | Cyber Risk Intelligence Platform | A dynamic map of assets and vulnerabilities, prioritized by real-time threat intelligence, across your enterprise and supply chain. |
| SP025 | Bitsight | Third Party Risk Management Solutions | 75K+ Mapped vendor profiles in the Bitsight Vendor Network |
| SP026 | Bitsight | Bitsight Named a Leader in Cybersecurity Risk Ratings, Praised By Customers for the Utility of its Data | Bitsight | With more than 3,500 customers and over 68,000 organizations active on its platform |
| SP027 | Gartner Peer Insights | Best Managed Detection and Response Reviews 2026 | Gartner Peer Insights | MDR offers outcome-driven security incident management... and the delivery of active threat disruption and containment actions. |
| SP028 | PeerSpot | BlueVoyant CORE Reviews, Competitors and Pricing | As of June 2026, the mindshare of BlueVoyant CORE in the Managed Detection and Response (MDR) category stands at 0.9%, down from 1.2% compared to the previous year. |
| SP029 | PeerSpot | Compare BlueVoyant CORE vs CrowdStrike Falcon Complete MDR | BlueVoyant is ranked #34, while CrowdStrike is ranked #2... BlueVoyant holds a 0.9% mindshare in MDR, compared to CrowdStrike’s 5.4% mindshare. |
| SP030 | Ciphers Security | Best Vendor Risk Management Platforms In 2026 | Two fundamentally different approaches dominate this market... Security ratings platforms... assess vendors from the outside in. |
| SP031 | Decryption Digest | Best MDR Services 2026: CrowdStrike vs Arctic Wolf vs Huntress Compared | MSSPs monitor firewall and SIEM alerts and deliver notifications... not meaningful security improvement. |
| SP032 | CRN | Managed Security Firm Arctic Wolf Raises $60 Million In Pursuit Of IPO | Arctic Wolf has closed a $60 million funding round to help the managed detection and response vendor prepare for an IPO. |
| SP033 | SC Media | Arctic Wolf backs off IPO talk, looks to scale business with latest acquisition | the company – which was reportedly valued at $4.3 billion – planned for an IPO this year. But he made no commitments |
| SP034 | Help Net Security | eSentire launches new Atlas AI Operatives for autonomous threat detection and response - Help Net Security | The Atlas Platform... operates vendor-independently across any integration. |
| SI001 | BlueVoyant | MDR, TPRM, Digital Risk Protection | BlueVoyant | BlueVoyant packages Agentic SecOps, MDR, TPRM, DRP, and professional services with 1,200+ Microsoft Sentinel deployments and 24x7 monitoring. |
| SI002 | BlueVoyant | Company | Headquartered in New York City, the company has over 600 employees across offices spanning five continents. |
| SI003 | BlueVoyant | Channel Partners | Operational cybersecurity demands collaboration, and BlueVoyant highlights partners including GuidePoint Security and CDW. |
| SI004 | BlueVoyant | Build Your Own SOC or Partner with an MSSP | The annual cost of setting up your own 24/7/365 SOC can add up to more than $1.2 million. |
| SI005 | BlueVoyant | BlueVoyant Enters 2022 With Triple Digit Growth Momentum and More Than 700 Global Customers | Customer count increased by more than 80%, with more than 700 customers globally in 30 countries worldwide. |
| SI006 | BlueVoyant | BlueVoyant Raises $250 Million Series D Led by Liberty Strategic Capital | Since 2018, BlueVoyant has grown annual recurring revenues at 117% on average. |
| SI007 | BlueVoyant | BlueVoyant Acquires Conquest Cyber | BlueVoyant raised more than $140 million in Series E funding to accompany the acquisition of Conquest Cyber. |
| SI008 | BlueVoyant | BlueVoyant Welcomes Timothy Yost as Chief Financial Officer | Tim will focus on setting and managing the company’s financial and strategic plans and continue to build BlueVoyant’s world-class global finance organization. |
| SI009 | BlueVoyant | New Security Operations Centre in Cork, Ireland | BlueVoyant serves over 1,000 customers in more than 45 countries, and local revenue grew 70% in 2024. |
| SI010 | BlueVoyant | Total Economic Impact™ of BlueVoyant MDR Services | The commissioned Forrester TEI study cites 210% ROI over three years. |
| SI011 | BlueVoyant | Total Economic Impact™ of BlueVoyant Supply Chain Defense Report | The Forrester TEI study cites nearly 300% return and a 62% reduction in time to remediate critical risks. |
| SI012 | BlueVoyant | Snappi Neobank: Enterprise-Grade Security from Day One | Snappi built 24/7 SOC coverage within months by partnering with Veracloud and BlueVoyant. |
| SI013 | BlueVoyant | ODEON Cinemas Group | ODEON consolidated security across 8 countries and 280+ cinemas while cutting alert volume by 98%. |
| SI014 | BlueVoyant | BlueVoyant TPRM Is on Google Cloud Marketplace | Making BlueVoyant TPRM available on GCP Enterprise Agreement eligibility removes procurement friction. |
| SI015 | BlueVoyant | Maximizing Security ROI | A recent BlueVoyant analysis found that an enterprise organization can have an annual cost of up to $750,000 to optimize its Microsoft security stack internally. |
| SI016 | BlueVoyant | Successful Deployments of Microsoft Sentinel eBook | The eBook summarizes insights from hundreds of hands-on deployments and 16 anonymized case studies. |
| SI017 | BlueVoyant | ClearBank's Journey with BlueVoyant | Webinar | BlueVoyant says it optimized ClearBank’s existing Microsoft Security investment for better outcomes. |
| SI018 | GovConWire | BlueVoyant Purchases Conquest Cyber, Raises Over $140M in Series E Funding Round | The acquisition coincided with a Series E funding round that raised over $140 million from BlueVoyant’s existing investors. |
| SI019 | FinTech Global | BlueVoyant bags $140m Series E and snaps up cybersecurity firm | This substantial investment was led by existing investors Liberty Strategic Capital and ISTARI. |
| SI020 | Pulse 2.0 | BlueVoyant: Conquest Cyber Acqusition And Over $140 Million In Series E Funding | BlueVoyant also raised over $140 million in Series E funding to accompany the acquisition of Conquest Cyber. |
| SI021 | The SaaS News | BlueVoyant Raises $140 Million in Series E | Funding details listed a $140.0M Series E in November 2023 led by Liberty Strategic Capital and ISTARI. |
| SI022 | Private Equity Insights | BlueVoyant raises $250m in funding round led by Steven Mnuchin-backed PE firm | The firm intends to use the capital raised to ramp up the development of its products and expand into new international markets. |
| SI023 | CB Insights | BlueVoyant Stock Price, Funding, Valuation, Revenue & Financial Statements | CB Insights says BlueVoyant has raised $665.5M over 9 rounds and estimated 2024 revenue at $750M. |
| SI024 | GetLatka | BlueVoyant Revenue 2025: $213.5M ARR, $1B Valuation | In 2025, BlueVoyant's revenue reached $213.5M and the profile estimated roughly 650 employees. |
| SI025 | Origin by Dialectica | BlueVoyant: Ownership, Revenue & Funding Data | Dialectica lists BlueVoyant as PE-backed with 653 employees and Liberty Strategic Capital as investor. |
| SI026 | Clay | How Much Did BlueVoyant Raise? Funding & Key Investors | Clay lists total amount raised at $665.5 million, 11 investors, and over 1,000 customers across 45 countries. |
| SI027 | Tracxn | BlueVoyant | Tracxn reports BlueVoyant has raised a total of $696M over 6 funding rounds. |
| SI028 | PitchBook | BlueVoyant Company Profile: Valuation & Investors | PitchBook | The accessible PitchBook snapshot showed 363 employees, a $30M latest deal amount, and a historical Debt - PPP entry dated 27-Apr-2020. |
| SI029 | Companies House | BLUEVOYANT UK LIMITED filing history - Find and update company information | BlueVoyant UK Limited filed full accounts made up to 31 December 2024 on 30 Sep 2025. |
| SI030 | Companies House | BLUEVOYANT LTD filing history - Find and update company information | BlueVoyant Ltd filed full accounts made up to 31 December 2024 on 30 Sep 2025. |
| SI031 | Indeed via Wayback | Working at BlueVoyant: Employee Reviews | A featured review warned that BlueVoyant was extremely top heavy with consistent bi-yearly layoffs and limited resources in some business units. |
| SE001 | BlueVoyant | MDR, TPRM, Digital Risk Protection | BlueVoyant | |
| SE002 | BlueVoyant | BlueVoyant Cyber Defense Platform | Seamlessly integrated MDR, TPRM, and DRP. |
| SE003 | BlueVoyant | BlueVoyant AI | Agentic SecOps Platform | AI that knows where to act and when to ask. |
| SE004 | BlueVoyant | Managed Detection & Response | |
| SE005 | BlueVoyant | MDR for Microsoft | 24/7 detection and response across your full Microsoft security stack. |
| SE006 | BlueVoyant | Continuous Optimization for Microsoft Solutions | |
| SE007 | BlueVoyant | Continuous Optimization for Microsoft Security | |
| SE008 | BlueVoyant | Third-Party Risk Management (TPRM) | |
| SE009 | BlueVoyant | Continuous Monitoring & Remediation | |
| SE010 | BlueVoyant | Questionnaire Management | |
| SE011 | BlueVoyant | Digital Risk Protection (DRP) | |
| SE012 | BlueVoyant | Brand Protection | |
| SE013 | BlueVoyant | Dark Web Watcher | |
| SE014 | BlueVoyant | Executive Cyber Guard | |
| SE015 | BlueVoyant | Comprehensive Third-Party Cyber Risk Management Solution | |
| SE016 | BlueVoyant | BlueVoyant Acquires Conquest Cyber | Conquest Cyber's SaaS technology modernizes risk management with a platform that unifies an organization's entire cyber risk management program. |
| SE017 | BlueVoyant | BlueVoyant Trust Center | BlueVoyant delivers a comprehensive cloud-native security operations platform that provides real-time threat monitoring for networks, endpoints, and supply chains, extending to the clear, deep, and dark web. |
| SE018 | GitHub | Bluevoyant | |
| SE019 | GitHub | Bluevoyant | |
| SE020 | GitHub | GitHub - Bluevoyant/BV-Security-Copilot: Public Content for Copilot for Security | Public Content for Copilot for Security. |
| SE021 | PR Newswire | BlueVoyant Unveils Leading-Edge Security Operations Platform | The platform integrates internal, external, and supply chain defense solutions into a single, cloud-native platform. |
| SE022 | PR Newswire | BlueVoyant Ignites the Next Era of Cyber Defense with Launch of BlueVoyant AI | BlueVoyant AI brings true AI-native Security Operations Center (SOC) capabilities to life, delivering real-time, deterministic decision-making, automated response, and faster containment. |
| SE023 | PR Newswire | BlueVoyant Expands Offerings to Establish the Only Comprehensive Third-Party Cyber Risk Management Solution | |
| SE024 | PR Newswire | BlueVoyant Acquires Conquest Cyber to Meet Market Need for Comprehensive Managed Detection and Response and Cyber Risk Posture Solutions | |
| SE025 | PeerSpot | BlueVoyant CORE Reviews, Competitors and Pricing | |
| SE026 | Cyber Magazine | BlueVoyant Launch Platform to Tackle Supplier Attack Surface | |
| SE027 | SecuritySenses | BlueVoyant Unveils Leading-Edge Security Operations Platform | |
| SE028 | Gartner Peer Insights | BlueVoyant Reviews, Ratings & Features 2026 | Gartner Peer Insights | |
| SE029 | Gartner Peer Insights | BlueVoyant Digital Risk Protection Reviews & Ratings 2026 | Gartner Peer Insights | Effective detection and ticket management with occasional takedown challenges |
| SE030 | Spiceworks Community | BlueVoyant | Thoughts, opinions, experiences? | They are a startup, which is concerning ... I believe the back-end is Splunk. |
| SE031 | InNetwork Tech | BlueVoyant Core: MDR for Microsoft (Managed Detection and Response) | BlueVoyant’s service allows you to keep your security data in your own environment, reducing cost and ensuring stronger compliance. |
| SE032 | Microsoft | How to order the SWAG as part of attending "BLUEVOYANT Shadow Hunter -Security Immersion Workshop - Microsoft Q&A | |
| SU001 | BlueVoyant | California’s Innovative Cybersecurity Initiative | 70% Reduction in Mean Time to Detect (MTTD); 60% Reduction in Mean Time to Respond (MTTR); $2.1 Million annual personnel cost savings/entity utilizing SOCaas |
| SU002 | BlueVoyant | ODEON Cinemas Group | 98% reduction in alerts requiring InfoSec or Regional IT review |
| SU003 | BlueVoyant | Snappi Neobank: Enterprise-Grade Security from Day One | 24/7 SOC coverage operational from the outset |
| SU004 | BlueVoyant | Partners | |
| SU005 | BlueVoyant | Beeks Group Selects BlueVoyant to Strengthen its 24x7 SOC | |
| SU006 | BlueVoyant | Maximizing Your Investment with Microsoft Security | Webinar | |
| SU007 | BlueVoyant | Digital Brand Protection for Financial Institutions | |
| SU008 | BlueVoyant | Financial Exchanges - External Cyber Defense for When Your Attack… | |
| SU009 | BlueVoyant | Securing State and Local Governments from Threats | |
| SU010 | BlueVoyant | Avoiding the Government Third-Party Risk Domino Effect | |
| SU011 | BlueVoyant | Total Economic Impact™ of BlueVoyant Supply Chain Defense Report | |
| SU012 | BlueVoyant | The State of Supply Chain Defense: Annual Global Insights Report 2025 | |
| SU013 | BlueVoyant | BlueVoyant and Carahsoft Partnership | |
| SU014 | BlueVoyant | ClearBank's Journey with BlueVoyant | Webinar | |
| SU015 | BlueVoyant | Protecting the Grid: The Evolving Threat Landscape and Proactive… | |
| SU016 | BlueVoyant | Defending Law Firms from Cyber Threats | |
| SU017 | BlueVoyant | Total Economic Impact™ of BlueVoyant MDR Services | |
| SU018 | BlueVoyant | Microsoft Security Excellence Award Winners | |
| SU019 | Navy SBIR/STTR Program | Success Story | In October 2021, Naval Sea Systems Command (NAVSEA) ... awarded a three-year single-award indefinite delivery contract to BlueVoyant Government Solutions |
| SU020 | PR Newswire | BlueVoyant's 202 Group Expands its Supply Chain Risk Management Solutions and Rebrands as BlueVoyant Government Solutions | |
| SU021 | FeaturedCustomers | 14 BlueVoyant Customer Reviews & References | |
| SU022 | FeaturedCustomers | 9 BlueVoyant Customer Reviews & References | |
| SU023 | PeerSpot | BlueVoyant CORE Reviews, Competitors and Pricing | |
| SU024 | Carahsoft | BlueVoyant and Carahsoft Partner to Defend Public Sector from Cyber Threats | Carahsoft | |
| SU025 | AWS Marketplace | MDR for Splunk Cloud. Please contact BlueVoyant for Private Offer. | |
| SU026 | Beeks Group | Beeks Group Collaborating With BlueVoyant | Beeks Group | |
| SU027 | Intelligence Community News | BlueVoyant and Carahsoft announce partnership - Intelligence Community News | |
| SU028 | UpGuard | BlueVoyant Security Rating, Vendor Risk Report, and Data Breaches | UpGuard | |
| SU029 | Slashdot | Compare BitSight vs. BlueVoyant in 2026 | |
| SU030 | Carahsoft | BlueVoyant Government IT Procurement Contracts | Carahsoft | |
| SU031 | BlueVoyant Government Solutions | SCRM Solutions Offered on GSA's SCRIPTS BPA via Carahsoft | |
| SU032 | Carahsoft | Technology Reseller Partner Program | Carahsoft | |
| SU033 | Intelligent CISO | BlueVoyant strengthens cyber defence for ODEON Cinemas Group across eight countries – Intelligent CISO | |
| SU034 | Veracloud | How Snappi Built Enterprise-Grade Cybersecurity from Day One with Veracloud and BlueVoyant | |
| SU035 | MaltaCEOs | Veracloud brings operational security to Greece’s first neobank | |
| SU036 | California Department of Technology | Security Operations Center as a Service (SOCaaS) | |
| SU037 | California Department of Technology | How California is Centralizing Public Sector Cybersecurity | |
| SU038 | MSSP Alert | MSSP BlueVoyant Launches SOCaaS Powered by Microsoft Azure Sentinel - | |
| SR001 | BlueVoyant | Privacy Policy & Legal Notice | BlueVoyant LLC is the controller of your personal data and may share personal information with affiliate companies unless prohibited by law. |
| SR002 | BlueVoyant | BlueVoyant & Microsoft | Streamline security with Microsoft XDR/E5 and Sentinel, delivering unified threat detection, response, and monitoring across your environment. |
| SR003 | BlueVoyant | MDR for Microsoft - Manage & Monitor | Harness the full power of Microsoft Security with our elite 24x7 SOC and security operations team backed by BlueVoyant AI. |
| SR004 | BlueVoyant | Next Era of Cyber Defense with BlueVoyant AI | BlueVoyant AI provides both with its fully managed service - supported 24/7 with BlueVoyant’s elite SOC team - or as an enterprise-grade SaaS platform. |
| SR005 | BlueVoyant | BlueVoyant Acquires Conquest Cyber | BlueVoyant raised more than $140 million in Series E funding to accompany the acquisition of Conquest Cyber. |
| SR006 | BlueVoyant | John Hernandez Joins BlueVoyant as CEO | John Hernandez will succeed Jim Rosenthal as Chief Executive Officer with a focus on scaling an AI-driven cybersecurity platform. |
| SR007 | BlueVoyant | BlueVoyant Welcomes New Chief Product Officer | Amit Jasuja will guide BlueVoyant’s strategic product direction, aiming to unify product lines and expand the company’s share of the cybersecurity market. |
| SR008 | BlueVoyant | New Security Operations Centre in Cork, Ireland | The new SOC will provide 24x7 monitoring of Irish and EU clients’ networks and digital ecosystems. |
| SR009 | BlueVoyant | Microsoft Security Excellence Award Winners | BlueVoyant also won the Security Trailblazer award. |
| SR010 | BlueVoyant | 2024 Microsoft Worldwide Security Partner of the Year | BlueVoyant announced it has won the 2024 Microsoft Worldwide Security Partner of the Year Award. |
| SR011 | BlueVoyant Government Solutions | BlueVoyant Government Solutions | Supply Chain Defense | BlueVoyant Government Solutions operationalizes mission assurance with deep supply chain risk visibility and expert-led threat remediation at scale. |
| SR012 | BlueVoyant Government Solutions | Customers | Supporting federal government agencies with end-to-end cyber supply chain risk management. |
| SR013 | PR Newswire | BlueVoyant is a proud participant in the Microsoft Sentinel partner ecosystem | BlueVoyant is working with Microsoft product teams to shape Sentinel product development. |
| SR014 | PR Newswire | BlueVoyant Recognized as the Winner of 2024 Microsoft Worldwide Security Partner of the Year | The company has additionally been named the Microsoft United States Security Partner of the Year for the third consecutive time. |
| SR015 | PR Newswire UK | BlueVoyant Expands in EU with New Cutting-Edge Security Operations Centre in Cork, Ireland | With cyber security teams grappling with the enforcement of new EU regulations such as NIS 2 and DORA, clients now require a holistic, next-generation managed security service. |
| SR016 | Microsoft Security Blog | BlueVoyant optimizes customer security with Microsoft security services | BlueVoyant speaks with a lot of companies about their security technology deployment and one of the main trends found is tech sprawl. |
| SR017 | Microsoft Security Blog | Microsoft announces the 2025 Security Excellence Awards winners | The Microsoft Security Excellence Awards honor outstanding contributions across several categories. |
| SR018 | Protiviti | BlueVoyant Partnership | Protiviti US | The platform integrates advanced AI technology with expert human insight to offer extensive protection and swift threat mitigation. |
| SR019 | Carahsoft | BlueVoyant Government IT Procurement Contracts | Carahsoft | Carahsoft lists NASA SEWP V, ITES-SW2, SCRIPTS BPA, and CMAS contract access for BlueVoyant. |
| SR020 | PacerMonitor | Steward Health Care System LLC, et al., v. Bluevoyant LLC | Complaint to (I) Avoid and Recover Avoidable Transfer(s) and (II) Disallow Claims by Steward Health Care System LLC against Bluevoyant LLC. |
| SR021 | National Institute of Standards and Technology | Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations | The security requirements are intended for use by federal agencies in contractual vehicles or other agreements established between those agencies and nonfederal organizations. |
| SR022 | U.S. Department of Defense CIO | CIO - CMMC Resources & Documentation | CMMC Phase 1 Implementation (Nov 10, 2025 - Nov 9, 2026) focuses primarily on CMMC Level 1 and Level 2 self-assessments. |
| SR023 | U.S. Department of Defense | CMMC 2.0 Details and Links to Key Resources | Beginning November 10, contracting officers will include the new CMMC requirements in new solicitations and contracts. |
| SR024 | PM Insights | BlueVoyant Valuation | PM Insights | Sample data shown with delay for preview purposes. Real-time, institutional-grade datasets available to subscribers. |
| SR025 | SourceForge | Best BlueVoyant Alternatives & Competitors | SourceForge ranks the best alternatives to BlueVoyant in 2026. |
| SR026 | PeerSpot | BlueVoyant CORE Reviews, Competitors and Pricing | Their MDR service offers 24/7 monitoring and threat hunting by a team of experts, utilizing advanced analytics and machine learning. |
| SR027 | SecuritySenses | BlueVoyant Recognised as Microsoft Security Excellence Award Winners | BlueVoyant also won the Security Trailblazer award. |
| SR028 | Yahoo Finance | BlueVoyant is a proud participant in the Microsoft Sentinel partner ecosystem | BlueVoyant is building on it with custom analytics, Copilot-ready content, and lessons tested in the field. |
| SR029 | Pavilion | BlueVoyant Government Solutions Government Contracts | Pavilion | BlueVoyant provides government-focused supply chain risk management and cybersecurity services, including CMMC + NIST 800-171 compliance management. |
| SR030 | SAM.gov | Contract Award Data in SAM.gov | The contract award search function in SAM.gov allows users to search federal procurement data and to filter by keyword, agency, and legal business name. |
| SR031 | USAspending | Government Spending Open Data | USAspending | USAspending is the official open data source of federal spending information, including information about federal awards such as contracts, grants, and loans. |
| SR032 | SecuritySenses | BlueVoyant Ignites the Next Era of Cyber Defence with Launch of BlueVoyant AI | BlueVoyant AI brings true AI-native Security Operations Centre capabilities to life. |
| SR033 | BlueVoyant | Successful Deployments of Microsoft Sentinel eBook | This eBook summarizes the guide’s 16 real world anonymized case studies based on hundreds of hands-on deployments. |
| SR034 | BlueVoyant | BlueVoyant Recognized in Gartner’s Market Guide for Third-Party Risk Management | The percentage of cyber breaches involving third parties doubled over the past year to 30% according to Verizon’s 2025 DBIR. |
| SV001 | BlueVoyant | BlueVoyant Enters 2023 with Momentous Growth | Growing annual recurring revenues at an average of 108% since 2018, with recurring revenue growing 80% in 2022. |
| SV002 | PR Newswire / BlueVoyant | BlueVoyant Acquires Conquest Cyber to Meet Market Need for Comprehensive Managed Detection and Response and Cyber Risk Posture Solutions | BlueVoyant raised more than $140 million in Series E funding to accompany the acquisition. |
| SV003 | PR Newswire / BlueVoyant | BlueVoyant Raises $250 Million Series D Led by Liberty Strategic Capital | Liberty Strategic Capital ... led the $250-million round with participation from ... ISTARI ... Eden Global Partners ... and 8VC. |
| SV004 | Caplight | BlueVoyant | Valuation, Funding Rounds & Stock Price | Caplight | Last Round Series E ... Nov 29, 2023 ... Est. Valuation $1B ... Total Funding Raised $665.5M. |
| SV005 | Notice.co | BlueVoyant Stock $1.36 | How to Buy, Valuation, Stock Price, IPO | Notice.co | The current Notice Price premium (+) or discount (-) to the last round ... -39%. |
| SV006 | Forge | Invest and Sell BlueVoyant Stock - Forge | Market activity ... Limited ... Forge Price $-- Not yet available ... Last known valuation $1B 2/23/2022. |
| SV007 | Hiive | BlueVoyant Stock | Invest or Sell | Buy and sell BlueVoyant stock. Get stock prices & access to pre-IPO shares in one place at Hiive. |
| SV008 | Tracxn | BlueVoyant - 2026 Funding Rounds & List of Investors | BlueVoyant has raised a total of $696M over 6 funding rounds. |
| SV009 | GetLatka | BlueVoyant Revenue 2025: $213.5M ARR, $1B Valuation | In 2025, BlueVoyant's revenue reached $213.5M. |
| SV010 | BlueVoyant | MDR, TPRM, Digital Risk Protection | BlueVoyant | Agentic SecOps, MDR, and TPRM to protect your entire attack surface. |
| SV011 | Eden Global Partners | BlueVoyant Raises $250 Million Series D Led by Liberty Strategic Capital | BlueVoyant Raises $250 Million Series D Led by Liberty Strategic Capital. |
| SV012 | U.S. Securities and Exchange Commission | EDGAR Search Results — BlueVoyant | Acc-no: 0000950103-20-013356 ... 2020-07-08 ... Acc-no: 0000950103-19-005109 ... 2019-04-25 ... Acc-no: 0000950103-17-007618 ... 2017-08-04. |
| SV013 | CompaniesMarketCap | CrowdStrike (CRWD) - Market capitalization | As of June 2026 CrowdStrike has a market cap of $178.47 Billion USD. |
| SV014 | CompaniesMarketCap | SentinelOne (S) - Market capitalization | As of June 2026 SentinelOne has a market cap of $5.43 Billion USD. |
| SV015 | CompaniesMarketCap | Rapid7 (RPD) - Market capitalization | As of June 2026 Rapid7 has a market cap of $0.51 Billion USD. |
| SV016 | CompaniesMarketCap | Tenable (TENB) - Market capitalization | As of June 2026 Tenable has a market cap of $3.33 Billion USD. |
| SV017 | CompaniesMarketCap | Qualys (QLYS) - Market capitalization | As of June 2026 Qualys has a market cap of $4.34 Billion USD. |
| SV018 | Windsor Drake | Cybersecurity Valuations: Q2 2026 | The public cybersecurity median is 6.0x–6.5x NTM revenue ... managed security services to 3x–5x. |
| SV019 | multiples.vc | Largest Cybersecurity Public Companies | CrowdStrike ... endpoint, cloud workload, identity, and security operations ... Rapid7 ... expanded its portfolio to provide extended detection and response, SIEM ... |
| SV020 | Tablestat | Valuation Trading Multiples & Precedent Transactions: Enterprise Cybersecurity Software Providers | Revenue growth Median 15.7% 2025E 16.0% 2026E ... 8.4x ... 6.8x. |
| SV021 | Yahoo Finance | CrowdStrike Holdings, Inc. (CRWD) Stock Price, News, Quote & History - Yahoo Finance | Enterprise Value/Revenue 34.30 ... Revenue (ttm) 5.09B. |
| SV022 | Yahoo Finance | SentinelOne, Inc. (S) Stock Price, News, Quote & History - Yahoo Finance | Enterprise Value/Revenue 4.61 ... Revenue (ttm) 1.05B. |
| SV023 | Yahoo Finance | Rapid7, Inc. (RPD) Stock Price, News, Quote & History - Yahoo Finance | Enterprise Value/Revenue 0.93 ... Revenue (ttm) 859.23M. |
| SV024 | Yahoo Finance | Tenable Holdings, Inc. (TENB) Stock Price, News, Quote & History - Yahoo Finance | Enterprise Value/Revenue 3.32 ... Revenue (ttm) 1.02B. |
| SV025 | Yahoo Finance | Qualys, Inc. (QLYS) Stock Price, News, Quote & History - Yahoo Finance | Enterprise Value/Revenue 5.73 ... Revenue (ttm) 684.86M. |
| SV026 | PM Insights | BlueVoyant Valuation | PM Insights | BlueVoyant Secondary Market ROI ... BlueVoyant Bid-Ask Volume Ratios ... BlueVoyant Mutual Fund Valuations (NAV) ... BlueVoyant Funding Rounds & Cap Table Details. |
| SV027 | CB Insights | BlueVoyant - Products, Competitors, Financials, Employees, Headquarters Locations | Stage Series E | Alive ... Total Raised $665.5M ... Last Raised $140M. |
| SV028 | Yahoo Finance | Palo Alto Networks, Inc. (PANW) Stock Price, News, Quote & History - Yahoo Finance | Enterprise Value/Revenue 23.28 ... Revenue (ttm) 10.61B. |
| SV029 | Yahoo Finance | Fortinet, Inc. (FTNT) Stock Price, News, Quote & History - Yahoo Finance | Enterprise Value/Revenue 15.20 ... Revenue (ttm) 7.11B. |
| SV030 | CompaniesMarketCap | Palo Alto Networks (PANW) - Market capitalization | As of June 2026 Palo Alto Networks has a market cap of $247.92 Billion USD. |
| SV031 | CompaniesMarketCap | Fortinet (FTNT) - Market capitalization | As of June 2026 Fortinet has a market cap of $110.88 Billion USD. |
| SV032 | SiliconANGLE | BlueVoyant acquires cyber defense company Conquest Cyber, raises $140M | Including the new funding, BlueVoyant has raised about $646 million to date, according to data from Tracxn. |