Startup Diligence
Diligence report Cybersecurity / MDR and third-party cyber risk management Series E (private unicorn) 2026-06-29

BlueVoyant

Cyber Defense Platform with MDR and TPRM Scale, but Private-Market Opacity

BlueVoyant is a credible late-stage cybersecurity platform with real MDR and TPRM scale, differentiated regulated-industry positioning, and strong Microsoft ecosystem leverage, but its private-company opacity and unresolved valuation/revenue conflicts justify a track posture rather than a conviction buy.

Cover facts

Company profile

BlueVoyant was founded in 2017 and is headquartered in New York City. Public company materials position the business as a unified cyber defense platform spanning MDR, third-party risk management, digital risk protection, and professional services, with especially deep alignment to Microsoft security tooling and a meaningful footprint in government and other regulated sectors. The company has credible commercial scale — over 1,000 customers in 45 countries, 600+ employees, and a publicly announced 2023 Series E above $140M following the 2022 $250M Series D that pushed it above the $1B unicorn threshold. However, current valuation, ARR quality, margin profile, and ownership structure remain only partially visible in public data, leaving underwriting confidence constrained.

Website
www.bluevoyant.com
Founders
Jim Rosenthal, Tom Glocer
Founding location
New York, New York, USA
Headquarters
New York, New York, USA (6 East 45th Street, Floor 17)
Product
BlueVoyant sells a cyber defense platform spanning managed detection and response, third-party risk management / supply chain defense, digital risk protection, and professional services. The current roadmap emphasizes AI-native SecOps, Microsoft-native deployment, and continuous supplier-risk remediation rather than point-in-time assessments.
Customers
Large enterprises, financial services firms, government agencies, defense-industrial-base entities, and other regulated organizations that need managed SOC coverage, Microsoft security optimization, and third-party cyber risk management across vendors and suppliers.
Business model
Recurring managed security and software revenue tied to MDR, TPRM, DRP, and consulting / response services, with cross-sell through Microsoft ecosystem work, public-sector programs, and channel partners.
Stage
Series E (private unicorn)
Funding status
Public capital history includes a $250M Series D in February 2022 led by Liberty Strategic Capital and a more-than-$140M Series E announced in November 2023 alongside the Conquest Cyber acquisition. Third-party datasets place total funding around $665.5M to $696M.
[CO001, CO002, CO003, CO004, CO005, CO020, CO021, CO023]

Executive summary

Top strengths

  • BlueVoyant spans MDR, TPRM, DRP, and services in one platform, letting it sell unified cyber defense rather than a single control point.
  • The company has credible enterprise scale, with over 1,000 customers in 45 countries, more than 600 employees, and meaningful public-sector and regulated-industry traction.
  • BlueVoyant's Microsoft specialization is a durable go-to-market advantage, reinforced by large deployment counts, verified partner status, and customer ROI studies.
  • Funding support from Liberty Strategic Capital, ISTARI, Temasek-linked capital, and other investors gives the company strategic credibility despite a difficult private-market backdrop.

Top risks

  • Public financial visibility is poor: audited ARR, growth, gross margin, burn, NRR, and cap-table terms are not disclosed, while public revenue estimates conflict sharply.
  • The last clear unicorn valuation anchor is stale, and private-market data does not provide a clean, high-confidence read on current enterprise value or liquidation preferences.
  • BlueVoyant competes in crowded MDR and cyber-risk markets against larger platforms such as Palo Alto Networks, CrowdStrike, Rapid7, Arctic Wolf, and risk specialists like BitSight and SecurityScorecard.
  • The business model still depends materially on services delivery and Microsoft ecosystem execution, which can pressure margin scalability and increase platform-dependence risk.
  • AI-led product repositioning in 2026 raises execution risk because the company must prove differentiation beyond marketing while maintaining service quality across a growing platform.

Open gaps

  • Audited ARR, revenue growth, gross margin, NRR, burn, and cash balance.
  • Fully diluted cap table, preferred terms, liquidation preferences, and any secondary-market transaction details.
  • Precise current valuation for the November 2023 Series E and whether 2026 secondary clears validate or discount the unicorn mark.
  • Revenue mix across MDR, TPRM, DRP, professional services, and government programs.
  • Customer concentration and retention by vertical, especially government and financial services.
  • Independent proof of AI product adoption, pricing, and conversion impact following the June 2026 BlueVoyant AI launch.

Contents

Chapter 01

01Company Overview

1.1 Identity, Headquarters, and Business Model

BlueVoyant presents itself as a cyber-defense platform company founded in 2017 and headquartered in New York. Its official company and contact pages anchor the present footprint in Manhattan while also showing a wider multinational operating base. The company says it has over 600 employees and more than 1,000 customers across 45 countries, which places it beyond startup incubation stage and into scaled private-company territory even before considering third-party estimates. Product-wise, BlueVoyant does not describe itself as a single-point tool vendor. Its platform combines managed detection and response, third-party risk management, digital risk protection, and professional services, with revenue implied to come from both recurring software modules and analyst-led managed operations. The reviewed materials consistently position BlueVoyant around enterprise, government, and critical-infrastructure use cases rather than a narrow SME or consumer motion. That mix matters for later diligence because it suggests longer sales cycles, service-heavy onboarding, and differentiated exposure to regulated or mission-critical buyers.[CO001, CO002, CO003, CO004, CO005, CO006]

Snapshot KPI table
MetricValue / statusDateConfidenceGap / note
Founded20172017HighCorroborated by official and independent sources
Headquarters6 East 45th Street, Floor 17, New York, NY 100172026-06-29HighOfficial leadership/contact pages
Official employee disclosure600+ employees2026-06-29MediumCompany-claimed; third-party estimates are higher
Customer disclosure1,000+ customers in 45 countries2026-06-29MediumCompany-claimed on contact page
Core platformMDR + TPRM + DRP + professional services2026-06-29HighOfficial suite pages
Last publicly identified financing> $140M Series E with Conquest Cyber acquisition2023-11-29HighPublic record reviewed does not show a later named round
Third-party total funding estimate~$665.5M2025-11-28MediumPrivate-market database estimate, not audited
Third-party valuation estimate~$1B2025-11-28MediumNo official current valuation disclosed
Current CEOJohn Hernandez2026-05-05HighSucceeded co-founder Jim Rosenthal
Recent product launchBlueVoyant AI2026-06-09HighAI-native / agentic SecOps positioning
Microsoft recognition2024 Worldwide + U.S. + Canada Security Partner of the Year honors2024HighHistorical award signal, not a current financial metric

Funding, valuation, and external headcount figures mix official disclosure with private-market or monitoring estimates; treat non-official numeric rows as directional rather than audited.

[CO001, CO002, CO003, CO004, CO005, CO016]
FO002: Company snapshot logic

BlueVoyant links a founder-shaped governance layer to an integrated cyber platform, Microsoft ecosystem leverage, a global customer footprint, and a private-capital base with still-private economics.

[CO005, CO017, CO028, CO032, CO035, CO043]
FO003: Snapshot KPIs

The clearest public signals point to a scaled private cybersecurity platform with strong ecosystem recognition but still-private economics.

Funding and valuation are third-party private-market estimates; customer and employee figures use the company’s own minimum disclosed thresholds rather than a precise audited count.

[CO003, CO004, CO015, CO028]

1.2 Leadership, Governance, and Key-Person Risk

BlueVoyant’s current public leadership picture is shaped by a recent transition. John Hernandez is now CEO, while co-founder Jim Rosenthal moved into the chairman role and co-founder Thomas Glocer remains vice chairman. The current operating bench is broad enough to cover finance, product, technology, information security, HR, government solutions, regional sales, and partnerships, which reduces dependence on any single functional lieutenant. Even so, founder influence is still material because Rosenthal and Glocer remain central governance figures and the public company narrative still leans heavily on founder identity. That mix suggests a meaningful but manageable key-person risk: BlueVoyant has completed a top-of-house handoff, but its public credibility, investor continuity, and strategic storytelling still run through the founders. A prior public COO appointment for Michael Montoya also shows that BlueVoyant has been willing to refresh the operating layer below the board during its scale-up period.[CO009, CO010, CO011, CO012, CO013, CO014]

Leadership and founder table
PersonRoleBackground / public contextFunctional coverage / founder-market fitKey-person dependency
John HernandezChief Executive OfficerNamed CEO in May 2026 to scale an AI-driven cybersecurity platform globallyCurrent operating leader and transition point after founder-led phaseMedium
James RosenthalCo-founder; Chairman of the BoardCo-founder and former CEO; remains governance anchor after CEO handoffHigh founder-market fit across strategy, investor continuity, and board influenceHigh
Thomas GlocerCo-founder; Vice Chairman of the BoardCo-founder and former Thomson Reuters chief executiveAdds enterprise operating and board credibility beyond pure cyber pedigreeMedium
Ravi SubramanianChief Financial OfficerPublicly listed finance leader on current leadership pageCovers planning, finance, and investor-readiness functionsMedium
Sebastian SobolevChief Product OfficerCurrent product leader on leadership pageOwns roadmap and packaging of platform / AI evolutionMedium-High
Jim BiedaGlobal Chief Technology OfficerCurrent technology leader on leadership pageCovers technical architecture and platform credibilityMedium-High
John HarbaughChief Information Security OfficerCurrent security leader on leadership pageSupports trust, security posture, and enterprise credibilityMedium
Lonny AndersonPresident, BlueVoyant Government SolutionsPublic leader for government-focused business lineImportant for public-sector and regulated-environment GTMMedium

Table reflects only leaders publicly surfaced on BlueVoyant pages and corroborating CEO-transition coverage; private-company committee structure and full board roster remain incomplete.

[CO009, CO010, CO011, CO012, CO013, CO042]

1.3 Funding History, Investors, and Ownership Visibility

BlueVoyant’s publicly visible capital story has two major inflection points. First, the company closed a $250 million Series D in February 2022 led by Liberty Strategic Capital, with participation from ISTARI, Eden Global Partners, and 8VC. Second, in November 2023 it paired the Conquest Cyber acquisition with more than $140 million in Series E funding led by existing investors Liberty Strategic Capital and ISTARI. Third-party market-data platforms now cluster around roughly $665.5 million of total capital raised and an estimated $1 billion valuation, but those figures are database estimates rather than company-certified financial disclosure. The evidence therefore supports a strong capital base and credible institutional sponsorship, yet not an exact present-day mark. Public materials are also thin on board committees, protective provisions, debt, secondaries, and cap-table concentration, so investor map rows below should be treated as a diligence scaffold rather than a fully verified control chart.[CO020, CO021, CO023, CO026, CO027, CO028]

Stakeholder or investor map
StakeholderRoleControl / economic importancePublic supportDiligence ask
Liberty Strategic CapitalLead investor in 2022 Series D; co-led 2023 Series EAnchor institutional sponsor; official sources tie the fund to both major recent financings$125M investment disclosed by Liberty in 2022; present again in 2023 fundingConfirm board seat, protective provisions, and any step-up rights
ISTARI (Temasek-founded cyber investor / advisor)Series D participant; Series E co-leadStrategic cyber investor with likely information-rights relevanceNamed in 2022 and 2023 company-linked financing coverageConfirm ownership stake, board observer rights, and strategic-commercial links
Eden Global Partners / Eden Global Capital PartnersSeries D participant and strategic advisor; affiliate advised on 2023 transactionGrowth-equity and placement support rather than clearly disclosed controlNamed in 2022 official release and 2023 transaction coverageClarify whether advisory role carries any continuing governance rights
8VCSeries D participantSignals venture participation in the 2022 scale-up roundNamed in official 2022 financing coverageConfirm follow-on participation and present ownership percentage
James RosenthalCo-founder; chairmanLikely meaningful insider ownership plus governance continuity after CEO handoffPublic materials show continuing board role but not share countRequest current cap table and voting-control summary
Thomas GlocerCo-founder; vice chairmanBoard-level strategic influence and reputational capitalPublicly identified as co-founder and vice chairmanConfirm equity stake and any reserved consent rights
Conquest Cyber assets / teamAcquired strategic platform extensionImportant for regulated, government, and DIB product expansion rather than pure ownership controlAcquisition announced with Series E in Nov. 2023Review integration milestones, earnouts, and customer-retention assumptions

Public sources identify round leaders and strategic roles but do not disclose ownership percentages, liquidation stack, debt, or observer rights; rows therefore emphasize diligence asks over inferred control.

[CO020, CO023, CO025, CO026, CO028, CO042]

1.4 Platform Evolution, Ecosystem, and Commercial Positioning

BlueVoyant’s positioning is not just about detecting threats; it is about wrapping multiple cyber workflows into a managed platform narrative. Its Microsoft page and awards history show unusually strong ecosystem alignment, including repeated security-partner recognition and service packaging around Sentinel, Defender, Purview, and Copilot-era security operations. The partner program also indicates a channel-led route to market rather than purely direct sales. On the product side, the company has expanded its story from managed cyber defense into a broader AI-native or agentic SecOps message, capped by the June 2026 BlueVoyant AI launch. The November 2023 Conquest Cyber acquisition sits in the middle of that evolution by adding SaaS-heavy capabilities for regulated and government-sensitive environments. The Auto-ISAC partnership then extends the third-party-risk narrative into a named vertical. Together, these moves imply a company trying to deepen wallet share inside complex accounts rather than merely add logos.[CO015, CO016, CO017, CO018, CO019, CO023]

1.5 Milestones, Scale Signals, and Adverse Considerations

The public milestone pattern shows BlueVoyant moving from a 2017 founding story to a capital-intensive scaling phase, then into platform broadening and management transition. By 2026, the company is describing itself as global, Microsoft-aligned, and AI-forward, with more than 1,000 customers and more than 600 employees according to official pages. At the same time, diligence should resist over-precision. Third-party headcount signals range meaningfully above the official disclosure, while valuation and revenue numbers mostly come from private-market databases rather than audited reporting. The strongest public adverse signal in the retained source set is UpGuard’s June 2026 external risk report, which flags specific website-security hardening issues such as CSP weaknesses and unsafe-eval usage. That is not a thesis-breaking event, but it is notable because BlueVoyant sells security outcomes. Combined with sparse public governance and financial disclosure, it argues for a diligence posture that separates clear operating momentum from still-private economic quality.[CO021, CO028, CO029, CO030, CO031, CO032]

Milestone table
DateEventTypeAmount / valuation / statusParticipantsImplication
2017BlueVoyant founded in New YorkfoundingCompany launchFounders including James Rosenthal and Thomas GlocerEstablishes the company as a post-2016 cyber-defense entrant with founder-led governance roots
2022-02-23Series D closesfinancing$250MLiberty Strategic Capital, ISTARI, Eden Global Partners, 8VC, othersMajor scale-up round for technical capability and global expansion
2022-02BlueVoyant publicly described as a cybersecurity unicornscale> $1B valuation; $525M total raised to dateSecurityWeek / TechCrunch public coverageExternal market validation of the 2022 financing inflection point
2023-11-29Conquest Cyber acquisition announced with Series E financingproduct> $140M Series EBlueVoyant, Conquest Cyber, Liberty Strategic Capital, ISTARIBroadens platform depth and adds regulated-environment SaaS capability
2023-11-29Acquisition positioned for highly regulated and government environmentsregulatoryStrategic expansionBlueVoyant, Conquest CyberShows deliberate move toward defense-industrial-base and regulated buyer relevance
2024Microsoft security partner awards highlighted on awards pagepartnershipWorldwide + U.S. + Canada honorsBlueVoyant, MicrosoftStrengthens ecosystem credibility and channel positioning
2025-09-24Auto-ISAC strategic engagement announcedpartnershipTPRM collaborationBlueVoyant, Auto-ISACAdds named automotive vertical wedge for supply-chain cyber products
2026-05-05John Hernandez succeeds Jim Rosenthal as CEOgovernanceLeadership transitionJohn Hernandez, Jim Rosenthal, BlueVoyant boardMarks shift from founder-led operations to hired-CEO scaling phase
2026-06-09BlueVoyant AI launchedproductAI-native / agentic SecOps platformBlueVoyantRepositions company around AI-led SOC workflows
2026-06-29UpGuard vendor risk report flags website-security hardening issuesadverseCSP / unsafe-eval findingsUpGuardCreates the clearest adverse public signal in the retained source set

Timeline blends official company announcements with high-signal third-party corroboration; later financing and governance details remain incomplete because BlueVoyant is private.

[CO001, CO016, CO020, CO021, CO023, CO025]
FO001: Company milestone timeline

The public record shows BlueVoyant moving from 2017 founding to 2022 financing scale-up, 2023 platform broadening, and 2026 management plus AI-product repositioning.

[CO016, CO020, CO021, CO023, CO032, CO036]

1.6 Exhibits

Chapter 02

02Market Analysis

2.1 Market Boundary and Adjacent Spend

BlueVoyant should be framed as operating in the overlap between managed detection and response and cyber-focused third-party risk management, not as a generic cybersecurity vendor and not as a broad GRC suite. The MDR pages emphasize augmentation of existing EDR, SIEM, cloud, and Microsoft security stacks with 24x7 monitoring, incident response, and automation. The TPRM pages emphasize continuous monitoring, analyst-directed remediation, questionnaire workflows, zero-day alerting, and fourth-party mapping. That boundary matters because it defines what spend belongs in the core opportunity. Included spend is the part of security operations and vendor-risk budgets that buys continuous detection, validation, remediation, and external dependency visibility. Adjacent spend sits in GRC, board reporting, and broader resilience workflows, while the main substitutes remain in-house SOC buildouts, periodic questionnaires, spreadsheet-led vendor reviews, and point products that only solve one layer of the problem.[CM001, CM002, CM003, CM004, CM005, CM006]

Market definition table
Segment / categoryIncluded spendExcluded spendBuyer / payerRelevance
MDR overlay / managed SecOps24x7 monitoring, threat triage, incident response, tuning of existing EDR, SIEM, cloud, and Microsoft security toolsStandalone endpoint licenses, firewalls, or generic network hardwareCISO, SOC leader, security operations budgetCore BlueVoyant MDR boundary
Cyber-focused TPRMContinuous monitoring, vendor cyber findings, analyst-led remediation, questionnaire workflows, zero-day alertingGeneric vendor master data and non-cyber procurement administrationCISO, third-party risk leader, compliance, procurementCore BlueVoyant TPRM boundary
Fourth-party and concentration analyticsDependency mapping, nth-party visibility, what-if analysis, concentration exposure managementPure one-time assessments with no dependency mappingEnterprise risk, resilience, security, procurementImportant expansion wedge inside supply-chain cyber risk
AI-assisted cyber triageAttack-surface monitoring, threat intelligence enrichment, vulnerability prioritization, automated triage supportGeneral-purpose AI tooling without security workflow integrationSecurity operations and cyber defense teamsSupports MDR and digital-risk adjacencies
GRC / board reporting adjacencyControls reporting, governance workflows, board-ready cyber risk summaries, policy evidence managementBroad legal, audit, HR, and non-cyber governance suitesCompliance, audit, board, enterprise riskAdjacent spend that should not be counted as pure BlueVoyant core TAM
Status quo and substitute motionIn-house SOCs, spreadsheet-led vendor reviews, annual questionnaires, narrow point tools, manual remediation emailsN/AExisting process ownersExplains why conversion is gradual and multi-step

Boundary is the overlap of managed SecOps and cyber-focused vendor-risk monitoring. Generic GRC and stand-alone security controls are adjacent, not direct core TAM.

[CM001, CM002, CM003, CM004, CM005, CM006]

2.2 Sizing Lens — TAM, SAM, and Contradictory Published Estimates

BlueVoyant's market can be sized, but only with layered logic rather than a single headline TAM. MDR estimates span from $3.92B in 2026 according to Precedence Research to $5.09B according to Mordor, with The Business Research Company at $4.16B. TPRM is even more definition-sensitive: TBRC gives a direct 2026 value of $8.09B, while NextMSC's 2025 baseline and Grand View Research's 2023 baseline imply normalized 2026 values near $11B. Those contradictions are not noise; they reflect differing treatment of software versus services, compliance workflows versus cyber monitoring, and adjacent GRC scope. For BlueVoyant, a reasonable gross 2026 core-market ceiling is roughly $12–16B when MDR and TPRM published baselines are combined before overlap. A more practical SAM narrows to about $5–8B after applying large-enterprise, regulated-buyer, and western-market filters. Public data does not support a precise dollar SOM because BlueVoyant does not disclose segment revenue or win-rate by module, so SOM should be treated as evidence-constrained rather than invented.[CM009, CM010, CM011, CM012, CM013, CM014]

TAM / SAM / SOM or sizing lens table
LensPublisherYear / periodGeographyValueCAGR / shareMethodologyConfidenceLimitation
MDR published baselinePrecedence Research2026 to 2035GlobalUSD 3.92B in 2026 -> USD 13.90B by 203515.12%Category forecast for MDR marketmediumLong horizon and publisher-specific category definition
MDR alternate published baselineMordor Intelligence2026 to 2031GlobalUSD 5.09B in 2026 -> USD 13.45B by 203121.45%Current-category market sizing with segment sharesmediumBroader service scope than some peers
MDR third published baselineThe Business Research Company2026 to 2030GlobalUSD 4.16B in 2026 -> USD 8.57B by 203019.8%Headline MDR market forecastmediumDifferent time window and scope from Precedence and Mordor
TPRM direct 2026 baselineThe Business Research Company2026 to 2030GlobalUSD 8.09B in 2026 -> USD 15.45B by 203017.6%Headline TPRM market forecastmediumMay include solution and service layers beyond BlueVoyant's cyber-specific wedge
TPRM 2026 proxy from 2025 baseNextMSC2025 to 2030GlobalUSD 9.71B in 2025; ~USD 11.02B normalized to 2026; USD 18.28B by 203013.48%2025 base projected forward one year for 2026 comparabilitylow2026 figure is transformed from a 2025 baseline
TPRM 2026 proxy from 2023 baseGrand View Research2023 to 2030GlobalUSD 7.42B in 2023; ~USD 11.49B normalized to 2026; USD 20.59B by 203015.7%2023 base compounded forward for 2026 comparabilitylow2026 figure is transformed from a 2023 baseline
Adjacent GRC contextMordor Intelligence2026 to 2031GlobalUSD 23.32B in 2026 -> USD 39.01B by 203110.84%Broader governance, risk, and compliance software marketmediumUseful adjacency, but too broad to count as direct BlueVoyant core TAM
BlueVoyant gross 2026 core ceilingAnalyst synthesis from MDR + TPRM baselines2026 proxyGlobalRoughly USD 12.0B to USD 16.6Bn/aLow and high ends sum published MDR and normalized TPRM baselines before overlaplowDouble-counts some overlapping budgets and excludes pricing/module mix detail
BlueVoyant practical SAMAnalyst synthesis from category filters2026 proxyRegulated large enterprise; North America / Europe weightedRoughly USD 5B to USD 8Bn/aApplies large-enterprise, regulated-buyer, and western-market filters to the core ceilinglowNeeds management data on region, segment, and module mix to validate
BlueVoyant public SOMPublic-data lens2026BlueVoyant target accountsNot supportable from public datan/aNo public segment revenue or module share disclosurelowRequires management disclosure on revenue mix, win rates, and customer concentration

Contradictory analyst estimates are preserved intentionally. TPRM 2026 proxy rows transform older baselines to a common 2026 view; SAM and SOM rows are analyst-derived lenses, not disclosed company numbers.

[CM009, CM010, CM011, CM012, CM013, CM014]
FM001: Layered market sizing lens for BlueVoyant

Three-layer view from adjacent governance context to BlueVoyant's narrower practical SAM.

The top layer uses Mordor's 2026 GRC estimate. The middle layer is the midpoint of published MDR and normalized TPRM baselines before overlap. The bottom layer is a low-confidence SAM midpoint after large-enterprise, regulated-buyer, and western-market filters; it is not a disclosed company number.

[CM017, CM018, CM019]
FM002: Published market estimate range — contradictory 2026 baselines

Low/high ranges in USD billions showing how much published 2026 market baselines diverge before company-specific filtering.

MDR low/high come directly from Precedence and Mordor 2026 baselines. TPRM high converts Grand View's 2023 base to a 2026 proxy using its stated CAGR, while TPRM low uses TBRC's direct 2026 value. The core-ceiling row sums published category ranges before overlap; SAM is a filtered estimate, not a reported company figure.

[CM012, CM016, CM018, CM019]

2.3 Buyer, Budget Owner, and Adoption Path

The buyer map is cross-functional. On the MDR side, the economic buyer is usually the CISO or security leader who already owns SIEM, EDR, and Microsoft security budgets but needs better response coverage, better tuning, or more 24x7 capacity. On the TPRM side, the day-to-day operator is often a vendor-risk or compliance team, but payer authority can sit with security, procurement, enterprise risk, or a regulated business-line owner depending on where supplier exposure is measured. The adoption trigger is usually not abstract 'cyber maturity.' It is a recent incident, a regulatory deadline, repeated questionnaire fatigue, a zero-day exposure across vendors, or an internal realization that fourth-party risk is largely invisible. BlueVoyant's official surfaces suggest an adoption path that starts with MDR overlay or TPRM monitoring inside an existing workflow, then expands into remediation, fourth-party analytics, and broader resilience reporting once leadership decides manual processes are too slow.[CM021, CM022, CM023, CM024, CM025, CM026]

Segment / buyer map
SegmentBuyerUserPayerWorkflowBudget ownerAdoption trigger
Large-enterprise SOC modernizationCISO or VP SecuritySOC analysts, detection engineers, IR teamsSecurity operations budgetOverlay existing EDR/SIEM/Microsoft stack with 24x7 monitoring and responseCISO with CIO/CFO visibilityAlert fatigue, tool sprawl, staffing shortage, recent incident
Public-company third-party cyber programCISO, third-party risk lead, audit sponsorVendor-risk analysts, compliance teams, remediation coordinatorsSecurity or GRC budgetCollect evidence, monitor vendors continuously, escalate material findings, support board reportingCISO / CRO / chief compliance officerSEC governance pressure, recurring questionnaire burden, supplier incident
EU or regulated financial-resilience programOperational resilience or security leaderRisk teams, resilience office, procurement, security operationsRisk, compliance, or regulated business-line budgetMap critical suppliers, validate cyber posture, support resilience testing and remediationCRO, CISO, regulated-entity executiveNIS2-style deadlines, critical-vendor dependency mapping
Microsoft-heavy security environmentSecurity platform owner or CISOSentinel, Defender, M365, and cloud-security administratorsExisting Microsoft and security platform budgetTune alerts, expand automation, add managed coverage without stack replacementCISO / platform ownerUnder-used Microsoft security spend, need for faster response, limited internal tuning capacity
Procurement and vendor-onboarding programProcurement or vendor-management leader with security co-sponsorshipVendor-onboarding analysts, business owners, risk reviewersProcurement / operations budget with security inputQuestionnaire management, vendor tiering, remediation follow-up, exception trackingProcurement head with security sign-offSupplier onboarding backlog, contract clause enforcement, zero-day exposure across vendors

Rows blend MDR and TPRM buying centers because BlueVoyant sells across both motions. Budget ownership is inferred from product fit plus survey evidence, not disclosed BlueVoyant pipeline data.

[CM021, CM022, CM023, CM024, CM027, CM029]
FM003: Buyer / segment map — decision authority and budget flow

Qualitative map of how authority, budget, and trigger logic change by buyer archetype across BlueVoyant's MDR and TPRM motions.

Cells are qualitative and synthesized from BlueVoyant's product surfaces plus survey evidence on who feels the pain and who controls the budget. This is a decision-map exhibit, not a company-disclosed segmentation table.

[CM024, CM025, CM026, CM029, CM030]
FM004: Adoption path from incident pain to cross-category expansion

Typical path from an initial cyber pain point to wider BlueVoyant adoption across MDR and TPRM workflows.

This flow is qualitative. It synthesizes survey evidence on trigger events and BlueVoyant's module structure; it is not a disclosed funnel conversion chart.

[CM027, CM029, CM037, CM047, CM048, CM049]

2.4 Growth Drivers, Regulation, and Category Expansion

The strongest demand drivers in 2026 are regulation, demonstrated third-party incident pain, and the rising cost of operating fragmented security programs without enough skilled people. SEC disclosure rules put cyber governance and incident materiality into board processes for U.S. public companies. NIS2 broadens EU cyber obligations across 18 critical sectors. CISA and NIST frame supply-chain cyber risk as a formal resilience problem spanning hardware, software, and managed services. That policy stack meets real operating pain: Marsh reports that 70% of organizations experienced a material third-party cyber incident in the past year and that 66% plan to increase cyber investment, while Panorays shows that most CISOs still lack full supply-chain visibility and formal breach-response playbooks. BlueVoyant's positioning aligns with those pressures because it combines monitoring, validation, remediation, and AI-assisted triage across both internal defense and external vendor exposure.[CM025, CM026, CM027, CM028, CM031, CM032]

Growth drivers and constraints table
Driver / constraintDirectionTimingImplication for BlueVoyantDiligence ask
SEC cyber disclosure governanceDriverCurrentExpands buyer set from SOC teams to audit, legal, and board stakeholders who need evidence-backed cyber workflowsAsk management which share of pipeline is tied to public-company governance requirements
NIS2 and broader EU cyber obligationsDriverCurrent through 2026 enforcement cyclesMakes supplier cyber posture and resilience reporting more urgent for covered sectorsQuantify BlueVoyant's exposure to NIS2-covered industries and EU-headquartered accounts
CISA / NIST supply-chain formalizationDriverStructuralValidates cyber supply-chain risk as a resilience discipline spanning hardware, software, and managed servicesTest whether BlueVoyant wins when buyers frame SCRM as resilience rather than procurement compliance
Third-party incident frequencyDriverImmediateReal incidents create emergency budgets for continuous monitoring, remediation, and dependency mappingAsk for case studies where supplier incidents accelerated purchase timing
Fourth-party blind spots and concentration riskDriverImmediate and expandingStrengthens demand for dependency mapping and what-if analysis beyond direct vendorsVerify how often fourth-party analytics expands existing TPRM deals
AI-assisted triage and Microsoft optimizationDriverNear-termSupports MDR upsell into Microsoft-heavy environments and lowers cost-to-serve narrativeRequest independent proof of alert-volume reduction and remediation-time improvement
Tool sprawl and weak integrationConstraintPersistentDisconnected buyer workflows slow cross-sell and standardization across MDR and TPRM modulesRequest win/loss data on deals blocked by platform overlap or internal integration issues
MDR label confusion and crowded evaluationsConstraintCurrentBuyer confusion raises proof burden and favors vendors with clearer category ownership or bundling powerAsk how BlueVoyant differentiates against managed EDR and larger XDR platforms
Insurance softening and budget scrutinyConstraintCurrentFalling insurance pricing can reduce one urgency lever even while claims severity stays highTest whether pipeline quality changes when cyber-insurance pricing softens
No public SOM disclosureConstraintCurrentMakes market-share underwriting imprecise and limits valuation confidence from public evidence aloneRequest module-level revenue mix, ACV bands, and renewal/cross-sell metrics

Timing and strategic implications are synthesized from regulation, market surveys, and BlueVoyant product positioning. Constraint rows are as important as driver rows for valuation relevance.

[CM027, CM031, CM032, CM033, CM034, CM035]

2.5 Constraints, Adverse Signals, and Valuation Relevance

The market case is good, but it is not frictionless. KPMG shows that most programs are still only partly integrated with enterprise risk and that end-to-end managed-service adoption remains low, which means buyers often approach TPRM and MDR through disconnected tools, partial pilots, or narrow use cases. CyberProof warns that some providers misuse the MDR label by offering managed EDR or tool-centric monitoring without full human response leadership, which creates buyer confusion and slows category conversion. PeerSpot's crowded MDR category and CRC's evidence of softer cyber-insurance pricing both reinforce the idea that budget urgency can ebb even when claims severity keeps rising. For valuation, the right takeaway is that BlueVoyant participates in markets large enough and painful enough to matter, but multiple compression remains sensitive to how effectively the company can turn its cross-category story into measurable module penetration, lower buyer confusion, and a publicly supportable SOM.[CM036, CM039, CM040, CM041, CM042, CM043]

2.6 Exhibits

Chapter 03

03Competitors

3.1 Competitive Landscape and Buyer Alternatives

BlueVoyant does not sit in a single clean market box. Gartner's 2026 MDR market definition treats managed detection and response as a turnkey, provider-operated SOC capability with active containment rather than alerting-only monitoring, while BlueVoyant's own homepage markets four adjacent offers at once: MDR, third-party risk management, digital risk protection, and professional services. That creates a broader competitive field than a normal MDR shortlist. On one side, BlueVoyant faces direct MDR rivals such as CrowdStrike, Palo Alto Networks, Arctic Wolf, Rapid7, ReliaQuest, and eSentire. On the other, it faces TPRM and cyber-ratings platforms such as SecurityScorecard and BitSight, plus workflow-oriented alternatives such as OneTrust- or ProcessUnity-style vendor-risk programs and the internal-SOC status quo. The practical implication is that BlueVoyant can win when the buyer wants one partner across SOC operations and supplier cyber defense, but it can be displaced when the budget owner narrows the problem to either platform-native MDR or procurement-centered vendor-risk automation.[CP001, CP002, CP005, CP027, CP029, CP033]

Competitor Profile Table
CompetitorCategoryScale / Funding SignalBuyer Sweet SpotKey DifferentiationPrimary Limitation vs. BlueVoyant
BlueVoyantHybrid MDR + TPRM / C-SCRM600+ employees; 1,200+ Sentinel deployments; private funding not refreshed in retained 2026 sourcesMicrosoft-heavy enterprise, regulated buyers, government supply chainsCombines MDR, TPRM, DRP, and services with strong Microsoft delivery depthLower MDR visibility than the biggest platform-native rivals; public funding/pricing detail is thin
Palo Alto Networks Unit 42 / Cortex XSIAMPlatform-native MDR / SOC16K+ employees; 70K+ customers globallyLarge enterprise standardized on Palo AltoUnified AI SOC platform plus Unit 42 services and deep first-party telemetryBest economics and outcomes are tied to the Palo Alto stack; limited TPRM overlap
CrowdStrike Falcon CompletePlatform-native MDRPublic-company scale; 2.7M detections remediated monthly; 1-minute median time-to-containEnterprise and security-mature mid-market willing to standardize on FalconNative endpoint, identity, cloud, and SIEM telemetry with autonomous and human responseHigher platform lock-in and less open-stack flexibility than BlueVoyant or ReliaQuest
Arctic WolfOpen-XDR MDR10K+ customers; 1,000+ security engineers; $60M Series D and ~$4.3B valuation reported historicallyMid-enterprise to enterprise buyers wanting co-managed outcomesConcierge delivery, open XDR, warranty, and security-journey modelTPRM and supply-chain cyber defense are not core buying motions
Rapid7Platform-led managed operations11,500+ customers worldwide; public-company scaleLarge SMB, mid-market, and enterprise buyers wanting unified exposure plus detectionCommand Platform connects exposure management, telemetry, and managed operationsLess differentiated service identity than BlueVoyant; TPRM overlap is limited
ReliaQuestOpen-platform enterprise SecOps50K+ alerts processed daily; 255+ technology partners; customer count not disclosed on retained pagesFortune 1000 and heterogeneous-tool enterprisesAny-source normalization, agentic AI teammates, and broad integration depthPublic scale and pricing disclosure are limited; no TPRM-specific data-network moat
eSentireVendor-independent MDR2,000+ customers across 35+ industries; 300+ integrationsRegulated mid-market, private-equity portfolios, and upper-mid-enterprise teamsHuman-led containment plus multi-signal XDR and unlimited hunting/incident handling messagingBrand scale is below the largest public suites and TPRM is not core
SecurityScorecardThreat-informed TPRM / supply-chain detection3,300+ customer organizations; 12M+ monitored and rated organizationsVendor-risk, cyber insurance, procurement, and board-reporting programsContinuous ratings plus AI assessment automation, nth-party visibility, and remediation workflowsManaged SOC depth is lighter than BlueVoyant MDR; outside-in methods do not replace internal telemetry
BitSightCyber risk intelligence / TPRM3,500+ customers; 68K+ active organizations; 75K+ mapped vendor profilesRatings-centric enterprise risk and supply-chain programsLarge mapped supply-chain dataset, independently validated ratings claims, and strong analyst recognitionMDR is not core and customers may still need separate workflow or service layers
Internal SOC / workflow-only programStatus quo / substituteBuyer-funded people, tools, or GRC-suite budgetVery large enterprises or compliance-led procurement teamsMaximum control or lowest incremental spend if a workflow suite already existsHighest staffing burden or weaker threat-response outcomes than full MDR

Scale signals mix employees, deployments, customer counts, vendor profiles, and historical private-market funding markers; they are directional rather than like-for-like revenue measures.

[CP002, CP005, CP011, CP012, CP014, CP017]
FP001: Competitive Positioning Map

Evidence-backed ordinal view of competitor openness and budget breadth; higher y-values indicate broader overlap across SOC, procurement, insurance, or supply-chain workflows.

Axes are ordinal scores derived from retained product pages and market guides rather than audited market-share data. X = stack openness/tool neutrality from 1 (closed suite) to 5 (open ecosystem). Y = budget breadth from 1 (SOC-only) to 5 (SOC plus supply-chain/procurement/insurance relevance).

[CP001, CP002, CP014, CP021, CP027, CP032]

3.2 MDR Head-to-Head: Platform Suites vs Open-Stack Providers

The MDR field around BlueVoyant splits into two economically different competitor classes. Palo Alto Networks and CrowdStrike sell managed response as an extension of broader proprietary platforms; their pitch is automation depth, native telemetry, and bundle economics. Palo Alto layers Unit 42 services on top of Cortex XSIAM's unified SIEM, SOAR, EDR, NDR, and CDR stack, while CrowdStrike's Falcon Complete emphasizes one-minute median time-to-contain, millions of monthly remediations, and deep endpoint, identity, cloud, and third-party telemetry from the Falcon ecosystem. Arctic Wolf, ReliaQuest, Rapid7, and eSentire attack from the opposite direction: they position themselves as more open, service-intensive partners that work across an existing tool estate. Arctic Wolf leads with concierge delivery and open XDR; ReliaQuest with any-source normalization and broad integrations; Rapid7 with integrated exposure plus detection; and eSentire with vendor-independent XDR and human-led containment. BlueVoyant belongs closer to this second camp operationally, but with a stronger Microsoft-specific services identity than most of those rivals.[CP003, CP004, CP009, CP010, CP011, CP012]

Feature / Capability Matrix
Buying CriterionBlueVoyantPalo AltoCrowdStrikeArctic WolfRapid7ReliaQuesteSentireSecurityScorecardBitSight
Hands-on managed response authorityHighHighHighHighMediumHighHighLowLow
Proprietary platform lock-in pressureMediumHighHighLowMediumLowLowLowLow
Microsoft ecosystem depthHighMediumMediumMediumMediumMediumMediumLowLow
EDR / SIEM opennessMediumLowLowHighMediumHighHighLowLow
Third-party / supply-chain cyber monitoringHighLowLowLowLowLowLowHighHigh
Board / procurement / insurance reporting utilityMediumMediumMediumMediumMediumMediumMediumHighHigh
Publicly signaled AI / agentic roadmapHighHighHighHighHighHighHighHighHigh
Best fit for mixed-tool enterprisesMediumLowLowHighMediumHighHighLowLow

High/Medium/Low values are author assessments derived from retained public product pages and independent buyer guides; they indicate publicly stated capability and operating model, not audited benchmark performance.

[CP003, CP009, CP012, CP014, CP016, CP020]
FP002: Feature Breadth / Capability Map

Condensed capability map showing where BlueVoyant overlaps with MDR suite vendors versus TPRM platforms.

High/Medium/Low values are author assessments from retained public documentation and buyer-guide sources; they show the public capability narrative, not audited feature parity.

[CP003, CP006, CP013, CP023, CP025, CP028]

3.3 Supply-Chain and TPRM Competition

BlueVoyant's supply-chain defense introduces a separate buyer alternative set from its MDR competitors. SecurityScorecard and BitSight are the clearest overlaps because both frame cyber risk as a continuous, outside-in view of vendor exposure, then connect that data to board reporting, procurement oversight, insurance workflows, and remediation programs. SecurityScorecard goes further in presenting itself as supply-chain detection and response with questionnaire automation, nth-party visibility, and AI-assisted remediation. BitSight pairs a large mapped vendor network with Forrester-recognized ratings credibility and a cyber-risk intelligence dataset measured in tens of millions of monitored companies. Independent market guides also point out that many buyers do not stop at ratings tools; they pair them with workflow-centric platforms such as ProcessUnity, OneTrust, Venminder, or internal questionnaire programs. That matters for BlueVoyant because its outside-in C-SCRM proposition competes not only with rival data networks, but also with workflow software that can make standalone intelligence layers look interchangeable unless BlueVoyant proves faster remediation and stronger analyst involvement.[CP006, CP007, CP021, CP022, CP023, CP024]

3.4 BlueVoyant Differentiation, Packaging, and Likely Win Zones

BlueVoyant's most distinctive public story is the combination of Microsoft-heavy MDR, outside-in supplier defense, and adjacent digital-risk services rather than a claim to be the single best endpoint or ratings vendor. Its retained pages emphasize 1,200-plus Microsoft Sentinel deployments, 24x7 regional SOC coverage, 50-plus certified Microsoft delivery and SOC engineers, and a government product that can map tens of thousands of suppliers using 70,000-plus data feeds without requiring proprietary supplier data. The June 2026 BlueVoyant AI launch adds a second important angle: management is trying to move from pure services into an agentic SecOps platform that can be consumed either as a managed service or self-service SaaS. That gives BlueVoyant a plausible win zone in regulated, Microsoft-heavy environments where the buyer wants one provider across managed SOC operations and third-party cyber defense. It is a weaker fit for buyers who want the lowest investigation burden inside one proprietary security suite, or for procurement-led TPRM programs that already prefer a ratings vendor plus workflow software.[CP003, CP004, CP006, CP007, CP008, CP027]

Pricing / Packaging Comparison
VendorPublic Pricing VisibilityContract / Packaging SignalWhat Is Publicly EmphasizedCompetitive Implication
BlueVoyantNo public list pricing on retained pagesQuote-based platform and managed-service bundlesMDR, TPRM, DRP, and professional services sold togetherCross-sell flexibility is a strength, but outside buyers cannot benchmark list ACV from public pages
CrowdStrike Falcon CompleteNo public list pricing on retained pagesQuote-based MDR on the Falcon platformAgentic MDR, deterministic automation, and broad native telemetryCustomers already on Falcon can rationalize spend inside a broader platform contract
Palo Alto NetworksNo public list pricing on retained pagesQuote-based XSIAM plus Unit 42 managed servicesUnified SOC stack and managed servicesBundle economics can undercut service-led challengers in large-suite accounts
Arctic WolfNo public list pricing on retained pagesSecurity operations bundles with concierge delivery and warrantyOutcome-led managed service rather than tool purchaseAppeals to buyers seeking outsourced outcomes, but public comparability is still low
Rapid7No public list pricing on retained pagesPlatform subscription plus managed operationsExposure management + SIEM + managed operationsNatural expansion path for Rapid7 customers, but opaque public pricing remains a diligence item
ReliaQuestNo public list pricing on retained pagesEnterprise platform with integration-heavy deploymentAny-source GreyMatter operations and integrationsBest fit for complex enterprises, but procurement likely remains custom and services-heavy
eSentireNo public list pricing on retained pagesManaged MDR / XDR service contractUnlimited hunting and incident handling messagingGood for outcome buyers, but less transparent for early shortlist cost screens
SecurityScorecard / BitSightNo public list pricing on retained pagesQuote-based ratings / TPRM programsContinuous monitoring, questionnaires, AI summaries, vendor-network intelligenceBudget path often runs through procurement, risk, or insurance rather than the SOC

This table compares pricing visibility and packaging signals only. Retained official pages generally omit enterprise list pricing, so contract values and realized discounts remain a diligence gap.

[CP041, CP042, CP043, CP044]
FP003: Moat / Readiness KPIs — BlueVoyant Competitive Snapshot

Six public indicators that summarize BlueVoyant’s competitive position as of June 2026, combining strengths and adverse signals.

[CP003, CP005, CP007, CP008, CP034, CP040]

3.5 Weaknesses, Adverse Evidence, and Moat Durability

The most important disconfirming evidence is not that BlueVoyant lacks product breadth, but that larger competitors can frame the same job with stronger market visibility or lower operational friction. PeerSpot's June 2026 review page puts BlueVoyant at just 0.9% MDR mindshare, down from 1.2% a year earlier, and its direct comparison page ranks BlueVoyant #34 versus CrowdStrike #2 while noting weaker reporting customization and potentially heavier configuration. Daylight's 2026 buyer guide is blunter: it classifies BlueVoyant among MSSP-style MDR providers chosen for broad security partnership, but with more analyst-hours-intensive workflows than AI-native or XDR-extended alternatives. On the TPRM side, BlueVoyant must also defend against much larger external data networks from SecurityScorecard and BitSight. Public pricing opacity across nearly every retained competitor page compounds the challenge because it makes incumbent suite bundling and multi-product discounts harder to benchmark from the outside. BlueVoyant therefore has a real moat in cross-budget service breadth, but not an obviously durable moat in category visibility, data-network scale, or platform lock-in.[CP017, CP018, CP034, CP035, CP036, CP037]

Moat Durability / Competitive Risk Register
Moat or Risk ClaimPrimary ThreatSeverityCurrent Mitigation SignalDiligence Ask
Microsoft-specialist MDR depthCrowdStrike, Palo Alto, and Microsoft-native alternatives can offer more native automation or bundle economicsHighBlueVoyant AI launch and 1,200+ Sentinel deployments strengthen the specialist storyBreak out revenue mix from Microsoft-heavy accounts vs. non-Microsoft accounts
Cross-budget MDR + TPRM + DRP positioningBuyers may still split SOC and vendor-risk budgets and select separate best-of-breed toolsHighBlueVoyant markets all four motions together and government C-SCRM broadens the storyMeasure multi-product attach rate and expansion from MDR into TPRM
Outside-in supplier illuminationSecurityScorecard and BitSight operate much larger public data networks and stronger ratings brandsHighBlueVoyant adds analyst-led remediation and government mission framing rather than ratings aloneBenchmark supplier coverage, false positives, and remediation speed against ratings vendors
Services-led delivery modelAI-native and platform-native MDR can shift more investigation burden into software and automationHighBlueVoyant AI moves the model toward agentic SecOps and self-service SaaSTest analyst-to-customer leverage and escalation load before and after BlueVoyant AI deployment
Public pricing opacitySuite vendors can hide discounts inside broader contracts and make standalone comparison harderMediumBlueVoyant can package MDR and TPRM together when buyers want one partnerObtain apples-to-apples ACV, ramp, and renewal benchmarks in diligence
Lower MDR market visibilityPeerSpot mindshare and ranking suggest weaker shortlist gravity than CrowdStrike or category leadersMediumBlueVoyant can target regulated or Microsoft-led use cases instead of generic MDR bake-offsValidate enterprise brand awareness and RFP inclusion rates by vertical

Severity reflects author judgment based on retained public evidence. Diligence asks identify the private data needed to test whether the observed moat or risk is durable.

[CP017, CP018, CP034, CP035, CP036, CP037]
Chapter 04

04Financials

4.1 Revenue model and monetization visibility

BlueVoyant's public commercial surface looks like a recurring cybersecurity platform wrapped around MDR, TPRM, DRP, and professional services rather than a one-off project business. The homepage and product materials emphasize ongoing monitoring, response, remediation, and takedown work, while customer proofs and TEI studies reinforce a subscription-or-retainer style value proposition. That said, the public record is much stronger on outcomes than on monetization detail. BlueVoyant discloses deployment counts, ROI claims, and marketplace procurement routes, but it does not publish standard list prices for its core offers, nor does it expose realized pricing, discounting, or revenue mix between recurring managed services and project-based work. The result is a clear top-line revenue mechanism but an incomplete view of revenue quality and contribution margin by stream.[CI001, CI002, CI003, CI004, CI005, CI006]

Revenue streams table
StreamMechanismPublic evidenceMonetization visibilityQuality / caveatDiligence ask
Managed Detection & ResponseRecurring managed monitoring and response1,200+ Sentinel deployments; 24x7 SOC coverageContracted / recurring, but list pricing not publicStrong demand proxy; weak pricing transparencyRequest contract terms, seat/device basis, and gross margin by customer segment
Third-Party Risk ManagementRecurring monitoring, validation, and remediation support18x faster remediation; 98% accuracy; GCP marketplace routeRecurring / enterprise procurement eligibleOutcome data strong; revenue realization opaqueRequest per-vendor pricing, remediation fees, and attach rates
Digital Risk ProtectionOngoing monitoring and takedown services50,000 domain takedowns over two years; social and website takedown success ratesLikely recurring service bundleHigh activity signal; no price disclosureRequest pricing by protected brand/account and takedown economics
Professional Services / DFIRProject, retainer, and advisory revenueHomepage and case studies position incident response and strategic services alongside MDRProject / retainer mix not disclosedMost likely lumpy compared with MDR/TPRMRequest retainer attach rate and services utilization data

Official pages show the revenue mechanisms clearly, but they do not reconcile stream mix, realized pricing, or stream-level margin.

[CI001, CI002, CI004, CI005, CI006, CI007]
Pricing / monetization table
Offer / channelPublic pricing signalRealized pricing visibilityProcurement pathRevenue implication
MDR / SOC outsourcingBuild-vs-buy page frames >$1.2M self-build cost and <25% MSSP alternativeNo public contract price or per-endpoint rateDirect sales and partnersValue proposition is explicit, but realized ASP and gross margin are unknown
TPRM on GCP MarketplaceMarketplace availability public; no numeric list price disclosedNo public net price, discount, or minimum commitCloud marketplace / enterprise agreementShould reduce procurement friction and channel cycle time
Microsoft optimization servicesBlog says internal optimization can cost up to $750k annuallyNo BlueVoyant service price card disclosedDirect enterprise sale, likely consultativeSupports advisory upsell logic, not actual BlueVoyant pricing realization
Partner-assisted dealsPartner contribution hit 50% of new business in 2021Channel discounts and rev-share not disclosedResellers, consultancies, and technology partnersCould improve top-of-funnel efficiency while compressing realized price
Customer case-study expansionsOdeon and Snappi show multi-product land-and-expand motionNo disclosed contract valuesDirect / partner blendSupports wallet-share story without supplying ARR per account

This table separates public procurement routes from missing realized-price data; the public record shows how buyers can buy, not what they actually pay.

[CI012, CI013, CI017, CI034, CI035, CI038]
FI001: Revenue model bridge

BlueVoyant converts direct demand, partner demand, and marketplace access into recurring managed-security revenue plus a smaller professional-services layer, but public materials stop before realized gross profit can be quantified.

This bridge is qualitative because public materials expose route-to-market and outcomes but not realized revenue mix or gross margin by stream.

[CI001, CI011, CI017, CI034, CI038, CI060]

4.2 GTM motion and sales-efficiency proxies

BlueVoyant appears to scale through a hybrid of direct enterprise selling, partner-led demand, and lower-friction cloud-marketplace procurement. The company explicitly says partners contributed half of all new business in 2021, and its channel pages show that reseller and consulting relationships are central rather than incidental. That matters because partner leverage can offset the staffing intensity that usually accompanies 24x7 managed services. BlueVoyant also markets hard savings arguments against the in-house SOC alternative, claiming both that self-build can exceed $1.2 million annually and that an MSSP can cost under one quarter of that level. Customer-value studies add more evidence, though they are company-sponsored: the Forrester TEI materials, ODEON outcomes, and Sentinel case-study guide all point to meaningful operational savings, but they still stop short of giving true CAC, payback, or realized gross-margin data.[CI011, CI012, CI013, CI017, CI029, CI030]

Unit economics and sales-efficiency proxy table
ProxyPublic value / statusConfidenceWhy it mattersDiligence ask
ARR growth since 2018117% average growth claimmediumSignals strong top-line momentum if still directionally trueRequest audited bookings/ARR bridge by year
Partner-sourced new business50% of 2021 new businessmediumSuggests distribution leverage beyond direct sales headcountRequest partner-sourced pipeline, win-rate, and margin split
Build-vs-buy alternative cost>$1.2M self-build annual SOC costmediumFrames customer ROI and willingness-to-pay ceilingRequest ROI model assumptions and actual competitive win-loss data
Outsourced SOC savings claim<25% of internal SOC costmediumSupports payback narrative but not realized priceRequest contract examples and customer payback models
MDR TEI value proxy210% ROI; 90% fewer escalated alerts; 70% faster MTTRmediumSupports retention and expansion thesis if representativeRequest customer cohort methodology and non-sponsored references
Supply-chain-defense value proxy~300% ROI; 62% faster critical-risk remediationmediumSuggests higher-value TPRM economics than pure compliance toolingRequest customer retention and expansion metrics for TPRM accounts

These are sales-efficiency and value proxies, not closed-loop unit economics; public evidence is directional and mostly company-sponsored.

[CI017, CI018, CI029, CI030, CI031, CI032]
FI002: Unit economics bridge

BlueVoyant presents strong customer-value proxies and outsourcing economics, but the public trail breaks before CAC, payback, and margin can be measured directly.

Nodes summarize evidence quality, not hidden internal telemetry; downstream economic outputs remain intentionally unresolved.

[CI012, CI013, CI017, CI029, CI030, CI031]

4.3 Public scale signals and operating leverage proxies

BlueVoyant's official scale narrative is directionally strong and internally consistent on growth, but not consistent enough on exact current size to underwrite without caveat. Official press releases progress from more than 700 customers in 30 countries in early 2022, to more than 900 global customers in mid-2024, to more than 1,000 customers in over 45 countries by March 2025. Headcount signals are more uneven: BlueVoyant says it has over 600 employees, GetLatka estimates about 650, Dialectica lists 653, and an accessible historical PitchBook snapshot showed only 363 employees. That spread is too wide to ignore, especially because revenue-per-employee and sales-efficiency proxies change meaningfully depending on which denominator is used. The prudent read is that BlueVoyant has real enterprise scale and international delivery reach, but public databases remain stale or inconsistent on the exact operating baseline.[CI010, CI014, CI015, CI016, CI020, CI025]

Public traction, customer, and headcount proxies
Metric2022 signal2024 signal2025 / database signalCaveat
Customer count>700 customers in 30 countries>900 global customers>1,000 customers in >45 countriesProgression is directionally strong, but exact current count is still company-claimed
Headcount>560 employees at Series D>600 employees on company page650 (GetLatka); 653 (Dialectica); 363 (historical PitchBook)Private databases disagree and some snapshots are stale
Partner leveragePartners contributed 50% of new businessChannel roster broadened on official siteMarketplace route added for TPRMGood GTM signal, weak disclosed economics
Delivery scale1,200+ Sentinel deployments; 24x7 SOCODEON across 8 countries and 280+ cinemasHundreds of deployments / 16 case studies in guideProof of scale exists, but not all deployments translate to comparable ARR
EMEA investmentExpanded into >10 countries in 2021Finance function and acquisition buildout in 2024Cork launch, local revenue +70% in 2024Scale signals support growth, not profitability

These proxies mix official disclosures and private-database snapshots; they are useful for trend direction, not as a clean single-period operating baseline.

[CI010, CI015, CI016, CI017, CI020, CI021]

4.4 Capital base, investor syndicate, and conflicting private-company signals

BlueVoyant's capital history clearly includes two large late-stage rounds: a $250 million Series D in 2022 and a more-than-$140 million Series E tied to the Conquest Cyber acquisition in 2023. Liberty Strategic Capital and ISTARI are recurring anchors in that investor base, with Eden Global Partners recurring as adviser or participant. Beyond that, third-party databases start to diverge. CB Insights and Clay both report roughly $665.5 million of cumulative funding, while Tracxn reports $696 million; investor counts vary from 9 on a historical PitchBook snapshot to 11 on Clay and 15 on CB Insights. Revenue signals diverge even more sharply, with GetLatka showing a $213.5 million 2025 estimate while CB Insights shows $750 million for 2024. Those contradictions do not prove any single source is wrong, but they do make plain that the public/private data exhaust is insufficiently reconciled for investment underwriting without management confirmation.[CI019, CI021, CI022, CI023, CI024, CI041]

Capital adequacy table
DimensionPublic signalSource-backed value / statusUnderwriting implicationDiligence ask
Series D equity capitalLarge late-stage round2022 Series D, $250M, Liberty Strategic Capital leadMaterial balance-sheet support for scale-up and hiringRequest post-money cash bridge and uses of proceeds
Series E + acquisition capitalAcquisition-linked growth funding> $140M Series E alongside Conquest acquisition in 2023Shows continued investor support and M&A appetiteRequest integration budget and revenue contribution from Conquest
Investor base depthRepeat strategic sponsorsLiberty, ISTARI/Temasek, Eden, 8VC, plus varying database investor countsSyndicate quality looks strong, but exact breadth is inconsistentRequest current cap table and ownership by round
Debt / leverage signalOnly historical public debt trace retainedPitchBook snapshot shows 2020 Debt-PPP entry; no retained current debt facilityCurrent leverage may be zero, modest, or simply undisclosedRequest debt schedule, lender names, and covenant package
Cash / burn / runwayNot publicly disclosedNo retained public source verified them as of run dateThis is the largest underwriting blockerRequest latest cash balance, burn, and runway model
Regional expansion commitmentsEMEA buildout and SOC expansion visibleCork opening tied to multi-million-euro investment and 70% local revenue growthExpansion suggests ongoing spend even without cash disclosureRequest EMEA hiring plan, opex, and expected payback

Historical funding chronology belongs in Company Overview; this table focuses on forward adequacy and current blind spots needed for underwriting.

[CI019, CI022, CI023, CI026, CI028, CI041]
Conflicting private-company financial signals table
MetricSource ASource BSource CWhy it conflicts / how to use
Total raisedCB Insights: $665.5M over 9 roundsClay: $665.5M total raisedTracxn: $696M over 6 roundsConsensus is roughly mid-$600Ms, but round counting and treatment differ; management should provide the cap table
Revenue / ARRGetLatka: $213.5M in 2025CB Insights: $750M in 2024No official revenue disclosureThese figures are not directly reconcilable and could reflect ARR vs broader revenue vs stale estimates
EmployeesCompany page: >600GetLatka: 650; Dialectica: 653PitchBook snapshot: 363Later sources cluster around 600+, while the accessible PitchBook snapshot looks stale or partial
Investor countClay: 11 investorsCB Insights: 15 investorsPitchBook snapshot: 9 investorsDatabase coverage varies; use public round announcements plus cap table request instead of any single count
Latest deal historySeries E $140M in 2023 appears in official/news sourcesPitchBook accessible snapshot shows latest deal amount of $30MPitchBook also shows historical Debt-PPP entryA stale or archived profile can materially distort current financing and leverage assumptions

The point is not to choose a favorite database; it is to preserve contradictory estimates until management reconciles them.

[CI042, CI043, CI044, CI045, CI046, CI047]
FI003: Financial estimate range

Publicly surfaced funding, revenue, customer, and employee figures span wide ranges because the company is private and database snapshots are inconsistent.

Ranges intentionally preserve contradictory years and source methodologies instead of collapsing them into a false point estimate.

[CI042, CI044, CI045, CI046, CI047, CI049]

4.5 Financial verdict and diligence blockers

The retained evidence supports a company with real recurring demand, substantial private-capital backing, and enough customer breadth to matter in enterprise cybersecurity. It does not, however, support a clean financial underwriting case. Cash, burn, runway, debt obligations, realized pricing, gross margin, retention, CAC, and payback remain outside the public record. A historical PPP debt signal and UK filing trail show corporate-document activity, but they do not answer current leverage or liquidity questions. The adverse workforce review does not overturn the growth narrative, yet it does warn that resource constraints may coexist with acquisitive expansion and executive buildout. The right financial conclusion is therefore constructive but not investable on public evidence alone: BlueVoyant looks commercially relevant, but management data is still required to judge revenue quality, operating leverage, and next-round dependency.[CI026, CI028, CI053, CI054, CI055, CI056]

Public financial gaps table
Missing metricWhy it mattersCurrent proxySpecific diligence path
Cash on hand / runwayDetermines financing dependency and next-round urgencyLarge past raises and ongoing expansion onlyRequest current balance sheet, cash forecast, and board runway scenario deck
Monthly burn and hiring planShows whether growth is self-funded or cash-consumingCork expansion, CFO buildout, and customer growth are indirect proxiesRequest monthly burn bridge, hiring plan, and variance to budget
Gross margin by product lineNeeded to separate software-like recurring economics from staffing-heavy service economicsTEI and case studies show outcomes, not marginRequest gross margin and utilization by MDR, TPRM, DRP, and services
Realized pricing / discountsNeeded to judge price discipline and renewal qualityMarketplace route and build-vs-buy framing onlyRequest price books, discount approvals, and recent contract samples
Debt schedule and covenantsNeeded to understand leverage, restrictions, and refinancing riskOnly a historical 2020 Debt-PPP trace surfaced directlyRequest lender agreements, covenant package, and any acquisition-related borrowing

Nulls here are intentional diligence blockers rather than formatting omissions; they mark the minimum dataset required for underwriting.

[CI052, CI058, CI059, CI060, CI061, CI062]

4.6 Exhibits

Chapter 05

05Product & Technology

5.1 Platform definition and converged architecture

BlueVoyant now markets the company less as a stand-alone MDR provider and more as a unified cyber-defense operating system. The homepage, the Cyber Defense Platform page, and the 2024 launch materials consistently describe one cloud-native platform spanning internal defense, third-party risk, and external digital-risk monitoring. That matters because the product definition is customer-workflow specific: a security team can run internal SOC triage, supplier remediation, and brand or credential takedown work from the same operating model instead of stitching together separate point tools. The company’s newer AI layer reinforces that convergence thesis rather than replacing it; BlueVoyant AI is framed as a control plane that decides when to route work to deterministic automation, when to call a human analyst, and when to let agents act. The diligence-positive takeaway is that the portfolio is coherently packaged. The diligence caveat is that the public architecture remains marketing-layer deep outside a few Microsoft-specific documents.[CE001, CE003, CE004, CE005, CE006, CE007]

Product module / asset matrix
Module / assetPrimary buyer or userCurrent public maturityDifferentiation signalDiligence gap
Cyber Defense PlatformCISO, SOC leader, security operations teamCurrent umbrella productConverges MDR, TPRM, DRP, and services on one cloud-native surfaceNo public architecture document that shows shared schemas, tenancy, or data-routing details
BlueVoyant AIBlueVoyant SOC or customer SOCNew 2026 launch / active go-to-marketAgentic model pairs human judgment, deterministic automation, and AI agents with managed or self-service deploymentNo public benchmark pack for false-positive reduction, MTTR change, or model-governance details
MDR for MicrosoftMicrosoft-native security teamsCore and deeply evidencedMost concrete technical proof in the portfolio, including tenant-resident data handling and specific Microsoft stack coverageBreadth outside Microsoft tools is still described only at a higher level
Continuous Optimization for Microsoft SolutionsSecurity engineering, compliance, and platform-ops teamsCurrent module / advisory-plus-software layerExtends beyond monitoring into Sentinel, Defender, M365, and Purview optimizationCommercial packaging, repeatability, and automation depth are not publicly broken out
Third-Party Risk Management / Supply Chain DefenseVendor-risk, procurement, and cyber-risk teamsCurrent and feature-complete in public materialsCombines continuous monitoring, remediation, questionnaires, and advisory work instead of only passive scoringSoftware versus analyst-labor contribution is not publicly quantified
Digital Risk ProtectionBrand-protection, fraud, and external-risk teamsCurrent and modularCovers web, social, app, dark-web, and executive-protection workflows with published takedown metricsOutcome quality depends on external platforms and partner responsiveness
Conquest-enhanced compliance and posture layerDefense, government, and regulated buyersIntegration-stage capability expansionAdds risk-maturity, posture, and compliance mapping useful for CMMC-heavy environmentsPublic sources do not show how completely Conquest workflows are now embedded in core BlueVoyant UX

Rows separate currently marketed modules from the acquisition-expanded posture/compliance layer that is still best evidenced through release materials.

[CE001, CE003, CE007, CE011, CE019, CE025]
FE001: Product architecture map

The public product story resolves into a five-layer stack from signal collection through AI orchestration and analyst-driven outcomes.

This figure is synthesized from current product pages, launch releases, trust-center metadata, and Microsoft collateral rather than copied from a vendor-published system diagram.

[CE004, CE005, CE006, CE007, CE016, CE030]

5.2 Microsoft-centric MDR and agentic SOC operations

The most concrete technical depth is in BlueVoyant’s Microsoft ecosystem story. The MDR suite explicitly nests MDR for Microsoft and Continuous Optimization for Microsoft Solutions, and the Microsoft-specific pages are more precise than the generic platform prose. BlueVoyant publicly claims 24/7 coverage across the Microsoft security stack, multiple partner designations and specializations, a large engagement base around Sentinel and Defender, and a delivery model that can keep customer security data in the customer tenant instead of exporting it to an MSSP-controlled data lake. The 2026 BlueVoyant AI launch expands that position by describing automated containment actions, a managed or self-service deployment choice, and models trained on years of Microsoft-native operating history. In practice, this suggests BlueVoyant’s strongest technical moat is not a broad open integration catalog; it is process depth, tuning, automation, and analyst workflows around Microsoft environments.[CE002, CE006, CE007, CE008, CE009, CE010]

Workflow / use-case table
User jobCurrent workflow problemBlueVoyant solutionPublished benefit or operating signalLimitation
Microsoft SOC triage and containmentToo many alerts across Sentinel, Defender, identity, endpoint, and cloud surfacesMDR for Microsoft plus BlueVoyant AI24/7 monitoring, automated response actions, and high-fidelity alerting are explicitly marketedPublic proof is strongest for claims, not for independent measured outcomes
Microsoft cost and posture optimizationCustomers overpay or under-configure Sentinel, Defender, M365, and PurviewContinuous Optimization for Microsoft SolutionsBlueVoyant cites 1,000+ engagements and cost-control guidance for licensing and Sentinel consumptionSavings methodology and realized customer distributions are not public
Third-party critical finding remediationVendor-risk teams discover issues but struggle to drive closureContinuous Monitoring & RemediationROC analysts validate findings and contact third parties directlyNo public disclosure of closure-rate distributions by customer segment
Supplier assessment operationsQuestionnaires are manual, slow, and hard to verifyQuestionnaire Management platform and managed serviceAutomation plus validation of supplier claims is presented as the differentiatorPublic material does not show integrations into customer GRC stacks
Brand impersonation takedownsPhishing sites, fake pages, and rogue apps move quickly across many platformsBrand ProtectionUnlimited takedowns and 300+ app-store coverage are marketed, with public success metrics on the homepageTakedown success still depends on registrar, social, or app-store cooperation
Credential, fraud, and leak monitoringSecurity teams lack visibility into underground communities and leaked dataDark Web WatcherContinuous monitoring of underground sources plus account-takeover and leakage workflows are describedPublic evidence does not show signal-to-noise ratios or time-to-detect distributions
Executive-targeted attack preventionVIPs face personal-data exposure and account-takeover risk outside core IT controlsExecutive Cyber GuardReal-time alerts and tools to stop attacks are part of the marketed workflowPublic materials do not quantify adoption or measured executive-risk reduction

This table focuses on user jobs and operational workflows, not on contractual SKUs or internal package names.

[CE007, CE008, CE012, CE015, CE021, CE023]
FE002: Customer workflow / operating flow

BlueVoyant’s Microsoft-heavy workflow starts with telemetry and identity signals, then moves through AI-assisted triage, human validation, and containment or optimization action.

The flow emphasizes the Microsoft-centric MDR path because that is where the public evidence is most specific.

[CE007, CE008, CE012, CE015, CE016, CE018]

5.3 Third-party risk and supply-chain workflows

BlueVoyant’s supply-chain defense materials are specific enough to treat TPRM as a productized workflow, not just a consulting wrapper around external ratings. The current TPRM overview, the continuous-monitoring page, and the 2023 expansion release align on the same operating model: vendor monitoring is tiered by risk, BlueVoyant analysts validate findings inside a Risk Operations Center, and remediation is driven directly with suppliers instead of being left entirely to the customer. Questionnaire management is also described as both software and managed service, which fits the overall BlueVoyant pattern of combining automation with labor-intensive execution where the workflow is messy. Publicly, the best substantiated differentiators are analyst-directed remediation, zero-day alerting, AI/ML-based business-risk monitoring, and the ability to combine continuous monitoring with periodic due-diligence assessments. The remaining diligence question is how much of this is repeatable software leverage versus scale achieved through expert staffing and service process discipline.[CE019, CE020, CE021, CE022, CE023, CE024]

Technology / operating architecture table
Layer / componentRoleKey dependencyMain risk
Customer telemetry and asset surfacesSupply internal, external, and supplier signals into the platformCustomer tenancy, cloud workloads, endpoints, suppliers, and dark-web monitoring accessPublic materials do not explain normalization, retention, or cross-domain schema design
Microsoft-native data planeProvides Sentinel, Defender, identity, and compliance context for MDR workflowsMicrosoft ecosystem depth and continued API / feature accessA heavy Microsoft concentration raises concentration risk if buyers want broader heterogeneous-stack transparency
AI and deterministic automation layerEnriches, triages, and can trigger automated containment actions at machine speedModel tuning, playbooks, approval logic, and data qualityPublic evidence does not expose model-governance, evaluation, or rollback controls
Human analyst layerSOC and ROC experts validate alerts, tune logic, and communicate with customers or vendorsSkilled labor availability and repeatable processesService quality can become people-intensive as volume scales
Third-party risk analytics layerMonitors vendors, risk events, questionnaires, and remediation workflowsLarge external data-source coverage plus customer vendor inventoriesNo public documentation of customer-side integrations into procurement or GRC systems
External takedown and monitoring networkExecutes brand, app, social, and credential-remediation outcomesRegistrars, social platforms, app stores, and underground-source accessOutcome quality can vary with external platform responsiveness
Conquest posture and compliance layerExtends the platform into posture, maturity, and government-oriented compliance workflowsSuccessful post-acquisition product integrationPublic sources do not show whether the UX is fully unified or still portfolio-level

The architecture is synthesized from reviewed product pages, releases, and Microsoft collateral rather than from a vendor-published engineering diagram.

[CE004, CE006, CE015, CE016, CE021, CE022]

5.4 Digital risk protection and external dependency chain

The external-risk side of the platform is organized into a clean three-module structure: Brand Protection, Dark Web Watcher, and Executive Cyber Guard. Those modules map to concrete user jobs rather than abstract threat-intelligence buzzwords. BlueVoyant claims brand takedowns across web, social, and rogue-app channels; dark-web monitoring for fraud, leaked credentials, and exposed data; and executive monitoring for high-value account compromise or personal-data exposure. The company also publishes at least some measurable DRP performance signals, including website and social-media takedown success rates and a median server-level takedown time. Operationally, however, this product line is the most obviously dependent on outside platforms and counterparties: registrars, social networks, app stores, underground monitoring access, and customer response playbooks all sit in the outcome chain. That makes DRP strategically important but also dependency-heavy, which is why the Gartner review headline about occasional takedown challenges deserves attention.[CE025, CE026, CE027, CE028, CE029, CE030]

FE003: Critical dependency map

BlueVoyant’s product outcomes depend on a chain of technology and ecosystem counterparties, especially Microsoft plus external takedown and supplier-response channels.

The dependency map focuses on counterparties visible in fetched sources; undisclosed internal infrastructure vendors are intentionally omitted.

[CE021, CE027, CE028, CE030, CE033, CE035]

5.5 Trust controls, capability expansion, and product risks

BlueVoyant has enough public trust and roadmap proof to support enterprise diligence, but not enough to eliminate buyer follow-up. The Trust Center confirms that the company wants to be seen as a cloud-native, AI-plus-human platform with more than 1,000 clients, while the Microsoft and Conquest materials show explicit alignment to compliance-heavy environments. Conquest is particularly important because it expands BlueVoyant from detection and risk visibility into risk-maturity mapping, posture management, and government-oriented compliance workflows such as CMMC and FedRAMP-adjacent environments. At the same time, the public developer surface is thin: GitHub shows only one visible public repository, and that repository is branded as content for Copilot for Security rather than core platform code or reusable integrations. Independent review and community sources also surface real caution signals—occasional DRP takedown friction, long-running questions about proprietary depth, and limited public evidence for non-Microsoft integrations, SLAs, or independently audited product performance.[CE016, CE031, CE032, CE033, CE034, CE035]

Trust / quality / compliance table
Control / signalStatusScopeGap
Trust Center presenceVerifiedVanta-hosted public Trust Center states BlueVoyant is cloud-native and AI-plus-human with 1,000+ clientsFetched public surface does not expose the full certificate and report inventory in readable text
Tenant-resident Microsoft data handlingVerified in collateralMDR for Microsoft PDF says customers can keep security data in their own environmentThis proof is in partner collateral, not a public architecture or data-processing white paper
Microsoft partner recognitions and specializationsVerified company claimMDR for Microsoft page lists partner awards, designations, and security specializationsAwards signal delivery credibility more than platform control maturity
CMMC / FedRAMP / defense-environment relevanceVerified through Conquest acquisitionRelease materials tie Conquest and BlueVoyant to CMMC RPO accreditation, DIB use cases, and ARMED ATK on the FedRAMP marketplacePublic sources still do not map those controls to the main commercial platform in detail
Independent review signal on DRP executionMixedGartner surface shows a favorable DRP review headline that still flags occasional takedown challengesA single public review headline is not enough to underwrite broad reliability
Public developer transparencyLowGitHub shows one visible public repository focused on Copilot for Security contentOpen-source evidence is too thin to evaluate connector depth, release cadence, or engineering reuse at scale

This table separates trust signals that are directly visible in fetched sources from the larger control inventory that still requires private diligence.

[CE016, CE017, CE031, CE032, CE035, CE036]
Roadmap / release / development-stage table
Date / stageFeature / milestoneStatusImplicationSource
2023-03 partner trainingBlueVoyant Shadow Hunter Microsoft Security Immersion WorkshopHistorical / partner-enabledShows Microsoft practitioner engagement before the broader platform convergence story was fully publicSE032
2023-09 product expansionComprehensive third-party cyber risk management expansionLaunchedAdded questionnaire management, multi-tier monitoring, zero-day alerting, and advisory workflows to Supply Chain DefenseSE015/SE023
2023-11 acquisitionConquest Cyber acquisitionClosed / integration underwayExpanded posture, compliance, and government-defense capabilities with a risk-maturity lensSE016/SE024
2024-07 platform launchBlueVoyant Cyber Defense PlatformLaunchedEstablished one cloud-native umbrella across internal, external, and supply-chain defenseSE021/SE026/SE027
2025-09 developer signalBV-Security-Copilot repo updated publicly on GitHubVisible but narrowIndicates some practitioner-facing artifact creation, but not broad open engineering transparencySE018/SE019/SE020
2026 current go-to-marketMDR for Microsoft and Continuous Optimization are live modules inside the platformCurrentConfirms the product is sold both as operations coverage and as optimization around Microsoft security spend and controlsSE005/SE006/SE007
2026 AI launchBlueVoyant AI agentic SecOps platformLaunchedMoves the roadmap from converged surfaces to an AI-native orchestration layer for managed and self-service SOCsSE022

Because BlueVoyant does not publish a public changelog, roadmap evidence is reconstructed from releases, collateral, GitHub activity, and current solution pages.

[CE004, CE007, CE015, CE024, CE033, CE034]
FE004: Product maturity / capability map

Public proof is strongest for Microsoft delivery depth and module breadth, weaker for open engineering transparency, non-Microsoft integrations, and hard operational benchmarks.

[CE015, CE022, CE035, CE036, CE037, CE039]

5.6 Exhibits

Chapter 06

06Customers

6.1 Customer Segmentation and Buyer Structure

BlueVoyant’s public customer file points to enterprise and government buyers with complicated security operations, meaningful regulatory exposure, or large third-party ecosystems rather than a broad SMB base. The buyer is usually a CISO, Office of Information Security, security architecture lead, or infrastructure owner; the daily user is the SOC or IT operations team; and the payer is typically an agency procurement budget, a regulated enterprise security budget, or a partner-enabled contract vehicle. The strongest visible segments are public sector and financial services: California’s OIS, NAVSEA and Carahsoft-backed government routes on one side, and Snappi, Beeks, ClearBank, and financial-services-oriented Microsoft content on the other. ODEON broadens the file into multi-country consumer operations, but the pattern is still complex, high-stakes environments. Energy and legal are clearly targeted verticals, yet the reviewed corpus does not show equally strong named production references there.[CU001, CU002, CU003, CU004, CU030, CU031]

Customer Segmentation Table
Segment / cohortBuyer / user / payerRepresentative public proofWhat the evidence provesMain gap
State and local governmentBuyer: OIS/CISO; user: SOC and IT teams; payer: agency or statewide cybersecurity budgetCalifornia OIS SOCaaS and CDT SOCaaS pagesBlueVoyant can support shared-service monitoring in resource-constrained public entitiesPublic proof is concentrated in California and does not disclose contract economics
Federal defense and acquisitionBuyer: program/procurement leadership; user: supply-chain and security analysts; payer: federal contract vehicleNAVSEA / 202 Group Phase III work and SCRIPTS BPA availabilityBlueVoyant has real federal procurement traction in supply-chain risk use casesProgram and supplier-coverage proof is stronger than end-user adoption detail
Digital banking and regulated financeBuyer: CISO / board / security leadership; user: SOC and compliance teams; payer: enterprise security budgetSnappi and ClearBank public materialsBlueVoyant resonates where resilience, reporting, and Microsoft operations matterNamed bank roster remains thin in public materials
Capital-markets infrastructureBuyer: CISO / IT leadership; user: SOC analysts; payer: platform operator budgetBeeks Group customer statementsBlueVoyant can support customer-facing financial infrastructure and reassure downstream clientsLittle public evidence on expansion beyond the initial deployment
Multi-site commercial operatorsBuyer: central InfoSec / cloud services; user: regional security teams; payer: corporate security budgetODEON case study and independent coverageBlueVoyant can unify noisy multi-country environments and add third-party risk visibilityPublic commercial proof is led by one flagship entertainment reference
Energy and legal go-to-market motionsBuyer: sector CISO or IT/security lead; user: security teams; payer: enterprise security budgetEnergy webinar and law-firm solution spotlightBlueVoyant actively targets other regulated segments beyond banking and governmentReviewed sources do not name comparable production customers in these verticals

Rows separate segments with named proof from sectors that are currently supported mainly by solution marketing or thought leadership.

[CU001, CU002, CU003, CU004, CU030, CU031]
FU001: Customer Journey Map

The visible buyer journey usually starts with compliance or alert-fatigue pain, moves through partner- or Microsoft-led onboarding, and expands into always-on operations plus third-party risk visibility.

[CU001, CU002, CU026, CU027, CU030, CU042]

6.2 Named Production Proof and Buyer Outcomes

BlueVoyant’s strongest public customer evidence comes from a small set of named references with concrete operational outcomes. California OIS provides the clearest state-government proof, showing a Microsoft-centered SOCaaS deployment with faster detection and response plus budget savings. ODEON adds a multinational commercial reference with a quantified alert-noise reduction, third-party vulnerability resolution, and a more detailed technical narrative about moving from fragmented tooling to Sentinel plus MDR. Snappi is weaker on numerical ROI but strong on regulated-banking readiness: 24/7 SOC coverage, board reporting, tabletop-tested response, and DORA preparedness within months of launch. Beeks is the best financial-markets proof because the customer itself says BlueVoyant reduced alert fatigue, lowered data-ingestion costs, and went live in under three months. NAVSEA and the BlueVoyant Government Solutions material prove real federal deployment relevance, although the proof is programmatic and contract-led rather than seat-count or renewal-led.[CU005, CU006, CU007, CU008, CU009, CU010]

Customer Growth / Adoption Trajectory Table
Date / signalPublic metric or proof pointSourceInterpretationCaveat
May 2025Trusted by more than 1,000 clients globallyBlueVoyant Microsoft awards press releaseShows the company is comfortable making a four-digit client-count claim in recent public materialsCompany-wide claim is not segmented by product, geography, or revenue scale
June 2025California SOCaaS protects 112 public sector organizations with more than $54 million of combined savingsCalifornia Department of Technology newsroomShows a production public-sector program at meaningful statewide scaleCDT does not break out how much of the current program is attributable specifically to BlueVoyant
April 2025SCD-G currently identifies critical risks for more than 4 million suppliersBlueVoyant Government Solutions SCRIPTS BPA press releaseDemonstrates large monitored ecosystem scale in government supply-chain defenseSupplier coverage is platform scope, not a customer-count metric
2026 review surfacesFeaturedCustomers shows a 4.7/5 reference rating across 133 total customer referencesFeaturedCustomers testimonials pageThird-party review surface suggests a material stock of customer references existsReference platforms are not audited retention or usage disclosures
2026 marketplace visibilityReviewed AWS Marketplace and Slashdot pages show zero customer reviews or ratingsAWS Marketplace and Slashdot comparison pageIndependent public review density is still shallow on some buyer-facing surfacesNo reviews does not prove low adoption; it mainly shows low visible feedback volume

This table mixes company-claimed scale, program scale, and third-party visibility proxies because BlueVoyant does not publish a full public customer cohort series.

[CU009, CU025, CU036, CU037, CU039]
Named Customer Proof Table
Customer / programSegmentDeployment statusPublicly reported outcomeWhat it provesLimitation
California OIS SOCaaSState governmentProduction shared-service program70% lower MTTD, 60% lower MTTR, $2.1M annual personnel savings per participating entityBlueVoyant can support a large, Microsoft-based public-sector operating modelReviewed corpus does not show contract value or renewal mechanics
ODEON Cinemas GroupEntertainment / multi-site operationsProduction multinational deployment98% fewer alerts requiring review, 30 critical/high third-party vulnerabilities resolvedBlueVoyant can cut noise and add supplier-risk visibility in a distributed environmentMost proof is still vendor or partner authored rather than audited by ODEON
SnappiDigital banking / neobankProduction launch-phase deployment24/7 SOC, DORA readiness, board-level KPI reporting, tabletop-validated incident responseBlueVoyant can help a regulated bank launch security operations quicklyProof emphasizes resilience readiness more than commercial or user-volume outcomes
Beeks GroupCapital markets infrastructureProduction customer deploymentGo-live in less than three months with lower alert fatigue and lower data-ingestion costsBlueVoyant can strengthen a customer-facing financial platform where cyber trust affects client acquisitionPublic proof does not quantify renewal, expansion, or contract scale
NAVSEA / BlueVoyant Government SolutionsFederal defense supply chainProduction government programPhase III contract, delivery orders, and current platform claim covering more than 4M suppliersBlueVoyant has real federal supply-chain adoption and procurement relevanceProgrammatic proof is stronger than conventional SaaS account metrics

Rows focus on the deepest named proofs in the reviewed corpus and separate operational milestones from traditional SaaS retention metrics.

[CU005, CU006, CU007, CU008, CU011, CU013]
FU003: Customer Proof Matrix

Proof quality is strongest for a handful of named references, but retention visibility remains weak even where quantified outcomes are strong.

[CU005, CU011, CU018, CU020, CU023, CU039]

6.3 Government and Financial Services Depth

Government and financial services are the most defensible parts of BlueVoyant’s public customer story. On the government side, the company can point to California’s statewide SOCaaS model, NAVSEA supply-chain work inherited through 202 Group, and a widening procurement footprint through Carahsoft, SEWP, ITES-SW2, NASPO, CMAS, and the SCRIPTS BPA. That is more than logo evidence: it shows real contract pathways and operating use cases. On the financial-services side, the proof is narrower but still credible. Beeks offers capital-markets infrastructure proof with a direct customer statement. Snappi shows a new regulated bank using BlueVoyant to stand up cyber operations from day one, and ClearBank indicates BlueVoyant can speak publicly with an established UK bank customer on Microsoft optimization. The caution is that public depth is strongest around Microsoft-centric managed security and resilience themes, not around a broad roster of named banks or insurers.[CU003, CU004, CU017, CU018, CU020, CU021]

6.4 Channel and Procurement Routes

BlueVoyant’s route to market appears deliberately partner-heavy. The company advertises a formal partner program with co-selling, enablement, account planning, and OEM/tech-alliance support. Carahsoft is the clearest channel amplifier for public sector demand, because it gives BlueVoyant access to existing reseller networks and contract vehicles rather than forcing direct procurement one agency at a time. BlueVoyant Government Solutions then adds a more specialized federal path through SCRIPTS and supply-chain-defense motions. AWS Marketplace contributes another procurement path, though the reviewed listing is private-offer oriented and thin on external feedback. The practical implication is that expansion may come through partner and platform ecosystems as much as through net-new direct sales. That can be efficient, especially for Microsoft-centric buyers, but it also means customer visibility can lag behind route-to-market breadth because some wins surface through distributors, webinars, or partner pages rather than through detailed standalone case studies.[CU024, CU025, CU026, CU027, CU028, CU029]

Government / Financial-Services Procurement Route Table
RouteBuyer or user typePublic proofWhat it enablesLimitation
Direct Microsoft-centered enterprise saleCISO / SOC / cloud-security teamsODEON, Snappi, Beeks, ClearBank, California OISSupports fast onboarding into Sentinel, Defender, MDR, and reporting workflowsPublic proof is strongest where Microsoft is already strategic
Carahsoft public-sector distributionFederal, state, local, tribal, education, healthcare buyersCarahsoft partnership and contract pagesGives agencies access through existing reseller channels and contract vehiclesIndirect route can reduce visibility into end-customer economics
SCRIPTS BPA / BlueVoyant Government SolutionsDoD and FCEB supply-chain-risk buyersBlueVoyantGov SCRIPTS BPA press releaseStreamlines access to SCD-G and analyst support for federal programsProgram scale does not automatically translate into commercial-style retention data
AWS Marketplace private offerCloud-first security buyersAWS Marketplace MDR listingProvides procurement through AWS billing and marketplace workflowsReviewed listing still shows no customer reviews and requires private offers
Partner-led external advocacyPartner, distributor, and customer reference ecosystemsPartners page, Carahsoft reseller page, Beeks and Veracloud external storiesExtends reach and credibility beyond BlueVoyant-owned channelsRoute breadth exceeds the depth of independently visible renewal evidence

This extra table separates procurement mechanics from customer outcomes so partner and contract routes are not mistaken for proof of retention.

[CU026, CU027, CU028, CU029, CU030, CU031]
FU002: Adoption / Deployment Flow

BlueVoyant’s public deployments tend to follow a route from procurement access into Microsoft-centered onboarding, then into continuous operations and partner-visible expansion.

[CU013, CU018, CU021, CU026, CU029, CU042]

6.5 Retention, Concentration, and Visibility Risks

The biggest gap in BlueVoyant’s customer file is not absence of reference accounts; it is absence of durability disclosure. None of the reviewed sources provide NRR, GRR, churn, logo-retention, cohort renewal curves, or revenue concentration by customer. PeerSpot hints that annual or multi-year agreements are common, but that is still generic third-party commentary rather than company-verified cohort evidence. Independent review surfaces help only partially. FeaturedCustomers shows a meaningful stock of references and a positive rating, yet AWS Marketplace and Slashdot pages still show zero public ratings on the reviewed listings. Most quantified proof is vendor-authored or partner-authored, which is useful for seeing deployment outcomes but weak for underwriting concentration and renewal risk. The diligence conclusion is therefore mixed: BlueVoyant has credible marquee proofs and regulated-sector relevance, but a buyer still needs private data on top-customer exposure, expansion rates, renewal rates, and segment economics before treating the public customer story as fully underwritten.[CU037, CU038, CU039, CU040, CU041, CU042]

Retention / Repeat Usage / Satisfaction Table
Metric / proxyPublic valueSegmentConfidenceDiligence ask
Net revenue retention (NRR)Overall customer baseLowRequest NRR by product line and customer segment for the last eight quarters
Gross retention / logo retentionOverall customer baseLowRequest logo-retention and gross-dollar-retention cohorts
Churn rateOverall customer baseLowRequest gross and net churn with top-20 customer contribution
Contract duration / renewal structureAnnual or multi-year agreements mentioned on PeerSpotMixed enterprise segmentsLowObtain sample order forms, renewal dates, and termination rights by segment
Public satisfaction / visibility proxyFeaturedCustomers 4.7/5 with 133 references, but 0 AWS reviews and 0 Slashdot ratings on reviewed pagesPublic proof surfaceMediumReconcile public review density with actual renewal and support KPIs

Null means the metric was not publicly disclosed in the reviewed corpus; the visible review and contract signals are proxies, not substitutes for retention data.

[CU037, CU038, CU039, CU040]
Expansion and Concentration Risk Table
Expansion driver or concentration riskWhat public evidence showsImpact on the thesisDiligence path
Microsoft-centric cross-sellCalifornia, ODEON, Snappi, Beeks, and ClearBank all tie BlueVoyant closely to Microsoft-centric security operationsStrong expansion logic inside Microsoft-heavy accounts, but product breadth outside that stack is less visibleRequest product-by-product ARR, attach rates, and win rates outside Microsoft-led deployments
Public-sector contract route dependenceCarahsoft, SEWP, ITES-SW2, CMAS, and SCRIPTS create meaningful government accessHelps scale distribution, but procurement timing and channel execution could shape revenue concentrationRequest bookings split by direct vs channel and by contract vehicle
Financial-services compliance pullSnappi, Beeks, and financial-services content suggest compliance-led demand and operational-resilience valueGood sector fit, but named-bank depth is still limitedRequest top financial-services accounts, pipeline conversion, and referenceability by subsegment
Marquee-reference concentrationThe public proof set is led by a small number of deep stories rather than a broad set of equally detailed referencesA few flagship accounts may overstate overall deployment depth if the long tail is shallowerRequest top-10 customer revenue share and number of customers above material ARR thresholds
Durability visibility gapNo public NRR, GRR, churn, renewal, or top-customer concentration disclosures were foundThis is the largest remaining diligence blocker for underwriting customer qualityObtain cohort tables, renewal dashboards, and concentration schedules under NDA

This exhibit mixes upside and risk because BlueVoyant’s public file is strongest on why accounts buy and weakest on how durable those accounts are over time.

[CU026, CU028, CU030, CU031, CU039, CU040]
Chapter 07

07Risks

7.1 Regulatory, Privacy, and Adverse Signals

BlueVoyant does not present as a company under broad public enforcement today, but its visible operating surfaces still create real regulatory and legal exposure. The company’s privacy and legal notice says BlueVoyant LLC is the controller for website personal data and may share personal information with affiliates unless prohibited by law, which is not unusual but still matters for buyers that scrutinize controller boundaries, affiliate access, and global data handling. The bigger external constraint comes from the company’s government- and defense-adjacent motion. BlueVoyant Government Solutions explicitly sells supply-chain defense, CMMC support, and NIST 800-171 compliance management into federal and defense contexts, and the DoD’s CMMC rollout is now active in live contracts. That means the risk is not abstract regulation; it is execution against procurement-linked cyber controls that can delay or disqualify wins if BlueVoyant or its customers cannot evidence readiness. The clearest adverse company-specific signal in the current public file is the Steward Health adversary complaint against Bluevoyant LLC in Texas bankruptcy court. Public docket text alone does not quantify exposure, merit, or expected outcome, but it is still the one live adverse item that warrants direct diligence on factual background, insurance, reserve treatment, and whether it reflects a billing, delivery, or vendor-management dispute. Separately, SAM.gov and USAspending make federal award data publicly traceable, which is useful because BlueVoyant’s contract-vehicle breadth is visible while actual agency-level concentration and renewal dependence are not. Overall, legal and regulatory risk is manageable only if the company can show privacy governance discipline, current public-sector compliance readiness, and a contained explanation of the Steward matter.[CR015, CR016, CR017, CR018, CR019, CR020]

Regulatory / Legal Risk Register
Rule / case / controlJurisdictionStatusLikelihoodSeverityMitigationResidual exposureDiligence path
DoD CMMC rollout for defense-linked workUnited States / DoDPhase 1 active from 2025-11-10 with Level 1 and Level 2 self-assessmentsHighHighUse existing CMMC and NIST support positioning to evidence readinessHigh — missing or weak certification evidence can slow awards or exclude bidsObtain internal CMMC level mapping, latest SPRS affirmations, and customer references tied to CMMC work
NIST SP 800-171 obligations in contract executionUnited States / federal procurementPersistent baseline control framework for nonfederal systems handling CUIHighHighMap delivery processes to 800-171 control coverageMedium-High — control gaps become procurement, audit, or remediation burdensRequest formal control matrix, inheritance model, and any third-party assessments
Steward Health adversary complaintTexas Southern Bankruptcy CourtActive public docket as of 2026-06-26MediumMedium-HighLegal defense, insurance, and negotiated resolution if exposure is limitedMedium — factual and dollar exposure remain unclear from the public docket aloneReview complaint, answer, claimed amount, payment history, and any insurer correspondence
Website privacy governance and affiliate sharingWebsite / cross-border data governancePrivacy notice states BlueVoyant LLC is controller and may share with affiliates unless prohibitedMediumMediumClarify controller boundaries, affiliate access, and retention limits in deal-specific DPAsMedium — buyer diligence burden rises if data flows are not crisply boundedRequest product-level DPA, subprocessors, and regional data-flow maps
Federal award transparency and agency scrutinyUnited States / procurement dataSAM.gov and USAspending make contract-award diligence feasible but company mix is undisclosedMediumMediumPre-build agency and vehicle analytics before underwriting concentrationMedium — hidden concentration can surface late in diligencePull agency-level awards by legal business name and reconcile to management revenue segmentation

Rows are ordered by residual severity using public evidence only; they are not a substitute for counsel review or contract-by-contract compliance testing.

[CR015, CR016, CR017, CR018, CR019, CR020]

7.2 Microsoft Ecosystem and Competitive Platform Risk

BlueVoyant’s strongest public advantage is also one of its largest strategic dependencies. The company markets itself as a Microsoft security specialist across Sentinel, Defender, Purview, Copilot readiness, and adjacent cost-of-adoption assessments; Microsoft and BlueVoyant materials both reinforce that BlueVoyant helps shape Sentinel use cases, analytics, and Security Copilot content. Awards and ecosystem recognition confirm real channel credibility, and the partner stack is clearly not superficial. But that also means BlueVoyant’s differentiation is exposed to Microsoft roadmap choices, pricing changes, packaging shifts, and native-feature expansion. If Microsoft makes more workflows turnkey inside its own stack, BlueVoyant has to keep proving that its expert services, content, and operational judgment justify the extra spend rather than becoming optional wraparound labor. Competitive intensity is high because BlueVoyant is not defending a narrow wedge. Public materials and review directories place it across MDR, Microsoft-managed security, digital risk, supply-chain defense, and third-party risk management. That gives the company multiple shots on goal, but it also means buyers can compare BlueVoyant against more specialized vendors in each category. The company’s own Sentinel case-study eBook and Gartner-market-guide blog suggest that BlueVoyant wins by reducing complexity and helping customers operationalize risk, not by owning a unique underlying platform. That is valuable, but it is harder to defend if Microsoft partners proliferate, if focused MDR vendors outperform on service depth, or if best-of-breed TPRM vendors out-execute on a single workflow. In short, Microsoft channel strength de-risks demand generation while increasing commoditization and concentration risk at the same time.[CR001, CR002, CR003, CR004, CR005, CR006]

Partner / Dependency Risk Register
DependencyCounterparty / ecosystemRoleConcentrationFailure scenarioSeverityMitigationResidual exposure
Microsoft security stackMicrosoftCore telemetry, workflow, and services substrate for major BlueVoyant offersHighNative Microsoft improvements compress the value of BlueVoyant overlay servicesHighKeep proving differentiated deployment, content, and managed-operations valueHigh
Microsoft channel credibility and awardsMicrosoft / MISA ecosystemDemand generation and trust signal for Microsoft-centered buyersHighRoadmap, co-sell, or partner-program shifts weaken pipeline efficiencyHighDiversify proof points beyond awards and Microsoft-only success storiesMedium-High
Sentinel partner ecosystem build-outMicrosoft Sentinel ecosystemBlueVoyant creates analytics, playbooks, queries, and Copilot agents on top of SentinelHighAPIs, platform economics, or store distribution rules change materiallyHighStay close to product teams and maintain delivery assets customers cannot easily replicateHigh
Public-sector procurement vehiclesCarahsoft and government contracting channelsAccess route into agencies and defense-adjacent buyersMediumVehicle access exists but underlying award mix is concentrated in a few agencies or programsMedium-HighUse SAM.gov and USAspending to measure real concentration before underwritingMedium-High
Crowded cyber-risk categoriesMDR / TPRM / supply-chain and digital-risk marketSets the benchmark buyers use to price and compare BlueVoyantHighFocused vendors out-execute on one workflow while BlueVoyant carries platform sprawlMedium-HighClarify where BlueVoyant wins on operating outcomes rather than breadth aloneMedium-High

Dependency risk is led by Microsoft concentration, but procurement-channel and category-breadth dependence also matter because they shape conversion, renewal, and pricing power.

[CR001, CR002, CR003, CR004, CR005, CR006]
FR003: Dependency Map

BlueVoyant depends on Microsoft, human SOC talent, procurement channels, and compliance proof more than on any single proprietary public metric.

[CR001, CR002, CR003, CR007, CR021, CR022]

7.3 Human Services Delivery and AI Execution Risk

BlueVoyant is trying to extend a human-led managed-security franchise into an AI-native product story without giving up the promise of expert oversight. The June 2026 BlueVoyant AI launch says customers can buy either a fully managed service backed by BlueVoyant’s elite SOC team or a SaaS platform that puts the same capabilities in customer hands. That is attractive commercially, but it raises a real operating challenge: the company now has to deliver high-quality analyst-driven service, credible autonomous workflows, and coherent pricing and packaging across both modes. Public claims about machine-speed containment, false-positive reduction, and deterministic response are ambitious. If those claims are not supported by strong guardrails, human override processes, and measurable quality outcomes, BlueVoyant could create more scrutiny rather than less—especially in regulated or high-consequence customer environments. The operating model also remains labor intensive. BlueVoyant still emphasizes 24x7 expert monitoring, global SOC coverage, and regional expansion such as the Cork center for Irish and EU clients. Those are meaningful mitigants, but they imply ongoing recruiting, training, localization, and quality-control requirements even as the company pitches automation. Leadership changes add another layer of execution risk. John Hernandez took over as CEO in 2026 with an AI-growth mandate, while the 2023 CPO hire was explicitly about unifying product direction after product-line expansion. The risk is not that BlueVoyant lacks ambition; it is that the company may have to manage service consistency, model trust, analyst workflows, and product integration all at once. Public review and directory sources acknowledge broad capability, but they do not give the SLA, MTTR, staffing-ratio, or alert-tuning evidence that would fully de-risk execution.[CR008, CR009, CR010, CR011, CR012, CR013]

Operational / Quality / Security Risk Register
Failure modeLikelihoodSeverityMitigation maturityResidual exposureUnresolved gap
Agentic-AI response misfire or weak human overrideMedium-HighHighMedium — human-centered workflow language exists, but hard quality metrics are not publicHighNo public false-positive, false-negative, or intervention-rate data for BlueVoyant AI
Managed-service and SaaS coexistence complexityHighHighMedium — one platform/two deployment modes is clear, but packaging and support boundaries are unproven publiclyHighNo public pricing architecture or migration path between managed and self-service modes
24x7 SOC staffing or analyst-quality driftHighMedium-HighMedium — regional SOC expansion is visible, but staffing ratios and SLAs are notHighNo public MTTR, staffing, or escalation-quality metrics
Regional compliance and service localization burdenMediumMedium-HighMedium — Cork expansion adds in-region coverage for EU clientsMedium-HighNo public evidence on multilingual support depth, local data-boundary design, or audit cadence
Feature sprawl across MDR, TPRM, and supply-chain productsMediumMedium-HighLow-Medium — product breadth is a sales asset but also a coordination burdenMedium-HighNo public roadmap on how product, service, and AI layers are sequenced or simplified

Operational risk is elevated by the need to sustain human delivery quality while simultaneously expanding platform breadth and AI automation claims.

[CR008, CR009, CR010, CR011, CR012, CR013]

7.4 Public-Sector Exposure, Leadership, and Financing Opacity

BlueVoyant’s public-sector posture creates both resilience and concentration risk. On the positive side, the company is visible on multiple contract vehicles through Carahsoft and presents a government-specific value proposition around supply-chain defense, cybersecurity, and compliance support. That can create durable demand because the work maps to real procurement and mission needs rather than discretionary experimentation. The downside is that government-linked revenue tends to be slower-moving, more compliance-gated, and more sensitive to certification evidence and contract execution than generic commercial SaaS. BlueVoyant’s public materials do not disclose what share of revenue comes from government or defense customers, which agencies matter most, or how renewals are distributed across programs. So the public record can establish exposure, but not diversification. Financing visibility is similarly incomplete. The clearest capital fact in the current file is the 2023 announcement that BlueVoyant raised more than $140 million in Series E financing to support the Conquest Cyber acquisition. PM Insights shows that there is at least some secondary-market and valuation monitoring around the company, but the public-facing preview is intentionally thin and does not provide underwritable current metrics. There is no cited public disclosure here on ARR, burn, runway, leverage, liquidation preferences, or current valuation. That does not prove stress, but it does mean late-stage private-market risk is real: if growth, Microsoft economics, or public-sector win rates soften, outside investors would be asked to price a business whose most important operating metrics are still largely private.[CR011, CR012, CR013, CR014, CR023, CR024]

People / Execution Risk Register
Role / functionDependency or gapLikelihoodSeverityMitigationDiligence path
Chief executive leadershipFounder-to-operator transition to John Hernandez while AI story and global scale are being pushed simultaneouslyMediumHighExperienced incoming CEO with enterprise-platform backgroundReview first-year operating priorities, sales productivity, and leadership-team stability
Product leadership and integrationCPO mandate implies ongoing product unification across acquired and legacy linesMediumMedium-HighDedicated product leader with large-vendor and portfolio experienceRequest current product map, deprecation policy, and integration milestone tracking
MDR analyst bench24x7 expert monitoring remains central even after AI launchHighHighRegional SOC footprint and managed-service historyObtain analyst-to-customer ratios, attrition, certification coverage, and escalation protocols
Regional support and localizationCork expansion and EU servicing add staffing, compliance, and time-zone complexityMediumMedium-HighIn-region SOC investment and local hiringValidate staffing ramp, language coverage, and customer-support boundaries by geography
Government and compliance specialistsPublic-sector motion depends on scarce cyber/compliance talent that can speak CMMC, NIST, procurement, and remediationMediumMedium-HighDedicated government business and partner channelsReview bid support, compliance specialists, and renewal ownership for public-sector accounts

Execution risk is driven less by founder credibility than by the need to coordinate service labor, product integration, regional support, and public-sector specialization at the same time.

[CR011, CR012, CR013, CR014, CR023, CR024]

7.5 Monitoring Triggers, Mitigation Maturity, and Data Gaps

The mitigation picture is credible but incomplete. BlueVoyant has genuine strengths: Microsoft recognition across multiple years, visible public-sector contract access, a growing EMEA SOC footprint, and a product set that spans managed detection, third-party risk, and supply-chain defense. Those are not cosmetic signals. But the company’s most important residual risks are only partially mitigated by public evidence. Microsoft dependency is softened by channel strength, not removed. BlueVoyant AI may improve unit economics and service quality, but the same launch also broadens execution scope. Government exposure can create durable demand, but it also raises the bar for compliance evidence and procurement discipline. Financing risk is still hard to score because public disclosures stop well short of the metrics needed to size dilution or exit risk. The right way to treat BlueVoyant is therefore as a business with real strategic assets but a narrow margin for execution error. The most actionable kill criteria are observable: Microsoft feature commoditization that compresses service differentiation; weak AI quality or human-override evidence; inability to evidence CMMC/NIST readiness in public-sector pursuits; adverse movement in the Steward matter; or a new financing event that implies stress rather than optionality. The public file also leaves material diligence gaps around concentration, service quality, and capital structure. Those omissions do not negate the business, but they do keep residual-risk scoring elevated. Until management can produce hard metrics on customer mix, renewal durability, SOC quality, and capital terms, the prudent underwriting stance is to treat BlueVoyant as strategically interesting but execution-sensitive.[CR004, CR005, CR008, CR010, CR017, CR021]

Mitigation and Kill Criteria Table
RiskMonitorable triggerThreshold / eventAction implication
Microsoft ecosystem dependenceEvidence that Microsoft-native features subsume BlueVoyant service content or economicsRenewal objections rise around paying for partner overlay on top of Microsoft spendRe-rate differentiation and gross-margin durability downward
AI execution qualityHuman override, false-positive, and containment-quality evidence for BlueVoyant AIManagement cannot provide credible quality metrics or customer references for autonomous workflowsTreat AI launch as risk-increasing rather than de-risking
Public-sector compliance readinessCMMC, NIST, and award-level diligence outputsMissing SPRS affirmations, weak control mapping, or stalled agency pursuits tied to compliance readinessAssume slower government growth and higher cost-to-win
Legal / adverse signal containmentDirect facts on Steward litigation, insurance, and reserve postureComplaint expands materially, damages look meaningful, or management cannot narrate the dispute cleanlyEscalate legal risk rating and revisit counterparty/process diligence
Financing opacityCurrent ARR, burn, cash runway, and any new capital eventNext round implies stress, punitive preferences, or heavy dilution without clear operating accelerationLower conviction on entry price and require stronger downside protection

These kill criteria convert soft public signals into explicit diligence tests so that channel strength and press releases are not mistaken for closed risk.

[CR017, CR021, CR030, CR032, CR036, CR037]
FR001: Risk Heatmap

Highest-impact residual risks cluster around Microsoft dependence, financing opacity, public-sector compliance, and the quality of the managed-plus-AI operating model.

[CR046, CR047, CR048, CR049, CR050, CR051]
FR002: Risk Transmission Map

Platform, compliance, or execution failures would likely hit customer trust before they show up as financing or valuation pressure.

[CR046, CR047, CR048, CR049, CR052, CR053]
Chapter 08

08Valuation

8.1 Investment Thesis and Anti-Thesis

BlueVoyant has enough scale and category breadth to make the company investable at the right price. Official company materials describe a unified platform spanning MDR, TPRM, digital risk protection, and professional services, not a single-point tool. That breadth matters because it supports a comp set wider than pure MDR and gives BlueVoyant multiple product wedges into enterprise and public-sector budgets. The 2023 growth release also suggests meaningful commercial proof: more than 900 clients, presence in 40-plus countries, and historical triple-digit recurring-revenue expansion since 2018. If the third-party 2025 ARR proxy of $213.5 million is directionally right, BlueVoyant is already a scaled cybersecurity vendor rather than a speculative pre-revenue unicorn. The anti-thesis is valuation quality, not company existence. Public secondary evidence is the key disconfirming signal in this chapter: Notice shows a 39% discount to the last round, Forge calls market activity limited, and Hiive exposes no visible price history on the public listing page. Those signals imply that the private market is either illiquid, cautious, or both. Meanwhile, the company still lacks public disclosure of current gross margin, retention, services mix, diluted share count, and any post-2023 financing terms. That combination keeps the right call at research-more rather than buy, even though the core business appears credible. [CV012, CV013, CV015, CV016, CV017, CV018]

Recommendation Summary
DimensionValueRationale
Recommendationresearch-morePublic evidence supports a plausible but not clearly mispriced $1B mark; missing private metrics still matter.
ConfidencemediumMultiple cross-checks are coherent, but the main ARR and liquidity inputs come from third-party data vendors.
Risk RatinghighSecondary discount, thin visible liquidity, and undisclosed share-count and margin data create real downside sensitivity.
Valuation StancefairThe implied ~4.7x ARR proxy is within hybrid cyber peer ranges, but not cheap enough to offset disclosure gaps.
Decision ImplicationDiligence before price-takingUpgrade only if management proves software mix, margin quality, and recent clearing prices.

Public-only view as of 2026-06-29; valuation uses third-party ARR and secondary-market previews rather than audited financial disclosure.

[CV041, CV044, CV045, CV046, CV047, CV048]
Thesis / Anti-Thesis
SideArgumentWhat Would Change the View
ThesisBlueVoyant spans MDR, TPRM, DRP, and professional services, which broadens wallet share and comp relevance.Proof that platform modules are becoming a larger share of revenue would strengthen the case.
ThesisOfficial sources show meaningful commercial scale: >900 clients, 40-plus countries, and historical triple-digit recurring-revenue growth.A credible 2026 update on client count, ARR quality, and retention would make the scale argument more durable.
ThesisIf the $213.5M ARR proxy is directionally right, $1B equates to only about 4.7x ARR—well below premium cyber leaders.Disclosure of gross margin and software mix could justify moving toward higher-quality platform multiples.
Anti-thesisNotice shows a 39% discount to the last round, implying secondary buyers may clear materially below the headline mark.A recent broker sheet or executed transaction near or above $1B would directly rebut the discount signal.
Anti-thesisForge shows limited activity and no visible Forge Price, which weakens confidence in current liquidity.Visible bid-ask depth or matched secondary prints would reduce the liquidity discount.
Anti-thesisPublic sources disagree on total capital raised and do not expose current dilution, margins, or post-2023 financing terms.A clean cap table, share count, preference stack, and current financial pack would convert the case from narrative to underwritten.

Arguments are intentionally price-sensitive: the positive case is real, but the anti-thesis is rooted in observable secondary and disclosure gaps.

[CV007, CV008, CV012, CV013, CV015, CV018]
FV001: Recommendation Logic

Decision flow from scale and comparable support through secondary-market caution and disclosure gaps to the final research-more call.

Logical decision architecture only; it summarizes the weighting of public evidence rather than a formal scoring model.

[CV034, CV037, CV038, CV044, CV045, CV048]

8.2 Financing History, Disclosure Quality, and Secondary Signals

BlueVoyant's public funding history is clear at the headline level but fuzzy in the details that matter for pricing discipline. The retained sources confirm a $250 million Series D in February 2022 and more than $140 million of new funding in November 2023, but the public filing trail is incomplete. The SEC browse result surfaces Form D notices only for 2017, 2019, and 2020; it does not surface later financing terms. Caplight, CB Insights, and GetLatka converge on $665.5 million of total funding, while Tracxn reports $696 million across six rounds and SiliconANGLE quotes Tracxn at about $646 million after the 2023 round. This is not fatal, but it means investors are using vendor summaries instead of a crisp public ledger. The secondary-market platforms deepen that caution. Caplight still anchors BlueVoyant at an estimated $1 billion and shows the last round as Series E on November 29, 2023. Forge still shows the last known valuation as $1 billion from February 2022, calls current market activity limited, and does not publish a Forge Price. PM Insights and Hiive both confirm that secondary infrastructure exists, yet the public previews do not offer enough live depth to underwrite a precise clearing price. Put differently: the market offers directionally useful signals, but not enough transparent liquidity to turn those signals into conviction without direct broker data. [CV001, CV002, CV003, CV004, CV005, CV006]

8.3 Public Comparable and Multiple Analysis

The right public comp set for BlueVoyant is mixed by design. On the higher-growth end, CrowdStrike, Palo Alto Networks, and Fortinet represent scaled security platforms with strong security-operations franchises and materially higher software quality. On the more moderate end, SentinelOne, Qualys, Tenable, and Rapid7 are the better reference points for a hybrid model that still sits closer to operational security and risk management than to a pure cloud-security winner-take-all story. Windsor Drake's 2026 sector framing is the key macro anchor: public cyber trades around 6.0x to 6.5x NTM revenue, while managed security services sit lower at about 3x to 5x. BlueVoyant's implied 4.7x multiple on the 2025 ARR proxy lands near the lower-middle of that landscape. It is far below CrowdStrike's 34.3x and Palo Alto's 23.28x, below Fortinet's 15.2x, and much closer to SentinelOne at 4.61x, Qualys at 5.73x, and Tenable at 3.32x. That is directionally sensible if BlueVoyant's revenue mix includes a meaningful services component and if the platform's automation advantages have not yet translated into disclosed software-like margins. The comp conclusion is therefore nuanced: $1 billion is not obviously too high on a revenue-multiple basis, but it is not the kind of discount that creates a clear public-evidence entry opportunity. [CV015, CV016, CV022, CV023, CV024, CV025]

Comparable Valuation Table
ComparableSegment LensMarket CapRevenue (ttm)EV/RevenueRelevance to BlueVoyantKey Limitation
CrowdStrikeSecurity operations / XDR leader$178.47B$5.09B34.30xUpper-bound software/security-operations reference.Too software-pure and too premium to be a direct base-case anchor.
Palo Alto NetworksBroad security platform incl. operations$247.92B$10.61B23.28xShows what scaled platform breadth can command.Far more mature and profitable than BlueVoyant.
FortinetSecurity platform with operations exposure$110.88B$7.11B15.20xUseful premium benchmark below PANW/CRWD.Still materially higher quality and more hardware/subscription diversified.
SentinelOneMDR / endpoint platform$5.45B$1.05B4.61xClosest public multiple check for a growth-but-not-premium security platform.Pure endpoint/software mix is still cleaner than BlueVoyant's.
QualysRisk / compliance / vulnerability$4.34B$684.86M5.73xGood reference for risk and compliance adjacency.Not a services-heavy MDR business.
TenableExposure management / vulnerability$3.33B$1.02B3.32xUseful lower-band reference for risk-oriented cyber.Product mix and GTM differ from MDR plus services.
Rapid7XDR / SIEM / exposure management$0.51B$859.23M0.93xShows the floor when public markets discount quality and growth.Likely too punitive for BlueVoyant unless margins or growth disappoint badly.

Market cap and revenue figures come from Yahoo Finance and CompaniesMarketCap snapshots accessed on 2026-06-29; EV/revenue is taken from Yahoo Finance. Values are directional public-market references, not private-market clearing prices.

[CV022, CV023, CV024, CV025, CV026, CV027]
FV002: Valuation Sensitivity — Multiple on 2025 ARR Proxy

Illustrative enterprise value in USD millions at different ARR multiples applied to the $213.5M 2025 ARR proxy.

Values are calculated from the third-party $213.5M ARR proxy and rounded to the nearest USD million; they are not broker marks.

[CV022, CV023, CV034, CV035, CV041, CV042]

8.4 Bull, Base, and Bear Valuation Scenarios

The scenario framework starts with what is actually observable. In the base case, BlueVoyant deserves a multiple around 4.0x to 5.0x on the $213.5 million ARR proxy, which yields roughly $0.85 billion to $1.1 billion. That range is consistent with the company's real scale and product breadth, but also with hybrid-margin caution and limited liquidity. In the bull case, BlueVoyant can stretch into roughly $1.2 billion to $1.5 billion if management proves that recent growth is durable, that the software and platform layer is expanding faster than services, and that recent secondary or primary price discovery supports a higher-quality cyber multiple. The bull case is therefore an execution-and-disclosure case, not just a market-multiple case. The bear case is visible already. Notice's 39% discount to the last round and Forge's absent price signal point to a downside band around $0.6 billion to $0.8 billion if the next real clearing event comes below the headline mark or if investors decide BlueVoyant belongs in the 3x to 4x managed-security range instead of a platform premium bucket. The skew is important: the public evidence does not scream overvaluation, but it does show that downside is already partially discoverable while upside still depends on private facts the market has not shared. [CV018, CV019, CV022, CV023, CV034, CV035]

Bull / Base / Bear Scenario Table
ScenarioKey AssumptionsImplied MultipleValuation Range (USD B)Probability SignalKey Risk
BullGrowth remains strong, software mix expands, and diligence supports a higher-quality platform profile.5.5x–7.0x ARR1.2–1.5Requires private evidence to overpower secondary discounts.No margin proof or weak clearing prices would break the case.
BaseARR proxy is directionally right and BlueVoyant clears as a hybrid cyber platform with moderate services discount.4.0x–5.0x ARR0.85–1.10Most consistent with retained public evidence.If ARR quality is weaker than the proxy, even base compresses.
BearThe next real clearing event validates secondary discounts and pushes BlueVoyant toward managed-security or services ranges.3.0x–3.8x ARR0.60–0.80Consistent with Notice discount and thin visible liquidity.New capital at a lower mark or poor margins would accelerate the downside.

Scenario ranges are analytical estimates in USD billions using the public ARR proxy; they are not management guidance or broker marks.

[CV018, CV023, CV034, CV041, CV042, CV043]
Thesis-Break and Kill Triggers
TriggerThreshold / EventTransmission to ThesisAction Implication
Secondary discount widensObservable discount to the last round moves beyond ~50% or a new round prices below $0.8B.Would imply the market sees materially weaker quality or liquidity than the base case assumes.Pause and re-underwrite around bear-case levels.
Services-heavy economics confirmedGross margin or revenue mix shows the business is materially more services-heavy than implied.Would cap the justified multiple closer to the managed-security range.Move stance from fair toward stretched.
No real price discoveryNo broker-backed secondary clears, bids, or cap-table evidence emerge over the next diligence cycle.Liquidity discount remains unresolved, so the market cannot validate the headline mark.Keep recommendation at research-more or downgrade.
Opaque post-2023 financingManagement cannot document any post-2023 financing terms, share count, or preference stack.Without dilution mechanics, return math is unreliable even if enterprise value looks reasonable.Do not commit capital without a cap-table package.
Growth quality weakensARR proxy proves overstated, or retention / expansion metrics fall below software-like thresholds.Breaks the base-case assumption that BlueVoyant merits at least a hybrid platform multiple.Re-rate toward the bear band immediately.

Thresholds are diligence triggers rather than contractual covenants; they translate public-market evidence into concrete kill criteria.

[CV018, CV019, CV023, CV036, CV038, CV041]
FV003: Valuation / Return Range

Scenario valuation ranges in USD millions versus the current headline $1B mark.

Ranges are analyst estimates based on retained public evidence, secondary previews, and comparable multiple brackets.

[CV041, CV042, CV043, CV048]

8.5 Recommendation, Exit Discipline, and Final Diligence Asks

The recommendation from public evidence alone is research-more. BlueVoyant looks like a legitimate scaled cybersecurity platform, and the current $1 billion headline mark is not obviously detached from the retained ARR proxy. But that is not the same as calling the valuation attractive. The public market offers only preview-level secondary signals, and the strongest one available is negative. In addition, none of the retained sources disclose the current diluted share count, margin profile, retention metrics, or the terms of any financing after November 2023. Without those facts, a buyer can explain why $1 billion is plausible, but cannot yet explain why it is clearly mispriced in their favor. Exit readiness is also limited in public evidence. Hiive states that BlueVoyant remains privately held and accessible pre-IPO only through secondary marketplaces for accredited investors, and no retained source indicates an IPO process, a strategic sale process, or a fresh valuation reset. The actionable path is straightforward: obtain current ARR composition, gross margin, NRR or customer retention, the cap table and preference stack, and actual recent secondary clears from brokers or management. If those data confirm software-like economics and stable or improving secondary pricing, the call could upgrade. If they instead confirm services-heavy revenue and continued discount trading, the fair label would slide toward stretched. [CV021, CV033, CV041, CV042, CV043, CV044]

Final Diligence Asks
TopicMissing EvidenceWhy It MattersOwner / Diligence Path
2026 ARR qualityCurrent ARR, recurring vs. services mix, and ARR bridge from 2023 to 2026.Determines whether the 2025 ARR proxy is real and whether a 4.7x multiple is fair or too high.Request current board deck or CFO operating pack.
Margin and retention profileGross margin, adjusted EBITDA, gross retention, and NRR by major product line.Needed to know whether BlueVoyant deserves hybrid-services or software-platform multiples.Management diligence session plus cohort-level retention exhibits.
Cap table and diluted share countLatest fully diluted share count, preference stack, option pool, and liquidation waterfall.Per-share return can diverge sharply from enterprise-value math when dilution is opaque.Data room cap-table export or counsel-prepared summary.
Actual secondary-clearing pricesRecent broker sheets, matched trades, and bid-ask history from cap-table administrators or marketplaces.The best public secondary signal is negative; true clears can validate or refute that discount.Direct broker diligence and admin records from Forge / Notice / company.
Any post-2023 financing termsEvidence of debt, structured financing, or side letters after the Series E round.Later capital structure changes can alter downside protection, seniority, and valuation interpretation.CFO/legal confirmation plus financing documents.

Each ask is tied to a current blocker in the public record rather than a generic diligence wishlist.

[CV011, CV021, CV044, CV046, CV047, CV048]
FV004: Investment KPIs

IC-style scoring across six dimensions that matter most to BlueVoyant's current valuation decision.

Scores are analytical and relative, intended for IC discussion rather than as mechanically derived model outputs.

[CV037, CV038, CV044, CV046, CV047, CV048]

Disclaimer

This report is provided for diligence and informational purposes only and does not constitute investment, legal, accounting, or tax advice. BlueVoyant is a private company and multiple figures in the public record remain estimated, conflicting, or stale. Any investment decision should be based on direct management diligence, customer references, audited financials, and definitive legal documentation rather than public-source synthesis alone.

Evidence index

Claims
IDStatementConfidenceSources
CO001 BlueVoyant was founded in 2017. High SO001, SO020, SO021
CO002 BlueVoyant's current headquarters is 6 East 45th Street, Floor 17, New York, NY 10017. High SO002, SO003
CO003 BlueVoyant officially says it has over 600 employees. Medium SO001
CO004 BlueVoyant officially says it has more than 1,000 customers in 45 countries. Medium SO003
CO005 BlueVoyant's core platform spans managed detection and response, third-party risk management, digital risk protection, and professional services. High SO004, SO005, SO006
CO006 BlueVoyant's MDR offering covers internal networks, cloud instances, containers, and endpoints and advertises 500+ Microsoft Sentinel deployments. Medium SO005
CO007 BlueVoyant describes its TPRM product as a fully managed service in which ROC experts review, validate, and help remediate third-party findings. Medium SO006
CO008 BlueVoyant presents itself as an AI-driven provider of internal, external, and supply-chain cyber defense. Medium SO012, SO029
CO009 John Hernandez is BlueVoyant's current chief executive officer. High SO002, SO016, SO027
CO010 James Rosenthal is a co-founder and now serves as chairman of BlueVoyant's board. High SO002, SO016, SO027
CO011 Thomas Glocer is a co-founder and vice chairman of BlueVoyant's board. High SO002, SO001
CO012 BlueVoyant's public executive bench includes Ravi Subramanian (CFO), Sebastian Sobolev (CPO), Jim Bieda (Global CTO), John Harbaugh (CISO), and Sangya Sharma (CHRO). Medium SO002
CO013 BlueVoyant's leadership page also lists solution and regional leaders including Ron Feler, Austin Berglas, Chris Teekema, Michael Spencer, Robert Hannigan, Lonny Anderson, Justin Staffel, Holly Steele, and Patrick Shea. Medium SO002
CO014 BlueVoyant published a COO appointment for Michael Montoya, stating that he would oversee technology, product, and operations. Medium SO015
CO015 BlueVoyant says it has received more than 60 awards and nominations since 2019. High SO009, SO001
CO016 BlueVoyant's awards materials say it won Microsoft's 2024 Worldwide Security Partner of the Year and 2024 U.S. and Canada Security Partner of the Year honors. High SO009, SO008
CO017 BlueVoyant markets itself as a Microsoft security expert with 10x recognition and dedicated service packaging around Sentinel, Defender, Purview, and Copilot-era security operations. High SO008, SO009
CO018 BlueVoyant's partner program emphasizes end-to-end platform resale and 24x7 access to sales, marketing, training, and certification resources. Medium SO007
CO019 BlueVoyant says it is a member of the ISTARI Collective. Medium SO007
CO020 On 2022-02-23 BlueVoyant closed a $250 million Series D led by Liberty Strategic Capital with participation from ISTARI, Eden Global Partners, and 8VC. High SO013, SO017, SO021
CO021 Independent 2022 coverage said BlueVoyant's Series D valued the company at over $1 billion and brought total funding to $525 million at that time. High SO021, SO020
CO022 TechCrunch described BlueVoyant's pre-Series-D offering as a mix of proprietary technology, third-party best-in-class tools, and professional services for internal and external cyber risk. Medium SO020
CO023 BlueVoyant announced on 2023-11-29 that it acquired Conquest Cyber and paired the transaction with more than $140 million in Series E funding. Medium SO018, SO023, SO033
CO024 CRN reported that the combined BlueVoyant-Conquest proposition was aimed at customers securing Microsoft environments across both commercial and government sectors. Medium SO022, SO024
CO025 GovConWire and BankInfoSecurity framed the Conquest acquisition as expanding BlueVoyant's reach into highly regulated, U.S. government, and defense-industrial-base environments. Medium SO023, SO024, SO018
CO026 Caplight lists BlueVoyant's last round as a Series E on 2023-11-29, with an estimated $1 billion valuation and $665.5 million of total funding raised. Medium SO030
CO027 GetLatka lists a 2025 revenue estimate of $213.5 million, $665.5 million of total funding, a $1 billion valuation, and a team size near 650 for BlueVoyant. Low SO029
CO028 Third-party private-market datasets in the reviewed set cluster around roughly $665.5 million of total funding and a $1 billion valuation, but those figures remain unaudited estimates rather than company disclosure. Medium SO029, SO030
CO029 The reviewed official company sources do not publish current ARR, GAAP revenue, gross margin, or profitability. Medium SO001, SO013, SO018
CO030 Public headcount signals diverge: BlueVoyant officially says it has over 600 employees, while third-party datasets in the retained set range from about 649-650 to 750. Medium SO001, SO029, SO030, SO031
CO031 UpGuard's June 29, 2026 vendor risk report lists BlueVoyant with 750 employees and says its assessment is based on continuous external monitoring across five risk categories. Medium SO031
CO032 UpGuard flags CSP allowing insecure active sources and use of unsafe-eval on BlueVoyant's web estate, creating the clearest adverse public signal in the retained source set. Medium SO031
CO033 BlueVoyant's contact page lists offices in New York, Leeds, London, Tel Aviv, Makati, and Bogotá plus SOC locations in Riverdale and Cork. Medium SO003
CO034 BlueVoyant's company overview page separately describes offices or support presence in College Park, Washington, D.C., London, Leeds, Cork, Toronto, Tel Aviv, Bogota, Manila, and Singapore across five continents. Medium SO001
CO035 Taken together, BlueVoyant's official pages support a globally distributed operating footprint rather than a single-office New York vendor. High SO001, SO003
CO036 BlueVoyant launched BlueVoyant AI on 2026-06-09 as an AI-native or agentic SecOps platform for both managed and self-service SOCs. High SO012, SO025, SO026
CO037 The 2026 AI launch extends BlueVoyant's existing Microsoft and SOC positioning rather than creating a wholly new category. Medium SO012, SO008, SO011
CO038 On 2025-09-24 BlueVoyant and Auto-ISAC announced a strategic engagement to elevate third-party cyber risk management across the automotive industry. High SO014, SO019
CO039 BlueVoyant's careers page emphasizes mission-driven culture, a large proprietary dataset, automation playbooks, and continual training as part of its employment brand. Medium SO010
CO040 BlueVoyant explicitly markets to companies, government entities, and critical-infrastructure organizations rather than to a narrow single vertical. Medium SO001, SO018
CO041 Cyber Insurance News summarized BlueVoyant's 2025 State of Supply Chain Defense report as showing 97% of surveyed organizations suffered negative impact from at least one supply-chain cyber breach, reinforcing the demand case behind its TPRM positioning. Medium SO032, SO014
CO042 PRNewswire and Enterprise IT World show a May 2026 CEO transition from co-founder Jim Rosenthal to John Hernandez while Rosenthal remained chairman. High SO016, SO027, SO002
CO043 The CEO handoff reduces single-person operating dependence, but founder-linked governance and brand concentration remain meaningful because Rosenthal and Glocer continue in chair and vice-chair roles. Medium SO002, SO016, SO027
CO044 BlueVoyant's public leadership materials foreground founders in governance or advisory roles rather than as the day-to-day executive bench. Medium SO002
CO045 Caplight characterizes BlueVoyant's customer profile as a B2B mix of subscription SaaS, services and consulting, and government contracts. Medium SO030
CO046 Caplight tags BlueVoyant around threat intelligence, incident response, vulnerability management, cloud security, and compliance or risk workflows. Medium SO030
CO047 The combination of MDR, TPRM, and professional-services pages indicates BlueVoyant monetizes both recurring software modules and analyst-led managed services. Medium SO005, SO006, SO030
CO048 In the reviewed public source set, the last specifically dated financing event is the more-than-$140 million Series E announced on 2023-11-29 alongside the Conquest acquisition. Medium SO018, SO023, SO030, SO033
CM001 BlueVoyant markets MDR as protection for internal networks, cloud instances, containers, and endpoints that augments existing EDR, SIEM, and cloud security tools. Medium SM001
CM002 BlueVoyant markets TPRM as a fully managed solution that identifies, validates, and resolves critical cybersecurity issues in a third-party ecosystem. High SM002, SM003
CM003 BlueVoyant's TPRM module set includes continuous monitoring and remediation, questionnaire management, point-in-time risk assessments, and program consulting. Medium SM002
CM004 BlueVoyant's continuous-monitoring workflow includes analyst-directed remediation, business risk monitoring, tiered vendor analysis, zero-day alerting, fourth-party analytics, and APIs/integrations. Medium SM003
CM005 BlueVoyant's fourth-party analytics motion goes beyond direct-vendor questionnaires into fourth- and nth-party dependency mapping and what-if analysis. Medium SM005
CM006 BlueVoyant's AI positioning emphasizes augmenting human judgment in attack-surface monitoring, threat detection, and vulnerability analysis instead of promising a fully autonomous cyber workflow. Medium SM001, SM004
CM007 BlueVoyant's direct market boundary is the overlap between managed SecOps and cyber-focused third-party risk management rather than generic GRC or stand-alone security controls. High SM001, SM002, SM003, SM005
CM008 The most relevant adjacent budget pools are GRC, board reporting, and resilience workflows, but those categories should remain outside BlueVoyant's direct core TAM. Medium SM015, SM020, SM023
CM009 Precedence Research sizes the MDR market at USD 3.92B in 2026 and USD 13.90B by 2035, implying 15.12% CAGR from 2026 to 2035. Medium SM006
CM010 Mordor Intelligence sizes the MDR market at USD 5.09B in 2026 and USD 13.45B by 2031, implying 21.45% CAGR. Medium SM007
CM011 The Business Research Company sizes the MDR market at USD 4.16B in 2026 and USD 8.57B by 2030, implying 19.8% CAGR. Medium SM008
CM012 Published MDR baselines conflict materially, with 2026 starting values ranging from USD 3.92B to USD 5.09B and growth assumptions ranging from 15.12% to 21.45% CAGR. Medium SM006, SM007, SM008
CM013 Grand View Research sizes TPRM at USD 7.42B in 2023 and USD 20.59B by 2030 at 15.7% CAGR, with North America holding more than 38% of revenue in 2023. Medium SM009
CM014 NextMSC says the TPRM market reached USD 9.71B by end-2025 and will reach USD 18.28B by 2030 at 13.48% CAGR, with large enterprises expected to dominate demand. Medium SM010
CM015 The Business Research Company says the TPRM market will grow from USD 8.09B in 2026 to USD 15.45B by 2030 at 17.6% CAGR. Medium SM011
CM016 Published TPRM baselines also conflict materially, with direct and normalized 2026 values ranging from roughly USD 8.09B to USD 11.49B depending on methodology and category scope. Medium SM009, SM010, SM011
CM017 The broader adjacent GRC software market is much larger than BlueVoyant's direct wedge, at an estimated USD 23.32B in 2026 growing to USD 39.01B by 2031. Medium SM020
CM018 Combining MDR and TPRM published baselines suggests a gross 2026 core-market ceiling for BlueVoyant of roughly USD 12.0B to USD 16.6B before removing overlap. Low SM006, SM007, SM008, SM009, SM010, SM011
CM019 Applying large-enterprise, regulated-buyer, and western-market filters to the gross ceiling yields a practical BlueVoyant SAM of roughly USD 5B to USD 8B. Low SM007, SM009, SM010, SM011
CM020 Public data does not support a precise dollar SOM for BlueVoyant because the company does not disclose module-level revenue or the split between MDR, TPRM, Microsoft-managed services, and adjacent offerings. Low SM001, SM002, SM003, SM004, SM005
CM021 MDR spending is enterprise-skewed: Mordor says large enterprises accounted for 57.65% of 2025 MDR spend, while TBRC lists major adopters across BFSI, IT, government, and energy verticals. Medium SM007, SM008
CM022 BlueVoyant's practical SAM is likely western-market skewed because Mordor assigns North America 45.78% of MDR revenue in 2025 and Grand View gives North America more than 38% of TPRM revenue. Low SM007, SM009
CM023 Large enterprises dominate public TPRM demand because they manage extensive vendor ecosystems, global supply chains, and complex regulatory requirements. Medium SM010
CM024 BlueVoyant's TPRM workflow implies a buying committee that spans security, vendor-risk operations, compliance, procurement, and resilience owners rather than a single budget line. Medium SM002, SM003, SM005
CM025 Panorays says 85% of CISOs lack full supply-chain visibility and only 41% monitor fourth parties, validating a core buyer pain point for BlueVoyant's dependency-mapping and monitoring wedge. Medium SM014, SM005
CM026 Panorays says 62% of CISOs saw regulatory pressure increase and only 22% feel fully prepared, showing that buyer urgency is rising even where operating readiness remains low. Medium SM014
CM027 Marsh says 70% of organizations experienced at least one material third-party cyber incident in the past year and 66% plan to increase cybersecurity investment in the coming year. Medium SM013
CM028 KPMG says regulatory compliance and cyber risk are now the primary drivers shaping TPRM strategy globally. Medium SM012
CM029 BlueVoyant's MDR positioning is an overlay and optimization motion for existing security tooling, not a pure rip-and-replace platform sale. Medium SM001, SM004
CM030 BlueVoyant's TPRM positioning suggests payer logic often extends from security into procurement and enterprise-risk owners because remediation and onboarding workflows sit outside the SOC. Medium SM002, SM003
CM031 SEC cybersecurity disclosure rules require public companies to disclose material cyber incidents within four business days and to describe cybersecurity risk management, strategy, and governance. Medium SM016
CM032 NIS2 creates a unified EU cybersecurity framework across 18 critical sectors, expanding the set of organizations that must take supplier and operational cyber risk seriously. Medium SM017
CM033 CISA defines ICT supply-chain cyber risk as spanning hardware, software, and managed services from third-party vendors, suppliers, service providers, and contractors. High SM023, SM024
CM034 NIST CSF 2.0 and CISA's SCRM materials show that cyber supply-chain risk is now treated as a formal management and resilience discipline rather than a narrow procurement checklist. High SM015, SM023, SM024
CM035 Gartner says AI, geopolitical tension, regulatory volatility, and an accelerating threat landscape are the forces shaping cybersecurity buying priorities in 2026. Medium SM018
CM036 KPMG says only about one in five organizations have achieved full TPRM integration with ERM and only 5% have adopted end-to-end managed-service models. Medium SM012
CM037 Black Kite says that in 2025 each vendor breach compromised an average of 5.28 downstream companies, which makes fourth-party and concentration analysis commercially relevant. Medium SM021
CM038 BlueVoyant claims its TPRM monitoring uses AI/ML across more than 50,000 data sources and can issue zero-day alerts in as little as 90 minutes, aligning the product with continuous-risk rather than periodic-review buying criteria. Medium SM003, SM005
CM039 CyberProof says Gartner has warned that some providers misuse the MDR label by offering managed EDR or other tool-centric monitoring without full human-led incident-response leadership. Medium SM019
CM040 CyberProof says MDR has moved toward mainstream adoption, citing projections that half of organizations would use MDR services for 24x7 monitoring, detection, and containment. Low SM019
CM041 KPMG says most organizations still rely on a patchwork of disconnected tools, which constrains category standardization and slows end-to-end TPRM adoption. Medium SM012
CM042 Panorays' data implies that many buyers still operate with major blind spots beyond direct vendors, so category adoption is limited as much by process maturity as by software availability. Medium SM014
CM043 CRC says global cyber-insurance pricing fell about 7% in Q4 2025 as market capacity improved, which can soften one urgency lever for cyber-spend escalation. Medium SM022
CM044 CRC says ransomware remained the primary driver of business interruption claims and that supply-chain and vendor risk stayed a central underwriting focus in 2026. Medium SM022
CM045 PeerSpot's MDR category page shows that buyers actively compare many vendors and still ask what differentiates MDR from a traditional SOC, reinforcing category crowding and education friction. Medium SM025
CM046 BlueVoyant's market should not be equated with generic GRC because BlueVoyant sells cyber monitoring, validation, remediation, and dependency visibility rather than broad policy-and-audit software alone. Medium SM002, SM003, SM020
CM047 BlueVoyant's strongest valuation support comes from cross-sell between independently growing MDR and TPRM categories that are both being pulled forward by regulation and operating pain. Medium SM006, SM007, SM011, SM013, SM018
CM048 The main market risk is not whether the categories exist, but whether BlueVoyant can win inside crowded, definition-sensitive categories where buyer confusion, tool sprawl, and budget scrutiny can slow conversion. Medium SM012, SM019, SM022, SM025
CM049 BlueVoyant's differentiated TPRM wedge appears to be analyst-led remediation plus fourth-party mapping, not just questionnaire automation. Medium SM002, SM003, SM005, SM014
CM050 BlueVoyant's differentiated MDR wedge appears to be overlaying and optimizing existing Microsoft, EDR, and SIEM environments with 24x7 monitoring and automation rather than selling a stand-alone security control. Medium SM001, SM004
CP001 Gartner defines MDR as a provider-operated, outcome-driven SOC service that includes active disruption and containment rather than alerting alone. Medium SP027
CP002 BlueVoyant publicly positions itself across MDR, TPRM, digital risk protection, and professional services rather than as a single-product MDR vendor. Medium SP001
CP003 BlueVoyant highlights 1,200+ Microsoft Sentinel deployments, 10 Microsoft security awards, and 24x7 in-regional SOC monitoring across Europe and the US. Medium SP001
CP004 BlueVoyant’s MDR page advertises 50+ certified Microsoft Delivery and SOC engineers plus unlimited remote incident-response lifecycle support. Medium SP003
CP005 BlueVoyant says it was founded in 2017 and has over 600 employees across offices on five continents. Medium SP002
CP006 BlueVoyant Government’s C-SCRM product says it uses more than 70,000 unique proprietary, open-source, and commercial data feeds without requiring agency or vendor proprietary data. Medium SP005
CP007 BlueVoyant Government says it can map, monitor, and mitigate risk for tens of thousands of suppliers at once and validate 100% of supplier risk events. Medium SP005
CP008 BlueVoyant’s June 2026 launch of BlueVoyant AI signals a strategic move toward agentic SecOps that can be consumed either as a fully managed SOC or a self-service SaaS platform. Medium SP006
CP009 Palo Alto positions Cortex XSIAM as a unified AI-driven SOC platform spanning SIEM, SOAR, EDR, NDR, and CDR. Medium SP007
CP010 Palo Alto advertises 10,000+ detections, 2,600+ analytics models, and Unit 42-managed services on top of XSIAM. Medium SP007
CP011 Palo Alto says it has 16K+ employees and 70K+ customers globally, giving it distribution scale that BlueVoyant cannot match publicly. Medium SP008
CP012 CrowdStrike Falcon Complete advertises a one-minute median time-to-contain and 2.7 million detections remediated monthly. Medium SP009
CP013 CrowdStrike frames Falcon Complete as agentic MDR that combines deterministic automation, adaptive AI agents, human-in-the-loop experts, and native visibility across endpoint, identity, cloud, and third-party data. Medium SP009
CP014 Arctic Wolf positions around a fully managed agentic SOC with 10,000+ customers, 1,000+ security engineers, and 200+ integrations. Medium SP010, SP011
CP015 Arctic Wolf says its proactive MDR can reduce attack frequency and impact by up to 90% and completed more than 74,000 security posture reviews in 2025. Low SP010
CP016 Arctic Wolf’s value proposition centers on concierge delivery, open XDR, security-journey guidance, and warranty coverage rather than a single endpoint platform. Medium SP010, SP012
CP017 CRN reported that Arctic Wolf raised $60 million in Series D to help the company prepare for IPO-related thresholds. Medium SP032
CP018 SC Media reported that Arctic Wolf was valued at roughly $4.3 billion while management avoided committing to an IPO timeline. Medium SP033
CP019 Rapid7 says it serves more than 11,500 customers worldwide and positions itself as a leader in AI-powered managed cybersecurity operations. Medium SP013
CP020 Rapid7’s Incident Command platform ties exposure management, endpoint and cloud telemetry, third-party sources, Rapid7 Labs intelligence, and 20 years of data into one detection-and-response workflow. Medium SP014
CP021 ReliaQuest describes GreyMatter as an agentic AI security operations platform that detects, contains, investigates, and responds regardless of data source. Medium SP015
CP022 ReliaQuest’s homepage says GreyMatter processes 50K+ alerts daily with 255+ technology partners and 99.4% AI investigation accuracy. Medium SP016
CP023 ReliaQuest’s integrations posture supports enterprises that want to keep existing SIEM, EDR, and cloud tools rather than replace them with one vendor stack. Medium SP017
CP024 eSentire says it protects 2,000+ customers across 35+ industries and pairs Atlas AI with 24/7 expert human SOC coverage. Medium SP018
CP025 eSentire’s XDR platform and third-party coverage claim a vendor-independent model with broad integrations and human-controlled AI response. Medium SP019, SP034
CP026 eSentire’s competitive messaging explicitly emphasizes unlimited threat hunting, unlimited incident handling, and any-signal integration breadth. Medium SP020
CP027 SecurityScorecard says 70% of the Fortune 100 trust its data, 3,300+ organizations use the platform, and 12M+ organizations are monitored and rated. Medium SP022
CP028 SecurityScorecard’s TPRM pitch combines questionnaire review, technical-ground-truth validation, continuous monitoring, nth-party visibility, remediation blueprints, and risk quantification. Medium SP021, SP023
CP029 SecurityScorecard publicly frames itself as supply-chain detection and response rather than only a passive cyber-ratings tool. Medium SP021, SP022
CP030 BitSight says its TPRM product includes 75K+ mapped vendor profiles and claims a 75% reduction in third-party breach probability for customers. Low SP025
CP031 BitSight says it continuously monitors 40M+ companies and 250M+ digital assets and exposes cyber risk through APIs, integrations, and data feeds. Medium SP024, SP025
CP032 Bitsight’s April 2026 press release says it was named a Forrester Leader and had more than 3,500 customers plus over 68,000 organizations active on platform. Medium SP026
CP033 Gartner’s 2026 MDR market page lists 173 products and reiterates that immediate remote mitigative response is a mandatory MDR feature. Medium SP027
CP034 PeerSpot says BlueVoyant CORE held 0.9% MDR mindshare in June 2026, down from 1.2% the year before. Medium SP028
CP035 PeerSpot’s BlueVoyant-versus-CrowdStrike comparison ranks BlueVoyant #34 in MDR while CrowdStrike is ranked #2 and holds 5.4% mindshare versus BlueVoyant’s 0.9%. Medium SP029
CP036 PeerSpot says reviewers occasionally note limited reporting customization for BlueVoyant and characterize CrowdStrike as broader and faster to deploy. Medium SP029
CP037 Daylight’s 2026 buyer guide classifies BlueVoyant among MSSPs offering MDR that are chosen for broad security partnership but use more analyst-hours-intensive investigation workflows than AI-native or XDR-extended alternatives. Medium SP031
CP038 Ciphers Security says the TPRM market splits between outside-in security-ratings platforms and workflow-oriented lifecycle tools such as ProcessUnity, OneTrust, Venminder, and Prevalent. Medium SP030
CP039 The same Ciphers Security guide says ratings tools assess vendors from the outside in, while workflow platforms manage questionnaires and lifecycle tasks from the inside, so many buyers blend the two approaches. Medium SP030
CP040 BlueVoyant’s public combination of MDR, TPRM, digital-risk protection, and government C-SCRM gives it a cross-budget story that most MDR-only or ratings-only competitors do not present on one surface. Medium SP001, SP004, SP021, SP024
CP041 The retained official pages for BlueVoyant, CrowdStrike, Arctic Wolf, Rapid7, ReliaQuest, eSentire, SecurityScorecard, and BitSight do not disclose enterprise list pricing for their full offerings, implying quote-based sales motions and limited public comparability. Medium SP001, SP009, SP010, SP013, SP015, SP018, SP021, SP024
CP042 Platform-native competitors create bundling pressure because Palo Alto, CrowdStrike, and Rapid7 tie managed response to broader SOC, XDR, or SIEM suites with unified telemetry and automation. Medium SP007, SP009, SP014
CP043 Arctic Wolf, ReliaQuest, and eSentire represent a separate open-stack threat because all three publicly stress preserving the customer’s existing security tools while adding 24x7 expert operations. Medium SP010, SP017, SP019
CP044 BlueVoyant’s supply-chain defense competes against much larger publicly described data networks because SecurityScorecard and BitSight cite millions of monitored organizations or tens of thousands of mapped vendor profiles. Medium SP022, SP025, SP026
CP045 BlueVoyant is best aligned to Microsoft-heavy or regulated buyers that want managed SOC operations plus outside-in supplier defense rather than a single-vendor endpoint suite or a pure ratings tool. Medium SP001, SP003, SP005, SP006, SP021, SP024
CP046 Internal SOC build remains a substitute, but Gartner and Decryption Digest both frame outsourced MDR as a way to avoid the staffing and response burden of self-running security operations. Medium SP027, SP031
CI001 BlueVoyant publicly packages MDR, TPRM, DRP, and professional services as four core commercial solution families. Medium SI001
CI002 BlueVoyant claims more than 1,200 successful Microsoft Sentinel deployments. Medium SI001
CI003 BlueVoyant claims customers can reduce Sentinel costs by 40% without sacrificing coverage. Medium SI001
CI004 BlueVoyant claims it provides 24x7 in-regional SOC monitoring across Europe and the United States. Medium SI001
CI005 BlueVoyant claims its TPRM offer drives 18x faster remediation of critical issues. Medium SI001
CI006 BlueVoyant claims 98% accuracy for critical vulnerabilities identified in its TPRM motion. Medium SI001
CI007 BlueVoyant claims an average response time of 3.5 hours for recently disclosed zero-day vulnerabilities. Medium SI001
CI008 BlueVoyant claims it remediated more than 1,600 vulnerabilities on behalf of clients in the last 30 days. Medium SI001
CI009 BlueVoyant claims it completed 50,000 successful domain takedowns over the prior two years. Medium SI001
CI010 BlueVoyant says it has over 600 employees across offices spanning five continents. Medium SI002
CI011 BlueVoyant publicly positions channel partners such as GuidePoint Security and CDW as part of its distribution model. Medium SI003
CI012 BlueVoyant's build-versus-buy marketing says a self-built 24/7 SOC can cost more than $1.2 million annually. Medium SI004
CI013 The same BlueVoyant page says a partnered MSSP can cost less than 25% of the annual cost of building an internal SOC. Medium SI004
CI014 BlueVoyant said it added 299 new customers during 2021. Medium SI005
CI015 BlueVoyant said customer count exceeded 700 across 30 countries by early 2022. High SI005, SI006
CI016 BlueVoyant said its employee count increased by 130% during 2021. Medium SI005
CI017 BlueVoyant said partners contributed 50% of all new business in 2021. Medium SI005
CI018 BlueVoyant said annual recurring revenue had grown 117% on average since 2018. High SI005, SI006
CI019 BlueVoyant closed a $250 million Series D round led by Liberty Strategic Capital with participation from ISTARI, Eden Global Partners, and 8VC. High SI006, SI022
CI020 BlueVoyant said it had grown to more than 560 employees and more than 700 customers by the Series D announcement. Medium SI006
CI021 BlueVoyant said it expanded into more than 10 countries during 2021. Medium SI006
CI022 BlueVoyant acquired Conquest Cyber and raised more than $140 million of Series E funding alongside the deal. High SI007, SI018, SI019, SI020, SI021
CI023 The Series E funding was led by Liberty Strategic Capital and ISTARI, with Eden Global Capital Partners acting as strategic adviser. High SI007, SI018, SI019, SI020, SI021
CI024 BlueVoyant said Conquest Cyber added SaaS technology and FedRAMP Marketplace credentials for defense and government use cases. Medium SI007, SI020
CI025 BlueVoyant said it had more than 900 global customers when Timothy Yost joined as CFO in June 2024. Medium SI008
CI026 BlueVoyant framed the Timothy Yost hire as scaling the company's financial and strategic planning capability. Medium SI008
CI027 BlueVoyant said it served over 1,000 customers in more than 45 countries by March 2025. High SI009, SI026
CI028 BlueVoyant said local EMEA revenue grew 70% in 2024 and described Cork as part of a multi-million-euro regional investment program. Medium SI009
CI029 BlueVoyant's commissioned Forrester MDR study claims 210% ROI over three years. Medium SI010
CI030 The same MDR study claims a 90% reduction in total escalated alerts per month. Medium SI010
CI031 The same MDR study claims a 70% acceleration in mean time to resolve. Medium SI010
CI032 BlueVoyant's commissioned Supply Chain Defense study claims nearly 300% return on investment. Medium SI011
CI033 The same Supply Chain Defense study claims a 62% reduction in time to remediate critical risks. Medium SI011
CI034 BlueVoyant's Snappi case study says the customer achieved 24x7 SOC coverage within months instead of hiring across multiple vendors. Medium SI012
CI035 BlueVoyant's ODEON case study says the deployment spans 8 countries and more than 280 cinemas. Medium SI013
CI036 BlueVoyant's ODEON case study says the program cut alerts requiring InfoSec or regional IT review by 98%. Medium SI013
CI037 BlueVoyant's ODEON case study says the program resolved 30 critical or high third-party vulnerabilities. Medium SI013
CI038 BlueVoyant said Google Cloud Marketplace availability removes procurement friction for its TPRM offer. Medium SI014
CI039 BlueVoyant's Microsoft-security ROI blog says an enterprise can spend up to $750,000 annually to optimize the stack internally. Medium SI015
CI040 BlueVoyant's Sentinel deployment guide says its examples are drawn from hundreds of deployments and 16 anonymized case studies. Medium SI016
CI041 Private Equity Insights reported that BlueVoyant intended to use Series D proceeds for product development and international expansion. Medium SI022
CI042 CB Insights reported that BlueVoyant had raised $665.5 million over 9 rounds. Medium SI023
CI043 CB Insights reported a $1.0 billion valuation in February 2022. Medium SI023
CI044 CB Insights estimated BlueVoyant's 2024 revenue at $750 million, which conflicts with lower recurring-revenue estimates in other databases. Low SI023
CI045 GetLatka estimated BlueVoyant's 2025 revenue at $213.5 million. Low SI024
CI046 GetLatka estimated BlueVoyant employed about 650 people in 2025. Low SI024
CI047 Clay reported $665.5 million of total funding and a latest funding date of 2023-11-01. Medium SI026
CI048 Clay reported 11 investors and over 1,000 customers across 45 countries. Medium SI026
CI049 Dialectica listed BlueVoyant at 653 employees and named Liberty Strategic Capital as an investor. Medium SI025
CI050 Tracxn reported $696 million of total funding across 6 rounds, conflicting with the $665.5 million totals cited by CB Insights and Clay. Low SI027
CI051 PitchBook's accessible snapshot showed 363 employees and a $30 million latest deal amount, conflicting with the 600-plus employee signals from later sources. Low SI028
CI052 PitchBook's accessible snapshot included a historical Debt - PPP financing entry dated 2020-04-27. Medium SI028
CI053 Companies House shows BlueVoyant UK Limited filed full accounts for the year ended 2024 on 2025-09-30. Medium SI029
CI054 Companies House shows a compulsory strike-off action against BlueVoyant UK Limited was discontinued in March 2025. Medium SI029
CI055 Companies House shows BlueVoyant Ltd also filed full accounts for the year ended 2024 on 2025-09-30. Medium SI030
CI056 An archived Indeed review described BlueVoyant as extremely top heavy with management. Low SI031
CI057 The same archived review alleged consistent bi-yearly layoffs and resource cuts across some business units. Low SI031
CI058 No retained public source verified current cash on hand, monthly burn, or runway as of 2026-06-29. Medium SI001, SI002, SI006, SI007, SI008, SI009, SI023, SI024, SI026, SI027, SI028
CI059 No retained public source disclosed realized contract pricing, discounting, gross margin, NRR, or CAC payback for BlueVoyant. Medium SI001, SI004, SI010, SI011, SI014, SI015, SI023, SI024, SI026
CI060 The public record supports a recurring managed-services model but does not reconcile the mix between software-like recurring revenue and project-based services. Medium SI001, SI005, SI006, SI007, SI010, SI011, SI012, SI013
CI061 Using GetLatka's $213.5 million revenue estimate and Dialectica's 653-employee estimate implies roughly $327,000 of revenue per employee. Low SI024, SI025
CI062 Using the $665.5 million consensus total raised and GetLatka's $213.5 million revenue estimate implies cumulative funding of roughly 3.1x estimated annual revenue. Low SI024, SI026
CI063 BlueVoyant's current public financial signal set is too contradictory to underwrite revenue quality or runway without management data. Medium SI023, SI024, SI025, SI026, SI027, SI028, SI029, SI030, SI031
CE001 BlueVoyant currently defines its customer-facing offer as Agentic SecOps, MDR, and TPRM that protect the full attack surface. Medium SE001
CE002 BlueVoyant publicly advertises Microsoft-focused scale signals including 1,200-plus Sentinel deployments, 24x7 in-regional SOC monitoring, and named cost savings. Medium SE001
CE003 The Cyber Defense Platform page organizes the portfolio into MDR, TPRM, DRP, and professional-services suites. Medium SE002
CE004 BlueVoyant’s 2024 platform launch describes a single cloud-native platform integrating internal, external, and supply-chain defense. High SE002, SE021
CE005 The platform is described as processing signals and alerts from internal networks, supply chains, and the clear, deep, and dark web. High SE021, SE027
CE006 BlueVoyant AI says the company matches human expertise, deterministic automation, and AI agents to the mission rather than treating AI as a universal substitute. High SE003, SE022
CE007 BlueVoyant AI is offered both as a fully managed service and as a SaaS platform for internal security teams. High SE003, SE022
CE008 BlueVoyant AI publicly claims automated response actions including device isolation, credential revocation, and malicious-email eradication. Medium SE022
CE009 BlueVoyant AI attributes its Microsoft advantage to almost ten years of operating experience and more than 2,500 Microsoft-native customer deployments. Medium SE022
CE010 BlueVoyant MDR is marketed as protecting internal networks, cloud instances, containers, and endpoints while strengthening existing EDR, SIEM, and cloud-security tools. Medium SE004
CE011 MDR for Microsoft and Continuous Optimization for Microsoft Solutions are first-class modules inside the MDR suite. High SE004, SE006
CE012 BlueVoyant promises 24/7 detection and response across the full Microsoft security stack. High SE005, SE031
CE013 The MDR for Microsoft page lists 2026 Data Security and Compliance Trailblazer recognition, 2024 Worldwide Security Partner of the Year, three-time US Security Partner of the Year, and MISA membership. Medium SE005
CE014 BlueVoyant claims Microsoft Solutions Partner designations in Security, Infrastructure (Azure), and Modern Work plus security specializations in Cloud Security, Identity and Access Management, and Threat Protection. Medium SE005
CE015 Continuous Optimization for Microsoft Solutions extends the offer into Sentinel, Defender, M365, and Purview configuration and optimization based on 1,000-plus engagements. High SE006, SE007
CE016 BlueVoyant’s MDR for Microsoft collateral says customers can keep security data in their own environment instead of sending it to MSSP-owned infrastructure. Medium SE031
CE017 The Microsoft collateral frames the service around Microsoft Sentinel and Microsoft 365 Defender as the core security stack. Medium SE031
CE018 The MDR for Microsoft deployment playbook explicitly includes infrastructure setup, log-source ingestion, alert and SOAR configuration, knowledge transfer, and initial alert tuning. Medium SE031
CE019 BlueVoyant describes TPRM as a fully managed solution that identifies, validates, and resolves critical cybersecurity issues in a third-party ecosystem. Medium SE008
CE020 BlueVoyant’s TPRM suite includes continuous monitoring and remediation, questionnaire management, point-in-time risk assessments, and vendor consulting. High SE008, SE015
CE021 The continuous-monitoring workflow says Risk Operations Center analysts validate findings and work directly with third parties on remediation. Medium SE009
CE022 BlueVoyant says its business-risk monitoring uses AI and machine learning across more than 50,000 data sources and eight risk categories. Medium SE009
CE023 The questionnaire-management module automates assessment creation and distribution while validating supplier statements against observed performance. Medium SE010
CE024 BlueVoyant’s 2023 supply-chain expansion added multi-tier continuous monitoring, questionnaire workflows, point-in-time assessments, rapid zero-day alerting, and advisory workshops. High SE015, SE023
CE025 BlueVoyant positions DRP as protection against threats emerging from the clear, deep, and dark web before they affect the business or customers. Medium SE011
CE026 BlueVoyant’s DRP modules are Brand Protection, Dark Web Watcher, and Executive Cyber Guard. Medium SE011
CE027 Brand Protection covers web, social-media, and app impersonation with unlimited takedowns and monitoring across more than 300 official and unofficial app stores. Medium SE012
CE028 Dark Web Watcher monitors underground communities for fraud campaigns, sold credentials, and data leakage. Medium SE013
CE029 Executive Cyber Guard focuses on executive-data exposure, stolen credentials, and account-takeover prevention for high-value individuals. Medium SE014
CE030 BlueVoyant’s differentiated product story is convergence: Microsoft-centric MDR on the inside, TPRM across the supply chain, and DRP on the external attack surface under one operating model. Medium SE002, SE004, SE008, SE011
CE031 The Trust Center describes BlueVoyant as a cloud-native security-operations platform combining advanced AI with expert human insight across networks, endpoints, supply chains, and web or dark-web monitoring. Medium SE017
CE032 The Trust Center says BlueVoyant is trusted by more than 1,000 clients globally. Medium SE017
CE033 Conquest Cyber adds SaaS technology that unifies security posture, compliance, detection, and response through a risk-maturity lens. High SE016, SE024
CE034 BlueVoyant planned to integrate Conquest technology into existing products and services to create internal and external cyber defense mapped to risk maturity. High SE016, SE024
CE035 Conquest brought DIB and government credentials, CMMC RPO accreditation, FedRAMP-marketplace presence for ARMED ATK, and additional Microsoft security capabilities into BlueVoyant’s platform story. High SE016, SE024
CE036 Public GitHub evidence shows only one visible BlueVoyant repository, BV-Security-Copilot, with the public pages pointing to a September 22, 2025 update. High SE018, SE019, SE020
CE037 The visible BlueVoyant GitHub repo is framed as public content for Copilot for Security, implying limited open-source transparency relative to the breadth of the marketed platform. Medium SE020
CE038 Microsoft Learn records a BlueVoyant Shadow Hunter Microsoft Security Immersion Workshop, showing practitioner-facing Microsoft training activity beyond static marketing pages. Medium SE032
CE039 Gartner’s DRP page surfaces a favorable review headline that still notes occasional takedown challenges, signaling that takedown execution remains a real operational risk area. Medium SE029
CE040 A 2019 Spiceworks thread shows buyer skepticism that BlueVoyant was a startup relying on established tools such as Splunk, highlighting a long-running diligence question about proprietary depth versus service orchestration. Low SE030
CE041 PeerSpot describes BlueVoyant CORE as a combined MDR, digital-risk-protection, and supply-chain-defense suite backed by 24/7 monitoring and machine learning. Medium SE025
CE042 Cyber Magazine independently described the 2024 launch as a cloud-native platform specifically aimed at the supplier-driven attack surface. Medium SE026
CE043 BlueVoyant publicly reports a 99 percent website-takedown success rate, a 95 percent social-media-takedown success rate, and a 23-hour median server-level takedown time for DRP. Medium SE001
CU001 BlueVoyant’s visible customer base skews toward regulated or operationally complex organizations rather than broad SMB self-serve buyers. Low SU001, SU002, SU003, SU005, SU014, SU019
CU002 The deepest named public proofs span state government, federal defense supply chains, digital banking, capital-markets infrastructure, and multinational entertainment operations. Low SU001, SU002, SU003, SU005, SU019
CU003 Public financial-services proof is concentrated in Snappi, Beeks, ClearBank, and sector-specific Microsoft content rather than a long named roster of banks or insurers. Low SU003, SU005, SU006, SU014, SU026
CU004 Public-sector proof is concentrated in California OIS, NAVSEA, and Carahsoft-enabled procurement routes rather than a broad public list of named agencies. Low SU001, SU013, SU019, SU024, SU030, SU031
CU005 California OIS launched a cloud-based SOCaaS that integrated Microsoft Security with BlueVoyant’s MDR for Microsoft. Medium SU001
CU006 BlueVoyant’s California case study says the program reduced mean time to detect by 70 percent. Medium SU001
CU007 BlueVoyant’s California case study says the program reduced mean time to respond by 60 percent. Medium SU001
CU008 BlueVoyant’s California case study says participating entities saved about $2.1 million in annual personnel costs. Medium SU001
CU009 California’s Department of Technology said in June 2025 that SOCaaS protected 112 public-sector organizations and had produced more than $54 million of combined savings. Medium SU037
CU010 California CDT describes SOCaaS as a 24/7 continuous-monitoring service used to satisfy statewide monitoring requirements. Medium SU036, SU037
CU011 ODEON Cinemas Group runs more than 280 cinemas across eight countries. Medium SU002, SU033
CU012 ODEON’s public materials describe nearly 50 log sources and a previously fragmented, noisy security setup before BlueVoyant’s engagement. Medium SU002, SU033
CU013 BlueVoyant migrated ODEON to Microsoft Sentinel, onboarded MDR for Microsoft, and added DFIR plus third-party risk management. Medium SU002, SU033
CU014 ODEON’s case-study materials report a 98 percent reduction in alerts requiring review. Medium SU002, SU033
CU015 ODEON’s BlueVoyant case study reports 30 critical or high third-party vulnerabilities resolved. Medium SU002
CU016 Independent coverage quotes ODEON saying monthly alerts fell from hundreds to roughly 6 to 12 tickets. Medium SU033
CU017 Snappi is described in multiple public sources as Greece’s first ECB-licensed neobank. Medium SU003, SU034, SU035
CU018 Snappi used BlueVoyant and Veracloud to implement 24/7 SOC coverage, MDR, dark-web monitoring, and incident-response readiness within months of launch. Medium SU003, SU034, SU035
CU019 Snappi’s public proof emphasizes board visibility, monthly SOC KPI reporting, tabletop exercises, and DORA readiness rather than conventional revenue or usage metrics. Medium SU003, SU034
CU020 Beeks says BlueVoyant now supports a 24x7 end-to-end SOC for a platform serving capital-markets and financial-services customers. Medium SU005, SU026
CU021 Beeks says BlueVoyant lowered alert fatigue, reduced data-ingestion costs, and was operational in less than three months. Medium SU005, SU026
CU022 Beeks positions the partnership as a customer-acquisition differentiator because its own clients ask about cyber resilience. Medium SU005, SU026
CU023 NAVSEA awarded a three-year Phase III contract and delivery orders to BlueVoyant Government Solutions for industrial-base resilience and supply-chain illumination work. Medium SU019, SU020
CU024 BlueVoyant Government Solutions said in April 2025 that its SCD-G platform had been added to Carahsoft’s SCRIPTS BPA vehicle. Medium SU031
CU025 BlueVoyant Government Solutions said its platform currently identifies critical risks for more than 4 million suppliers. Medium SU031
CU026 Carahsoft distributes BlueVoyant through SEWP V, ITES-SW2, NASPO ValuePoint, and California CMAS procurement routes. Medium SU024, SU030
CU027 BlueVoyant’s partner program offers co-selling, training, account support, and marketing tooling across channel, tech-alliance, and OEM relationships. Medium SU004
CU028 Carahsoft says its reseller ecosystem includes more than 10,000 government contractors, VARs, solution providers, integrators, and MSPs. Medium SU032
CU029 AWS Marketplace shows BlueVoyant selling a private-offer MDR service with 24x7 SOC support. Medium SU025
CU030 BlueVoyant’s public financial-services evidence includes named work with Snappi, Beeks, and ClearBank plus sector materials featuring Fiserv and JP Morgan participants. Low SU003, SU005, SU006, SU008, SU014, SU026
CU031 BlueVoyant’s public government evidence includes California SOCaaS, NAVSEA supply-chain work, Carahsoft distribution, and contract-vehicle access. Low SU001, SU019, SU024, SU030, SU031, SU037
CU032 BlueVoyant actively markets to energy and legal buyers, but the reviewed corpus does not show equally deep named production proofs for those sectors. Low SU015, SU016
CU033 BlueVoyant’s 2024 MDR TEI summary claims 210 percent three-year ROI, 90 percent fewer escalated alerts per month, and 70 percent faster mean time to resolve for a composite customer. Medium SU017
CU034 BlueVoyant’s supply-chain-defense TEI summary claims nearly 300 percent ROI, 65 percent better monitoring efficiency, 70 percent fewer suppliers above risk threshold, and 60 percent faster remediation of critical risks. Medium SU011
CU035 BlueVoyant’s 2025 supply-chain survey says it captured 1,800 executives across financial services, healthcare, pharma, utilities, energy, retail, manufacturing, and defense. Medium SU012
CU036 BlueVoyant said in May 2025 that it was trusted by more than 1,000 clients globally and had guided thousands of clients on Microsoft Security. Medium SU018
CU037 FeaturedCustomers shows BlueVoyant with 9 reviews, 5 case studies, and a 4.7 out of 5 reference rating across 133 total customer references. Medium SU021, SU022
CU038 PeerSpot describes BlueVoyant deployments across finance, healthcare, and manufacturing and says licensing typically includes annual or multi-year agreements. Medium SU023
CU039 The reviewed AWS Marketplace and Slashdot pages both show zero visible customer ratings or reviews for BlueVoyant. Medium SU025, SU029
CU040 None of the reviewed public customer sources disclose NRR, GRR, churn, or cohort renewal performance. Low SU001, SU002, SU003, SU005, SU014, SU021, SU022, SU023
CU041 None of the reviewed public customer sources break out top-customer concentration or contract-duration exposure by revenue. Low SU001, SU002, SU003, SU005, SU014, SU019, SU021, SU023
CU042 The strongest public outcomes cluster around Microsoft-centered operations, managed detection and response, and supply-chain risk use cases rather than broad attach-rate disclosure across all product lines. Low SU001, SU002, SU003, SU005, SU014, SU017, SU031
CU043 Most quantified customer proof is vendor-authored or partner-authored rather than independently audited, so deployment outcomes are visible but durability evidence remains thin. Low SU001, SU002, SU003, SU005, SU022, SU028, SU029, SU033, SU034
CR001 BlueVoyant markets itself as a Microsoft security specialist across Sentinel, Defender, Purview, and Copilot-readiness work. Medium SR002, SR003
CR002 BlueVoyant says its MDR for Microsoft offer combines BlueVoyant AI with an elite 24x7 SOC and security operations team. Medium SR003, SR018
CR003 BlueVoyant says it works with Microsoft product teams on Sentinel scenarios, operations feedback, API extensibility, and Security Copilot agents. Medium SR013, SR028
CR004 BlueVoyant says it won the 2024 Microsoft Worldwide Security Partner of the Year Award and additional U.S. and Canada security partner awards. High SR010, SR014
CR005 BlueVoyant and Micah Heaton were recognized in the 2025 Microsoft Security Excellence Awards as Security Trailblazer and Security Changemaker winners. High SR009, SR017, SR027
CR006 BlueVoyant’s Sentinel eBook says it summarizes 16 anonymized case studies drawn from hundreds of hands-on Microsoft Sentinel deployments. Medium SR033
CR007 Protiviti describes BlueVoyant’s Microsoft offering as combining advanced AI with expert human insight in a joint services stack. Medium SR018
CR008 BlueVoyant launched BlueVoyant AI on 2026-06-09 as an AI-native Agentic SecOps platform. High SR004, SR032
CR009 BlueVoyant AI is offered in both fully managed and enterprise SaaS deployment models. High SR004, SR032
CR010 BlueVoyant says its AI workflows keep humans at the center of the strategy even when automated response actions occur at machine speed. Medium SR004, SR032
CR011 BlueVoyant’s Cork SOC announcement says the site provides 24x7 monitoring for Irish and EU clients. Medium SR008, SR015
CR012 BlueVoyant links its Cork expansion to NIS2 and DORA-driven customer demand and says local revenue grew 70% in 2024. Medium SR008, SR015
CR013 BlueVoyant changed CEOs in May 2026 when John Hernandez succeeded co-founder Jim Rosenthal. Medium SR006
CR014 BlueVoyant’s 2023 CPO appointment was framed as a move to unify product lines and expand share in cybersecurity. Medium SR007
CR015 BlueVoyant’s privacy notice says BlueVoyant LLC is the controller of personal data collected through its website. Medium SR001
CR016 BlueVoyant’s privacy notice says personal information may be shared with affiliate companies unless prohibited by law or other regulatory requirements. Medium SR001
CR017 PacerMonitor shows Steward Health filed an adversary complaint against Bluevoyant LLC in July 2025. Medium SR020
CR018 The public Steward docket describes avoidance and recovery claims under bankruptcy preference and fraudulent-transfer theories. Medium SR020
CR019 The DoD CIO CMMC page says Phase 1 implementation runs from 2025-11-10 to 2026-11-09 and focuses on Level 1 and Level 2 self-assessments. High SR022, SR023
CR020 The DoD CIO CMMC page reminds contractors to submit affirmations with CMMC assessments in SPRS. Medium SR022
CR021 The DoD CMMC 2.0 page says contracting officers now include the new CMMC requirements in new solicitations and contracts. Medium SR023
CR022 NIST SP 800-171 says its security requirements are intended for use in contractual vehicles and agreements between federal agencies and nonfederal organizations handling CUI. Medium SR021
CR023 BlueVoyant Government Solutions markets supply-chain visibility and expert-led threat remediation at scale for mission assurance. Medium SR011
CR024 BlueVoyant’s government customer page targets intelligence, federal civilian, acquisition, cybersecurity, and supply-chain risk-management use cases. Medium SR012
CR025 Carahsoft lists BlueVoyant on NASA SEWP V through 2026-09-30. Medium SR019
CR026 Carahsoft also lists ITES-SW2 through 2030-08-30 and SCRIPTS BPA through 2030-03-30 for BlueVoyant. Medium SR019
CR027 Pavilion says BlueVoyant Government Solutions includes CMMC and NIST 800-171 compliance management. Medium SR029
CR028 SAM.gov says contract-award search now supports filtering by keyword, agency, and legal business name. Medium SR030
CR029 USAspending says it is the official open data source for federal awards, including contracts, grants, and loans. Medium SR031
CR030 BlueVoyant said it raised more than $140 million in Series E funding to support the Conquest Cyber acquisition. Medium SR005
CR031 BlueVoyant said Conquest Cyber had traction in the U.S. Defense Industrial Base and government organizations. Medium SR005
CR032 PM Insights exposes only delayed preview data and gated institutional datasets for BlueVoyant valuation, secondary activity, and cap-table details. Medium SR024
CR033 SourceForge presents BlueVoyant alongside many alternative cyber platforms in 2026, underscoring a crowded competitive set. Medium SR025
CR034 PeerSpot describes BlueVoyant as spanning MDR, digital risk protection, and supply-chain defense with advanced analytics and a 24x7 SOC. Medium SR026
CR035 Microsoft’s 2021 security blog framed customer need around tech sprawl and positioned BlueVoyant as an optimizer of Microsoft security services. Medium SR016
CR036 Finance Yahoo and PR Newswire say BlueVoyant is building analytics, playbooks, hunting queries, notebooks, and Security Copilot agents on top of Sentinel. Medium SR013, SR028
CR037 BlueVoyant’s Microsoft page markets cost-of-adoption assessments for Sentinel, Defender for Cloud, Microsoft 365 E5, data security, and Copilot readiness. Medium SR002
CR038 BlueVoyant’s Sentinel eBook says customers use the company to optimize costs and migrate from other SIEMs. Medium SR033
CR039 BlueVoyant’s Gartner-market-guide blog cites rising third-party breach pressure and presents AI-driven assessment plus expert remediation as its TPRM answer. Medium SR034
CR040 Independent coverage of the BlueVoyant AI launch repeats the company’s claim that the platform delivers autonomous speed, precision, and control at scale. Medium SR032
CR041 BlueVoyant’s 2024 Microsoft award release says the company’s Microsoft customer base has grown over the past three years. Medium SR010, SR014
CR042 Microsoft’s 2025 awards page independently confirms BlueVoyant was among recognized security-ecosystem winners. Medium SR017
CR043 Protiviti says it and BlueVoyant jointly deliver Microsoft security, compliance, and identity solutions. Medium SR018
CR044 The PR Newswire UK Cork release says BlueVoyant’s EMEA build-out reflects a multi-million-Euro investment since 2017. Medium SR015
CR045 BlueVoyant’s Cork release says the company had local employees in Ireland before opening the permanent office. Medium SR008
CR046 BlueVoyant’s go-to-market and product differentiation are tightly coupled to Microsoft roadmap, pricing, and channel behavior. Medium SR002, SR003, SR013, SR028
CR047 The shift from managed MDR into agentic SOC software increases execution complexity around packaging, pricing, support, and quality control. Medium SR004, SR006, SR007, SR032
CR048 BlueVoyant’s public-sector motion is compliance-gated because the company markets CMMC and NIST support while DoD rules are now flowing into contracts. Medium SR021, SR022, SR023, SR027, SR029
CR049 Public-sector concentration is material but still unquantified because contract vehicles are visible while agency-level award mix and renewal concentration are not publicly disclosed. Medium SR019, SR030, SR031
CR050 The Steward complaint is the clearest company-specific adverse signal in the public record and should be diligenced for amount, defenses, and insurance coverage. Medium SR020
CR051 Competitive risk is elevated because BlueVoyant competes at once in Microsoft services, MDR, TPRM, and supply-chain defense against more specialized vendors. Medium SR025, SR026, SR034
CR052 Financing risk remains material because the public file shows a 2023 private raise and gated secondary-market previews, but not current ARR, runway, or valuation terms. Medium SR005, SR024
CR053 The highest-likelihood near-term risks are Microsoft-feature dependence and managed-service staffing drift because both sit inside BlueVoyant’s daily delivery loop. Medium SR003, SR008, SR013, SR018
CR054 The highest-impact downside risks are compliance slippage, financing opacity, and any legal escalation because those could impair growth or capital access quickly. Medium SR020, SR022, SR023, SR024
CR055 If Microsoft economics worsen or BlueVoyant AI underdelivers, BlueVoyant would likely feel the damage first in customer ROI and renewal confidence before financing flexibility changes. Medium SR003, SR004, SR013, SR024
CR056 Missing public metrics on SLA attainment, MTTR, analyst-to-customer ratios, agency concentration, and capital structure reduce confidence in residual-risk scoring. Medium SR024, SR030, SR031
CV001 BlueVoyant announced on November 29, 2023 that it raised more than $140 million to accompany its acquisition of Conquest Cyber. High SV002, SV032
CV002 BlueVoyant said Liberty Strategic Capital and ISTARI led the November 2023 funding round. High SV002, SV032
CV003 BlueVoyant's February 23, 2022 Series D raised $250 million. High SV003, SV011
CV004 BlueVoyant named Liberty Strategic Capital, ISTARI, Eden Global Partners, and 8VC as participants in the Series D round. High SV003, SV011, SV008
CV005 Caplight currently shows BlueVoyant's last round as Series E on November 29, 2023 with an estimated valuation of $1 billion. Medium SV004
CV006 Forge shows BlueVoyant's last known valuation as $1 billion dated February 23, 2022. Medium SV006
CV007 Caplight, CB Insights, and GetLatka each report BlueVoyant total funding at $665.5 million. High SV004, SV009, SV027
CV008 Tracxn reports BlueVoyant total funding at $696 million across six rounds. Medium SV008
CV009 CB Insights classifies BlueVoyant as Series E | Alive and lists the last raise as $140 million. Medium SV027
CV010 The SEC browse result for BlueVoyant shows Form D notices dated 2017-08-04, 2019-04-25, and 2020-07-08. Medium SV012
CV011 The retained SEC browse result does not surface later BlueVoyant financing filings, leaving the 2022 and 2023 round terms undisclosed in public filing search results. Medium SV012
CV012 BlueVoyant's February 2023 growth release said the company had more than 900 clients in 40-plus countries and nearly 1,000 clients globally. Medium SV001
CV013 BlueVoyant's February 2023 growth release said recurring revenue grew 80% in 2022 and 108% on average since 2018. Medium SV001
CV014 GetLatka estimates BlueVoyant's 2025 revenue at $213.5 million and employee count at about 650. Medium SV009
CV015 BlueVoyant's public materials position the company around MDR, TPRM, digital risk protection, and professional services on one platform. High SV001, SV010
CV016 Caplight tags BlueVoyant with MDR, third-party risk management, SOC-as-a-Service, supply chain risk management, and digital risk protection keywords. Medium SV004
CV017 Notice titles BlueVoyant at $1.36 per share. Medium SV005
CV018 Notice's page markup shows the current Notice Price at a 39% discount to the last round. Medium SV005
CV019 Forge labels BlueVoyant market activity as limited and shows no Forge Price. Medium SV006
CV020 Hiive's page data shows no daily price history and sets displayChart to false for BlueVoyant. Medium SV007
CV021 PM Insights' public preview exposes sections for secondary-market ROI, bid-ask ratios, mutual-fund NAV, and cap-table details, but not the underlying numbers. Medium SV026
CV022 Windsor Drake says the public cybersecurity median trades at roughly 6.0x to 6.5x NTM revenue in Q2 2026. Medium SV018
CV023 Windsor Drake says managed security services compress to roughly 3x to 5x revenue in 2026. Medium SV018
CV024 Tablestat shows median enterprise cybersecurity EV/revenue at 8.4x for 2025E and 6.8x for 2026E. Medium SV020
CV025 CrowdStrike trades at 34.30x EV/revenue on 5.09B of trailing revenue and about 178.47B of market cap. Medium SV013, SV021
CV026 Palo Alto Networks trades at 23.28x EV/revenue on 10.61B of trailing revenue and about 247.92B of market cap. Medium SV028, SV030
CV027 Fortinet trades at 15.20x EV/revenue on 7.11B of trailing revenue and about 110.88B of market cap. Medium SV029, SV031
CV028 SentinelOne trades at 4.61x EV/revenue on 1.05B of trailing revenue and about 5.45B of market cap. Medium SV014, SV022
CV029 Qualys trades at 5.73x EV/revenue on 684.86M of trailing revenue and about 4.34B of market cap. Medium SV017, SV025
CV030 Tenable trades at 3.32x EV/revenue on 1.02B of trailing revenue and about 3.33B of market cap. Medium SV016, SV024
CV031 Rapid7 trades at 0.93x EV/revenue on 859.23M of trailing revenue and about 508.58M of market cap. Medium SV015, SV023
CV032 multiples.vc describes CrowdStrike and SentinelOne as security-operations platforms and Rapid7, Qualys, and Tenable as exposure, XDR/SIEM, and compliance platforms, supporting their use as BlueVoyant comparables. Medium SV019
CV033 BlueVoyant's homepage advertises 24x7 in-region SOC monitoring, 1,200-plus Microsoft Sentinel deployments, and 1,600-plus vulnerabilities remediated in the last 30 days. Medium SV010
CV034 A $1 billion valuation on the $213.5 million ARR proxy implies roughly 4.7x ARR. Medium SV004, SV009
CV035 A 4.7x ARR multiple sits below the 2026 public cyber median and near SentinelOne, Qualys, and Tenable. Medium SV018, SV022, SV024, SV025
CV036 Because BlueVoyant mixes software with managed services and professional services, it should not command CrowdStrike-, Palo Alto-, or Fortinet-level software multiples without disclosed margin proof. Medium SV010, SV018, SV020
CV037 The bull thesis rests on real scale, broad cyber-risk product breadth, and historical triple-digit recurring-revenue growth. Medium SV001, SV010, SV032
CV038 The clearest anti-thesis is that public secondary data show a 39% discount, limited visible liquidity, and no obvious public valuation step-up after 2022. Medium SV004, SV005, SV006
CV039 Caplight still showing a $1 billion estimate and Forge still showing a $1 billion last-known mark suggest no public upward valuation reset despite the 2023 Series E. Medium SV004, SV006
CV040 Public sources disagree on exact capital raised, ranging from $665.5 million to $696 million, which signals data-room opacity rather than a clean public funding ledger. Medium SV004, SV008, SV027
CV041 A base-case valuation band of roughly $0.85 billion to $1.1 billion is supportable by applying 4.0x to 5.0x to the $213.5 million ARR proxy. Medium SV009, SV018, SV022
CV042 An upside range of roughly $1.2 billion to $1.5 billion requires sustained growth and a mix shift toward higher-margin platform revenue that would justify 5.5x to 7.0x multiples. Medium SV018, SV020, SV028, SV029
CV043 A downside range of roughly $0.6 billion to $0.8 billion is consistent with the Notice discount to the last round and the managed-security/services range. Medium SV005, SV018
CV044 The public evidence does not support a buy call because downside is observable in secondary signals while the upside case still depends on undisclosed margin, retention, and share-count data. Medium SV005, SV006, SV012, SV026
CV045 BlueVoyant is large enough and strategically relevant enough that the correct recommendation is research-more rather than avoid. Medium SV001, SV010, SV032
CV046 Confidence should be medium because the multiple work is directionally coherent, but the core ARR and liquidity inputs come from third-party datasets rather than audited disclosure. Medium SV009, SV026, SV027
CV047 Risk rating should remain high because private-market liquidity appears thin and the current mark could compress if growth or margin quality undershoots. Medium SV005, SV006, SV007
CV048 Valuation stance is fair rather than attractive because the $1 billion mark can be justified on the ARR proxy but leaves limited margin of safety against secondary discounts. Medium SV005, SV009, SV018, SV022
CV049 Hiive states that BlueVoyant remains privately held and pre-IPO access is limited to accredited investors via secondary marketplaces. Medium SV007
CV050 The highest-value diligence asks are current ARR and gross-margin mix, cap table and share count, actual secondary-clearing prices, and confirmation of any post-2023 financing terms. Medium SV007, SV012, SV026, SV027
Sources
IDPublisherTitleQuote
SO001 BlueVoyant Company Founded in 2017... Headquartered in New York City, the company has over 600 employees... spanning five continents.
SO002 BlueVoyant Leadership
SO003 BlueVoyant Contact Us More Than 1,000 Customers in 45 Countries
SO004 BlueVoyant BlueVoyant Cyber Defense Platform
SO005 BlueVoyant Managed Detection & Response
SO006 BlueVoyant Third-Party Risk Management (TPRM)
SO007 BlueVoyant Partners
SO008 BlueVoyant BlueVoyant & Microsoft
SO009 BlueVoyant Awards
SO010 BlueVoyant Careers
SO011 BlueVoyant Born in the SOC, Not in a Lab | Webinar
SO012 BlueVoyant Next Era of Cyber Defense with BlueVoyant AI BlueVoyant today announced BlueVoyant AI, an innovative Agentic SecOps platform that fundamentally redefines how modern enterprises prevent, detect, investigate, and stop cyber threats.
SO013 BlueVoyant BlueVoyant Raises $250 Million Series D Led by Liberty Strategic Capital Liberty Strategic Capital... led the $250-million round with participation from... ISTARI... Eden Global Partners... and 8VC.
SO014 BlueVoyant BlueVoyant and Auto-ISAC Partner to Elevate TPRM in Automotive
SO015 BlueVoyant BlueVoyant Welcomes Michael Montoya as COO Michael Montoya has joined the company as Chief Operating Officer (COO)... overseeing the technology, product, and operations organizations.
SO016 PR Newswire John Hernandez Joins BlueVoyant as CEO to Accelerate AI-Driven Cybersecurity Platform and Global Growth John Hernandez will succeed Jim Rosenthal as Chief Executive Officer (CEO).
SO017 PR Newswire Liberty Strategic Capital Leads Investment Round in BlueVoyant, an Industry-Leading Cyber Defense Platform
SO018 PR Newswire BlueVoyant Acquires Conquest Cyber to Meet Market Need for Comprehensive Managed Detection and Response and Cyber Risk Posture Solutions
SO019 PR Newswire BlueVoyant and Auto-ISAC Partner to Elevate Third-Party Cyber Risk Management Across the Automotive Industry
SO020 TechCrunch BlueVoyant nabs $250M to help enterprises nab malicious hackers and stop security breaches
SO021 SecurityWeek BlueVoyant Raises $250 Million to Boost Technical Capabilities, Global Expansion
SO022 CRN BlueVoyant Acquires Conquest Cyber In Deal That Reshapes Microsoft Security Landscape
SO023 GovCon Wire BlueVoyant Purchases Conquest Cyber, Raises Over $140M in Series E Funding Round
SO024 BankInfoSecurity BlueVoyant Raises $140M, Buys Resilience Firm Conquest Cyber
SO025 iTWire BlueVoyant Ignites the Next Era of Cyber Defence with Launch of BlueVoyant AI
SO026 UK Tech News BlueVoyant Ignites the Next Era of Cyber Defence with Launch of BlueVoyant AI
SO027 Enterprise IT World BlueVoyant Appoints John Hernandez as CEO to Drive AI-Led Cybersecurity Growth
SO028 Unify Employee Data and Trends for Bluevoyant
SO029 GetLatka BlueVoyant Revenue 2025: $213.5M ARR, $1B Valuation
SO030 Caplight BlueVoyant | Valuation, Funding Rounds & Stock Price
SO031 UpGuard BlueVoyant Security Rating, Vendor Risk Report, and Data Breaches The Content Security Policy is implemented with unsafe-eval, reducing protection against XSS attacks.
SO032 Cyber Insurance News BlueVoyant Warns Supply Chain Breaches Soar as Cyber Liability Insurance Requirements Shape Risk Strategy
SO033 The SaaS News BlueVoyant Raises $140 Million in Series E
SM001 BlueVoyant Managed Detection & Response Protect your internal network, cloud instances, containers, and endpoints from unknown threat actors, and strengthen your utilization of existing EDR, SIEM, and cloud security tools.
SM002 BlueVoyant Third-Party Risk Management (TPRM) BlueVoyant Third-Party Risk Management (TPRM) is a fully managed solution that identifies, validates, and resolves critical cybersecurity issues in your third-party ecosystem.
SM003 BlueVoyant Continuous Monitoring & Remediation
SM004 BlueVoyant AI-Driven Cyber Defense
SM005 BlueVoyant Fourth-Party Identification and Analytics
SM006 Precedence Research Managed Detection and Response (MDR) Market Size to Hit USD 13.90 Bn by 2035
SM007 Mordor Intelligence Managed Detection and Response Market Size & Trends, 2031
SM008 The Business Research Company Managed Detection And Response Market Insights 2026 to 2035
SM009 Grand View Research Third-party Risk Management Market Size Report, 2030
SM010 Next Move Strategy Consulting Third-Party Risk Management Market Analysis | 2025-2030
SM011 The Business Research Company Third-party Risk Management Market Growth Report 2026
SM012 KPMG The 2026 KPMG Global Third-Party Risk Management Survey This is not the time for incremental improvements or fragmented approaches.
SM013 Marsh Rising third-party risks and persistent ransomware threats drive increased cybersecurity investments in 2026 | Marsh 70% of organizations experienced at least one material third-party cyber incident in the past year.
SM014 Panorays 200 CISOs Reveal the Truth About Third-Party Cyber Risk 85% of CISOs surveyed admitted they do not have full visibility across their entire supply chain.
SM015 National Institute of Standards and Technology Cybersecurity Framework
SM016 Securities and Exchange Commission Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure For domestic registrants, this disclosure must be filed on Form 8-K within four business days of determining that a cybersecurity incident is material.
SM017 European Commission NIS2 Directive: securing network and information systems The NIS2 Directive establishes a unified legal framework to uphold cybersecurity in 18 critical sectors across the EU.
SM018 Gartner Gartner Identifies the Top Cybersecurity Trends for 2026 The chaotic rise of AI, geopolitical tensions, regulatory volatility and an accelerating threat landscape are the driving forces behind the top cybersecurity trends for 2026.
SM019 CyberProof Mapping the Managed Detection and Response (MDR) Market for 2026 Gartner has cautioned that many providers misusing the “MDR” label offer only tool-centric monitoring (e.g. managed EDR) without the critical human analysis and incident response leadership.
SM020 Mordor Intelligence GRC Software Market Size, Share & 2031 Growth Trends Report
SM021 Black Kite 2026 Third-Party Breach Report | Black Kite Supply Chain Risk Data For every single vendor breached, an average of 5.28 downstream companies were publicly compromised.
SM022 CRC Group 2026 Cyber + Technology State of the Market at a Glance
SM023 Cybersecurity and Infrastructure Security Agency Information and Communications Technology Supply Chain Risk Management | CISA If vulnerabilities in the ICT supply chain—composed of hardware, software, and managed services from third-party vendors, suppliers, service providers, and contractors—are exploited, the consequences can affect all users of that technology or service.
SM024 Cybersecurity and Infrastructure Security Agency ICT Supply Chain Risk Management Task Force | CISA The ICT SCRM Task Force—a public-private partnership charged with identifying challenges and developing actionable solutions to enhance global ICT supply chain resilience.
SM025 PeerSpot Top Rated Managed Detection and Response (MDR) Vendors
SP001 BlueVoyant MDR, TPRM, Digital Risk Protection | BlueVoyant Agentic SecOps, MDR, and TPRM to protect your entire attack surface.
SP002 BlueVoyant Company Founded in 2017... the company has over 600 employees across offices... spanning five continents.
SP003 BlueVoyant Managed Detection & Response 50+ certified Microsoft Delivery & SOC Engineers
SP004 BlueVoyant Government Solutions BlueVoyant Government Solutions | Supply Chain Defense BlueVoyant Government Solutions operationalizes mission assurance with deep supply chain risk visibility and expert-led threat remediation at scale.
SP005 BlueVoyant Government Solutions Products More than 70,000 unique proprietary, open-source, and commercially-available data feeds
SP006 PR Newswire BlueVoyant Ignites the Next Era of Cyber Defense with Launch of BlueVoyant AI BlueVoyant AI provides both with its fully managed service... or as an enterprise-grade SaaS platform.
SP007 Palo Alto Networks Explore Cortex XSIAM Security Analytics Every SOC capability on one platform.
SP008 Palo Alto Networks About Us 16K+ Employees | 70K+ Customers Globally | ~$100B Market Cap
SP009 CrowdStrike 24/7 Expert Protection | CrowdStrike Falcon® Complete Next-Gen MDR 1min Median time-to-contain (MTTC)
SP010 Arctic Wolf Managed Detection and Response (MDR) | Arctic Wolf The SOC uses trusted datasets drawn from 14+ years of security operations and insights from 10,000+ global customers, and 1,000+ security engineers.
SP011 Arctic Wolf A Higher Standard of Security Operations | Arctic Wolf Trusted by over 10,000 customers worldwide
SP012 Arctic Wolf Why Arctic Wolf? As the pioneer of the first open XDR platform that makes security work, the Aurora® Superintelligence Platform leverages AI to enable cyber defense at an unprecedented capacity and scale.
SP013 Rapid7 About Rapid7 - Cybersecurity Company Rapid7 unifies exposure and detection to transform the cybersecurity operations of more than 11,500 customers worldwide.
SP014 Rapid7 Incident Command: AI Powered Next-Gen SIEM | Rapid7 Incident Command delivers a new standard for detection and response built for scale, speed, and clarity across your entire threat landscape.
SP015 ReliaQuest About Us ReliaQuest exists to Make Security Possible, allowing enterprise security teams to detect, contain and respond to threats within minutes—anytime, anywhere—using the GreyMatter agentic AI security operations platform.
SP016 ReliaQuest Home | ReliaQuest GreyMatter: The Agentic AI Security Operations Platform for Agentic Defense 50K+ alerts processed daily; 255+ Technology Partners with security technologies; 99.4% accuracy of AI investigations.
SP017 ReliaQuest ReliaQuest GreyMatter Integrations: Your Environment + Agentic AI Powered Security Operations Your environment + agentic AI powered security operations
SP018 eSentire Managed Detection and Response Services & Security Operations Platform Protecting 2,000+ Customers Across 35+ Industries
SP019 eSentire XDR Extended Detection & Response Solutions Our distributed platform easily integrates with your existing security investments.
SP020 eSentire eSentire MDR vs the Competition The Atlas Platform connects to ANY SIGNAL, whether that's Endpoint, Network, Logs, Cloud, Vulnerability scanner, Browser, or Identity provider.
SP021 SecurityScorecard SecurityScorecard | Supply Chain & Third-Party Risk Platform The world’s first AI-powered platform for continuous, threat-informed third-party risk management
SP022 SecurityScorecard Company - SecurityScorecard 3,300+ global organizations... 12M+ organizations monitored and rated
SP023 SecurityScorecard Third-Party Risk Management (TPRM) | SecurityScorecard Validate Questionnaires with Technical Ground Truth
SP024 Bitsight Cyber Risk Intelligence Platform A dynamic map of assets and vulnerabilities, prioritized by real-time threat intelligence, across your enterprise and supply chain.
SP025 Bitsight Third Party Risk Management Solutions 75K+ Mapped vendor profiles in the Bitsight Vendor Network
SP026 Bitsight Bitsight Named a Leader in Cybersecurity Risk Ratings, Praised By Customers for the Utility of its Data | Bitsight With more than 3,500 customers and over 68,000 organizations active on its platform
SP027 Gartner Peer Insights Best Managed Detection and Response Reviews 2026 | Gartner Peer Insights MDR offers outcome-driven security incident management... and the delivery of active threat disruption and containment actions.
SP028 PeerSpot BlueVoyant CORE Reviews, Competitors and Pricing As of June 2026, the mindshare of BlueVoyant CORE in the Managed Detection and Response (MDR) category stands at 0.9%, down from 1.2% compared to the previous year.
SP029 PeerSpot Compare BlueVoyant CORE vs CrowdStrike Falcon Complete MDR BlueVoyant is ranked #34, while CrowdStrike is ranked #2... BlueVoyant holds a 0.9% mindshare in MDR, compared to CrowdStrike’s 5.4% mindshare.
SP030 Ciphers Security Best Vendor Risk Management Platforms In 2026 Two fundamentally different approaches dominate this market... Security ratings platforms... assess vendors from the outside in.
SP031 Decryption Digest Best MDR Services 2026: CrowdStrike vs Arctic Wolf vs Huntress Compared MSSPs monitor firewall and SIEM alerts and deliver notifications... not meaningful security improvement.
SP032 CRN Managed Security Firm Arctic Wolf Raises $60 Million In Pursuit Of IPO Arctic Wolf has closed a $60 million funding round to help the managed detection and response vendor prepare for an IPO.
SP033 SC Media Arctic Wolf backs off IPO talk, looks to scale business with latest acquisition the company – which was reportedly valued at $4.3 billion – planned for an IPO this year. But he made no commitments
SP034 Help Net Security eSentire launches new Atlas AI Operatives for autonomous threat detection and response - Help Net Security The Atlas Platform... operates vendor-independently across any integration.
SI001 BlueVoyant MDR, TPRM, Digital Risk Protection | BlueVoyant BlueVoyant packages Agentic SecOps, MDR, TPRM, DRP, and professional services with 1,200+ Microsoft Sentinel deployments and 24x7 monitoring.
SI002 BlueVoyant Company Headquartered in New York City, the company has over 600 employees across offices spanning five continents.
SI003 BlueVoyant Channel Partners Operational cybersecurity demands collaboration, and BlueVoyant highlights partners including GuidePoint Security and CDW.
SI004 BlueVoyant Build Your Own SOC or Partner with an MSSP The annual cost of setting up your own 24/7/365 SOC can add up to more than $1.2 million.
SI005 BlueVoyant BlueVoyant Enters 2022 With Triple Digit Growth Momentum and More Than 700 Global Customers Customer count increased by more than 80%, with more than 700 customers globally in 30 countries worldwide.
SI006 BlueVoyant BlueVoyant Raises $250 Million Series D Led by Liberty Strategic Capital Since 2018, BlueVoyant has grown annual recurring revenues at 117% on average.
SI007 BlueVoyant BlueVoyant Acquires Conquest Cyber BlueVoyant raised more than $140 million in Series E funding to accompany the acquisition of Conquest Cyber.
SI008 BlueVoyant BlueVoyant Welcomes Timothy Yost as Chief Financial Officer Tim will focus on setting and managing the company’s financial and strategic plans and continue to build BlueVoyant’s world-class global finance organization.
SI009 BlueVoyant New Security Operations Centre in Cork, Ireland BlueVoyant serves over 1,000 customers in more than 45 countries, and local revenue grew 70% in 2024.
SI010 BlueVoyant Total Economic Impact™ of BlueVoyant MDR Services The commissioned Forrester TEI study cites 210% ROI over three years.
SI011 BlueVoyant Total Economic Impact™ of BlueVoyant Supply Chain Defense Report The Forrester TEI study cites nearly 300% return and a 62% reduction in time to remediate critical risks.
SI012 BlueVoyant Snappi Neobank: Enterprise-Grade Security from Day One Snappi built 24/7 SOC coverage within months by partnering with Veracloud and BlueVoyant.
SI013 BlueVoyant ODEON Cinemas Group ODEON consolidated security across 8 countries and 280+ cinemas while cutting alert volume by 98%.
SI014 BlueVoyant BlueVoyant TPRM Is on Google Cloud Marketplace Making BlueVoyant TPRM available on GCP Enterprise Agreement eligibility removes procurement friction.
SI015 BlueVoyant Maximizing Security ROI A recent BlueVoyant analysis found that an enterprise organization can have an annual cost of up to $750,000 to optimize its Microsoft security stack internally.
SI016 BlueVoyant Successful Deployments of Microsoft Sentinel eBook The eBook summarizes insights from hundreds of hands-on deployments and 16 anonymized case studies.
SI017 BlueVoyant ClearBank's Journey with BlueVoyant | Webinar BlueVoyant says it optimized ClearBank’s existing Microsoft Security investment for better outcomes.
SI018 GovConWire BlueVoyant Purchases Conquest Cyber, Raises Over $140M in Series E Funding Round The acquisition coincided with a Series E funding round that raised over $140 million from BlueVoyant’s existing investors.
SI019 FinTech Global BlueVoyant bags $140m Series E and snaps up cybersecurity firm This substantial investment was led by existing investors Liberty Strategic Capital and ISTARI.
SI020 Pulse 2.0 BlueVoyant: Conquest Cyber Acqusition And Over $140 Million In Series E Funding BlueVoyant also raised over $140 million in Series E funding to accompany the acquisition of Conquest Cyber.
SI021 The SaaS News BlueVoyant Raises $140 Million in Series E Funding details listed a $140.0M Series E in November 2023 led by Liberty Strategic Capital and ISTARI.
SI022 Private Equity Insights BlueVoyant raises $250m in funding round led by Steven Mnuchin-backed PE firm The firm intends to use the capital raised to ramp up the development of its products and expand into new international markets.
SI023 CB Insights BlueVoyant Stock Price, Funding, Valuation, Revenue & Financial Statements CB Insights says BlueVoyant has raised $665.5M over 9 rounds and estimated 2024 revenue at $750M.
SI024 GetLatka BlueVoyant Revenue 2025: $213.5M ARR, $1B Valuation In 2025, BlueVoyant's revenue reached $213.5M and the profile estimated roughly 650 employees.
SI025 Origin by Dialectica BlueVoyant: Ownership, Revenue & Funding Data Dialectica lists BlueVoyant as PE-backed with 653 employees and Liberty Strategic Capital as investor.
SI026 Clay How Much Did BlueVoyant Raise? Funding & Key Investors Clay lists total amount raised at $665.5 million, 11 investors, and over 1,000 customers across 45 countries.
SI027 Tracxn BlueVoyant Tracxn reports BlueVoyant has raised a total of $696M over 6 funding rounds.
SI028 PitchBook BlueVoyant Company Profile: Valuation & Investors | PitchBook The accessible PitchBook snapshot showed 363 employees, a $30M latest deal amount, and a historical Debt - PPP entry dated 27-Apr-2020.
SI029 Companies House BLUEVOYANT UK LIMITED filing history - Find and update company information BlueVoyant UK Limited filed full accounts made up to 31 December 2024 on 30 Sep 2025.
SI030 Companies House BLUEVOYANT LTD filing history - Find and update company information BlueVoyant Ltd filed full accounts made up to 31 December 2024 on 30 Sep 2025.
SI031 Indeed via Wayback Working at BlueVoyant: Employee Reviews A featured review warned that BlueVoyant was extremely top heavy with consistent bi-yearly layoffs and limited resources in some business units.
SE001 BlueVoyant MDR, TPRM, Digital Risk Protection | BlueVoyant
SE002 BlueVoyant BlueVoyant Cyber Defense Platform Seamlessly integrated MDR, TPRM, and DRP.
SE003 BlueVoyant BlueVoyant AI | Agentic SecOps Platform AI that knows where to act and when to ask.
SE004 BlueVoyant Managed Detection & Response
SE005 BlueVoyant MDR for Microsoft 24/7 detection and response across your full Microsoft security stack.
SE006 BlueVoyant Continuous Optimization for Microsoft Solutions
SE007 BlueVoyant Continuous Optimization for Microsoft Security
SE008 BlueVoyant Third-Party Risk Management (TPRM)
SE009 BlueVoyant Continuous Monitoring & Remediation
SE010 BlueVoyant Questionnaire Management
SE011 BlueVoyant Digital Risk Protection (DRP)
SE012 BlueVoyant Brand Protection
SE013 BlueVoyant Dark Web Watcher
SE014 BlueVoyant Executive Cyber Guard
SE015 BlueVoyant Comprehensive Third-Party Cyber Risk Management Solution
SE016 BlueVoyant BlueVoyant Acquires Conquest Cyber Conquest Cyber's SaaS technology modernizes risk management with a platform that unifies an organization's entire cyber risk management program.
SE017 BlueVoyant BlueVoyant Trust Center BlueVoyant delivers a comprehensive cloud-native security operations platform that provides real-time threat monitoring for networks, endpoints, and supply chains, extending to the clear, deep, and dark web.
SE018 GitHub Bluevoyant
SE019 GitHub Bluevoyant
SE020 GitHub GitHub - Bluevoyant/BV-Security-Copilot: Public Content for Copilot for Security Public Content for Copilot for Security.
SE021 PR Newswire BlueVoyant Unveils Leading-Edge Security Operations Platform The platform integrates internal, external, and supply chain defense solutions into a single, cloud-native platform.
SE022 PR Newswire BlueVoyant Ignites the Next Era of Cyber Defense with Launch of BlueVoyant AI BlueVoyant AI brings true AI-native Security Operations Center (SOC) capabilities to life, delivering real-time, deterministic decision-making, automated response, and faster containment.
SE023 PR Newswire BlueVoyant Expands Offerings to Establish the Only Comprehensive Third-Party Cyber Risk Management Solution
SE024 PR Newswire BlueVoyant Acquires Conquest Cyber to Meet Market Need for Comprehensive Managed Detection and Response and Cyber Risk Posture Solutions
SE025 PeerSpot BlueVoyant CORE Reviews, Competitors and Pricing
SE026 Cyber Magazine BlueVoyant Launch Platform to Tackle Supplier Attack Surface
SE027 SecuritySenses BlueVoyant Unveils Leading-Edge Security Operations Platform
SE028 Gartner Peer Insights BlueVoyant Reviews, Ratings & Features 2026 | Gartner Peer Insights
SE029 Gartner Peer Insights BlueVoyant Digital Risk Protection Reviews & Ratings 2026 | Gartner Peer Insights Effective detection and ticket management with occasional takedown challenges
SE030 Spiceworks Community BlueVoyant | Thoughts, opinions, experiences? They are a startup, which is concerning ... I believe the back-end is Splunk.
SE031 InNetwork Tech BlueVoyant Core: MDR for Microsoft (Managed Detection and Response) BlueVoyant’s service allows you to keep your security data in your own environment, reducing cost and ensuring stronger compliance.
SE032 Microsoft How to order the SWAG as part of attending "BLUEVOYANT Shadow Hunter -Security Immersion Workshop - Microsoft Q&A
SU001 BlueVoyant California’s Innovative Cybersecurity Initiative 70% Reduction in Mean Time to Detect (MTTD); 60% Reduction in Mean Time to Respond (MTTR); $2.1 Million annual personnel cost savings/entity utilizing SOCaas
SU002 BlueVoyant ODEON Cinemas Group 98% reduction in alerts requiring InfoSec or Regional IT review
SU003 BlueVoyant Snappi Neobank: Enterprise-Grade Security from Day One 24/7 SOC coverage operational from the outset
SU004 BlueVoyant Partners
SU005 BlueVoyant Beeks Group Selects BlueVoyant to Strengthen its 24x7 SOC
SU006 BlueVoyant Maximizing Your Investment with Microsoft Security | Webinar
SU007 BlueVoyant Digital Brand Protection for Financial Institutions
SU008 BlueVoyant Financial Exchanges - External Cyber Defense for When Your Attack…
SU009 BlueVoyant Securing State and Local Governments from Threats
SU010 BlueVoyant Avoiding the Government Third-Party Risk Domino Effect
SU011 BlueVoyant Total Economic Impact™ of BlueVoyant Supply Chain Defense Report
SU012 BlueVoyant The State of Supply Chain Defense: Annual Global Insights Report 2025
SU013 BlueVoyant BlueVoyant and Carahsoft Partnership
SU014 BlueVoyant ClearBank's Journey with BlueVoyant | Webinar
SU015 BlueVoyant Protecting the Grid: The Evolving Threat Landscape and Proactive…
SU016 BlueVoyant Defending Law Firms from Cyber Threats
SU017 BlueVoyant Total Economic Impact™ of BlueVoyant MDR Services
SU018 BlueVoyant Microsoft Security Excellence Award Winners
SU019 Navy SBIR/STTR Program Success Story In October 2021, Naval Sea Systems Command (NAVSEA) ... awarded a three-year single-award indefinite delivery contract to BlueVoyant Government Solutions
SU020 PR Newswire BlueVoyant's 202 Group Expands its Supply Chain Risk Management Solutions and Rebrands as BlueVoyant Government Solutions
SU021 FeaturedCustomers 14 BlueVoyant Customer Reviews & References
SU022 FeaturedCustomers 9 BlueVoyant Customer Reviews & References
SU023 PeerSpot BlueVoyant CORE Reviews, Competitors and Pricing
SU024 Carahsoft BlueVoyant and Carahsoft Partner to Defend Public Sector from Cyber Threats | Carahsoft
SU025 AWS Marketplace MDR for Splunk Cloud. Please contact BlueVoyant for Private Offer.
SU026 Beeks Group Beeks Group Collaborating With BlueVoyant | Beeks Group
SU027 Intelligence Community News BlueVoyant and Carahsoft announce partnership - Intelligence Community News
SU028 UpGuard BlueVoyant Security Rating, Vendor Risk Report, and Data Breaches | UpGuard
SU029 Slashdot Compare BitSight vs. BlueVoyant in 2026
SU030 Carahsoft BlueVoyant Government IT Procurement Contracts | Carahsoft
SU031 BlueVoyant Government Solutions SCRM Solutions Offered on GSA's SCRIPTS BPA via Carahsoft
SU032 Carahsoft Technology Reseller Partner Program | Carahsoft
SU033 Intelligent CISO BlueVoyant strengthens cyber defence for ODEON Cinemas Group across eight countries – Intelligent CISO
SU034 Veracloud How Snappi Built Enterprise-Grade Cybersecurity from Day One with Veracloud and BlueVoyant
SU035 MaltaCEOs Veracloud brings operational security to Greece’s first neobank
SU036 California Department of Technology Security Operations Center as a Service (SOCaaS)
SU037 California Department of Technology How California is Centralizing Public Sector Cybersecurity
SU038 MSSP Alert MSSP BlueVoyant Launches SOCaaS Powered by Microsoft Azure Sentinel -
SR001 BlueVoyant Privacy Policy & Legal Notice BlueVoyant LLC is the controller of your personal data and may share personal information with affiliate companies unless prohibited by law.
SR002 BlueVoyant BlueVoyant & Microsoft Streamline security with Microsoft XDR/E5 and Sentinel, delivering unified threat detection, response, and monitoring across your environment.
SR003 BlueVoyant MDR for Microsoft - Manage & Monitor Harness the full power of Microsoft Security with our elite 24x7 SOC and security operations team backed by BlueVoyant AI.
SR004 BlueVoyant Next Era of Cyber Defense with BlueVoyant AI BlueVoyant AI provides both with its fully managed service - supported 24/7 with BlueVoyant’s elite SOC team - or as an enterprise-grade SaaS platform.
SR005 BlueVoyant BlueVoyant Acquires Conquest Cyber BlueVoyant raised more than $140 million in Series E funding to accompany the acquisition of Conquest Cyber.
SR006 BlueVoyant John Hernandez Joins BlueVoyant as CEO John Hernandez will succeed Jim Rosenthal as Chief Executive Officer with a focus on scaling an AI-driven cybersecurity platform.
SR007 BlueVoyant BlueVoyant Welcomes New Chief Product Officer Amit Jasuja will guide BlueVoyant’s strategic product direction, aiming to unify product lines and expand the company’s share of the cybersecurity market.
SR008 BlueVoyant New Security Operations Centre in Cork, Ireland The new SOC will provide 24x7 monitoring of Irish and EU clients’ networks and digital ecosystems.
SR009 BlueVoyant Microsoft Security Excellence Award Winners BlueVoyant also won the Security Trailblazer award.
SR010 BlueVoyant 2024 Microsoft Worldwide Security Partner of the Year BlueVoyant announced it has won the 2024 Microsoft Worldwide Security Partner of the Year Award.
SR011 BlueVoyant Government Solutions BlueVoyant Government Solutions | Supply Chain Defense BlueVoyant Government Solutions operationalizes mission assurance with deep supply chain risk visibility and expert-led threat remediation at scale.
SR012 BlueVoyant Government Solutions Customers Supporting federal government agencies with end-to-end cyber supply chain risk management.
SR013 PR Newswire BlueVoyant is a proud participant in the Microsoft Sentinel partner ecosystem BlueVoyant is working with Microsoft product teams to shape Sentinel product development.
SR014 PR Newswire BlueVoyant Recognized as the Winner of 2024 Microsoft Worldwide Security Partner of the Year The company has additionally been named the Microsoft United States Security Partner of the Year for the third consecutive time.
SR015 PR Newswire UK BlueVoyant Expands in EU with New Cutting-Edge Security Operations Centre in Cork, Ireland With cyber security teams grappling with the enforcement of new EU regulations such as NIS 2 and DORA, clients now require a holistic, next-generation managed security service.
SR016 Microsoft Security Blog BlueVoyant optimizes customer security with Microsoft security services BlueVoyant speaks with a lot of companies about their security technology deployment and one of the main trends found is tech sprawl.
SR017 Microsoft Security Blog Microsoft announces the 2025 Security Excellence Awards winners The Microsoft Security Excellence Awards honor outstanding contributions across several categories.
SR018 Protiviti BlueVoyant Partnership | Protiviti US The platform integrates advanced AI technology with expert human insight to offer extensive protection and swift threat mitigation.
SR019 Carahsoft BlueVoyant Government IT Procurement Contracts | Carahsoft Carahsoft lists NASA SEWP V, ITES-SW2, SCRIPTS BPA, and CMAS contract access for BlueVoyant.
SR020 PacerMonitor Steward Health Care System LLC, et al., v. Bluevoyant LLC Complaint to (I) Avoid and Recover Avoidable Transfer(s) and (II) Disallow Claims by Steward Health Care System LLC against Bluevoyant LLC.
SR021 National Institute of Standards and Technology Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations The security requirements are intended for use by federal agencies in contractual vehicles or other agreements established between those agencies and nonfederal organizations.
SR022 U.S. Department of Defense CIO CIO - CMMC Resources & Documentation CMMC Phase 1 Implementation (Nov 10, 2025 - Nov 9, 2026) focuses primarily on CMMC Level 1 and Level 2 self-assessments.
SR023 U.S. Department of Defense CMMC 2.0 Details and Links to Key Resources Beginning November 10, contracting officers will include the new CMMC requirements in new solicitations and contracts.
SR024 PM Insights BlueVoyant Valuation | PM Insights Sample data shown with delay for preview purposes. Real-time, institutional-grade datasets available to subscribers.
SR025 SourceForge Best BlueVoyant Alternatives & Competitors SourceForge ranks the best alternatives to BlueVoyant in 2026.
SR026 PeerSpot BlueVoyant CORE Reviews, Competitors and Pricing Their MDR service offers 24/7 monitoring and threat hunting by a team of experts, utilizing advanced analytics and machine learning.
SR027 SecuritySenses BlueVoyant Recognised as Microsoft Security Excellence Award Winners BlueVoyant also won the Security Trailblazer award.
SR028 Yahoo Finance BlueVoyant is a proud participant in the Microsoft Sentinel partner ecosystem BlueVoyant is building on it with custom analytics, Copilot-ready content, and lessons tested in the field.
SR029 Pavilion BlueVoyant Government Solutions Government Contracts | Pavilion BlueVoyant provides government-focused supply chain risk management and cybersecurity services, including CMMC + NIST 800-171 compliance management.
SR030 SAM.gov Contract Award Data in SAM.gov The contract award search function in SAM.gov allows users to search federal procurement data and to filter by keyword, agency, and legal business name.
SR031 USAspending Government Spending Open Data | USAspending USAspending is the official open data source of federal spending information, including information about federal awards such as contracts, grants, and loans.
SR032 SecuritySenses BlueVoyant Ignites the Next Era of Cyber Defence with Launch of BlueVoyant AI BlueVoyant AI brings true AI-native Security Operations Centre capabilities to life.
SR033 BlueVoyant Successful Deployments of Microsoft Sentinel eBook This eBook summarizes the guide’s 16 real world anonymized case studies based on hundreds of hands-on deployments.
SR034 BlueVoyant BlueVoyant Recognized in Gartner’s Market Guide for Third-Party Risk Management The percentage of cyber breaches involving third parties doubled over the past year to 30% according to Verizon’s 2025 DBIR.
SV001 BlueVoyant BlueVoyant Enters 2023 with Momentous Growth Growing annual recurring revenues at an average of 108% since 2018, with recurring revenue growing 80% in 2022.
SV002 PR Newswire / BlueVoyant BlueVoyant Acquires Conquest Cyber to Meet Market Need for Comprehensive Managed Detection and Response and Cyber Risk Posture Solutions BlueVoyant raised more than $140 million in Series E funding to accompany the acquisition.
SV003 PR Newswire / BlueVoyant BlueVoyant Raises $250 Million Series D Led by Liberty Strategic Capital Liberty Strategic Capital ... led the $250-million round with participation from ... ISTARI ... Eden Global Partners ... and 8VC.
SV004 Caplight BlueVoyant | Valuation, Funding Rounds & Stock Price | Caplight Last Round Series E ... Nov 29, 2023 ... Est. Valuation $1B ... Total Funding Raised $665.5M.
SV005 Notice.co BlueVoyant Stock $1.36 | How to Buy, Valuation, Stock Price, IPO | Notice.co The current Notice Price premium (+) or discount (-) to the last round ... -39%.
SV006 Forge Invest and Sell BlueVoyant Stock - Forge Market activity ... Limited ... Forge Price $-- Not yet available ... Last known valuation $1B 2/23/2022.
SV007 Hiive BlueVoyant Stock | Invest or Sell Buy and sell BlueVoyant stock. Get stock prices & access to pre-IPO shares in one place at Hiive.
SV008 Tracxn BlueVoyant - 2026 Funding Rounds & List of Investors BlueVoyant has raised a total of $696M over 6 funding rounds.
SV009 GetLatka BlueVoyant Revenue 2025: $213.5M ARR, $1B Valuation In 2025, BlueVoyant's revenue reached $213.5M.
SV010 BlueVoyant MDR, TPRM, Digital Risk Protection | BlueVoyant Agentic SecOps, MDR, and TPRM to protect your entire attack surface.
SV011 Eden Global Partners BlueVoyant Raises $250 Million Series D Led by Liberty Strategic Capital BlueVoyant Raises $250 Million Series D Led by Liberty Strategic Capital.
SV012 U.S. Securities and Exchange Commission EDGAR Search Results — BlueVoyant Acc-no: 0000950103-20-013356 ... 2020-07-08 ... Acc-no: 0000950103-19-005109 ... 2019-04-25 ... Acc-no: 0000950103-17-007618 ... 2017-08-04.
SV013 CompaniesMarketCap CrowdStrike (CRWD) - Market capitalization As of June 2026 CrowdStrike has a market cap of $178.47 Billion USD.
SV014 CompaniesMarketCap SentinelOne (S) - Market capitalization As of June 2026 SentinelOne has a market cap of $5.43 Billion USD.
SV015 CompaniesMarketCap Rapid7 (RPD) - Market capitalization As of June 2026 Rapid7 has a market cap of $0.51 Billion USD.
SV016 CompaniesMarketCap Tenable (TENB) - Market capitalization As of June 2026 Tenable has a market cap of $3.33 Billion USD.
SV017 CompaniesMarketCap Qualys (QLYS) - Market capitalization As of June 2026 Qualys has a market cap of $4.34 Billion USD.
SV018 Windsor Drake Cybersecurity Valuations: Q2 2026 The public cybersecurity median is 6.0x–6.5x NTM revenue ... managed security services to 3x–5x.
SV019 multiples.vc Largest Cybersecurity Public Companies CrowdStrike ... endpoint, cloud workload, identity, and security operations ... Rapid7 ... expanded its portfolio to provide extended detection and response, SIEM ...
SV020 Tablestat Valuation Trading Multiples & Precedent Transactions: Enterprise Cybersecurity Software Providers Revenue growth Median 15.7% 2025E 16.0% 2026E ... 8.4x ... 6.8x.
SV021 Yahoo Finance CrowdStrike Holdings, Inc. (CRWD) Stock Price, News, Quote & History - Yahoo Finance Enterprise Value/Revenue 34.30 ... Revenue (ttm) 5.09B.
SV022 Yahoo Finance SentinelOne, Inc. (S) Stock Price, News, Quote & History - Yahoo Finance Enterprise Value/Revenue 4.61 ... Revenue (ttm) 1.05B.
SV023 Yahoo Finance Rapid7, Inc. (RPD) Stock Price, News, Quote & History - Yahoo Finance Enterprise Value/Revenue 0.93 ... Revenue (ttm) 859.23M.
SV024 Yahoo Finance Tenable Holdings, Inc. (TENB) Stock Price, News, Quote & History - Yahoo Finance Enterprise Value/Revenue 3.32 ... Revenue (ttm) 1.02B.
SV025 Yahoo Finance Qualys, Inc. (QLYS) Stock Price, News, Quote & History - Yahoo Finance Enterprise Value/Revenue 5.73 ... Revenue (ttm) 684.86M.
SV026 PM Insights BlueVoyant Valuation | PM Insights BlueVoyant Secondary Market ROI ... BlueVoyant Bid-Ask Volume Ratios ... BlueVoyant Mutual Fund Valuations (NAV) ... BlueVoyant Funding Rounds & Cap Table Details.
SV027 CB Insights BlueVoyant - Products, Competitors, Financials, Employees, Headquarters Locations Stage Series E | Alive ... Total Raised $665.5M ... Last Raised $140M.
SV028 Yahoo Finance Palo Alto Networks, Inc. (PANW) Stock Price, News, Quote & History - Yahoo Finance Enterprise Value/Revenue 23.28 ... Revenue (ttm) 10.61B.
SV029 Yahoo Finance Fortinet, Inc. (FTNT) Stock Price, News, Quote & History - Yahoo Finance Enterprise Value/Revenue 15.20 ... Revenue (ttm) 7.11B.
SV030 CompaniesMarketCap Palo Alto Networks (PANW) - Market capitalization As of June 2026 Palo Alto Networks has a market cap of $247.92 Billion USD.
SV031 CompaniesMarketCap Fortinet (FTNT) - Market capitalization As of June 2026 Fortinet has a market cap of $110.88 Billion USD.
SV032 SiliconANGLE BlueVoyant acquires cyber defense company Conquest Cyber, raises $140M Including the new funding, BlueVoyant has raised about $646 million to date, according to data from Tracxn.