初创公司尽调
尽调报告 Cybersecurity / MDR and third-party cyber risk management Series E (private unicorn) 2026-06-29

BlueVoyant

网络防御平台具备 MDR 与 TPRM 规模,但私募市场信息仍不透明

BlueVoyant 是可信的后期网络安全平台,MDR 和 TPRM 已有真实规模,受监管行业定位有差异化,也能借 Microsoft 生态放大;但私营公司不透明,加上估值和收入冲突未解,更适合观察而不是确信买入。

封面要素

公司概况

BlueVoyant 成立于 2017 年,总部位于纽约市。公司公开材料将其定位为统一网络防御平台,覆盖 MDR、第三方风险管理、数字风险防护和专业服务,并且与 Microsoft 安全工具深度绑定,在政府及其他受监管行业有明显足迹。公司已有可信商业规模——45 个国家超过 1,000 家客户、600 多名员工,并在 2022 年完成 $250M Series D、跨过 $1B 独角兽门槛后,于 2023 年公开宣布超过 $140M 的 Series E。不过,当前估值、ARR 质量、利润率结构和所有权结构在公开数据中仍只露出一部分,限制了承销信心。

官网
www.bluevoyant.com
创始人
Jim Rosenthal, Tom Glocer
创立地点
New York, New York, USA
总部
New York, New York, USA (6 East 45th Street, Floor 17)
产品
BlueVoyant 销售一套网络防御平台,覆盖托管检测与响应、第三方风险管理 / 供应链防御、数字风险防护和专业服务。当前路线图强调 AI-native SecOps、Microsoft-native 部署和持续供应商风险修复,而不是一次性评估。
客户
大型企业、金融服务机构、政府机构、国防工业基础实体,以及其他需要托管 SOC 覆盖、Microsoft 安全优化和跨供应商第三方网络风险管理的受监管组织。
商业模式
围绕 MDR、TPRM、DRP 以及咨询 / 响应服务的经常性托管安全与软件收入,并借助 Microsoft 生态工作、公共部门项目和渠道伙伴做交叉销售。
阶段
Series E (private unicorn)
融资情况
公开资本历史包括 2022 年 2 月由 Liberty Strategic Capital 领投的 $250M Series D,以及 2023 年 11 月与收购 Conquest Cyber 同时宣布的超过 $140M Series E。第三方数据集将总融资额置于约 $665.5M 至 $696M。
[CO001, CO002, CO003, CO004, CO005, CO020, CO021, CO023]

执行摘要

主要优势

  • BlueVoyant 在一个平台里覆盖 MDR、TPRM、DRP 和服务,销售的是统一网络防御,而不是单点控制。
  • 公司已有可信企业规模:在 45 个国家超过 1,000 名客户、600 多名员工,并在公共部门和受监管行业拿到有分量的进展。
  • BlueVoyant 的 Microsoft 专长是耐久的 go-to-market 优势,大量部署、认证合作伙伴身份和客户 ROI 研究共同强化了这一点。
  • Liberty Strategic Capital、ISTARI、Temasek 相关资本和其他投资人的资金支持,让公司即便处在艰难私募市场背景下仍有战略可信度。

主要风险

  • 公开财务能见度差:经审计 ARR、增长、毛利率、烧钱速度、NRR 和股权结构条款都未披露,公开收入估计还彼此冲突很大。
  • 最后一个清晰的独角兽估值锚已经过期,私募市场数据也无法干净、高置信地读出当前企业价值或清算优先权。
  • BlueVoyant 在拥挤的 MDR 和网络风险市场竞争,对手包括 Palo Alto Networks、CrowdStrike、Rapid7、Arctic Wolf 等更大平台,以及 BitSight、SecurityScorecard 这类风险专攻者。
  • 业务模式仍实质依赖服务交付和 Microsoft 生态执行,可能压住利润率扩展,并放大平台依赖风险。
  • 2026 年 AI 产品再定位抬高了执行风险:公司必须证明差异化不只是营销,同时还要在不断扩大的平台上守住服务质量。

未决问题

  • 经审计 ARR、收入增长、毛利率、NRR、烧钱速度和现金余额。
  • 完全摊薄股权结构表、优先股条款、清算优先权和任何老股交易细节。
  • 2023 年 11 月 Series E 的精确当前估值,以及 2026 年老股成交是否验证或折价独角兽标记。
  • MDR、TPRM、DRP、专业服务和政府项目之间的收入组合。
  • 按垂直行业拆分的客户集中度和留存,尤其是政府和金融服务。
  • 2026 年 6 月 BlueVoyant AI 发布后,AI 产品采用、定价和转化影响的独立证据。

目录

Chapter 01

01公司概览

1.1 身份、总部与商业模式

BlueVoyant 将自己呈现为一家网络防御平台公司,成立于 2017 年,总部在纽约。其官方公司页和联系页把当前足迹锚定在曼哈顿,同时也显示出更广的跨国运营基础。公司称拥有 600 多名员工、45 个国家超过 1,000 家客户;即便不看第三方估算,也已越过创业孵化阶段,进入有规模的私营公司区间。产品上,BlueVoyant 并不把自己描述为单点工具厂商。其平台结合托管检测与响应、第三方风险管理、数字风险防护和专业服务,收入看起来来自经常性软件模块以及分析师主导的托管运营。所审阅材料始终把 BlueVoyant 放在企业、政府和关键基础设施用例中,而不是狭窄的 SME 或消费者路径。这一组合会影响后续尽调:它意味着更长销售周期、更重服务导入,以及对受监管或任务关键买家的差异化敞口。[CO001, CO002, CO003, CO004, CO005, CO006]

快照 KPI 表
指标数值 / 状态日期置信度缺口 / 备注
成立20172017官方和独立来源相互印证
总部6 East 45th Street, Floor 17, New York, NY 10017(总部地址)2026-06-29官方领导层 / 联系页面
官方员工披露600+ 名员工2026-06-29公司口径;第三方估算更高
客户披露45 个国家的 1,000+ 名客户2026-06-29公司在联系页披露
核心平台MDR + TPRM + DRP + 专业服务2026-06-29官方套件页面
最近一次公开确认融资> $140M Series E,伴随收购 Conquest Cyber2023-11-29已审阅公开记录未显示后续具名融资轮
第三方总融资估算~$665.5M2025-11-28私募市场数据库估算,未经审计
第三方估值估算~$1B2025-11-28未披露官方当前估值
现任 CEOJohn Hernandez2026-05-05接替联合创始人 Jim Rosenthal
近期产品发布BlueVoyant AI2026-06-09AI 原生 / agentic SecOps 定位
Microsoft 认可2024 Worldwide + U.S. + Canada 年度安全合作伙伴荣誉2024历史奖项信号,不是当前财务指标

融资、估值和外部员工数混合了官方披露与私募市场或监测估算;非官方数值行应视为方向性信息,而非审计数据。

[CO001, CO002, CO003, CO004, CO005, CO016]
FO002: 公司快照逻辑

BlueVoyant 把创始人塑造的治理层,连到一体化网络安全平台、Microsoft 生态杠杆、全球客户足迹,以及经济指标仍未公开的私募资本基础。

[CO005, CO017, CO028, CO032, CO035, CO043]
FO003: 快照 KPI

最清晰的公开信号指向一家已有规模的私营网络安全平台,生态认可度强,但经济指标仍未公开。

融资和估值是第三方私募市场估算;客户和员工数字使用公司自行披露的最低门槛,而非精确审计数量。

[CO003, CO004, CO015, CO028]

1.2 领导层、治理与关键人物风险

BlueVoyant 当前公开领导层图谱由近期交接塑造。John Hernandez 现任 CEO,联合创始人 Jim Rosenthal 转任主席,联合创始人 Thomas Glocer 仍任副主席。当前运营班底足以覆盖财务、产品、技术、信息安全、人力资源、政府解决方案、区域销售和伙伴关系,降低了对任何单一职能副手的依赖。即便如此,创始人影响力仍然重要,因为 Rosenthal 与 Glocer 仍是核心治理人物,公司的公开叙事也仍高度依赖创始人身份。这个组合指向一种显著但可管理的关键人物风险:BlueVoyant 已完成最高层交接,但其公共可信度、投资者连续性和战略叙事仍穿过创始人。此前公开任命 Michael Montoya 为 COO,也说明 BlueVoyant 在规模化阶段愿意刷新董事会以下的运营层。[CO009, CO010, CO011, CO012, CO013, CO014]

领导层与创始人表
人物职务背景 / 公开语境职能覆盖 / 创始人-市场匹配关键人物依赖
John Hernandez首席执行官2026 年 5 月获任 CEO,负责在全球扩展 AI 驱动的网络安全平台现任运营负责人,承接创始人主导阶段后的转折点
James Rosenthal联合创始人;董事会主席联合创始人、前 CEO;CEO 交接后仍是治理锚点在战略、投资者连续性和董事会影响力上具备高创始人-市场匹配
Thomas Glocer联合创始人;董事会副主席联合创始人,曾任 Thomson Reuters 首席执行官在纯网络安全履历之外,增加企业运营和董事会可信度
Ravi Subramanian首席财务官现任领导层页面公开列出的财务负责人覆盖规划、财务和投资者准备职能
Sebastian Sobolev首席产品官领导层页面列出的现任产品负责人负责平台 / AI 演进的路线图和打包中-高
Jim Bieda全球首席技术官领导层页面列出的现任技术负责人覆盖技术架构和平台可信度中-高
John Harbaugh首席信息安全官领导层页面列出的现任安全负责人支撑信任、安全态势和企业可信度
Lonny AndersonBlueVoyant Government Solutions 总裁面向政府业务线的公开负责人对公共部门和受监管环境 GTM 很重要

本表仅反映 BlueVoyant 页面和 CEO 交接报道中公开出现并得到印证的领导者;私人公司委员会结构和完整董事会名单仍不完整。

[CO009, CO010, CO011, CO012, CO013, CO042]

1.3 融资历史、投资者与所有权可见度

BlueVoyant 公开可见的资本故事有两个主要拐点。第一,公司在 2022 年 2 月完成由 Liberty Strategic Capital 领投的 $250 million Series D,ISTARI、Eden Global Partners 和 8VC 参投。第二,2023 年 11 月,公司把 Conquest Cyber 收购与超过 $140 million 的 Series E 绑定披露,领投方为既有投资者 Liberty Strategic Capital 和 ISTARI。第三方市场数据平台目前聚集在约 $665.5 million 累计融资和估算 $1 billion 估值,但这些数字是数据库估算,不是公司认证的财务披露。因此,证据支持其资本基础强、机构背书可信,却不能给出现时精确估值。公开材料对董事会委员会、保护性条款、债务、老股转让和股权结构集中度也很薄,所以下方投资者地图应被视为尽调脚手架,而不是完全验证的控制权图。[CO020, CO021, CO023, CO026, CO027, CO028]

利益相关方或投资者地图
利益相关方角色控制 / 经济重要性公开支持尽调问题
Liberty Strategic Capital2022 Series D 领投方;2023 Series E 共同领投方锚定型机构赞助方;官方来源把该基金与近期两次主要融资都关联起来Liberty 2022 年披露 $125M 投资;2023 年融资中再次出现确认董事席位、保护性条款和任何 step-up 权利
ISTARI(Temasek 创立的网络安全投资者 / 顾问)Series D 参与方;Series E 共同领投方战略网络安全投资者,可能具备信息权相关性在 2022 和 2023 年公司相关融资报道中被点名确认持股比例、董事会观察员权利和战略商业联系
Eden Global Partners / Eden Global Capital Partners(资本方)Series D 参与方和战略顾问;关联方为 2023 年交易提供顾问服务增长股权和配售支持,而非清晰披露的控制权在 2022 年官方发布和 2023 年交易报道中被点名澄清顾问角色是否带有任何持续治理权
8VCSeries D 参与方显示风险投资参与 2022 年扩张轮在 2022 年官方融资报道中被点名确认后续跟投和当前持股比例
James Rosenthal联合创始人;主席可能拥有有意义的内部人持股,并在 CEO 交接后保持治理连续性公开材料显示其继续担任董事会职务,但未披露股数要求提供当前 cap table 和投票控制摘要
Thomas Glocer联合创始人;副主席董事会层面的战略影响力和声誉资本公开确认其为联合创始人和副主席确认股权比例和任何保留同意权
Conquest Cyber 资产 / 团队被收购的战略平台延伸对受监管、政府和 DIB 产品扩张很重要,而不是单纯所有权控制2023 年 11 月随 Series E 宣布收购审查整合里程碑、earnouts 和客户留存假设

公开来源确认了轮次领投方和战略角色,但未披露持股比例、清算栈、债务或观察员权利;因此各行强调尽调问题,而不是推断控制权。

[CO020, CO023, CO025, CO026, CO028, CO042]

1.4 平台演进、生态系统与商业定位

BlueVoyant 的定位不只是检测威胁,而是把多条网络安全工作流包进托管平台叙事。其 Microsoft 页面和获奖历史显示出异常强的生态对齐,包括多次获得安全伙伴认可,并围绕 Sentinel、Defender、Purview 以及 Copilot 时代安全运营做服务打包。伙伴计划也表明,其上市路径依赖渠道,而非纯直销。产品侧,公司已把叙事从托管网络防御扩展到更宽的 AI-native 或 agentic SecOps,并以 2026 年 6 月 BlueVoyant AI 发布作为节点。2023 年 11 月收购 Conquest Cyber 正处在这一演进中段,为受监管和政府敏感环境补上 SaaS-heavy 能力。Auto-ISAC 伙伴关系又把第三方风险叙事延伸进一个具名垂直行业。合起来看,公司更像是在复杂账户中加深钱包份额,而不是单纯增加 logo。[CO015, CO016, CO017, CO018, CO019, CO023]

1.5 里程碑、规模信号与不利考量

公开里程碑显示,BlueVoyant 从 2017 年创立故事进入资本密集扩张期,随后拓宽平台并完成管理层交接。到 2026 年,公司按官方页面描述,已经是全球化、对齐 Microsoft 且 AI-forward 的公司,拥有超过 1,000 家客户和 600 多名员工。与此同时,尽调不应过度精确。第三方员工数信号明显高于官方披露,估值和收入数字也主要来自私募市场数据库而非审计报告。保留信源中最强的公开不利信号是 UpGuard 2026 年 6 月外部风险报告,指出 CSP 弱点和 unsafe-eval 使用等具体网站安全加固问题。这不是足以推翻投资论点的事件,但值得注意,因为 BlueVoyant 销售的是安全结果。结合稀疏的公开治理和财务披露,尽调应把清晰运营动能与仍属私有的经济质量分开看。[CO021, CO028, CO029, CO030, CO031, CO032]

里程碑表
日期事件类型金额 / 估值 / 状态参与方含义
2017BlueVoyant 在 New York 成立成立公司启动包括 James Rosenthal 和 Thomas Glocer 在内的创始人确立公司作为 2016 年后网络防御新进入者,并带有创始人主导治理根基
2022-02-23Series D 完成融资$250MLiberty Strategic Capital、ISTARI、Eden Global Partners、8VC 等面向技术能力和全球扩张的主要扩张轮
2022-02BlueVoyant 被公开描述为网络安全独角兽规模> $1B 估值;迄今总融资 $525MSecurityWeek / TechCrunch 公开报道外部市场验证了 2022 年融资拐点
2023-11-29Conquest Cyber 收购随 Series E 融资宣布产品> $140M Series EBlueVoyant、Conquest Cyber、Liberty Strategic Capital、ISTARI 参与拓宽平台深度,并增加受监管环境 SaaS 能力
2023-11-29收购被定位为面向高度受监管和政府环境监管战略扩张BlueVoyant、Conquest Cyber显示公司有意转向国防工业基础和受监管买方相关场景
2024奖项页面突出 Microsoft 安全合作伙伴奖项合作Worldwide + U.S. + Canada 荣誉BlueVoyant、Microsoft强化生态可信度和渠道定位
2025-09-24Auto-ISAC 战略合作宣布合作TPRM 协作BlueVoyant、Auto-ISAC为供应链网络产品增加具名汽车垂直切口
2026-05-05John Hernandez 接替 Jim Rosenthal 出任 CEO治理领导层交接John Hernandez、Jim Rosenthal、BlueVoyant 董事会标志运营从创始人主导转向外聘 CEO 扩张阶段
2026-06-09BlueVoyant AI 发布产品AI 原生 / agentic SecOps 平台BlueVoyant围绕 AI 主导的 SOC 工作流重新定位公司
2026-06-29UpGuard 供应商风险报告标记网站安全加固问题负面CSP / unsafe-eval 发现UpGuard构成保留来源集中最清晰的公开负面信号

时间线混合了公司官方公告和高信号第三方印证;由于 BlueVoyant 是私人公司,后续融资和治理细节仍不完整。

[CO001, CO016, CO020, CO021, CO023, CO025]
FO001: 公司里程碑时间线

公开记录显示,BlueVoyant 从 2017 年创立,走到 2022 年融资扩张、2023 年平台拓宽,并在 2026 年完成管理层和 AI 产品重新定位。

[CO016, CO020, CO021, CO023, CO032, CO036]

1.6 图表

Chapter 02

02市场分析

2.1 市场边界与相邻支出

BlueVoyant 应被框定在托管检测与响应和网络安全导向第三方风险管理的交集,而不是泛化网络安全厂商,也不是广义 GRC 套件。MDR 页面强调在既有 EDR、SIEM、云和 Microsoft 安全栈之上补充 24x7 监控、事件响应和自动化。TPRM 页面强调持续监控、分析师引导修复、问卷工作流、零日告警和第四方映射。边界很重要,因为它定义了核心机会中应计入哪些支出。纳入的支出,是安全运营和供应商风险预算中用于持续检测、验证、修复和外部依赖可见性的部分。相邻支出位于 GRC、董事会汇报和更广的韧性工作流,主要替代方案仍是自建 SOC、定期问卷、电子表格驱动的供应商审查,以及只解决单层问题的点产品。[CM001, CM002, CM003, CM004, CM005, CM006]

市场定义表
细分 / 品类纳入支出排除支出买方 / 付款方相关性
MDR 叠加 / 托管 SecOps24x7 监控、威胁分诊、事件响应、现有 EDR、SIEM、云和 Microsoft 安全工具调优独立端点许可证、防火墙或通用网络硬件CISO、SOC 负责人、安全运营预算BlueVoyant MDR 核心边界
网络安全聚焦 TPRM持续监控、供应商网络安全发现、分析师主导补救、问卷工作流、zero-day 告警通用供应商主数据和非网络安全采购管理CISO、第三方风险负责人、合规、采购BlueVoyant TPRM 核心边界
第四方与集中度分析依赖映射、nth-party 可见性、what-if 分析、集中度暴露管理不做依赖映射的一次性纯评估企业风险、韧性、安全、采购供应链网络风险中的重要扩张切口
AI 辅助网络安全分诊攻击面监控、威胁情报补强、漏洞优先级排序、自动化分诊支持未整合安全工作流的通用 AI 工具安全运营和网络防御团队支撑 MDR 和数字风险相邻业务
GRC / 董事会报告相邻业务控制报告、治理工作流、可提交董事会的网络风险摘要、政策证据管理宽泛的法律、审计、HR 和非网络安全治理套件合规、审计、董事会、企业风险相邻支出,不应计入纯 BlueVoyant 核心 TAM
现状和替代动作内部 SOC、电子表格驱动的供应商审查、年度问卷、狭窄点工具、手工补救邮件N/A现有流程负责人解释为什么转化是渐进且多步骤的

边界是托管 SecOps 与网络安全聚焦供应商风险监控的交集。通用 GRC 和独立安全控制是相邻领域,不是直接核心 TAM。

[CM001, CM002, CM003, CM004, CM005, CM006]

2.2 规模测算视角——TAM、SAM 与互相矛盾的公开估算

BlueVoyant 的市场可以测算,但只能用分层逻辑,不能只看一个 headline TAM。MDR 估算从 Precedence Research 的 2026 年 $3.92B,到 Mordor 的 $5.09B,The Business Research Company 则为 $4.16B。TPRM 对定义更敏感:TBRC 直接给出 2026 年 $8.09B,NextMSC 的 2025 年基线和 Grand View Research 的 2023 年基线则隐含接近 $11B 的标准化 2026 年数值。这些矛盾不是噪音,而是反映了各方对软件与服务、合规工作流与网络监控、相邻 GRC 范围的处理不同。对 BlueVoyant 而言,把 MDR 与 TPRM 公开基线合并、扣除重叠前,合理的 2026 年核心市场总天花板约为 $12–16B。更实际的 SAM 在套用大型企业、受监管买家和西方市场过滤后收窄到约 $5–8B。公开数据无法支持精确到美元的 SOM,因为 BlueVoyant 不披露分模块收入或胜率,所以 SOM 应被视为受证据约束,而不是被编造出来。[CM009, CM010, CM011, CM012, CM013, CM014]

TAM / SAM / SOM 或规模测算视角表
视角发布方年份 / 期间地区数值CAGR / 份额方法置信度局限
MDR 公开基准Precedence Research2026 to 2035全球2026 年 USD 3.92B -> 2035 年 USD 13.90B15.12%MDR 市场品类预测周期很长,且品类定义取决于发布方
MDR 另一公开基准Mordor Intelligence2026 to 2031全球2026 年 USD 5.09B -> 2031 年 USD 13.45B21.45%当前品类市场规模测算,包含细分份额服务范围比部分同行更宽
MDR 第三方公开基准The Business Research Company2026 to 2030全球2026 年 USD 4.16B -> 2030 年 USD 8.57B19.8%MDR 市场标题预测时间窗口和范围不同于 Precedence 与 Mordor
TPRM 直接 2026 基准The Business Research Company2026 to 2030全球2026 年 USD 8.09B -> 2030 年 USD 15.45B17.6%TPRM 市场标题预测可能包含 BlueVoyant 网络安全特定切口之外的解决方案和服务层
TPRM 2026 代理值,来自 2025 基准NextMSC2025 to 2030全球2025 年 USD 9.71B;折算 2026 年约 USD 11.02B;2030 年 USD 18.28B13.48%将 2025 基准向前推一年,以便与 2026 口径可比2026 数字由 2025 基准转换而来
基于 2023 年基准的 TPRM 2026 年代理值Grand View Research2023 年至 2030 年全球2023 年为 USD 7.42B;标准化到 2026 年约 USD 11.49B;2030 年达 USD 20.59B15.7%为保证 2026 年口径可比,将 2023 年基准向前复合推算2026 年数字由 2023 年基线转换而来
相邻 GRC 参照Mordor Intelligence2026 年至 2031 年全球2026 年为 USD 23.32B -> 2031 年达 USD 39.01B10.84%更宽口径的治理、风险与合规软件市场可作相邻参照,但口径太宽,不能计入 BlueVoyant 直接核心 TAM
BlueVoyant 2026 年核心总天花板分析师基于 MDR + TPRM 基线综合估算2026 年代理值全球约 USD 12.0B 至 USD 16.6Bn/a低端和高端分别相加已发布 MDR 与标准化 TPRM 基线,尚未扣除重叠部分预算重叠被重复计算,且未纳入定价 / 模块组合细节
BlueVoyant 可服务 SAM分析师基于品类筛选综合估算2026 年代理值受监管大型企业;北美 / 欧洲权重更高约 USD 5B 至 USD 8Bn/a在核心天花板上套用大型企业、受监管买方和西方市场筛选需要管理层提供地区、细分市场和模块组合数据来验证
BlueVoyant 公开数据下的 SOM公开数据视角2026BlueVoyant 目标账户公开数据无法支撑n/a没有公开披露细分收入或模块份额需要管理层披露收入组合、胜率和客户集中度

刻意保留相互矛盾的分析师估计。TPRM 2026 代理行把较早基线转换成统一的 2026 年视角;SAM 和 SOM 行是分析师推导视角,不是公司披露数字。

[CM009, CM010, CM011, CM012, CM013, CM014]
FM001: BlueVoyant 的分层市场规模视角

从邻近治理语境到 BlueVoyant 更窄的实际 SAM,形成三层视角。

顶层使用 Mordor 的 2026 年 GRC 估算。中层是在重叠扣除前,公开 MDR 和标准化 TPRM 基线的中点。底层是在大型企业、受监管买方和西方市场过滤后的低信心 SAM 中点;它不是公司披露数字。

[CM017, CM018, CM019]
FM002: 已发布市场估算区间——相互矛盾的 2026 年基线

以 USD 十亿美元展示低 / 高区间,说明在公司特定过滤之前,已发布的 2026 年市场基线分歧有多大。

MDR 低 / 高值直接来自 Precedence 和 Mordor 的 2026 年基线。TPRM 高值用 Grand View 的 2023 年基数和其披露 CAGR 换算为 2026 年代理值,TPRM 低值使用 TBRC 直接给出的 2026 年数值。核心上限行把重叠前的公开类别区间相加;SAM 是过滤后的估算,不是公司报告数字。

[CM012, CM016, CM018, CM019]

2.3 买方、预算所有者与采用路径

买方地图是跨职能的。MDR 侧,经济买方通常是 CISO 或安全负责人,已经掌握 SIEM、EDR 和 Microsoft 安全预算,但需要更好的响应覆盖、更好调优或更多 24x7 产能。TPRM 侧,日常操作者常是供应商风险或合规团队,但付款权可能落在安全、采购、企业风险或受监管业务线负责人手上,取决于供应商敞口在哪里被衡量。采用触发点通常不是抽象的「网络成熟度」,而是近期事件、监管期限、反复问卷疲劳、供应商范围内的零日敞口,或内部意识到第四方风险基本不可见。BlueVoyant 官方界面暗示的采用路径,是先在既有工作流中叠加 MDR 或 TPRM 监控;当领导层判断人工流程太慢后,再扩展到修复、第四方分析和更广的韧性报告。[CM021, CM022, CM023, CM024, CM025, CM026]

细分市场 / 买方图谱
细分市场买方用户付款方工作流预算负责人采用触发因素
大型企业 SOC 现代化CISO 或安全副总裁SOC 分析师、检测工程师、IR 团队安全运营预算在现有 EDR / SIEM / Microsoft 技术栈上叠加 24x7 监控与响应CISO,CIO / CFO 可见告警疲劳、工具蔓延、人手短缺、近期事件
上市公司第三方网络安全项目CISO、第三方风险负责人、审计发起人供应商风险分析师、合规团队、整改协调人安全或 GRC 预算收集证据,持续监控供应商,升级重大发现,支撑董事会报告CISO / CRO / 首席合规官SEC 治理压力、反复问卷负担、供应商事件
欧盟或受监管金融韧性项目运营韧性或安全负责人风险团队、韧性办公室、采购、安全运营风险、合规或受监管业务线预算梳理关键供应商,验证网络安全状态,支撑韧性测试和整改CRO、CISO、受监管实体高管NIS2 式截止期限、关键供应商依赖关系梳理
Microsoft 重度安全环境安全平台负责人或 CISOSentinel、Defender、M365 与云安全管理员现有 Microsoft 和安全平台预算调优告警,扩大自动化覆盖,在不替换技术栈的情况下增加托管覆盖CISO / 平台负责人Microsoft 安全投入利用不足、需要更快响应、内部调优能力有限
采购与供应商准入项目采购或供应商管理负责人,安全团队共同发起供应商准入分析师、业务负责人、风险评审人采购 / 运营预算,安全团队参与问卷管理、供应商分层、整改跟进、例外追踪采购负责人,安全团队签字供应商准入积压、合同条款执行、跨供应商零日暴露

各行混合 MDR 和 TPRM 采购中心,因为 BlueVoyant 同时覆盖两种销售动作。预算归属基于产品适配度和调研证据推断,不是 BlueVoyant 披露的管线数据。

[CM021, CM022, CM023, CM024, CM027, CM029]
FM003: 买方 / 细分地图——决策权与预算流向

定性展示 BlueVoyant 的 MDR 和 TPRM 动作中,不同买方画像的权力、预算和触发逻辑如何变化。

单元格为定性内容,综合自 BlueVoyant 的产品表面,以及关于谁感到痛点、谁控制预算的调查证据。这是一张决策地图展项,不是公司披露的细分表。

[CM024, CM025, CM026, CM029, CM030]
FM004: 从事件痛点到跨类别扩张的采用路径

从最初的网络安全痛点,到在 MDR 和 TPRM 工作流中更广泛采用 BlueVoyant 的典型路径。

该流程为定性内容。它综合触发事件的调查证据和 BlueVoyant 的模块结构;不是已披露的漏斗转化图。

[CM027, CM029, CM037, CM047, CM048, CM049]

2.4 增长驱动、监管与类别扩张

2026 年最强需求驱动来自监管、已被证明的第三方事件痛点,以及在技能人才不足下运营碎片化安全项目的成本上升。SEC 披露规则把网络治理和事件重大性纳入美国上市公司董事会流程。NIS2 把欧盟网络义务扩展到 18 个关键行业。CISA 和 NIST 将供应链网络风险定义为正式韧性问题,横跨硬件、软件和托管服务。这套政策栈遇到真实运营痛点:Marsh 报告称,过去一年 70% 的组织经历过重大第三方网络事件,66% 计划增加网络投资;Panorays 则显示多数 CISO 仍缺乏完整供应链可见性和正式泄露响应预案。BlueVoyant 的定位与这些压力吻合,因为它把内部防御和外部供应商敞口中的监控、验证、修复和 AI 辅助分诊组合在一起。[CM025, CM026, CM027, CM028, CM031, CM032]

增长驱动因素与约束表
驱动因素 / 约束方向时点对 BlueVoyant 的含义尽调问题
SEC 网络安全披露治理驱动因素当前买方从 SOC 团队扩展到审计、法务和董事会利益相关方;这些人需要有证据支撑的网络安全工作流询问管理层,管线中有多少比例与上市公司治理要求挂钩
NIS2 及更广泛的欧盟网络安全义务驱动因素当前至 2026 年执法周期覆盖行业更急于掌握供应商网络安全状态并提交韧性报告量化 BlueVoyant 对 NIS2 覆盖行业和欧盟总部账户的暴露
CISA / NIST 供应链正式化驱动因素结构性把网络供应链风险确认为一门韧性学科,范围横跨硬件、软件和托管服务测试买方把 SCRM 定义为韧性而非采购合规时,BlueVoyant 是否仍能赢单
第三方事件频率驱动因素立即真实事件会催生应急预算,用于持续监控、整改和依赖关系梳理要求提供供应商事件加快采购时点的案例
第四方盲区与集中度风险驱动因素立即且持续扩大强化对依赖关系梳理和直接供应商之外情景分析的需求核实第四方分析有多常扩展既有 TPRM 交易
AI 辅助分诊与 Microsoft 优化驱动因素近期支撑 MDR 向 Microsoft 重度环境加售,也降低服务成本叙事要求独立证明告警量下降和整改时间改善
工具蔓延与集成薄弱约束持续存在买方工作流彼此断开,会拖慢 MDR 与 TPRM 模块的交叉销售和标准化要求提供因平台重叠或内部集成问题受阻交易的赢单 / 输单数据
MDR 标签混乱与评估拥挤约束当前买方困惑会抬高举证门槛,也更偏向品类归属更清晰或打包能力更强的厂商询问 BlueVoyant 如何对托管 EDR 和更大型 XDR 平台做差异化
保险价格走软与预算审查约束当前保险价格下行可能削弱一个紧迫性杠杆,即便索赔严重度仍然较高测试网络保险定价走软时,管线质量是否变化
没有公开披露 SOM约束当前市场份额承销因此不精确,仅靠公开证据也难以支撑估值信心要求提供模块级收入组合、ACV 区间和续约 / 交叉销售指标

时点和战略含义综合自监管、市场调研和 BlueVoyant 产品定位。约束行和驱动因素行一样,对估值判断很重要。

[CM027, CM031, CM032, CM033, CM034, CM035]

2.5 约束、不利信号与估值相关性

市场论点不错,但并非没有摩擦。KPMG 显示,大多数项目仍只与企业风险部分整合,端到端托管服务采用率仍低,这意味着买方常用割裂工具、局部试点或狭窄用例接近 TPRM 与 MDR。CyberProof 警告,一些供应商滥用 MDR 标签,只提供托管 EDR 或工具中心监控,却没有完整的人类响应领导,这制造买方混淆并拖慢类别转化。PeerSpot 拥挤的 MDR 类别和 CRC 关于网络保险定价走软的证据,也强化了一个判断:即使索赔严重性继续上升,预算紧迫感也会回落。估值上,正确结论是 BlueVoyant 所在市场足够大、痛点足够重,但估值倍数压缩仍取决于公司能否把跨类别故事转化为可衡量的模块渗透、更低买方混淆,以及公开数据可支撑的 SOM。[CM036, CM039, CM040, CM041, CM042, CM043]

2.6 图表

Chapter 03

03竞争对手

3.1 竞争格局与买方替代方案

BlueVoyant 并不处在一个干净的单一市场盒子里。Gartner 的 2026 年 MDR 市场定义,将托管检测与响应视为供应商运营的一站式 SOC 能力,并强调主动遏制,而非只做告警监控;BlueVoyant 自己的主页则同时营销四个相邻产品:MDR、第三方风险管理、数字风险防护和专业服务。这让竞争场比普通 MDR 候选清单更宽。一侧,BlueVoyant 面对 CrowdStrike、Palo Alto Networks、Arctic Wolf、Rapid7、ReliaQuest 和 eSentire 等直接 MDR 对手。另一侧,它面对 SecurityScorecard、BitSight 等 TPRM 与网络评级平台,也面对 OneTrust 或 ProcessUnity 风格的供应商风险项目和内部 SOC 现状等工作流导向替代方案。实际含义是:当买方想要一个伙伴同时覆盖 SOC 运营和供应商网络防御时,BlueVoyant 可以胜出;当预算所有者把问题收窄为平台原生 MDR 或采购中心的供应商风险自动化时,它可能被替代。[CP001, CP002, CP005, CP027, CP029, CP033]

竞争对手画像表
竞争对手品类规模 / 融资信号买方甜蜜点关键差异化相比 BlueVoyant 的主要限制
BlueVoyant混合 MDR + TPRM / C-SCRM600+ 名员工;1,200+ 个 Sentinel 部署;保留的 2026 年来源未更新私募融资Microsoft 重度企业、受监管买方、政府供应链结合 MDR、TPRM、DRP 和服务,Microsoft 交付深度强MDR 可见度低于最大的平台原生对手;公开融资 / 定价细节偏少
Palo Alto Networks Unit 42 / Cortex XSIAM(平台)平台原生 MDR / SOC16K+ 名员工;全球 70K+ 客户已标准化 Palo Alto 的大型企业统一 AI SOC 平台,加上 Unit 42 服务和深度一方遥测最佳经济性和结果绑定 Palo Alto 技术栈;TPRM 重叠有限
CrowdStrike Falcon Complete平台原生 MDR上市公司规模;每月整改 2.7M 次检测;中位遏制时间 1 分钟愿意标准化 Falcon 的企业和安全成熟中型市场客户原生端点、身份、云与 SIEM 遥测,叠加自主和人工响应相比 BlueVoyant 或 ReliaQuest,平台锁定更强,开放技术栈灵活性更低
Arctic Wolf开放 XDR MDR10K+ 客户;1,000+ 名安全工程师;历史报道 $60M Series D 轮融资和约 $4.3B 估值希望共管结果的中大型企业到企业级买方Concierge 交付、开放 XDR、保修和安全旅程模型TPRM 和供应链网络防御不是核心采购动作
Rapid7平台主导的托管运营全球 11,500+ 客户;上市公司规模希望统一暴露管理和检测的大型 SMB、中型市场和企业级买方Command Platform 连接暴露管理、遥测和托管运营服务身份相比 BlueVoyant 差异化较弱;TPRM 重叠有限
ReliaQuest开放平台企业 SecOps每天处理 50K+ 告警;255+ 技术合作伙伴;保留页面未披露客户数Fortune 1000 和工具异构企业任意来源标准化、智能体 AI 队友和广泛集成深度公开规模和定价披露有限;没有 TPRM 专属数据网络护城河
eSentire厂商独立 MDR2,000+ 客户,覆盖 35+ 行业;300+ 集成受监管中型市场、私募股权组合公司和高端中型企业团队人工主导遏制,叠加多信号 XDR 和无限狩猎 / 事件处理叙事品牌规模低于最大上市套件,TPRM 也不是核心
SecurityScorecard威胁情报驱动的 TPRM / 供应链检测3,300+ 客户组织;12M+ 被监控和评级组织供应商风险、网络保险、采购和董事会报告项目持续评级,加上 AI 评估自动化、第 N 方可见性和整改工作流托管 SOC 深度弱于 BlueVoyant MDR;外部视角方法不能替代内部遥测
BitSight网络风险情报 / TPRM3,500+ 客户;68K+ 活跃组织;75K+ 已映射供应商画像以评级为中心的企业风险和供应链项目大规模已映射供应链数据集、独立验证的评级主张和强分析师认可MDR 不是核心,客户可能仍需要单独的工作流或服务层
内部 SOC / 仅工作流项目现状 / 替代方案买方自筹人员、工具或 GRC 套件预算超大型企业或合规主导的采购团队如果已有工作流套件,可获得最大控制权或最低增量支出相比完整 MDR,人手负担最高或威胁响应结果更弱

规模信号混合了员工、部署、客户数、供应商画像和历史私募融资标记;这些指标只看方向,不能直接类比收入。

[CP002, CP005, CP011, CP012, CP014, CP017]
FP001: 竞争定位图

基于证据的竞争者开放度与预算宽度序位视图;y 值越高,说明在 SOC、采购、保险或供应链工作流中的重叠越广。

坐标轴是根据留存产品页面和市场指南推导的序位评分,而非经审计市场份额数据。X = 技术栈开放度 / 工具中立性,从 1(封闭套件)到 5(开放生态)。Y = 预算宽度,从 1(仅 SOC)到 5(SOC 加供应链 / 采购 / 保险相关性)。

[CP001, CP002, CP014, CP021, CP027, CP032]

3.2 MDR 正面对比:平台套件 vs 开放栈供应商

BlueVoyant 周围的 MDR 市场分成两类经济属性不同的竞争者。Palo Alto Networks 和 CrowdStrike 把托管响应作为更大专有平台的延伸来销售;它们的卖点是自动化深度、原生遥测和捆绑经济性。Palo Alto 在 Cortex XSIAM 的统一 SIEM、SOAR、EDR、NDR 和 CDR 栈之上叠加 Unit 42 服务;CrowdStrike 的 Falcon Complete 强调一分钟中位遏制时间、每月数百万次修复,以及来自 Falcon 生态的端点、身份、云和第三方深度遥测。Arctic Wolf、ReliaQuest、Rapid7 和 eSentire 从相反方向进攻:它们把自己定位为更开放、服务更重的伙伴,可跨既有工具资产工作。Arctic Wolf 主打 concierge 交付和开放 XDR;ReliaQuest 主打任意来源归一化和广泛集成;Rapid7 主打暴露管理加检测;eSentire 主打厂商无关 XDR 和人类主导遏制。运营上,BlueVoyant 更接近第二阵营,但比多数同类对手拥有更强的 Microsoft-specific 服务身份。[CP003, CP004, CP009, CP010, CP011, CP012]

功能 / 能力矩阵
采购标准BlueVoyantPalo AltoCrowdStrikeArctic WolfRapid7ReliaQuesteSentireSecurityScorecardBitSight
动手托管响应权限
专有平台锁定压力
Microsoft 生态深度
EDR / SIEM 开放性
第三方 / 供应链网络监控
董事会 / 采购 / 保险报告效用
公开传递的 AI / 智能体路线图
混合工具企业最佳适配

高 / 中 / 低由作者根据留存的公开产品页面和独立买家指南判断;这些评级反映公开披露的能力和运营模式,不代表经审计的基准性能。

[CP003, CP009, CP012, CP014, CP016, CP020]
FP002: 功能宽度 / 能力地图

压缩能力地图,展示 BlueVoyant 与 MDR 套件厂商、TPRM 平台的重叠位置。

高 / 中 / 低取值是作者基于留存公开文档和买方指南来源作出的评估;它们展示公开能力叙事,不是经审计功能同等性。

[CP003, CP006, CP013, CP023, CP025, CP028]

3.3 供应链与 TPRM 竞争

BlueVoyant 的供应链防御带来一组不同于 MDR 对手的买方替代方案。SecurityScorecard 和 BitSight 是最清晰的重叠者,因为两者都把网络风险框定为对供应商敞口的持续、由外向内视图,再把数据连接到董事会报告、采购监督、保险工作流和修复项目。SecurityScorecard 进一步把自己呈现为供应链检测与响应,具备问卷自动化、nth-party 可见性和 AI 辅助修复。BitSight 则把大型映射供应商网络、Forrester 认可的评级可信度,以及覆盖数千万家受监控公司的网络风险情报数据集组合起来。独立市场指南也指出,许多买方不会止步于评级工具;他们会把评级工具与 ProcessUnity、OneTrust、Venminder 或内部问卷项目等工作流中心平台搭配使用。对 BlueVoyant 来说,这很重要,因为其由外向内 C-SCRM 主张不只与竞争数据网络竞争,也与工作流软件竞争;除非 BlueVoyant 证明修复更快、分析师参与更强,否则独立情报层容易显得可替换。[CP006, CP007, CP021, CP022, CP023, CP024]

3.4 BlueVoyant 差异化、打包方式与可能胜区

BlueVoyant 最有特色的公开故事,是 Microsoft-heavy MDR、由外向内供应商防御和相邻数字风险服务的组合,而不是宣称自己是最佳端点或评级厂商。其保留页面强调 1,200 多个 Microsoft Sentinel 部署、24x7 区域 SOC 覆盖、50 多名认证 Microsoft 交付和 SOC 工程师,以及一个政府产品:无需专有供应商数据,就能用 70,000 多个数据源映射数万家供应商。2026 年 6 月 BlueVoyant AI 发布增加了第二个重要角度:管理层正试图从纯服务走向 agentic SecOps 平台,既可作为托管服务消费,也可作为 self-service SaaS 使用。这让 BlueVoyant 在受监管、Microsoft-heavy 环境中有可信胜区,尤其当买方想用一个供应商覆盖托管 SOC 运营和第三方网络防御时。若买方想在单一专有安全套件内把调查负担降到最低,或采购主导的 TPRM 项目已经偏好评级厂商加工作流软件,BlueVoyant 就不那么合适。[CP003, CP004, CP006, CP007, CP008, CP027]

定价 / 打包对比
厂商公开价格可见度合约 / 打包信号公开重点竞争含义
BlueVoyant留存页面未公开标价平台与托管服务按报价打包MDR、TPRM、DRP 与专业服务一起销售交叉销售灵活性是优势,但外部买家无法靠公开页面对标标价 ACV
CrowdStrike Falcon Complete留存页面未公开标价Falcon 平台上的按报价 MDR智能体式 MDR、确定性自动化和广泛原生遥测已使用 Falcon 的客户可以把支出纳入更大的平台合约
Palo Alto Networks留存页面未公开标价按报价销售 XSIAM 与 Unit 42 托管服务统一 SOC 技术栈和托管服务在大型套件客户中,打包经济性可能压低服务驱动型挑战者的空间
Arctic Wolf留存页面未公开标价安全运营包,配套礼宾式交付和保障结果导向的托管服务,而不是工具采购吸引想外包结果的买家,但公开可比性仍然偏低
Rapid7留存页面未公开标价平台订阅加托管运营暴露面管理 + SIEM + 托管运营Rapid7 客户有自然扩张路径,但公开定价不透明仍需尽调
ReliaQuest留存页面未公开标价企业平台,部署高度依赖集成GreyMatter 支持任意来源运营和集成最适合复杂企业,但采购很可能仍是定制化、服务占比高
eSentire留存页面未公开标价托管 MDR / XDR 服务合约强调不限次数威胁狩猎和事件处置适合结果导向买家,但早期筛选名单的成本比较不够透明
SecurityScorecard / BitSight留存页面未公开标价评级 / TPRM 项目按报价销售持续监控、问卷、AI 摘要、供应商网络情报预算路径通常走采购、风险或保险,而不是 SOC

本表只比较价格可见度和打包信号。留存的官方页面通常不披露企业标价,因此合约金额和实际折扣仍是尽调缺口。

[CP041, CP042, CP043, CP044]
FP003: 护城河 / 就绪度 KPI — BlueVoyant 竞争快照

六项公开指标概括 BlueVoyant 截至 2026 年 6 月的竞争位置,同时纳入优势和反向信号。

[CP003, CP005, CP007, CP008, CP034, CP040]

3.5 弱点、不利证据与护城河持久性

最重要的反证并不是 BlueVoyant 缺少产品宽度,而是更大竞争者可以用更强市场可见度或更低运营摩擦来框定同一项工作。PeerSpot 2026 年 6 月评论页显示,BlueVoyant 的 MDR mindshare 仅 0.9%,低于一年前的 1.2%;其直接对比页将 BlueVoyant 排在第 34 位,而 CrowdStrike 第 2 位,并指出 BlueVoyant 报告定制较弱、配置可能更重。Daylight 的 2026 年买方指南更直白:它把 BlueVoyant 归入 MSSP-style MDR 供应商,买方选择它是为获得广泛安全伙伴关系,但其工作流比 AI-native 或 XDR-extended 替代方案更依赖分析师工时。TPRM 侧,BlueVoyant 还必须防御 SecurityScorecard 和 BitSight 规模大得多的外部数据网络。几乎所有保留竞品页面都缺乏公开定价,加剧了挑战,因为从外部很难基准化既有套件捆绑和多产品折扣。因此,BlueVoyant 在跨预算服务宽度上有真实护城河,但在类别可见度、数据网络规模或平台锁定上,护城河并不显然持久。[CP017, CP018, CP034, CP035, CP036, CP037]

护城河耐久度 / 竞争风险清单
护城河或风险判断主要威胁严重度当前缓释信号尽调问题
Microsoft 专项 MDR 深度CrowdStrike、Palo Alto 和 Microsoft 原生替代方案能提供更强原生自动化或打包经济性BlueVoyant AI 发布和 1,200+ 个 Sentinel 部署强化了专项能力叙事拆分 Microsoft 重度客户与非 Microsoft 客户的收入结构
跨预算的 MDR + TPRM + DRP 定位买家可能仍会拆分 SOC 与供应商风险预算,分别选择最佳单点工具BlueVoyant 将四条销售动线一起推广,政府 C-SCRM 又拓宽了叙事衡量多产品附加率,以及从 MDR 扩张到 TPRM 的情况
由外向内的供应商照明SecurityScorecard 和 BitSight 运营规模大得多的公开数据网络,评级品牌也更强BlueVoyant 增加分析师主导的整改和政府任务框架,而不只卖评级对标评级厂商,测试供应商覆盖、误报和整改速度
服务驱动型交付模式AI 原生和平台原生 MDR 能把更多调查负担转给软件和自动化BlueVoyant AI 推动模式转向智能体式 SecOps 和自助式 SaaS测试 BlueVoyant AI 部署前后的分析师 / 客户杠杆率和升级负载
公开定价不透明套件厂商可以把折扣藏进更大的合约,使单独比较更难买家想要单一合作伙伴时,BlueVoyant 可以把 MDR 和 TPRM 打包尽调中获取口径一致的 ACV、爬坡和续约基准
MDR 市场能见度较低PeerSpot 心智份额和排名显示,进入短名单的吸引力弱于 CrowdStrike 或品类领导者BlueVoyant 可以瞄准受监管或 Microsoft 主导的用例,而不是泛化 MDR 比拼按垂直行业验证企业品牌认知和 RFP 入围率

严重度是作者基于留存公开证据的判断。尽调问题指向需要哪些私有数据,才能测试已观察到的护城河或风险是否持久。

[CP017, CP018, CP034, CP035, CP036, CP037]
Chapter 04

04财务

4.1 收入模式与变现可见度

BlueVoyant 的公开商业界面看起来像一套围绕 MDR、TPRM、DRP 和专业服务包装的经常性网络安全平台,而不是一次性项目业务。主页和产品材料强调持续监控、响应、修复和下架工作;客户证明和 TEI 研究也强化了订阅或 retainer 式价值主张。话虽如此,公开记录在结果上远强于变现细节。BlueVoyant 披露部署数量、ROI 主张和 marketplace 采购路径,但不发布核心产品标准标价,也不展示实际成交价、折扣或经常性托管服务与项目型工作的收入组合。结果是,营收机制清晰,但收入质量和各收入流贡献利润率仍不完整。[CI001, CI002, CI003, CI004, CI005, CI006]

收入流表
收入流机制公开证据变现可见度质量 / 注意事项尽调问题
托管检测与响应经常性托管监控和响应1,200+ 个 Sentinel 部署;24x7 SOC 覆盖合约制 / 经常性,但标价不公开需求代理指标强;定价透明度弱索取合约条款、按席位 / 设备计费口径,以及按客户分群的毛利率
第三方风险管理经常性监控、验证和整改支持整改速度快 18x;准确率 98%;GCP 市场渠道经常性 / 可走企业采购结果数据强;收入兑现不透明索取按供应商计价、整改费用和附加率
数字风险防护持续监控和下架服务两年下架 50,000 个域名;社交和网站下架成功率可能是经常性服务包活动信号强;未披露价格索取按受保护品牌 / 账号计价,以及下架经济性
专业服务 / DFIR项目、长期服务合约和咨询收入主页和案例研究把事件响应、战略服务与 MDR 并列定位项目 / 长期服务合约组合未披露相比 MDR / TPRM,收入最可能更波动索取长期服务合约附加率和服务利用率数据

官方页面清楚展示了收入机制,但没有对收入流组合、实际定价或收入流层面的利润率做勾稽。

[CI001, CI002, CI004, CI005, CI006, CI007]
定价 / 变现表
产品 / 渠道公开定价信号实际定价可见度采购路径收入含义
MDR / SOC 外包自建与购买对比页面提出自建成本 >$1.2M,MSSP 替代方案 <25%未公开合约价格或单端点费率直销和合作伙伴价值主张明确,但实际 ASP 和毛利率未知
GCP Marketplace 上的 TPRM市场上架信息公开;未披露数字标价未公开净价、折扣或最低承诺云市场 / 企业协议应能降低采购摩擦并缩短渠道周期
Microsoft 优化服务博客称内部优化每年最高可花 $750k未披露 BlueVoyant 服务价目表企业直销,可能偏咨询式销售支撑咨询式追加销售逻辑,但不代表 BlueVoyant 实际定价兑现
合作伙伴辅助成交2021 年合作伙伴贡献新业务的 50%未披露渠道折扣和收入分成经销商、咨询公司和技术合作伙伴可能提升漏斗前端效率,同时压缩实际成交价格
客户案例扩张Odeon 和 Snappi 展示多产品落地后扩张路径未披露合约金额直销 / 合作伙伴混合支撑钱包份额叙事,但没有给出单账户 ARR

本表把公开采购路径与缺失的实际价格数据分开;公开记录展示买家如何购买,不展示实际支付金额。

[CI012, CI013, CI017, CI034, CI035, CI038]
FI001: 收入模型桥

BlueVoyant 把直销需求、伙伴需求和云市场入口转成经常性托管安全收入,外加一层规模较小的专业服务;但公开材料没有披露到可量化已实现毛利的程度。

这张桥接图是定性的:公开材料给出了上市路径和结果,却没有披露已实现收入结构,也没有按收入流拆出毛利率。

[CI001, CI011, CI017, CI034, CI038, CI060]

4.2 GTM 动作与销售效率代理指标

BlueVoyant 似乎依靠直销企业、伙伴带动需求和低摩擦云 marketplace 采购的混合模式扩张。公司明确表示,伙伴在 2021 年贡献了全部新业务的一半;渠道页面也显示,经销商和咨询关系是核心,而非附带。这很重要,因为伙伴杠杆可以抵消 24x7 托管服务通常伴随的人力密度。BlueVoyant 还营销相对自建 SOC 的硬成本节省,声称自建每年可超过 $1.2 million,而 MSSP 成本可低于该水平的四分之一。客户价值研究提供了更多证据,尽管由公司赞助:Forrester TEI 材料、ODEON 成果和 Sentinel 案例研究指南都指向显著运营节省,但仍未给出真正的 CAC、回本周期或实际毛利率数据。[CI011, CI012, CI013, CI017, CI029, CI030]

单位经济和销售效率代理指标表
代理指标公开数值 / 状态置信度重要性尽调问题
2018 年以来 ARR 增长声称平均增长 117%如果方向仍然成立,说明收入端动能强索取按年份审计的 bookings / ARR 桥表
合作伙伴来源新业务2021 年新业务的 50%显示直销人头之外的分销杠杆索取合作伙伴来源管线、胜率和利润分成
自建与购买替代成本>$1.2M 自建年度 SOC 成本界定客户 ROI 和支付意愿上限索取 ROI 模型假设和真实竞争胜负数据
外包 SOC 节省成本说法<25% 的内部 SOC 成本支撑回本叙事,但不代表实际成交价索取合约样本和客户回本模型
MDR TEI 价值代理指标210% ROI;升级告警减少 90%;MTTR 加快 70%如果样本有代表性,支撑留存和扩张判断索取客户分群方法和非赞助客户推荐
供应链防御价值代理指标~300% ROI;关键风险整改快 62%显示 TPRM 经济性可能高于纯合规工具索取 TPRM 账户的客户留存和扩张指标

这些是销售效率和价值代理指标,不是闭环单位经济;公开证据偏方向性,且大多由公司赞助。

[CI017, CI018, CI029, CI030, CI031, CI032]
FI002: 单位经济性桥

BlueVoyant 给出了较强的客户价值代理指标和外包经济性,但公开证据链在 CAC、回本周期和利润率可直接测算之前就断开了。

节点概括的是证据质量,不是隐藏的内部遥测;下游经济性输出仍有意保持未解。

[CI012, CI013, CI017, CI029, CI030, CI031]

4.3 公开规模信号与运营杠杆代理指标

BlueVoyant 官方规模叙事在增长方向上强且内部一致,但对当前精确规模不够一致,无法无保留承销。官方新闻稿从 2022 年初 30 个国家超过 700 家客户,推进到 2024 年中 900 多家全球客户,再到 2025 年 3 月 45 个以上国家超过 1,000 家客户。员工数信号更不均:BlueVoyant 称拥有 600 多名员工,GetLatka 估约 650 人,Dialectica 列出 653 人,一个可访问的历史 PitchBook 快照仅显示 363 名员工。这个跨度太大,不能忽略,尤其是收入 / 员工和销售效率代理指标会随分母不同而显著改变。谨慎解读是:BlueVoyant 具备真实企业规模和国际交付覆盖,但公开数据库在精确运营基线上仍陈旧或不一致。[CI010, CI014, CI015, CI016, CI020, CI025]

公开牵引力、客户和员工数代理指标
指标2022 信号2024 信号2025 / 数据库信号注意事项
客户数量>700 个客户,覆盖 30 个国家>900 个全球客户>1,000 个客户,覆盖 >45 个国家增长路径方向上强劲,但当前精确数量仍是公司口径
员工数Series D 时 >560 名员工公司页面显示 >600 名员工650 (GetLatka); 653 (Dialectica); 363 (历史 PitchBook)私有数据库互相不一致,部分快照已经过时
合作伙伴杠杆合作伙伴贡献新业务的 50%官方网站上的渠道名单变宽TPRM 新增市场采购路径GTM 信号好,但披露的经济性弱
交付规模1,200+ 个 Sentinel 部署;24x7 SOCODEON 覆盖 8 个国家和 280+ 家影院指南显示数百个部署 / 16 个案例研究规模已有证明,但并非所有部署都会转化为可比 ARR
EMEA 投资2021 年扩张到 >10 个国家2024 年搭建财务职能并推进收购整合Cork 启动,本地收入 2024 年 +70%规模信号支撑增长,不支撑盈利能力

这些代理指标混合了官方披露和私有数据库快照;它们适合判断趋势方向,不适合作为干净的单期经营基线。

[CI010, CI015, CI016, CI017, CI020, CI021]

4.4 资本基础、投资者财团与互相冲突的私营公司信号

BlueVoyant 资本历史明确包括两轮大型后期融资:2022 年 $250 million Series D,以及 2023 年与 Conquest Cyber 收购绑定的超过 $140 million Series E。Liberty Strategic Capital 和 ISTARI 是该投资者基础中的反复锚点,Eden Global Partners 也多次以顾问或参与方身份出现。除此之外,第三方数据库开始分歧。CB Insights 和 Clay 都报告累计融资约 $665.5 million,Tracxn 则报告 $696 million;投资者数量从历史 PitchBook 快照的 9 家,到 Clay 的 11 家和 CB Insights 的 15 家不等。收入信号分歧更大:GetLatka 给出 2025 年 $213.5 million 估算,CB Insights 则给出 2024 年 $750 million。这些矛盾不能证明任何单一来源是错的,但足以说明,公开 / 私有数据尾迹没有充分对齐,若无管理层确认,不足以支持投资承销。[CI019, CI021, CI022, CI023, CI024, CI041]

资本充足性表
维度公开信号有来源支持的数值 / 状态承销含义尽调问题
Series D 股权资本大型后期融资2022 年 Series D,$250M,Liberty Strategic Capital 领投为规模扩张和招聘提供实质性资产负债表支持索取投后现金桥表和资金用途
Series E + 收购资本与收购挂钩的增长资金2023 年伴随 Conquest 收购完成 > $140M Series E显示投资人持续支持,也显示 M&A 意愿索取整合预算和 Conquest 收入贡献
投资人基础深度战略赞助方重复出资Liberty、ISTARI/Temasek、Eden、8VC,加上各数据库不一的投资人数量财团质量看起来强,但确切广度不一致索取当前股权结构表和按轮次的所有权
债务 / 杠杆信号仅留存历史公开债务痕迹PitchBook 快照显示 2020 年 Debt-PPP 条目;未留存当前债务额度当前杠杆可能为零、温和,或只是未披露索取债务明细、贷款人名称和契约包
现金 / 烧钱 / 资金续航期未公开披露截至运行日,没有留存公开来源验证这些指标这是最大的承销障碍索取最新现金余额、烧钱和资金续航模型
区域扩张承诺EMEA 搭建和 SOC 扩张可见Cork 开业绑定数百万欧元投资和 70% 本地收入增长即使没有现金披露,扩张仍说明支出还在继续索取 EMEA 招聘计划、opex 和预期回本

历史融资时间线放在公司概览中;本表聚焦未来充足性和承销所需的当前盲点。

[CI019, CI022, CI023, CI026, CI028, CI041]
私有公司财务信号冲突表
指标来源 A来源 B来源 C冲突原因 / 使用方式
累计融资CB Insights: 9 轮融资 $665.5MClay: 累计融资 $665.5MTracxn: 6 轮融资 $696M共识大致落在 $600M 中段,但轮次数和处理口径不同;管理层应提供股权结构表
收入 / ARRGetLatka: 2025 年 $213.5MCB Insights: 2024 年 $750M没有官方收入披露这些数字无法直接勾稽,可能分别反映 ARR、更广义收入或过时估算
员工公司页面: >600GetLatka: 650; Dialectica: 653PitchBook 快照: 363较新来源集中在 600+,可访问的 PitchBook 快照看起来过时或不完整
投资人数量Clay: 11 名投资人CB Insights: 15 名投资人PitchBook 快照: 9 名投资人数据库覆盖不同;应使用公开轮次公告并索取股权结构表,而不是依赖单一数量
最新交易历史官方 / 新闻来源显示 2023 年 Series E $140M可访问的 PitchBook 快照显示最新交易金额为 $30MPitchBook 还显示历史 Debt-PPP 条目过时或归档的画像可能大幅扭曲当前融资和杠杆假设

重点不是选择偏好的数据库,而是在管理层勾稽之前保留相互矛盾的估算。

[CI042, CI043, CI044, CI045, CI046, CI047]
FI003: 财务估计区间

公开浮现的融资、收入、客户和员工数字跨度很大,因为公司仍是私有企业,各数据库快照也不一致。

区间刻意保留年份和来源方法之间的矛盾,而不是把它们压成一个虚假的点估计。

[CI042, CI044, CI045, CI046, CI047, CI049]

4.5 财务结论与尽调阻塞项

保留证据支持这样一家公司:真实经常性需求、充足私募资本背书,以及足够重要的企业客户宽度。但证据并不支持干净的财务承销案例。现金、烧钱速度、runway、债务义务、实际定价、毛利率、留存、CAC 和回本周期仍在公开记录之外。历史 PPP 债务信号和英国备案轨迹显示有公司文件活动,但无法回答当前杠杆或流动性问题。不利的员工评论没有推翻增长叙事,却提示资源约束可能与收购式扩张和高管扩编并存。因此,正确财务结论是建设性但仅凭公开证据不可投资:BlueVoyant 看起来具备商业意义,但仍需要管理层数据来判断收入质量、运营杠杆和下一轮融资依赖。[CI026, CI028, CI053, CI054, CI055, CI056]

公开财务缺口表
缺失指标重要性当前代理指标具体尽调路径
账上现金 / 资金续航期决定融资依赖和下一轮融资紧迫性只有历史大型融资和持续扩张可作代理索取当前资产负债表、现金预测和董事会资金续航情景材料
月度烧钱和招聘计划显示增长是自我供血还是消耗现金Cork 扩张、CFO 搭建和客户增长是间接代理索取月度烧钱桥表、招聘计划和预算差异
按产品线拆分毛利率需要把软件式经常性经济性和人力密集型服务经济性拆开TEI 和案例研究展示结果,不展示毛利要求提供 MDR、TPRM、DRP 和服务的毛利率与利用率
实际成交价格 / 折扣需要判断价格纪律和续约质量公开材料只呈现 marketplace 路径和自建 / 外购框架要求提供价格手册、折扣审批记录和近期合同样本
债务期限表和契约需要理解杠杆、限制条款和再融资风险直接浮现的只有 2020 年 Debt-PPP 历史痕迹要求提供贷款人协议、契约包和任何并购相关借款

此处的 null 是有意保留的尽调阻断项,不是格式遗漏;它们标出承销所需的最低数据集。

[CI052, CI058, CI059, CI060, CI061, CI062]

4.6 图表

Chapter 05

05产品与技术

5.1 平台定义与融合架构

BlueVoyant 现在营销自己时,较少说成独立 MDR 供应商,更多说成统一网络防御操作系统。主页、Cyber Defense Platform 页面和 2024 年发布材料一致描述了一个 cloud-native 平台,横跨内部防御、第三方风险和外部数字风险监控。这很重要,因为产品定义贴着客户工作流:安全团队可以在同一运营模型下运行内部 SOC 分诊、供应商修复以及品牌或凭证下架,而不必把分散点工具拼起来。公司较新的 AI 层强化了这一融合论点,而不是取代它;BlueVoyant AI 被描述为一个控制平面,用来决定何时把工作路由给确定性自动化、何时调用人类分析师、何时让 agents 行动。尽调正面结论是,产品组合打包有一致性。尽调保留意见是,除少数 Microsoft-specific 文档外,公开架构仍停留在营销层深度。[CE001, CE003, CE004, CE005, CE006, CE007]

产品模块 / 资产矩阵
模块 / 资产主要买方或用户当前公开成熟度差异化信号尽调缺口
Cyber Defense Platform(网络防御平台)CISO、SOC 负责人、安全运营团队当前伞形产品在一个云原生界面上汇聚 MDR、TPRM、DRP 和服务没有公开架构文件展示共享 schema、租户或数据路由细节
BlueVoyant AIBlueVoyant SOC 或客户 SOC2026 年新发布 / 正在推向市场Agentic 模型把人工判断、确定性自动化和 AI agents 组合起来,既支持托管部署,也支持自助部署没有公开基准包说明误报下降、MTTR 变化或模型治理细节
MDR for Microsoft(托管检测与响应)Microsoft 原生安全团队核心产品,证据很扎实组合中最具体的技术证据,包括租户内数据处理和具体 Microsoft 技术栈覆盖Microsoft 工具之外的广度仍只在更高层级描述
Continuous Optimization for Microsoft Solutions(持续优化)安全工程、合规和平台运维团队当前模块 / 咨询加软件层从监控延伸到 Sentinel、Defender、M365 和 Purview 优化商业包装、可重复性和自动化深度未公开拆分
Third-Party Risk Management / Supply Chain Defense(第三方风险 / 供应链防御)供应商风险、采购和网络风险团队当前产品,公开材料显示功能完整结合连续监控、修复、问卷和咨询工作,而不只是被动评分软件贡献和分析师人力贡献未公开量化
Digital Risk Protection品牌保护、欺诈和外部风险团队当前产品,模块化覆盖 web、社交、app、暗网和高管保护工作流,并披露下架指标结果质量取决于外部平台和合作伙伴响应速度
Conquest 增强的合规与态势层国防、政府和受监管买方整合阶段的能力扩展增加风险成熟度、态势和合规映射,对 CMMC 密集环境有用公开来源没有说明 Conquest 工作流现在多大程度嵌入核心 BlueVoyant UX

各行把当前营销中的模块,与并购扩展而来、仍主要靠发布材料佐证的态势 / 合规层分开。

[CE001, CE003, CE007, CE011, CE019, CE025]
FE001: 产品架构图

公开产品叙事可拆成五层栈:从信号采集,到 AI 编排,再到分析师驱动的结果。

该图综合了当前产品页、发布稿、信任中心元数据和 Microsoft 材料,并非复制供应商发布的系统图。

[CE004, CE005, CE006, CE007, CE016, CE030]

5.2 Microsoft-centric MDR 与 agentic SOC 运营

最具体的技术深度在 BlueVoyant 的 Microsoft 生态故事里。MDR 套件明确嵌入 MDR for Microsoft 和 Continuous Optimization for Microsoft Solutions,Microsoft-specific 页面也比泛平台文案更精确。BlueVoyant 公开声称覆盖 Microsoft 安全栈的 24/7 防护,拥有多个伙伴称号和专业化认证,围绕 Sentinel 与 Defender 有大型参与基础,并采用一种交付模式:客户安全数据可留在客户 tenant 内,而不是导出到 MSSP 控制的数据湖。2026 年 BlueVoyant AI 发布通过描述自动遏制动作、托管或 self-service 部署选择,以及用多年 Microsoft-native 运营历史训练的模型,扩展了这一位置。实践中,这意味着 BlueVoyant 最强技术护城河不是广泛开放集成目录,而是围绕 Microsoft 环境的流程深度、调优、自动化和分析师工作流。[CE002, CE006, CE007, CE008, CE009, CE010]

工作流 / 使用场景表
用户任务当前工作流问题BlueVoyant 方案已披露收益或运营信号局限
Microsoft SOC 分诊和遏制Sentinel、Defender、身份、终端和云界面上的告警太多MDR for Microsoft 加 BlueVoyant AI明确营销 24/7 监控、自动响应动作和高保真告警公开证据最强的是主张本身,不是独立衡量的结果
Microsoft 成本和态势优化客户为 Sentinel、Defender、M365 和 Purview 支付过多,或配置不足Continuous Optimization for Microsoft Solutions(持续优化)BlueVoyant 称有 1,000+ 次项目,并提供许可和 Sentinel 消耗的成本控制指导节省方法和客户实际分布未公开
第三方关键发现修复供应商风险团队能发现问题,但难以推动闭环Continuous Monitoring & RemediationROC 分析师验证发现,并直接联系第三方没有按客户分层披露闭环率分布
供应商评估运营问卷靠人工,速度慢,也难验证Questionnaire Management 平台和托管服务自动化加供应商主张验证被呈现为差异化点公开材料没有展示与客户 GRC 技术栈的集成
品牌冒充下架钓鱼网站、假页面和恶意 app 在多个平台上快速迁移Brand Protection营销材料称支持无限下架和覆盖 300+ app store,首页披露了成功指标下架成功仍取决于注册商、社交平台或 app store 配合
凭据、欺诈和泄露监控安全团队看不见地下社区和泄露数据Dark Web Watcher材料描述了地下来源连续监控,以及账号接管和泄露处理工作流公开证据没有展示信噪比或发现时间分布
面向高管的攻击预防VIP 在核心 IT 控制之外面临个人数据暴露和账号接管风险Executive Cyber Guard实时告警和阻断攻击的工具属于营销中的工作流公开材料未量化采用情况或衡量后的高管风险下降

本表聚焦用户任务和运营工作流,不聚焦合同 SKU 或内部包名。

[CE007, CE008, CE012, CE015, CE021, CE023]
FE002: 客户工作流 / 运营流程

BlueVoyant 偏 Microsoft 的工作流从遥测和身份信号开始,随后进入 AI 辅助分诊、人工验证,以及遏制或优化动作。

该流程突出以 Microsoft 为中心的 MDR 路径,因为这部分公开证据最具体。

[CE007, CE008, CE012, CE015, CE016, CE018]

5.3 第三方风险与供应链工作流

BlueVoyant 的供应链防御材料足够具体,可以把 TPRM 视为产品化工作流,而不是围绕外部评级的咨询包装。当前 TPRM 概览、持续监控页面和 2023 年扩张发布对齐在同一运营模型上:按风险对供应商监控分层,BlueVoyant 分析师在 Risk Operations Center 内验证发现,修复直接与供应商推进,而不是完全留给客户。问卷管理也被描述为软件和托管服务兼具,这符合 BlueVoyant 的整体模式:在工作流混乱处,把自动化与劳动密集执行结合。公开来看,最有证据支撑的差异点是分析师引导修复、零日告警、基于 AI/ML 的业务风险监控,以及把持续监控与定期尽职评估结合的能力。剩余尽调问题是,其中多少来自可重复软件杠杆,多少来自专家配置和服务流程纪律带来的规模。[CE019, CE020, CE021, CE022, CE023, CE024]

技术 / 运营架构表
层 / 组件作用关键依赖主要风险
客户遥测和资产界面向平台输入内部、外部和供应商信号客户租户、云工作负载、终端、供应商和暗网监控访问公开材料没有解释标准化、留存或跨域 schema 设计
Microsoft 原生数据平面为 MDR 工作流提供 Sentinel、Defender、身份和合规上下文Microsoft 生态深度,以及持续 API / 功能访问如果买方想要更广的异构技术栈透明度,重度集中在 Microsoft 会带来集中度风险
AI 和确定性自动化层以机器速度丰富、分诊,并可触发自动遏制动作模型调优、playbook、审批逻辑和数据质量公开证据没有揭示模型治理、评估或回滚控制
人类分析师层SOC 和 ROC 专家验证告警、调优逻辑,并与客户或供应商沟通熟练人力供给和可重复流程规模扩大时,服务质量可能变得人力密集
第三方风险分析层监控供应商、风险事件、问卷和修复工作流大规模外部数据源覆盖,加客户供应商清单没有公开文档说明客户侧如何集成采购或 GRC 系统
外部下架和监控网络执行品牌、app、社交和凭据修复结果注册商、社交平台、app store 和地下来源访问结果质量会随外部平台响应速度而变化
Conquest 态势和合规层把平台延伸到态势、成熟度和面向政府的合规工作流并购后产品整合成功公开来源没有说明 UX 已完全统一,还是仍停留在组合层面

该架构由已审阅的产品页面、发布材料和 Microsoft 宣传资料综合而来,而不是来自供应商发布的工程图。

[CE004, CE006, CE015, CE016, CE021, CE022]

5.4 数字风险防护与外部依赖链

平台的外部风险侧被组织成清晰的三模块结构:Brand Protection、Dark Web Watcher 和 Executive Cyber Guard。这些模块映射到具体用户任务,而不是抽象威胁情报 buzzwords。BlueVoyant 声称可在网站、社交和 rogue-app 渠道做品牌下架;监控 dark-web 中的欺诈、泄露凭证和暴露数据;并监控高价值账号被攻陷或个人数据暴露等高管风险。公司也至少发布了一些可衡量的 DRP 表现信号,包括网站和社交媒体下架成功率,以及服务器级下架中位时间。不过在运营上,这条产品线最明显依赖外部平台和对手方:注册商、社交网络、应用商店、地下监控访问和客户响应预案都位于结果链条中。这让 DRP 具有战略重要性,但也高度依赖外部环节,因此 Gartner 评论标题中关于偶发下架挑战的提醒值得关注。[CE025, CE026, CE027, CE028, CE029, CE030]

FE003: 关键依赖图

BlueVoyant 的产品结果依赖一串技术和生态对手方,尤其是 Microsoft,以及外部下架和供应商响应渠道。

依赖图聚焦抓取来源中可见的对手方;未披露的内部基础设施供应商被有意省略。

[CE021, CE027, CE028, CE030, CE033, CE035]

5.5 信任控制、能力扩张与产品风险

BlueVoyant 公开信任与路线图证据足以支撑企业尽调,但不足以消除买方追问。Trust Center 确认公司希望被视为 cloud-native、AI-plus-human 平台,拥有超过 1,000 名客户;Microsoft 和 Conquest 材料则显示其明确对齐合规要求重的环境。Conquest 尤其重要,因为它把 BlueVoyant 从检测和风险可见性扩展到风险成熟度映射、态势管理,以及 CMMC 和 FedRAMP-adjacent 环境等政府导向合规工作流。与此同时,公开开发者界面很薄:GitHub 只显示一个可见公开仓库,且该仓库被标为 Copilot for Security 内容,而不是核心平台代码或可复用集成。独立评论和社区来源也浮现真实警示信号——偶发 DRP 下架摩擦、围绕专有深度的长期疑问,以及非 Microsoft 集成、SLA 或独立审计产品表现的公开证据有限。[CE016, CE031, CE032, CE033, CE034, CE035]

信任 / 质量 / 合规表
控制 / 信号状态范围缺口
Trust Center 存在已验证Vanta 托管的公开 Trust Center 称 BlueVoyant 是云原生、AI 加人工,并拥有 1,000+ 客户抓取到的公开界面没有以可读文本披露完整证书和报告清单
租户内 Microsoft 数据处理宣传资料已验证MDR for Microsoft PDF 称客户可把安全数据留在自有环境证据来自合作伙伴宣传资料,不是公开架构或数据处理白皮书
Microsoft 合作伙伴认可和专业化已验证的公司主张MDR for Microsoft 页面列出合作伙伴奖项、资质和安全专业化奖项更能证明交付可信度,而不是平台控制成熟度
CMMC / FedRAMP / 国防环境相关性通过 Conquest 并购已验证发布材料把 Conquest 和 BlueVoyant 与 CMMC RPO 认证、DIB 使用场景,以及 FedRAMP marketplace 上的 ARMED ATK 联系起来公开来源仍未把这些控制详细映射到主商业平台
DRP 执行的独立评价信号混合Gartner 界面显示一条正面的 DRP 评价标题,但仍提示偶发下架挑战单条公开评价标题不足以承销广泛可靠性
公开开发者透明度GitHub 显示一个可见公开仓库,聚焦 Copilot for Security 内容开源证据太薄,无法评估连接器深度、发布节奏或规模化工程复用

本表把抓取来源中直接可见的信任信号,与仍需私下尽调的更大控制清单分开。

[CE016, CE017, CE031, CE032, CE035, CE036]
路线图 / 发布 / 开发阶段表
日期 / 阶段功能 / 里程碑状态含义来源
2023-03 合作伙伴培训BlueVoyant Shadow Hunter Microsoft Security Immersion Workshop(安全沉浸式工作坊)历史 / 合作伙伴赋能说明在更广的平台汇聚叙事完全公开前,Microsoft 从业者互动已存在SE032
2023-09 产品扩展全面的第三方网络风险管理扩展已发布为 Supply Chain Defense 增加问卷管理、多层级监控、零日告警和咨询工作流SE015/SE023
2023-11 并购Conquest Cyber 并购已交割 / 正在整合用风险成熟度视角扩展态势、合规和政府国防能力SE016/SE024
2024-07 平台发布BlueVoyant Cyber Defense Platform(网络防御平台)已发布建立一个覆盖内部、外部和供应链防御的云原生伞形平台SE021/SE026/SE027
2025-09 开发者信号BV-Security-Copilot 仓库在 GitHub 公开更新可见但狭窄显示公司产出了一些面向从业者的资料,但没有广泛公开工程透明度SE018/SE019/SE020
2026 当前市场推广MDR for Microsoft 和 Continuous Optimization 是平台内上线模块当前确认该产品既作为运营覆盖销售,也围绕 Microsoft 安全支出和控制做优化销售SE005/SE006/SE007
2026 AI 发布BlueVoyant AI agentic SecOps platform(智能体 SecOps 平台)已发布路线图从汇聚界面推进到面向托管和自助 SOC 的 AI 原生编排层SE022

BlueVoyant 不发布公开 changelog,因此路线图证据由发布材料、宣传资料、GitHub 活动和当前方案页面重建。

[CE004, CE007, CE015, CE024, CE033, CE034]
FE004: 产品成熟度 / 能力图

公开证据最能支撑 Microsoft 交付深度和模块广度;在开放工程透明度、非 Microsoft 集成和硬运营基准测试上较弱。

[CE015, CE022, CE035, CE036, CE037, CE039]

5.6 图表

Chapter 06

06客户

6.1 客户分层与买方结构

BlueVoyant 的公开客户文件指向企业和政府买方:它们安全运营复杂、监管敞口明显,或拥有大型第三方生态,而不是广泛 SMB 基础。买方通常是 CISO、信息安全办公室、安全架构负责人或基础设施所有者;日常用户是 SOC 或 IT 运营团队;付款方通常是机构采购预算、受监管企业安全预算,或由伙伴支持的合同工具。最强的可见细分是公共部门和金融服务:一侧是 California OIS、NAVSEA 以及 Carahsoft 支持的政府路径,另一侧是 Snappi、Beeks、ClearBank 和面向金融服务的 Microsoft 内容。ODEON 把客户文件拓宽到多国消费者运营,但模式仍是复杂、高风险环境。能源和法律显然是目标垂直行业,但所审阅语料没有同等强度的具名生产引用。[CU001, CU002, CU003, CU004, CU030, CU031]

客户分层表
分层 / 群组买方 / 用户 / 付款方代表性公开证据证据证明什么主要缺口
州和地方政府买方:OIS/CISO;用户:SOC 和 IT 团队;付款方:机构或全州网络安全预算California OIS SOCaaS 和 CDT SOCaaS 页面BlueVoyant 能支持资源受限公共实体的共享服务监控公开证据集中在 California,且不披露合同经济性
联邦国防和采购买方:项目 / 采购负责人;用户:供应链和安全分析师;付款方:联邦合同工具NAVSEA / 202 Group Phase III 工作,以及 SCRIPTS BPA 可用性BlueVoyant 在供应链风险使用场景中具备真实联邦采购牵引力项目和供应商覆盖证据强于终端用户采用细节
数字银行和受监管金融买方:CISO / 董事会 / 安全负责人;用户:SOC 和合规团队;付款方:企业安全预算Snappi 和 ClearBank 公开材料韧性、报告和 Microsoft 运营重要时,BlueVoyant 有吸引力公开材料中的具名银行名单仍偏少
资本市场基础设施买方:CISO / IT 负责人;用户:SOC 分析师;付款方:平台运营方预算Beeks Group 客户表述BlueVoyant 能支持面向客户的金融基础设施,并安抚下游客户关于初始部署之外扩展的公开证据很少
多站点商业运营商买方:中央 InfoSec / 云服务;用户:区域安全团队;付款方:公司安全预算ODEON 案例研究和独立报道BlueVoyant 能统一嘈杂的多国环境,并增加第三方风险可见性公开商业证据由一个旗舰娱乐业客户背书主导
能源和法律行业市场动作买方:行业 CISO 或 IT / 安全负责人;用户:安全团队;付款方:企业安全预算能源 webinar 和律所方案 spotlightBlueVoyant 正积极瞄准银行和政府之外的其他受监管行业已审阅来源没有在这些垂直领域列出可比的生产客户

各行把有具名证据的分层,与当前主要由方案营销或思想领导力支持的行业分开。

[CU001, CU002, CU003, CU004, CU030, CU031]
FU001: 客户旅程图

可见买方旅程通常从合规或告警疲劳痛点开始,经由伙伴或 Microsoft 主导的导入,扩展到全天候运营和第三方风险可见度。

[CU001, CU002, CU026, CU027, CU030, CU042]

6.2 具名生产证明与买方结果

BlueVoyant 最强公开客户证据来自少量具名引用,并附带具体运营结果。California OIS 给出最清晰的州政府证明,展示以 Microsoft 为中心的 SOCaaS 部署,带来更快检测与响应以及预算节省。ODEON 增加了一个跨国商业引用,包含量化的告警噪音降低、第三方漏洞解决,以及从碎片化工具迁移到 Sentinel 加 MDR 的更详细技术叙事。Snappi 在数字 ROI 上较弱,但在受监管银行准备度上很强:上线数月内获得 24/7 SOC 覆盖、董事会汇报、桌面演练验证的响应,以及 DORA 准备。Beeks 是最好的金融市场证明,因为客户自己表示 BlueVoyant 降低了告警疲劳、降低数据摄取成本,并在不到三个月内上线。NAVSEA 和 BlueVoyant Government Solutions 材料证明其具备真实联邦部署意义,尽管这些证据更偏项目和合同驱动,而不是席位数或续约驱动。[CU005, CU006, CU007, CU008, CU009, CU010]

客户增长 / 采用轨迹表
日期 / 信号公开指标或证明点来源解读注意事项
2025 年 5 月全球超过 1,000 家客户信任BlueVoyant Microsoft awards 新闻稿显示公司愿意在近期公开材料中提出四位数客户数主张公司整体主张未按产品、地域或收入规模拆分
2025 年 6 月California SOCaaS 保护 112 个公共部门组织,合计节省超过 $54 millionCalifornia Department of Technology 新闻室显示一个有意义的全州规模公共部门生产项目CDT 没有拆分当前项目有多少具体归因于 BlueVoyant
2025 年 4 月SCD-G 目前为超过 4 million 家供应商识别关键风险BlueVoyant Government Solutions SCRIPTS BPA 新闻稿证明政府供应链防御中的大型受监控生态规模供应商覆盖是平台范围,不是客户数指标
2026 年评价界面FeaturedCustomers 显示 133 条客户参考的总体评分为 4.7/5FeaturedCustomers 证言页面第三方评价界面暗示存在相当规模的客户参考存量参考平台不是经审计的留存或使用披露
2026 年 marketplace 可见性已审阅的 AWS Marketplace 和 Slashdot 页面显示 0 条客户评价或评分AWS Marketplace 和 Slashdot 对比页面一些面向买方界面上的独立公开评价密度仍较浅无评价不证明采用率低,主要说明可见反馈量低

本表混合公司宣称规模、项目规模和第三方可见性代理指标,因为 BlueVoyant 不发布完整公开客户 cohort 序列。

[CU009, CU025, CU036, CU037, CU039]
具名客户证据表
客户 / 项目分层部署状态公开报告的结果证明什么局限
California OIS SOCaaS州政府生产共享服务项目MTTD 降低 70%,MTTR 降低 60%,每个参与实体每年节省 $2.1M 人员成本BlueVoyant 能支持大型、基于 Microsoft 的公共部门运营模型已审阅语料没有显示合同价值或续约机制
ODEON Cinemas Group娱乐 / 多站点运营生产级跨国部署需审查告警减少 98%,已解决 30 个关键 / 高危第三方漏洞BlueVoyant 能在分布式环境中降噪,并增加供应商风险可见性大部分证据仍由供应商或合作伙伴撰写,而非 ODEON 审计
Snappi数字银行 / neobank生产发布阶段部署24/7 SOC、DORA 就绪、董事会级 KPI 报告、经桌面演练验证的事件响应BlueVoyant 能帮助受监管银行快速上线安全运营证据更强调韧性就绪,而不是商业或用户量结果
Beeks Group资本市场基础设施生产客户部署不到三个月上线,告警疲劳和数据摄取成本同步下降客户面向外部的金融平台需要网络信任支撑获客,BlueVoyant 能强化这一环公开证据没有量化续约、扩张或合同规模
NAVSEA / BlueVoyant Government Solutions联邦国防供应链政府生产项目Phase III 合同、交付订单,以及当前平台覆盖超过 4M 家供应商的说法BlueVoyant 已在联邦供应链场景落地,也具备采购相关性项目级证据强于常规 SaaS 账户指标

行项目聚焦已审阅材料中最深入的具名证据,并把运营里程碑与传统 SaaS 留存指标分开。

[CU005, CU006, CU007, CU008, CU011, CU013]
FU003: 客户证据矩阵

少数具名引用的证据质量最强;但即便量化结果很强,留存可见度仍然偏弱。

[CU005, CU011, CU018, CU020, CU023, CU039]

6.3 政府与金融服务深度

政府和金融服务是 BlueVoyant 公开客户故事中最可辩护的部分。政府侧,公司可以指向 California 全州 SOCaaS 模式、通过 202 Group 继承的 NAVSEA 供应链工作,以及经 Carahsoft、SEWP、ITES-SW2、NASPO、CMAS 和 SCRIPTS BPA 扩大的采购足迹。这不只是 logo 证据,而是显示真实合同路径和运营用例。金融服务侧,证明更窄但仍可信。Beeks 提供资本市场基础设施证明,并有直接客户表述。Snappi 展示一家新受监管银行从第一天起就用 BlueVoyant 建立网络运营,ClearBank 则表明 BlueVoyant 可与一家成熟英国银行客户公开谈 Microsoft 优化。需要谨慎的是,公开深度最强处围绕 Microsoft-centric 托管安全和韧性主题,而不是一长串具名银行或保险公司。[CU003, CU004, CU017, CU018, CU020, CU021]

6.4 渠道与采购路径

BlueVoyant 的上市路径显然刻意偏重伙伴。公司宣传正式伙伴计划,包含联合销售、赋能、账户规划和 OEM / 技术联盟支持。Carahsoft 是公共部门需求最清晰的渠道放大器,因为它让 BlueVoyant 接入既有经销商网络和合同工具,而不是逐个机构强推直接采购。BlueVoyant Government Solutions 又通过 SCRIPTS 和供应链防御动作增加了一条更专门的联邦路径。AWS Marketplace 提供另一条采购路径,尽管所审阅 listing 偏 private-offer,外部反馈很少。实际含义是,扩张可能既来自伙伴和平台生态,也来自净新增直销。对 Microsoft-centric 买方尤其高效,但也意味着客户可见度可能落后于上市路径宽度,因为部分胜单通过分销商、网络研讨会或伙伴页面浮现,而不是通过详细独立案例研究出现。[CU024, CU025, CU026, CU027, CU028, CU029]

政府 / 金融服务采购路径表
路径买方或用户类型公开证据可实现的能力限制
以 Microsoft 为中心的企业直销CISO / SOC / 云安全团队ODEON、Snappi、Beeks、ClearBank、California OIS 等客户支持快速接入 Sentinel、Defender、MDR 和报告工作流公开证据在 Microsoft 已具战略地位的场景最强
Carahsoft 公共部门分销联邦、州、地方、部落、教育、医疗买方Carahsoft 合作伙伴关系和合同页面让机构通过既有经销渠道和合同载体采购间接路径会降低终端客户经济性的可见度
SCRIPTS BPA / BlueVoyant Government Solutions(政府解决方案)DoD 和 FCEB 供应链风险买方BlueVoyantGov SCRIPTS BPA 新闻稿简化联邦项目获取 SCD-G 和分析师支持的路径项目规模不会自动转化为商业 SaaS 式留存数据
AWS Marketplace 私有报价云优先安全买方AWS Marketplace MDR 列表通过 AWS 账单和 marketplace 工作流完成采购已审阅列表仍显示无客户评论,并要求私有报价
合作伙伴主导的外部背书合作伙伴、分销商和客户引用生态合作伙伴页面、Carahsoft 经销商页面、Beeks 和 Veracloud 外部案例把触达和可信度延伸到 BlueVoyant 自有渠道之外路径广度超过独立可见续约证据的深度

这张补充表把采购机制与客户结果分开,避免把合作伙伴和合同路径误当作留存证据。

[CU026, CU027, CU028, CU029, CU030, CU031]
FU002: 采用 / 部署流程

BlueVoyant 的公开部署通常先拿到采购入口,再进入以 Microsoft 为中心的导入,随后转向持续运营和伙伴可见的扩张。

[CU013, CU018, CU021, CU026, CU029, CU042]

6.5 留存、集中度与可见度风险

BlueVoyant 客户文件中最大的缺口不是没有参考账户,而是没有耐久性披露。所审阅来源均未提供 NRR、GRR、流失率、logo 留存、队列续约曲线或按客户划分的收入集中度。PeerSpot 暗示年度或多年协议较常见,但这仍是泛化第三方评论,而非公司验证的队列证据。独立评论界面只能部分帮上忙。FeaturedCustomers 显示有一定数量参考和正面评分,但 AWS Marketplace 和 Slashdot 页面在所审阅 listing 上仍显示零公开评分。多数量化证明由厂商或伙伴撰写,有助于看到部署结果,却不足以承销集中度和续约风险。因此尽调结论是混合的:BlueVoyant 拥有可信标杆证明和受监管行业相关性,但买方仍需 top-customer 敞口、扩张率、续约率和分部经济性的私有数据,才能把公开客户故事视为完全承销。[CU037, CU038, CU039, CU040, CU041, CU042]

留存 / 重复使用 / 满意度表
指标 / 代理指标公开数值细分置信度尽调事项
净收入留存率(NRR)整体客户群索取过去八个季度按产品线和客户细分拆分的 NRR
总留存 / Logo 留存整体客户群索取 Logo 留存和总美元留存 cohort
流失率整体客户群索取总流失和净流失,并列出前 20 大客户贡献
合同期限 / 续约结构PeerSpot 提到年度或多年期协议企业细分混合按细分获取订单表样本、续约日期和终止权
公开满意度 / 可见度代理指标FeaturedCustomers 评分 4.7/5,含 133 条引用;但审阅页面显示 AWS 评论为 0、Slashdot 评分为 0公开证据表面将公开评论密度与真实续约和支持 KPI 对齐核验

Null 表示已审阅材料未公开该指标;可见评论和合同信号只是代理指标,不能替代留存数据。

[CU037, CU038, CU039, CU040]
扩张与集中风险表
扩张驱动或集中风险公开证据显示什么对投资判断的影响尽调路径
以 Microsoft 为中心的交叉销售California、ODEON、Snappi、Beeks 和 ClearBank 都把 BlueVoyant 与以 Microsoft 为中心的安全运营紧密绑定Microsoft 重度账户内的扩张逻辑很强,但该技术栈之外的产品广度不够可见索取按产品拆分的 ARR、挂载率,以及 Microsoft 主导部署之外的胜率
公共部门合同路径依赖Carahsoft、SEWP、ITES-SW2、CMAS 和 SCRIPTS 带来有意义的政府准入有助于放大分销,但采购节奏和渠道执行可能塑造收入集中度索取按直销与渠道、合同载体拆分的 bookings
金融服务合规拉动Snappi、Beeks 以及金融服务内容显示需求由合规驱动,并强调运营韧性价值行业适配度好,但具名银行深度仍有限索取头部金融服务账户、pipeline 转化,以及按子细分拆分的可背书程度
旗舰客户引用集中公开证据由少数深度案例主导,而不是一组同样细致的广泛引用如果长尾部署更浅,少数旗舰账户可能高估整体部署深度索取前 10 大客户收入占比,以及超过重要 ARR 门槛的客户数量
耐久性可见度缺口未发现公开 NRR、GRR、流失、续约或头部客户集中度披露这是承保客户质量时最大的剩余尽调障碍在 NDA 下获取 cohort 表、续约仪表盘和集中度明细

该图表同时列出上行空间和风险,因为 BlueVoyant 的公开材料最擅长说明客户为什么购买,却最缺少这些客户能持续多久的证据。

[CU026, CU028, CU030, CU031, CU039, CU040]
Chapter 07

07风险

7.1 监管、隐私与不利信号

BlueVoyant 目前并未表现为处在大范围公开执法压力下的公司,但其可见运营界面仍带来真实的监管和法律暴露。公司的隐私和法律声明称,BlueVoyant LLC 是网站个人数据控制者,并可在法律未禁止时与关联方共享个人信息;这并不罕见,但对会审查控制者边界、关联方访问和全球数据处理的买方仍然重要。更大的外部约束来自公司贴近政府和国防的业务动作。BlueVoyant Government Solutions 明确向联邦和国防场景销售供应链防御、CMMC 支持和 NIST 800-171 合规管理,而 DoD 的 CMMC 推行已经进入实际合同。因此,风险不是抽象监管,而是能否按采购绑定的网络控制要求执行;如果 BlueVoyant 或其客户无法证明准备就绪,项目中标可能被拖延,甚至被取消资格。 当前公开材料里,最清晰的公司特定负面信号是 Steward Health 在 Texas bankruptcy court 对 Bluevoyant LLC 提起的对抗性申诉。仅靠公开案卷文字无法量化暴露、胜算或预期结果,但这是一个仍在推进的负面事项,需要直接尽调事实背景、保险、准备金处理,以及它是否反映计费、交付或供应商管理争议。另一个方面,SAM.gov 和 USAspending 让联邦授标数据可以公开追踪,这一点有用,因为 BlueVoyant 的合同工具覆盖面可见,但实际机构层面的集中度和续约依赖不可见。整体看,只有当公司能证明隐私治理克制、公共部门合规准备处在当下可用状态,并能给 Steward 事项一个边界清楚的解释时,法律和监管风险才算可控。[CR015, CR016, CR017, CR018, CR019, CR020]

监管 / 法律风险登记表
规则 / 案件 / 控制司法辖区状态可能性严重性缓释措施剩余敞口尽调路径
面向国防相关工作的 DoD CMMC 推进美国 / DoDPhase 1 自 2025-11-10 起生效,涵盖 Level 1 和 Level 2 自评用现有 CMMC 和 NIST 支持定位证明准备度高 — 认证证据缺失或薄弱会拖慢授标,或导致投标出局获取内部 CMMC 等级映射、最新 SPRS 确认,以及与 CMMC 工作绑定的客户引用
合同执行中的 NIST SP 800-171 义务美国 / 联邦采购处理 CUI 的非联邦系统需遵守的持续基线控制框架将交付流程映射到 800-171 控制覆盖中高 — 控制缺口会变成采购、审计或整改负担索取正式控制矩阵、继承模型和任何第三方评估
Steward Health 对抗性诉状Texas Southern Bankruptcy Court截至 2026-06-26,公开案卷仍活跃中高如果敞口有限,可通过法律抗辩、保险和协商解决中 — 仅凭公开案卷,事实敞口和金额敞口仍不清楚审阅诉状、答辩、索赔金额、付款历史和任何保险公司往来
网站隐私治理和关联方共享网站 / 跨境数据治理隐私声明称 BlueVoyant LLC 为控制者,除非被禁止,否则可与关联方共享在交易特定 DPA 中明确控制者边界、关联方访问和保留期限中 — 如果数据流边界不清,买方尽调负担会上升索取产品级 DPA、子处理方和区域数据流图
联邦授标透明度和机构审查美国 / 采购数据SAM.gov 和 USAspending 让合同授标尽调可行,但公司组合未披露在承保集中度前,预先搭建机构和合同载体分析中 — 隐性集中可能在尽调后期浮出水面按法定企业名称拉取机构级授标,并与管理层收入分部对账

各行仅用公开证据按剩余严重性排序;不能替代律师审阅或逐合同合规测试。

[CR015, CR016, CR017, CR018, CR019, CR020]

7.2 Microsoft 生态系统与竞争平台风险

BlueVoyant 最强的公开优势,也正是其最大的战略依赖之一。公司把自己定位为 Microsoft 安全专家,覆盖 Sentinel、Defender、Purview、Copilot readiness 以及相邻的采用成本评估;Microsoft 和 BlueVoyant 的材料也共同强调,BlueVoyant 帮助塑造 Sentinel 用例、分析能力和 Security Copilot 内容。奖项和生态认可证明其渠道可信度真实存在,合作伙伴栈显然不是表面文章。但这也意味着,BlueVoyant 的差异化暴露在 Microsoft 路线图选择、定价变化、打包方式调整和原生功能扩张之下。如果 Microsoft 把更多工作流直接做进自家栈,BlueVoyant 就必须持续证明,其专家服务、内容和运营判断值得额外付费,而不是变成可选的外包人力。 竞争强度很高,因为 BlueVoyant 防守的不是一个狭窄切口。公开材料和评测目录把它放在 MDR、Microsoft 托管安全、数字风险、供应链防御和第三方风险管理等多个领域。多条进攻路径给了公司更多机会,但也意味着买方可以在每个品类里拿 BlueVoyant 与更专精的供应商对比。公司自己的 Sentinel case-study eBook 和 Gartner-market-guide 博客显示,BlueVoyant 的胜法是降低复杂度、帮助客户把风险运营起来,而不是拥有独一无二的底层平台。这很有价值,但一旦 Microsoft 伙伴激增、专注 MDR 的供应商在服务深度上胜出,或 best-of-breed TPRM 供应商把单一工作流执行得更好,防守难度就会上升。简言之,Microsoft 渠道实力降低了需求生成风险,同时也抬高了商品化和集中度风险。[CR001, CR002, CR003, CR004, CR005, CR006]

合作伙伴 / 依赖风险登记表
依赖交易对手 / 生态角色集中度失效场景严重性缓释措施剩余敞口
Microsoft 安全技术栈MicrosoftBlueVoyant 主要产品的核心遥测、工作流和服务底座Microsoft 原生能力改进,挤压 BlueVoyant 叠加服务的价值持续证明差异化部署、内容和托管运营价值
Microsoft 渠道可信度和奖项Microsoft / MISA 生态面向 Microsoft 中心型买方的需求生成和信任信号路线图、联合销售或合作伙伴计划变化削弱 pipeline 效率将证据点扩展到奖项和纯 Microsoft 成功案例之外中高
Sentinel 合作伙伴生态建设Microsoft Sentinel 生态BlueVoyant 在 Sentinel 之上构建分析、playbook、查询和 Copilot agentAPI、平台经济性或商店分发规则发生重大变化贴近产品团队,并维护客户难以轻易复制的交付资产
公共部门采购载体Carahsoft 和政府承包渠道进入机构和国防相邻买方的准入路径载体准入存在,但底层授标组合集中在少数机构或项目中高承保前用 SAM.gov 和 USAspending 衡量真实集中度中高
拥挤的网络风险品类MDR / TPRM / 供应链和数字风险市场设定买方为 BlueVoyant 定价和比较时使用的基准聚焦型厂商在单一工作流上执行更好,而 BlueVoyant 承担平台蔓延中高说明 BlueVoyant 哪些胜利来自运营结果,而不只是产品广度中高

依赖风险由 Microsoft 集中度主导,但采购渠道和品类广度依赖同样重要,因为它们会塑造转化、续约和定价权。

[CR001, CR002, CR003, CR004, CR005, CR006]
FR003: 依赖图

相比任何单一专有公开指标,BlueVoyant 更依赖 Microsoft、人工 SOC 人才、采购渠道和合规证据。

[CR001, CR002, CR003, CR007, CR021, CR022]

7.3 人力服务交付与 AI 执行风险

BlueVoyant 正试图把一个以人为主导的托管安全业务,延展成 AI 原生产品叙事,同时不放弃专家监督的承诺。2026 年 6 月发布的 BlueVoyant AI 称,客户既可以买由 BlueVoyant 精英 SOC 团队支撑的全托管服务,也可以买把同样能力交到客户手里的 SaaS 平台。商业上这很有吸引力,但也提出了真实的运营挑战:公司现在必须在两种模式下同时交付高质量的分析师驱动服务、可信的自治工作流,以及一致的定价和打包。关于机器速度遏制、降低误报和确定性响应的公开说法都很激进。如果没有强护栏、人工接管流程和可衡量的质量结果支撑,BlueVoyant 可能招来更多审查,而不是更少,尤其是在受监管或高后果的客户环境里。 运营模式仍然偏重人力。BlueVoyant 依然强调 24x7 专家监控、全球 SOC 覆盖,以及 Cork 中心服务爱尔兰和欧盟客户等区域扩张。这些都是有意义的缓释因素,但也意味着即便公司在推自动化,招聘、培训、本地化和质量控制仍会持续消耗资源。领导层变化又增加了一层执行风险。John Hernandez 于 2026 年接任 CEO,带着 AI 增长使命;2023 年聘任 CPO 的目的也被明确表述为在产品线扩张后统一产品方向。风险不在于 BlueVoyant 缺乏野心,而在于公司可能要同时管理服务一致性、模型信任、分析师工作流和产品整合。公开评测和目录来源承认其能力覆盖面广,但没有给出 SLA、MTTR、人员配比或告警调优证据,无法完全消除执行风险。[CR008, CR009, CR010, CR011, CR012, CR013]

运营 / 质量 / 安全风险登记表
失效模式可能性严重性缓释成熟度剩余敞口未解决缺口
Agentic-AI 响应误判或人工兜底薄弱中高中 — 已有以人为中心的工作流表述,但硬质量指标未公开BlueVoyant AI 没有公开误报、漏报或干预率数据
托管服务与 SaaS 共存复杂度中 — 一个平台 / 两种部署模式的叙事清楚,但打包方式和支持边界尚无公开证据托管模式与自助模式之间没有公开定价架构或迁移路径
24x7 SOC 人员配置或分析师质量漂移中高中 — 区域 SOC 扩张可见,但人员比例和 SLA 不可见没有公开 MTTR、人员配置或升级质量指标
区域合规和服务本地化负担中高中 — Cork 扩张为 EU 客户增加区域内覆盖中高没有公开多语言支持深度、本地数据边界设计或审计节奏证据
MDR、TPRM 和供应链产品的功能蔓延中高中低 — 产品广度是销售资产,也带来协调负担中高没有公开路线图说明产品、服务和 AI 层如何排序或简化

运营风险被抬高,因为公司既要守住人工交付质量,又要同时扩展平台广度和 AI 自动化叙事。

[CR008, CR009, CR010, CR011, CR012, CR013]

7.4 公共部门暴露、领导层与融资不透明

BlueVoyant 的公共部门定位同时带来韧性和集中度风险。积极一面是,公司通过 Carahsoft 出现在多个合同工具上,并围绕供应链防御、网络安全和合规支持提出政府专属价值主张。由于这些工作对应真实采购和任务需求,而不是可有可无的试验,需求可能更耐久。负面一面是,政府相关收入通常推进更慢、合规门槛更高,也比普通商业 SaaS 更依赖认证证据和合同执行。BlueVoyant 的公开材料没有披露政府或国防客户贡献多少收入、哪些机构最关键,或续约如何分布在各项目之间。因此,公开记录能确认暴露存在,却无法确认分散度。 融资能见度同样不完整。当前材料里最清晰的资本事实,是 2023 年公告称 BlueVoyant 为支持收购 Conquest Cyber 完成超过 $140 million 的 Series E 融资。PM Insights 显示,围绕公司的二级市场和估值监测至少存在一定活动,但公开预览有意保持很薄,无法提供可承销的当前指标。这里没有引用任何关于 ARR、烧钱、runway、杠杆、清算优先权或当前估值的公开披露。这并不证明公司承压,但意味着后期私募市场风险真实存在:如果增长、Microsoft 经济性或公共部门中标率走弱,外部投资者将不得不给一家关键运营指标仍基本私有的公司定价。[CR011, CR012, CR013, CR014, CR023, CR024]

人员 / 执行风险登记表
角色 / 职能依赖或缺口可能性严重性缓释措施尽调路径
首席执行官领导力AI 叙事和全球规模同步推进时,创始人领导过渡到 John Hernandez 这位运营型 CEO新任 CEO 经验丰富,具备企业平台背景审阅第一年运营优先级、销售生产率和领导团队稳定性
产品领导力和整合CPO 职权意味着收购线和传统业务线仍需持续产品统一中高专职产品负责人具备大型供应商和产品组合经验索取当前产品地图、弃用政策和整合里程碑跟踪
MDR 分析师队伍即便 AI 发布后,24x7 专家监控仍是核心区域 SOC 布局和托管服务历史获取分析师与客户比例、流失率、认证覆盖和升级协议
区域支持和本地化Cork 扩张和 EU 服务增加人员、合规与时区复杂度中高区域内 SOC 投资和本地招聘按地域验证人员爬坡、语言覆盖和客户支持边界
政府和合规专家公共部门动作依赖稀缺的网络安全 / 合规人才,需要能讲清 CMMC、NIST、采购和整改中高专门的政府业务和合作伙伴渠道审阅公共部门账户的投标支持、合规专家和续约责任归属

执行风险更多来自同时协调服务人力、产品整合、区域支持和公共部门专业化,而不是创始人可信度本身。

[CR011, CR012, CR013, CR014, CR023, CR024]

7.5 监测触发器、缓释成熟度与数据缺口

缓释图景可信,但不完整。BlueVoyant 的确有真实强项:多年获得 Microsoft 认可、可见的公共部门合同入口、不断扩大的 EMEA SOC 足迹,以及横跨托管检测、第三方风险和供应链防御的产品组合。这些不是装饰性信号。但公司的关键剩余风险,只能被公开证据部分缓释。Microsoft 依赖被渠道实力削弱了,但没有消失。BlueVoyant AI 可能改善单位经济性和服务质量,但同一次发布也扩大了执行范围。政府暴露能创造耐久需求,也会提高合规证据和采购纪律门槛。融资风险仍很难打分,因为公开披露远远没有达到衡量稀释或退出风险所需的指标粒度。 因此,更合适的看法是:BlueVoyant 拥有真实战略资产,但执行容错空间很窄。最可操作的否决标准都可以观察:Microsoft 功能商品化压缩服务差异化;AI 质量或人工接管证据薄弱;在公共部门竞标中无法证明 CMMC/NIST 准备就绪;Steward 事项出现不利进展;或新的融资事件暗示压力而非选择权。公开材料还在集中度、服务质量和资本结构上留下实质性尽调缺口。这些遗漏不会否定业务,但会让剩余风险评分保持偏高。除非管理层能拿出客户组合、续约耐久性、SOC 质量和资本条款的硬指标,审慎的承销立场应是:BlueVoyant 具备战略吸引力,但对执行高度敏感。[CR004, CR005, CR008, CR010, CR017, CR021]

缓释与否决标准表
风险可监控触发因素阈值 / 事件行动含义
Microsoft 生态依赖证据显示 Microsoft 原生功能吸收 BlueVoyant 的服务内容或经济性续约异议围绕在 Microsoft 支出之上继续为合作伙伴叠加层付费而上升下调差异化和毛利率耐久性评估
AI 执行质量BlueVoyant AI 的人工兜底、误报和遏制质量证据管理层无法为自主工作流提供可信质量指标或客户引用将 AI 发布视为增加风险,而不是降低风险
公共部门合规准备度CMMC、NIST 和授标级尽调产出缺少 SPRS 确认、控制映射薄弱,或与合规准备度相关的机构推进停滞假设政府增长更慢,获胜成本更高
法律 / 负面信号控制Steward 诉讼、保险和准备金姿态的直接事实诉状实质扩张、损害赔偿看起来重大,或管理层无法清楚叙述争议上调法律风险评级,并重审交易对手 / 流程尽调
融资不透明当前 ARR、burn、现金 runway,以及任何新资本事件下一轮显示压力、惩罚性优先权,或在没有明确运营加速时大幅稀释降低对入场价格的信心,并要求更强下行保护

这些否决标准把柔性的公开信号转成明确尽调测试,避免把渠道强度和新闻稿误当作风险已经关闭。

[CR017, CR021, CR030, CR032, CR036, CR037]
FR001: 风险热力图

影响最大的残余风险集中在 Microsoft 依赖、融资不透明、公共部门合规,以及托管加 AI 运营模型质量。

[CR046, CR047, CR048, CR049, CR050, CR051]
FR002: 风险传导图

平台、合规或执行失误很可能先打到客户信任,然后才体现为融资或估值压力。

[CR046, CR047, CR048, CR049, CR052, CR053]
Chapter 08

08估值

8.1 投资论点与反论点

BlueVoyant 已有足够规模和品类宽度,只要价格合适,就具备可投资性。公司官方材料描述的是一个统一平台,覆盖 MDR、TPRM、数字风险防护和专业服务,而不是单点工具。这种宽度很重要,因为它支撑了比纯 MDR 更宽的可比公司集合,也让 BlueVoyant 能以多个产品切口进入企业和公共部门预算。2023 年增长公告也显示出有意义的商业验证:超过 900 家客户、覆盖 40 多个国家,并且自 2018 年以来经常性收入曾保持三位数扩张。如果第三方给出的 2025 年 ARR 代理值 $213.5 million 大体方向正确,BlueVoyant 已是一家有规模的网络安全供应商,而不是仍在收入前阶段押注的独角兽。 反论点在于估值质量,而不是公司是否存在。本章最关键的反证信号来自公开二级市场证据:Notice 显示较上一轮折价 39%,Forge 称市场活动有限,Hiive 的公开挂牌页没有可见价格历史。这些信号意味着私募市场要么流动性不足,要么态度谨慎,或两者兼有。同时,公司仍未公开当前毛利率、留存、服务收入占比、稀释后股数,以及 2023 年之后任何融资条款。尽管核心业务看起来可信,这组因素仍把正确结论留在继续研究,而不是买入。 [CV012, CV013, CV015, CV016, CV017, CV018]

建议摘要
维度取值理由
建议继续研究公开证据支持一个看似合理、但尚未明显错价的 $1B 估值;缺失的私有指标仍然关键。
信心多项交叉验证彼此吻合,但核心 ARR 和流动性输入来自第三方数据供应商。
风险评级二级市场折价、可见流动性稀薄,以及未披露的股数和利润率数据,都会带来真实的下行情景敏感性。
估值立场合理隐含约 4.7x ARR 代理值落在混合型网络安全可比公司的区间内,但还不够便宜,无法抵消披露缺口。
决策含义尽调后再接受价格只有管理层证明软件收入占比、利润率质量和近期成交价之后,才上调判断。

截至 2026-06-29 的公开资料视角;估值使用第三方 ARR 和二级市场预览,而非经审计财务披露。

[CV041, CV044, CV045, CV046, CV047, CV048]
投资论点 / 反论点
立场论点什么会改变判断
投资论点BlueVoyant 覆盖 MDR、TPRM、DRP 和专业服务,拓宽了钱包份额,也提升了可比性。如果能证明平台模块正在贡献更高收入占比,正面案例会更强。
投资论点官方来源显示公司已有可观商业规模:超过 900 名客户、覆盖 40 多个国家,并曾实现经常性收入三位数增长。可信的 2026 年客户数、ARR 质量和留存更新,会让规模论点更站得住。
投资论点如果 $213.5M ARR 代理值大体正确,$1B 仅相当于约 4.7x ARR,明显低于高溢价网络安全龙头。披露毛利率和软件收入占比,可能支持向更高质量的平台倍数靠拢。
反论点Notice 显示相对上一轮有 39% 折价,意味着二级市场买家可能以显著低于头部估值的价格成交。近期经纪商报价单或接近、超过 $1B 的已执行交易,可以直接反驳折价信号。
反论点Forge 显示交易活动有限,且没有可见 Forge Price,削弱了对当前流动性的信心。可见的买卖盘深度或撮合完成的二级市场成交,可降低流动性折价。
反论点公开来源对累计融资额说法不一,也没有披露当前稀释、利润率或 2023 年之后的融资条款。清晰的股权结构表、股数、优先权堆栈和当前财务包,会把案例从叙事推进到可承销。

这些论点刻意围绕价格敏感性展开:正面案例真实存在,但反论点扎根于可观察的二级市场和披露缺口。

[CV007, CV008, CV012, CV013, CV015, CV018]
FV001: 建议逻辑

决策流从规模和可比公司支撑出发,经过二级市场谨慎信号和披露缺口,最后落到继续研究的判断。

这只是逻辑决策架构;它概括公开证据的权重,而不是正式评分模型。

[CV034, CV037, CV038, CV044, CV045, CV048]

8.2 融资历史、披露质量与二级市场信号

BlueVoyant 的公开融资历史在标题层面清楚,但在影响定价纪律的细节上模糊。保留来源确认,2022 年 2 月有 $250 million Series D,2023 年 11 月有超过 $140 million 新融资,但公开申报轨迹并不完整。SEC 浏览结果只显示 2017、2019 和 2020 年的 Form D 通知,没有显示后续融资条款。Caplight、CB Insights 和 GetLatka 都指向 $665.5 million 总融资额,Tracxn 报告六轮合计 $696 million,SiliconANGLE 则引用 Tracxn 称 2023 年那轮后约为 $646 million。这不是致命问题,但说明投资者用的是供应商摘要,而不是清晰的公开账本。 二级市场平台进一步加深了这种谨慎。Caplight 仍把 BlueVoyant 锚定在估算 $1 billion,并显示上一轮为 2023 年 11 月 29 日的 Series E。Forge 仍显示上一轮已知估值为 2022 年 2 月的 $1 billion,称当前市场活动有限,且不公布 Forge Price。PM Insights 和 Hiive 都确认二级交易基础设施存在,但公开预览没有给出足够实时深度,无法承销一个精确清算价格。换句话说,市场提供了方向上有用的信号,但透明流动性不足;没有直接经纪商数据,很难把这些信号转化为确信度。 [CV001, CV002, CV003, CV004, CV005, CV006]

8.3 公开可比公司与倍数分析

BlueVoyant 的合适公开可比公司集合本来就应是混合型。高增长一端,CrowdStrike、Palo Alto Networks 和 Fortinet 代表有规模的安全平台,具备强安全运营业务和明显更高的软件质量。相对温和的一端,SentinelOne、Qualys、Tenable 和 Rapid7 更适合作为参考,因为 BlueVoyant 的混合模式仍更接近运营安全和风险管理,而不是纯云安全赢家通吃叙事。Windsor Drake 的 2026 年行业框架是关键宏观锚点:公开网络安全公司约按 6.0x 到 6.5x NTM 收入交易,而托管安全服务约低在 3x 到 5x。 按 2025 年 ARR 代理值计算,BlueVoyant 隐含 4.7x 倍数,落在这片区间的中低位置。它远低于 CrowdStrike 的 34.3x 和 Palo Alto 的 23.28x,也低于 Fortinet 的 15.2x,更接近 SentinelOne 的 4.61x、Qualys 的 5.73x 和 Tenable 的 3.32x。如果 BlueVoyant 的收入组合包含有意义的服务成分,且平台自动化优势尚未转化为已披露的类软件利润率,这个位置在方向上合理。因此,可比公司结论需要保留层次:从收入倍数看,$1 billion 并不显然过高,但折价也不足以构成一个公开证据清晰支持的入场机会。 [CV015, CV016, CV022, CV023, CV024, CV025]

可比估值表
可比公司细分视角市值收入(ttm)EV/收入与 BlueVoyant 的相关性关键限制
CrowdStrike安全运营 / XDR 龙头$178.47B$5.09B34.30x软件 / 安全运营的上限参照。软件属性过纯、溢价过高,无法直接作为基准情景锚点。
Palo Alto Networks含运营能力的综合安全平台$247.92B$10.61B23.28x展示成熟平台宽度可以获得的估值。比 BlueVoyant 成熟且盈利能力强得多。
Fortinet具有运营敞口的安全平台$110.88B$7.11B15.20x是低于 PANW/CRWD 的有用高端基准。质量仍显著更高,硬件 / 订阅收入也更分散。
SentinelOneMDR / 端点平台$5.45B$1.05B4.61x最接近的公开市场倍数校验,适用于成长型但非高溢价安全平台。纯端点 / 软件组合仍比 BlueVoyant 更清晰。
Qualys风险 / 合规 / 漏洞$4.34B$684.86M5.73x可作为风险与合规邻近领域参照。不是服务占比较高的 MDR 业务。
Tenable暴露管理 / 漏洞$3.33B$1.02B3.32x可作为风险导向网络安全的低端区间参照。产品组合和 GTM 与 MDR 加服务不同。
Rapid7XDR / SIEM / 暴露管理$0.51B$859.23M0.93x展示公开市场折价质量和增长时的估值底部。除非利润率或增长严重不及预期,否则对 BlueVoyant 可能过于惩罚。

市值和收入数字来自 2026-06-29 访问的 Yahoo Finance 和 CompaniesMarketCap 截图;EV/收入取自 Yahoo Finance。这些值是方向性的公开市场参照,不是私募市场成交价。

[CV022, CV023, CV024, CV025, CV026, CV027]
FV002: 估值敏感性 — 2025 年 ARR 代理值的倍数

将不同 ARR 倍数应用于 $213.5M 的 2025 年 ARR 代理值,得到以百万美元计的示意企业价值。

数值按第三方 $213.5M ARR 代理值测算,并四舍五入至最接近的百万美元;它们不是经纪商报价。

[CV022, CV023, CV034, CV035, CV041, CV042]

8.4 牛市、基准与熊市估值情景

情景框架从真正可观察的内容出发。基准情景下,BlueVoyant 以 $213.5 million ARR 代理值计,应获得约 4.0x 到 5.0x 倍数,对应大约 $0.85 billion 到 $1.1 billion。这个区间既符合公司的真实规模和产品宽度,也反映了对混合利润率和有限流动性的谨慎。牛市情景下,如果管理层证明近期增长可持续、软件和平台层扩张快于服务,并且近期二级或一级价格发现支持更高质量的网络安全倍数,BlueVoyant 可上探约 $1.2 billion 到 $1.5 billion。因此,牛市情景依赖执行和披露改善,而不只是市场倍数扩张。 熊市情景已经可见。Notice 较上一轮折价 39%,Forge 又没有价格信号;如果下一次真实清算事件低于标题估值,或投资者认为 BlueVoyant 应归入 3x 到 4x 托管安全区间而非平台溢价桶,下行区间大约在 $0.6 billion 到 $0.8 billion。偏度很关键:公开证据并没有强烈显示估值过高,但已经显示部分下行可以被发现,而上行仍依赖市场尚未共享的私有事实。 [CV018, CV019, CV022, CV023, CV034, CV035]

牛市 / 基准 / 熊市情景表
情景关键假设隐含倍数估值区间(USD B)概率信号关键风险
牛市增长保持强劲,软件收入占比扩大,且尽调支持更高质量的平台画像。ARR 倍数 5.5x–7.0x1.2–1.5需要私有证据压过二级市场折价。没有利润率证明,或成交价偏弱,都会打破该案例。
基准ARR 代理值大体正确,BlueVoyant 被市场认可为混合型网络安全平台,并带有中等服务折价。ARR 倍数 4.0x–5.0x0.85–1.10与留存的公开证据最一致。如果 ARR 质量弱于代理值,即便基准情景也会被压缩。
熊市下一次真实成交事件验证二级市场折价,并把 BlueVoyant 推向托管安全或服务类公司的估值区间。ARR 倍数 3.0x–3.8x0.60–0.80与 Notice 折价和可见流动性稀薄一致。新资本以更低估值进入,或利润率不佳,都会加速下行。

情景区间是使用公开 ARR 代理值作出的 USD 十亿美元口径分析估算;它们不是管理层指引,也不是经纪商报价。

[CV018, CV023, CV034, CV041, CV042, CV043]
论点破裂与终止触发器
触发器阈值 / 事件如何传导到论点行动含义
二级市场折价扩大相对上一轮的可观察折价超过约 50%,或新一轮定价低于 $0.8B。这意味着市场认为质量或流动性明显弱于基准情景假设。暂停,并按熊市情景水平重新承销。
服务型经济特征得到确认毛利率或收入结构显示业务的服务占比显著高于隐含水平。合理倍数会被压到更接近托管安全区间。将立场从合理转向偏贵。
没有真实价格发现下一轮尽调周期内没有出现经纪商背书的二级市场成交、买盘或股权结构证据。流动性折价仍未解决,市场无法验证头部估值。保持继续研究,或下调建议。
2023 年后融资不透明管理层无法提供任何 2023 年后融资条款、股数或优先权堆栈文件。没有稀释机制,即便企业价值看起来合理,回报测算也不可靠。没有股权结构包之前,不投入资本。
增长质量转弱ARR 代理值被证明高估,或留存 / 扩张指标低于软件型门槛。打破了 BlueVoyant 至少应获得混合型平台倍数的基准假设。立即重估至熊市区间。

这些阈值是尽调触发器,不是合同契约;它们把公开市场证据转化成具体终止标准。

[CV018, CV019, CV023, CV036, CV038, CV041]
FV003: 估值 / 回报区间

各情形估值区间以百万美元计,并与当前 $1B 的公开标记对比。

区间为分析师估算,依据保留下来的公开证据、二级市场预览和可比倍数区间得出。

[CV041, CV042, CV043, CV048]

8.5 建议、退出纪律与最终尽调问题

仅从公开证据看,建议是继续研究。BlueVoyant 看起来是一家合法且有规模的网络安全平台,当前 $1 billion 标题估值也没有明显脱离保留的 ARR 代理值。但这不等于估值有吸引力。公开市场只提供预览级二级信号,其中最强的一个还是负面信号。此外,保留来源没有披露当前稀释后股数、利润率画像、留存指标,或 2023 年 11 月之后任何融资条款。缺少这些事实,买方可以解释为什么 $1 billion 说得通,但还不能解释为什么它明显对自己有利地错价。 公开证据中的退出准备度也有限。Hiive 称 BlueVoyant 仍为私人持有,合格投资者只能通过二级市场在 IPO 前获得访问;没有任何保留来源显示 IPO 进程、战略出售进程或新的估值重置。可操作路径很直接:拿到当前 ARR 结构、毛利率、NRR 或客户留存、cap table 和优先权栈,以及经纪商或管理层给出的近期真实二级成交。如果这些数据确认类软件经济性,且二级价格稳定或改善,评级可以上调。若它们反而确认收入偏服务、二级交易继续折价,合理标签就会滑向估值偏紧。 [CV021, CV033, CV041, CV042, CV043, CV044]

最终尽调要求
主题缺失证据重要性负责人 / 尽调路径
2026 年 ARR 质量当前 ARR、经常性收入与服务收入占比,以及 2023 至 2026 年 ARR 桥接。决定 2025 年 ARR 代理值是否真实,也决定 4.7x 倍数是合理还是偏高。要求提供当前董事会材料或 CFO 经营包。
利润率和留存画像按主要产品线列示的毛利率、调整后 EBITDA、总留存和 NRR。需要判断 BlueVoyant 应得混合服务倍数,还是软件平台倍数。管理层尽调会,加上队列级留存展项。
股权结构和摊薄后股数最新完全摊薄股数、优先权堆栈、期权池和清算瀑布。稀释不透明时,每股回报可能与企业价值测算大幅背离。数据室股权结构导出,或律师准备的摘要。
实际二级市场成交价来自股权结构管理方或交易平台的近期经纪商报价单、撮合交易和买卖盘历史。最好的公开二级市场信号偏负面;真实成交可以验证或反驳该折价。直接做经纪商尽调,并调取 Forge / Notice / 公司管理记录。
2023 年后任何融资条款Series E 轮之后的债务、结构化融资或附函证据。后续资本结构变化会改变下行保护、优先级和估值解读。CFO / 法务确认,并提供融资文件。

每项要求都对应公开记录中的当前卡点,而不是泛泛的尽调愿望清单。

[CV011, CV021, CV044, CV046, CV047, CV048]
FV004: 投资 KPI

按 IC 视角给六个维度打分,这些维度最影响 BlueVoyant 当前估值判断。

分数是分析性、相对性的判断,供 IC 讨论使用,不是模型机械推导出的结果。

[CV037, CV038, CV044, CV046, CV047, CV048]

免责声明

本报告仅供尽调和信息参考,不构成投资、法律、会计或税务建议。BlueVoyant 是私营公司,公开记录中的多项数字仍是估算值, 彼此冲突或已经过时。任何投资决定都应基于对管理层的直接尽调、客户访谈、经审计财务和最终法律文件,而不能只依赖公开来源汇总。

证据索引

结论
编号陈述可信度来源
CO001 BlueVoyant was founded in 2017. SO001, SO020, SO021
CO002 BlueVoyant's current headquarters is 6 East 45th Street, Floor 17, New York, NY 10017. SO002, SO003
CO003 BlueVoyant officially says it has over 600 employees. SO001
CO004 BlueVoyant officially says it has more than 1,000 customers in 45 countries. SO003
CO005 BlueVoyant's core platform spans managed detection and response, third-party risk management, digital risk protection, and professional services. SO004, SO005, SO006
CO006 BlueVoyant's MDR offering covers internal networks, cloud instances, containers, and endpoints and advertises 500+ Microsoft Sentinel deployments. SO005
CO007 BlueVoyant describes its TPRM product as a fully managed service in which ROC experts review, validate, and help remediate third-party findings. SO006
CO008 BlueVoyant presents itself as an AI-driven provider of internal, external, and supply-chain cyber defense. SO012, SO029
CO009 John Hernandez is BlueVoyant's current chief executive officer. SO002, SO016, SO027
CO010 James Rosenthal is a co-founder and now serves as chairman of BlueVoyant's board. SO002, SO016, SO027
CO011 Thomas Glocer is a co-founder and vice chairman of BlueVoyant's board. SO002, SO001
CO012 BlueVoyant's public executive bench includes Ravi Subramanian (CFO), Sebastian Sobolev (CPO), Jim Bieda (Global CTO), John Harbaugh (CISO), and Sangya Sharma (CHRO). SO002
CO013 BlueVoyant's leadership page also lists solution and regional leaders including Ron Feler, Austin Berglas, Chris Teekema, Michael Spencer, Robert Hannigan, Lonny Anderson, Justin Staffel, Holly Steele, and Patrick Shea. SO002
CO014 BlueVoyant published a COO appointment for Michael Montoya, stating that he would oversee technology, product, and operations. SO015
CO015 BlueVoyant says it has received more than 60 awards and nominations since 2019. SO009, SO001
CO016 BlueVoyant's awards materials say it won Microsoft's 2024 Worldwide Security Partner of the Year and 2024 U.S. and Canada Security Partner of the Year honors. SO009, SO008
CO017 BlueVoyant markets itself as a Microsoft security expert with 10x recognition and dedicated service packaging around Sentinel, Defender, Purview, and Copilot-era security operations. SO008, SO009
CO018 BlueVoyant's partner program emphasizes end-to-end platform resale and 24x7 access to sales, marketing, training, and certification resources. SO007
CO019 BlueVoyant says it is a member of the ISTARI Collective. SO007
CO020 On 2022-02-23 BlueVoyant closed a $250 million Series D led by Liberty Strategic Capital with participation from ISTARI, Eden Global Partners, and 8VC. SO013, SO017, SO021
CO021 Independent 2022 coverage said BlueVoyant's Series D valued the company at over $1 billion and brought total funding to $525 million at that time. SO021, SO020
CO022 TechCrunch described BlueVoyant's pre-Series-D offering as a mix of proprietary technology, third-party best-in-class tools, and professional services for internal and external cyber risk. SO020
CO023 BlueVoyant announced on 2023-11-29 that it acquired Conquest Cyber and paired the transaction with more than $140 million in Series E funding. SO018, SO023, SO033
CO024 CRN reported that the combined BlueVoyant-Conquest proposition was aimed at customers securing Microsoft environments across both commercial and government sectors. SO022, SO024
CO025 GovConWire and BankInfoSecurity framed the Conquest acquisition as expanding BlueVoyant's reach into highly regulated, U.S. government, and defense-industrial-base environments. SO023, SO024, SO018
CO026 Caplight lists BlueVoyant's last round as a Series E on 2023-11-29, with an estimated $1 billion valuation and $665.5 million of total funding raised. SO030
CO027 GetLatka lists a 2025 revenue estimate of $213.5 million, $665.5 million of total funding, a $1 billion valuation, and a team size near 650 for BlueVoyant. SO029
CO028 Third-party private-market datasets in the reviewed set cluster around roughly $665.5 million of total funding and a $1 billion valuation, but those figures remain unaudited estimates rather than company disclosure. SO029, SO030
CO029 The reviewed official company sources do not publish current ARR, GAAP revenue, gross margin, or profitability. SO001, SO013, SO018
CO030 Public headcount signals diverge: BlueVoyant officially says it has over 600 employees, while third-party datasets in the retained set range from about 649-650 to 750. SO001, SO029, SO030, SO031
CO031 UpGuard's June 29, 2026 vendor risk report lists BlueVoyant with 750 employees and says its assessment is based on continuous external monitoring across five risk categories. SO031
CO032 UpGuard flags CSP allowing insecure active sources and use of unsafe-eval on BlueVoyant's web estate, creating the clearest adverse public signal in the retained source set. SO031
CO033 BlueVoyant's contact page lists offices in New York, Leeds, London, Tel Aviv, Makati, and Bogotá plus SOC locations in Riverdale and Cork. SO003
CO034 BlueVoyant's company overview page separately describes offices or support presence in College Park, Washington, D.C., London, Leeds, Cork, Toronto, Tel Aviv, Bogota, Manila, and Singapore across five continents. SO001
CO035 Taken together, BlueVoyant's official pages support a globally distributed operating footprint rather than a single-office New York vendor. SO001, SO003
CO036 BlueVoyant launched BlueVoyant AI on 2026-06-09 as an AI-native or agentic SecOps platform for both managed and self-service SOCs. SO012, SO025, SO026
CO037 The 2026 AI launch extends BlueVoyant's existing Microsoft and SOC positioning rather than creating a wholly new category. SO012, SO008, SO011
CO038 On 2025-09-24 BlueVoyant and Auto-ISAC announced a strategic engagement to elevate third-party cyber risk management across the automotive industry. SO014, SO019
CO039 BlueVoyant's careers page emphasizes mission-driven culture, a large proprietary dataset, automation playbooks, and continual training as part of its employment brand. SO010
CO040 BlueVoyant explicitly markets to companies, government entities, and critical-infrastructure organizations rather than to a narrow single vertical. SO001, SO018
CO041 Cyber Insurance News summarized BlueVoyant's 2025 State of Supply Chain Defense report as showing 97% of surveyed organizations suffered negative impact from at least one supply-chain cyber breach, reinforcing the demand case behind its TPRM positioning. SO032, SO014
CO042 PRNewswire and Enterprise IT World show a May 2026 CEO transition from co-founder Jim Rosenthal to John Hernandez while Rosenthal remained chairman. SO016, SO027, SO002
CO043 The CEO handoff reduces single-person operating dependence, but founder-linked governance and brand concentration remain meaningful because Rosenthal and Glocer continue in chair and vice-chair roles. SO002, SO016, SO027
CO044 BlueVoyant's public leadership materials foreground founders in governance or advisory roles rather than as the day-to-day executive bench. SO002
CO045 Caplight characterizes BlueVoyant's customer profile as a B2B mix of subscription SaaS, services and consulting, and government contracts. SO030
CO046 Caplight tags BlueVoyant around threat intelligence, incident response, vulnerability management, cloud security, and compliance or risk workflows. SO030
CO047 The combination of MDR, TPRM, and professional-services pages indicates BlueVoyant monetizes both recurring software modules and analyst-led managed services. SO005, SO006, SO030
CO048 In the reviewed public source set, the last specifically dated financing event is the more-than-$140 million Series E announced on 2023-11-29 alongside the Conquest acquisition. SO018, SO023, SO030, SO033
CM001 BlueVoyant markets MDR as protection for internal networks, cloud instances, containers, and endpoints that augments existing EDR, SIEM, and cloud security tools. SM001
CM002 BlueVoyant markets TPRM as a fully managed solution that identifies, validates, and resolves critical cybersecurity issues in a third-party ecosystem. SM002, SM003
CM003 BlueVoyant's TPRM module set includes continuous monitoring and remediation, questionnaire management, point-in-time risk assessments, and program consulting. SM002
CM004 BlueVoyant's continuous-monitoring workflow includes analyst-directed remediation, business risk monitoring, tiered vendor analysis, zero-day alerting, fourth-party analytics, and APIs/integrations. SM003
CM005 BlueVoyant's fourth-party analytics motion goes beyond direct-vendor questionnaires into fourth- and nth-party dependency mapping and what-if analysis. SM005
CM006 BlueVoyant's AI positioning emphasizes augmenting human judgment in attack-surface monitoring, threat detection, and vulnerability analysis instead of promising a fully autonomous cyber workflow. SM001, SM004
CM007 BlueVoyant's direct market boundary is the overlap between managed SecOps and cyber-focused third-party risk management rather than generic GRC or stand-alone security controls. SM001, SM002, SM003, SM005
CM008 The most relevant adjacent budget pools are GRC, board reporting, and resilience workflows, but those categories should remain outside BlueVoyant's direct core TAM. SM015, SM020, SM023
CM009 Precedence Research sizes the MDR market at USD 3.92B in 2026 and USD 13.90B by 2035, implying 15.12% CAGR from 2026 to 2035. SM006
CM010 Mordor Intelligence sizes the MDR market at USD 5.09B in 2026 and USD 13.45B by 2031, implying 21.45% CAGR. SM007
CM011 The Business Research Company sizes the MDR market at USD 4.16B in 2026 and USD 8.57B by 2030, implying 19.8% CAGR. SM008
CM012 Published MDR baselines conflict materially, with 2026 starting values ranging from USD 3.92B to USD 5.09B and growth assumptions ranging from 15.12% to 21.45% CAGR. SM006, SM007, SM008
CM013 Grand View Research sizes TPRM at USD 7.42B in 2023 and USD 20.59B by 2030 at 15.7% CAGR, with North America holding more than 38% of revenue in 2023. SM009
CM014 NextMSC says the TPRM market reached USD 9.71B by end-2025 and will reach USD 18.28B by 2030 at 13.48% CAGR, with large enterprises expected to dominate demand. SM010
CM015 The Business Research Company says the TPRM market will grow from USD 8.09B in 2026 to USD 15.45B by 2030 at 17.6% CAGR. SM011
CM016 Published TPRM baselines also conflict materially, with direct and normalized 2026 values ranging from roughly USD 8.09B to USD 11.49B depending on methodology and category scope. SM009, SM010, SM011
CM017 The broader adjacent GRC software market is much larger than BlueVoyant's direct wedge, at an estimated USD 23.32B in 2026 growing to USD 39.01B by 2031. SM020
CM018 Combining MDR and TPRM published baselines suggests a gross 2026 core-market ceiling for BlueVoyant of roughly USD 12.0B to USD 16.6B before removing overlap. SM006, SM007, SM008, SM009, SM010, SM011
CM019 Applying large-enterprise, regulated-buyer, and western-market filters to the gross ceiling yields a practical BlueVoyant SAM of roughly USD 5B to USD 8B. SM007, SM009, SM010, SM011
CM020 Public data does not support a precise dollar SOM for BlueVoyant because the company does not disclose module-level revenue or the split between MDR, TPRM, Microsoft-managed services, and adjacent offerings. SM001, SM002, SM003, SM004, SM005
CM021 MDR spending is enterprise-skewed: Mordor says large enterprises accounted for 57.65% of 2025 MDR spend, while TBRC lists major adopters across BFSI, IT, government, and energy verticals. SM007, SM008
CM022 BlueVoyant's practical SAM is likely western-market skewed because Mordor assigns North America 45.78% of MDR revenue in 2025 and Grand View gives North America more than 38% of TPRM revenue. SM007, SM009
CM023 Large enterprises dominate public TPRM demand because they manage extensive vendor ecosystems, global supply chains, and complex regulatory requirements. SM010
CM024 BlueVoyant's TPRM workflow implies a buying committee that spans security, vendor-risk operations, compliance, procurement, and resilience owners rather than a single budget line. SM002, SM003, SM005
CM025 Panorays says 85% of CISOs lack full supply-chain visibility and only 41% monitor fourth parties, validating a core buyer pain point for BlueVoyant's dependency-mapping and monitoring wedge. SM014, SM005
CM026 Panorays says 62% of CISOs saw regulatory pressure increase and only 22% feel fully prepared, showing that buyer urgency is rising even where operating readiness remains low. SM014
CM027 Marsh says 70% of organizations experienced at least one material third-party cyber incident in the past year and 66% plan to increase cybersecurity investment in the coming year. SM013
CM028 KPMG says regulatory compliance and cyber risk are now the primary drivers shaping TPRM strategy globally. SM012
CM029 BlueVoyant's MDR positioning is an overlay and optimization motion for existing security tooling, not a pure rip-and-replace platform sale. SM001, SM004
CM030 BlueVoyant's TPRM positioning suggests payer logic often extends from security into procurement and enterprise-risk owners because remediation and onboarding workflows sit outside the SOC. SM002, SM003
CM031 SEC cybersecurity disclosure rules require public companies to disclose material cyber incidents within four business days and to describe cybersecurity risk management, strategy, and governance. SM016
CM032 NIS2 creates a unified EU cybersecurity framework across 18 critical sectors, expanding the set of organizations that must take supplier and operational cyber risk seriously. SM017
CM033 CISA defines ICT supply-chain cyber risk as spanning hardware, software, and managed services from third-party vendors, suppliers, service providers, and contractors. SM023, SM024
CM034 NIST CSF 2.0 and CISA's SCRM materials show that cyber supply-chain risk is now treated as a formal management and resilience discipline rather than a narrow procurement checklist. SM015, SM023, SM024
CM035 Gartner says AI, geopolitical tension, regulatory volatility, and an accelerating threat landscape are the forces shaping cybersecurity buying priorities in 2026. SM018
CM036 KPMG says only about one in five organizations have achieved full TPRM integration with ERM and only 5% have adopted end-to-end managed-service models. SM012
CM037 Black Kite says that in 2025 each vendor breach compromised an average of 5.28 downstream companies, which makes fourth-party and concentration analysis commercially relevant. SM021
CM038 BlueVoyant claims its TPRM monitoring uses AI/ML across more than 50,000 data sources and can issue zero-day alerts in as little as 90 minutes, aligning the product with continuous-risk rather than periodic-review buying criteria. SM003, SM005
CM039 CyberProof says Gartner has warned that some providers misuse the MDR label by offering managed EDR or other tool-centric monitoring without full human-led incident-response leadership. SM019
CM040 CyberProof says MDR has moved toward mainstream adoption, citing projections that half of organizations would use MDR services for 24x7 monitoring, detection, and containment. SM019
CM041 KPMG says most organizations still rely on a patchwork of disconnected tools, which constrains category standardization and slows end-to-end TPRM adoption. SM012
CM042 Panorays' data implies that many buyers still operate with major blind spots beyond direct vendors, so category adoption is limited as much by process maturity as by software availability. SM014
CM043 CRC says global cyber-insurance pricing fell about 7% in Q4 2025 as market capacity improved, which can soften one urgency lever for cyber-spend escalation. SM022
CM044 CRC says ransomware remained the primary driver of business interruption claims and that supply-chain and vendor risk stayed a central underwriting focus in 2026. SM022
CM045 PeerSpot's MDR category page shows that buyers actively compare many vendors and still ask what differentiates MDR from a traditional SOC, reinforcing category crowding and education friction. SM025
CM046 BlueVoyant's market should not be equated with generic GRC because BlueVoyant sells cyber monitoring, validation, remediation, and dependency visibility rather than broad policy-and-audit software alone. SM002, SM003, SM020
CM047 BlueVoyant's strongest valuation support comes from cross-sell between independently growing MDR and TPRM categories that are both being pulled forward by regulation and operating pain. SM006, SM007, SM011, SM013, SM018
CM048 The main market risk is not whether the categories exist, but whether BlueVoyant can win inside crowded, definition-sensitive categories where buyer confusion, tool sprawl, and budget scrutiny can slow conversion. SM012, SM019, SM022, SM025
CM049 BlueVoyant's differentiated TPRM wedge appears to be analyst-led remediation plus fourth-party mapping, not just questionnaire automation. SM002, SM003, SM005, SM014
CM050 BlueVoyant's differentiated MDR wedge appears to be overlaying and optimizing existing Microsoft, EDR, and SIEM environments with 24x7 monitoring and automation rather than selling a stand-alone security control. SM001, SM004
CP001 Gartner defines MDR as a provider-operated, outcome-driven SOC service that includes active disruption and containment rather than alerting alone. SP027
CP002 BlueVoyant publicly positions itself across MDR, TPRM, digital risk protection, and professional services rather than as a single-product MDR vendor. SP001
CP003 BlueVoyant highlights 1,200+ Microsoft Sentinel deployments, 10 Microsoft security awards, and 24x7 in-regional SOC monitoring across Europe and the US. SP001
CP004 BlueVoyant’s MDR page advertises 50+ certified Microsoft Delivery and SOC engineers plus unlimited remote incident-response lifecycle support. SP003
CP005 BlueVoyant says it was founded in 2017 and has over 600 employees across offices on five continents. SP002
CP006 BlueVoyant Government’s C-SCRM product says it uses more than 70,000 unique proprietary, open-source, and commercial data feeds without requiring agency or vendor proprietary data. SP005
CP007 BlueVoyant Government says it can map, monitor, and mitigate risk for tens of thousands of suppliers at once and validate 100% of supplier risk events. SP005
CP008 BlueVoyant’s June 2026 launch of BlueVoyant AI signals a strategic move toward agentic SecOps that can be consumed either as a fully managed SOC or a self-service SaaS platform. SP006
CP009 Palo Alto positions Cortex XSIAM as a unified AI-driven SOC platform spanning SIEM, SOAR, EDR, NDR, and CDR. SP007
CP010 Palo Alto advertises 10,000+ detections, 2,600+ analytics models, and Unit 42-managed services on top of XSIAM. SP007
CP011 Palo Alto says it has 16K+ employees and 70K+ customers globally, giving it distribution scale that BlueVoyant cannot match publicly. SP008
CP012 CrowdStrike Falcon Complete advertises a one-minute median time-to-contain and 2.7 million detections remediated monthly. SP009
CP013 CrowdStrike frames Falcon Complete as agentic MDR that combines deterministic automation, adaptive AI agents, human-in-the-loop experts, and native visibility across endpoint, identity, cloud, and third-party data. SP009
CP014 Arctic Wolf positions around a fully managed agentic SOC with 10,000+ customers, 1,000+ security engineers, and 200+ integrations. SP010, SP011
CP015 Arctic Wolf says its proactive MDR can reduce attack frequency and impact by up to 90% and completed more than 74,000 security posture reviews in 2025. SP010
CP016 Arctic Wolf’s value proposition centers on concierge delivery, open XDR, security-journey guidance, and warranty coverage rather than a single endpoint platform. SP010, SP012
CP017 CRN reported that Arctic Wolf raised $60 million in Series D to help the company prepare for IPO-related thresholds. SP032
CP018 SC Media reported that Arctic Wolf was valued at roughly $4.3 billion while management avoided committing to an IPO timeline. SP033
CP019 Rapid7 says it serves more than 11,500 customers worldwide and positions itself as a leader in AI-powered managed cybersecurity operations. SP013
CP020 Rapid7’s Incident Command platform ties exposure management, endpoint and cloud telemetry, third-party sources, Rapid7 Labs intelligence, and 20 years of data into one detection-and-response workflow. SP014
CP021 ReliaQuest describes GreyMatter as an agentic AI security operations platform that detects, contains, investigates, and responds regardless of data source. SP015
CP022 ReliaQuest’s homepage says GreyMatter processes 50K+ alerts daily with 255+ technology partners and 99.4% AI investigation accuracy. SP016
CP023 ReliaQuest’s integrations posture supports enterprises that want to keep existing SIEM, EDR, and cloud tools rather than replace them with one vendor stack. SP017
CP024 eSentire says it protects 2,000+ customers across 35+ industries and pairs Atlas AI with 24/7 expert human SOC coverage. SP018
CP025 eSentire’s XDR platform and third-party coverage claim a vendor-independent model with broad integrations and human-controlled AI response. SP019, SP034
CP026 eSentire’s competitive messaging explicitly emphasizes unlimited threat hunting, unlimited incident handling, and any-signal integration breadth. SP020
CP027 SecurityScorecard says 70% of the Fortune 100 trust its data, 3,300+ organizations use the platform, and 12M+ organizations are monitored and rated. SP022
CP028 SecurityScorecard’s TPRM pitch combines questionnaire review, technical-ground-truth validation, continuous monitoring, nth-party visibility, remediation blueprints, and risk quantification. SP021, SP023
CP029 SecurityScorecard publicly frames itself as supply-chain detection and response rather than only a passive cyber-ratings tool. SP021, SP022
CP030 BitSight says its TPRM product includes 75K+ mapped vendor profiles and claims a 75% reduction in third-party breach probability for customers. SP025
CP031 BitSight says it continuously monitors 40M+ companies and 250M+ digital assets and exposes cyber risk through APIs, integrations, and data feeds. SP024, SP025
CP032 Bitsight’s April 2026 press release says it was named a Forrester Leader and had more than 3,500 customers plus over 68,000 organizations active on platform. SP026
CP033 Gartner’s 2026 MDR market page lists 173 products and reiterates that immediate remote mitigative response is a mandatory MDR feature. SP027
CP034 PeerSpot says BlueVoyant CORE held 0.9% MDR mindshare in June 2026, down from 1.2% the year before. SP028
CP035 PeerSpot’s BlueVoyant-versus-CrowdStrike comparison ranks BlueVoyant #34 in MDR while CrowdStrike is ranked #2 and holds 5.4% mindshare versus BlueVoyant’s 0.9%. SP029
CP036 PeerSpot says reviewers occasionally note limited reporting customization for BlueVoyant and characterize CrowdStrike as broader and faster to deploy. SP029
CP037 Daylight’s 2026 buyer guide classifies BlueVoyant among MSSPs offering MDR that are chosen for broad security partnership but use more analyst-hours-intensive investigation workflows than AI-native or XDR-extended alternatives. SP031
CP038 Ciphers Security says the TPRM market splits between outside-in security-ratings platforms and workflow-oriented lifecycle tools such as ProcessUnity, OneTrust, Venminder, and Prevalent. SP030
CP039 The same Ciphers Security guide says ratings tools assess vendors from the outside in, while workflow platforms manage questionnaires and lifecycle tasks from the inside, so many buyers blend the two approaches. SP030
CP040 BlueVoyant’s public combination of MDR, TPRM, digital-risk protection, and government C-SCRM gives it a cross-budget story that most MDR-only or ratings-only competitors do not present on one surface. SP001, SP004, SP021, SP024
CP041 The retained official pages for BlueVoyant, CrowdStrike, Arctic Wolf, Rapid7, ReliaQuest, eSentire, SecurityScorecard, and BitSight do not disclose enterprise list pricing for their full offerings, implying quote-based sales motions and limited public comparability. SP001, SP009, SP010, SP013, SP015, SP018, SP021, SP024
CP042 Platform-native competitors create bundling pressure because Palo Alto, CrowdStrike, and Rapid7 tie managed response to broader SOC, XDR, or SIEM suites with unified telemetry and automation. SP007, SP009, SP014
CP043 Arctic Wolf, ReliaQuest, and eSentire represent a separate open-stack threat because all three publicly stress preserving the customer’s existing security tools while adding 24x7 expert operations. SP010, SP017, SP019
CP044 BlueVoyant’s supply-chain defense competes against much larger publicly described data networks because SecurityScorecard and BitSight cite millions of monitored organizations or tens of thousands of mapped vendor profiles. SP022, SP025, SP026
CP045 BlueVoyant is best aligned to Microsoft-heavy or regulated buyers that want managed SOC operations plus outside-in supplier defense rather than a single-vendor endpoint suite or a pure ratings tool. SP001, SP003, SP005, SP006, SP021, SP024
CP046 Internal SOC build remains a substitute, but Gartner and Decryption Digest both frame outsourced MDR as a way to avoid the staffing and response burden of self-running security operations. SP027, SP031
CI001 BlueVoyant publicly packages MDR, TPRM, DRP, and professional services as four core commercial solution families. SI001
CI002 BlueVoyant claims more than 1,200 successful Microsoft Sentinel deployments. SI001
CI003 BlueVoyant claims customers can reduce Sentinel costs by 40% without sacrificing coverage. SI001
CI004 BlueVoyant claims it provides 24x7 in-regional SOC monitoring across Europe and the United States. SI001
CI005 BlueVoyant claims its TPRM offer drives 18x faster remediation of critical issues. SI001
CI006 BlueVoyant claims 98% accuracy for critical vulnerabilities identified in its TPRM motion. SI001
CI007 BlueVoyant claims an average response time of 3.5 hours for recently disclosed zero-day vulnerabilities. SI001
CI008 BlueVoyant claims it remediated more than 1,600 vulnerabilities on behalf of clients in the last 30 days. SI001
CI009 BlueVoyant claims it completed 50,000 successful domain takedowns over the prior two years. SI001
CI010 BlueVoyant says it has over 600 employees across offices spanning five continents. SI002
CI011 BlueVoyant publicly positions channel partners such as GuidePoint Security and CDW as part of its distribution model. SI003
CI012 BlueVoyant's build-versus-buy marketing says a self-built 24/7 SOC can cost more than $1.2 million annually. SI004
CI013 The same BlueVoyant page says a partnered MSSP can cost less than 25% of the annual cost of building an internal SOC. SI004
CI014 BlueVoyant said it added 299 new customers during 2021. SI005
CI015 BlueVoyant said customer count exceeded 700 across 30 countries by early 2022. SI005, SI006
CI016 BlueVoyant said its employee count increased by 130% during 2021. SI005
CI017 BlueVoyant said partners contributed 50% of all new business in 2021. SI005
CI018 BlueVoyant said annual recurring revenue had grown 117% on average since 2018. SI005, SI006
CI019 BlueVoyant closed a $250 million Series D round led by Liberty Strategic Capital with participation from ISTARI, Eden Global Partners, and 8VC. SI006, SI022
CI020 BlueVoyant said it had grown to more than 560 employees and more than 700 customers by the Series D announcement. SI006
CI021 BlueVoyant said it expanded into more than 10 countries during 2021. SI006
CI022 BlueVoyant acquired Conquest Cyber and raised more than $140 million of Series E funding alongside the deal. SI007, SI018, SI019, SI020, SI021
CI023 The Series E funding was led by Liberty Strategic Capital and ISTARI, with Eden Global Capital Partners acting as strategic adviser. SI007, SI018, SI019, SI020, SI021
CI024 BlueVoyant said Conquest Cyber added SaaS technology and FedRAMP Marketplace credentials for defense and government use cases. SI007, SI020
CI025 BlueVoyant said it had more than 900 global customers when Timothy Yost joined as CFO in June 2024. SI008
CI026 BlueVoyant framed the Timothy Yost hire as scaling the company's financial and strategic planning capability. SI008
CI027 BlueVoyant said it served over 1,000 customers in more than 45 countries by March 2025. SI009, SI026
CI028 BlueVoyant said local EMEA revenue grew 70% in 2024 and described Cork as part of a multi-million-euro regional investment program. SI009
CI029 BlueVoyant's commissioned Forrester MDR study claims 210% ROI over three years. SI010
CI030 The same MDR study claims a 90% reduction in total escalated alerts per month. SI010
CI031 The same MDR study claims a 70% acceleration in mean time to resolve. SI010
CI032 BlueVoyant's commissioned Supply Chain Defense study claims nearly 300% return on investment. SI011
CI033 The same Supply Chain Defense study claims a 62% reduction in time to remediate critical risks. SI011
CI034 BlueVoyant's Snappi case study says the customer achieved 24x7 SOC coverage within months instead of hiring across multiple vendors. SI012
CI035 BlueVoyant's ODEON case study says the deployment spans 8 countries and more than 280 cinemas. SI013
CI036 BlueVoyant's ODEON case study says the program cut alerts requiring InfoSec or regional IT review by 98%. SI013
CI037 BlueVoyant's ODEON case study says the program resolved 30 critical or high third-party vulnerabilities. SI013
CI038 BlueVoyant said Google Cloud Marketplace availability removes procurement friction for its TPRM offer. SI014
CI039 BlueVoyant's Microsoft-security ROI blog says an enterprise can spend up to $750,000 annually to optimize the stack internally. SI015
CI040 BlueVoyant's Sentinel deployment guide says its examples are drawn from hundreds of deployments and 16 anonymized case studies. SI016
CI041 Private Equity Insights reported that BlueVoyant intended to use Series D proceeds for product development and international expansion. SI022
CI042 CB Insights reported that BlueVoyant had raised $665.5 million over 9 rounds. SI023
CI043 CB Insights reported a $1.0 billion valuation in February 2022. SI023
CI044 CB Insights estimated BlueVoyant's 2024 revenue at $750 million, which conflicts with lower recurring-revenue estimates in other databases. SI023
CI045 GetLatka estimated BlueVoyant's 2025 revenue at $213.5 million. SI024
CI046 GetLatka estimated BlueVoyant employed about 650 people in 2025. SI024
CI047 Clay reported $665.5 million of total funding and a latest funding date of 2023-11-01. SI026
CI048 Clay reported 11 investors and over 1,000 customers across 45 countries. SI026
CI049 Dialectica listed BlueVoyant at 653 employees and named Liberty Strategic Capital as an investor. SI025
CI050 Tracxn reported $696 million of total funding across 6 rounds, conflicting with the $665.5 million totals cited by CB Insights and Clay. SI027
CI051 PitchBook's accessible snapshot showed 363 employees and a $30 million latest deal amount, conflicting with the 600-plus employee signals from later sources. SI028
CI052 PitchBook's accessible snapshot included a historical Debt - PPP financing entry dated 2020-04-27. SI028
CI053 Companies House shows BlueVoyant UK Limited filed full accounts for the year ended 2024 on 2025-09-30. SI029
CI054 Companies House shows a compulsory strike-off action against BlueVoyant UK Limited was discontinued in March 2025. SI029
CI055 Companies House shows BlueVoyant Ltd also filed full accounts for the year ended 2024 on 2025-09-30. SI030
CI056 An archived Indeed review described BlueVoyant as extremely top heavy with management. SI031
CI057 The same archived review alleged consistent bi-yearly layoffs and resource cuts across some business units. SI031
CI058 No retained public source verified current cash on hand, monthly burn, or runway as of 2026-06-29. SI001, SI002, SI006, SI007, SI008, SI009, SI023, SI024, SI026, SI027, SI028
CI059 No retained public source disclosed realized contract pricing, discounting, gross margin, NRR, or CAC payback for BlueVoyant. SI001, SI004, SI010, SI011, SI014, SI015, SI023, SI024, SI026
CI060 The public record supports a recurring managed-services model but does not reconcile the mix between software-like recurring revenue and project-based services. SI001, SI005, SI006, SI007, SI010, SI011, SI012, SI013
CI061 Using GetLatka's $213.5 million revenue estimate and Dialectica's 653-employee estimate implies roughly $327,000 of revenue per employee. SI024, SI025
CI062 Using the $665.5 million consensus total raised and GetLatka's $213.5 million revenue estimate implies cumulative funding of roughly 3.1x estimated annual revenue. SI024, SI026
CI063 BlueVoyant's current public financial signal set is too contradictory to underwrite revenue quality or runway without management data. SI023, SI024, SI025, SI026, SI027, SI028, SI029, SI030, SI031
CE001 BlueVoyant currently defines its customer-facing offer as Agentic SecOps, MDR, and TPRM that protect the full attack surface. SE001
CE002 BlueVoyant publicly advertises Microsoft-focused scale signals including 1,200-plus Sentinel deployments, 24x7 in-regional SOC monitoring, and named cost savings. SE001
CE003 The Cyber Defense Platform page organizes the portfolio into MDR, TPRM, DRP, and professional-services suites. SE002
CE004 BlueVoyant’s 2024 platform launch describes a single cloud-native platform integrating internal, external, and supply-chain defense. SE002, SE021
CE005 The platform is described as processing signals and alerts from internal networks, supply chains, and the clear, deep, and dark web. SE021, SE027
CE006 BlueVoyant AI says the company matches human expertise, deterministic automation, and AI agents to the mission rather than treating AI as a universal substitute. SE003, SE022
CE007 BlueVoyant AI is offered both as a fully managed service and as a SaaS platform for internal security teams. SE003, SE022
CE008 BlueVoyant AI publicly claims automated response actions including device isolation, credential revocation, and malicious-email eradication. SE022
CE009 BlueVoyant AI attributes its Microsoft advantage to almost ten years of operating experience and more than 2,500 Microsoft-native customer deployments. SE022
CE010 BlueVoyant MDR is marketed as protecting internal networks, cloud instances, containers, and endpoints while strengthening existing EDR, SIEM, and cloud-security tools. SE004
CE011 MDR for Microsoft and Continuous Optimization for Microsoft Solutions are first-class modules inside the MDR suite. SE004, SE006
CE012 BlueVoyant promises 24/7 detection and response across the full Microsoft security stack. SE005, SE031
CE013 The MDR for Microsoft page lists 2026 Data Security and Compliance Trailblazer recognition, 2024 Worldwide Security Partner of the Year, three-time US Security Partner of the Year, and MISA membership. SE005
CE014 BlueVoyant claims Microsoft Solutions Partner designations in Security, Infrastructure (Azure), and Modern Work plus security specializations in Cloud Security, Identity and Access Management, and Threat Protection. SE005
CE015 Continuous Optimization for Microsoft Solutions extends the offer into Sentinel, Defender, M365, and Purview configuration and optimization based on 1,000-plus engagements. SE006, SE007
CE016 BlueVoyant’s MDR for Microsoft collateral says customers can keep security data in their own environment instead of sending it to MSSP-owned infrastructure. SE031
CE017 The Microsoft collateral frames the service around Microsoft Sentinel and Microsoft 365 Defender as the core security stack. SE031
CE018 The MDR for Microsoft deployment playbook explicitly includes infrastructure setup, log-source ingestion, alert and SOAR configuration, knowledge transfer, and initial alert tuning. SE031
CE019 BlueVoyant describes TPRM as a fully managed solution that identifies, validates, and resolves critical cybersecurity issues in a third-party ecosystem. SE008
CE020 BlueVoyant’s TPRM suite includes continuous monitoring and remediation, questionnaire management, point-in-time risk assessments, and vendor consulting. SE008, SE015
CE021 The continuous-monitoring workflow says Risk Operations Center analysts validate findings and work directly with third parties on remediation. SE009
CE022 BlueVoyant says its business-risk monitoring uses AI and machine learning across more than 50,000 data sources and eight risk categories. SE009
CE023 The questionnaire-management module automates assessment creation and distribution while validating supplier statements against observed performance. SE010
CE024 BlueVoyant’s 2023 supply-chain expansion added multi-tier continuous monitoring, questionnaire workflows, point-in-time assessments, rapid zero-day alerting, and advisory workshops. SE015, SE023
CE025 BlueVoyant positions DRP as protection against threats emerging from the clear, deep, and dark web before they affect the business or customers. SE011
CE026 BlueVoyant’s DRP modules are Brand Protection, Dark Web Watcher, and Executive Cyber Guard. SE011
CE027 Brand Protection covers web, social-media, and app impersonation with unlimited takedowns and monitoring across more than 300 official and unofficial app stores. SE012
CE028 Dark Web Watcher monitors underground communities for fraud campaigns, sold credentials, and data leakage. SE013
CE029 Executive Cyber Guard focuses on executive-data exposure, stolen credentials, and account-takeover prevention for high-value individuals. SE014
CE030 BlueVoyant’s differentiated product story is convergence: Microsoft-centric MDR on the inside, TPRM across the supply chain, and DRP on the external attack surface under one operating model. SE002, SE004, SE008, SE011
CE031 The Trust Center describes BlueVoyant as a cloud-native security-operations platform combining advanced AI with expert human insight across networks, endpoints, supply chains, and web or dark-web monitoring. SE017
CE032 The Trust Center says BlueVoyant is trusted by more than 1,000 clients globally. SE017
CE033 Conquest Cyber adds SaaS technology that unifies security posture, compliance, detection, and response through a risk-maturity lens. SE016, SE024
CE034 BlueVoyant planned to integrate Conquest technology into existing products and services to create internal and external cyber defense mapped to risk maturity. SE016, SE024
CE035 Conquest brought DIB and government credentials, CMMC RPO accreditation, FedRAMP-marketplace presence for ARMED ATK, and additional Microsoft security capabilities into BlueVoyant’s platform story. SE016, SE024
CE036 Public GitHub evidence shows only one visible BlueVoyant repository, BV-Security-Copilot, with the public pages pointing to a September 22, 2025 update. SE018, SE019, SE020
CE037 The visible BlueVoyant GitHub repo is framed as public content for Copilot for Security, implying limited open-source transparency relative to the breadth of the marketed platform. SE020
CE038 Microsoft Learn records a BlueVoyant Shadow Hunter Microsoft Security Immersion Workshop, showing practitioner-facing Microsoft training activity beyond static marketing pages. SE032
CE039 Gartner’s DRP page surfaces a favorable review headline that still notes occasional takedown challenges, signaling that takedown execution remains a real operational risk area. SE029
CE040 A 2019 Spiceworks thread shows buyer skepticism that BlueVoyant was a startup relying on established tools such as Splunk, highlighting a long-running diligence question about proprietary depth versus service orchestration. SE030
CE041 PeerSpot describes BlueVoyant CORE as a combined MDR, digital-risk-protection, and supply-chain-defense suite backed by 24/7 monitoring and machine learning. SE025
CE042 Cyber Magazine independently described the 2024 launch as a cloud-native platform specifically aimed at the supplier-driven attack surface. SE026
CE043 BlueVoyant publicly reports a 99 percent website-takedown success rate, a 95 percent social-media-takedown success rate, and a 23-hour median server-level takedown time for DRP. SE001
CU001 BlueVoyant’s visible customer base skews toward regulated or operationally complex organizations rather than broad SMB self-serve buyers. SU001, SU002, SU003, SU005, SU014, SU019
CU002 The deepest named public proofs span state government, federal defense supply chains, digital banking, capital-markets infrastructure, and multinational entertainment operations. SU001, SU002, SU003, SU005, SU019
CU003 Public financial-services proof is concentrated in Snappi, Beeks, ClearBank, and sector-specific Microsoft content rather than a long named roster of banks or insurers. SU003, SU005, SU006, SU014, SU026
CU004 Public-sector proof is concentrated in California OIS, NAVSEA, and Carahsoft-enabled procurement routes rather than a broad public list of named agencies. SU001, SU013, SU019, SU024, SU030, SU031
CU005 California OIS launched a cloud-based SOCaaS that integrated Microsoft Security with BlueVoyant’s MDR for Microsoft. SU001
CU006 BlueVoyant’s California case study says the program reduced mean time to detect by 70 percent. SU001
CU007 BlueVoyant’s California case study says the program reduced mean time to respond by 60 percent. SU001
CU008 BlueVoyant’s California case study says participating entities saved about $2.1 million in annual personnel costs. SU001
CU009 California’s Department of Technology said in June 2025 that SOCaaS protected 112 public-sector organizations and had produced more than $54 million of combined savings. SU037
CU010 California CDT describes SOCaaS as a 24/7 continuous-monitoring service used to satisfy statewide monitoring requirements. SU036, SU037
CU011 ODEON Cinemas Group runs more than 280 cinemas across eight countries. SU002, SU033
CU012 ODEON’s public materials describe nearly 50 log sources and a previously fragmented, noisy security setup before BlueVoyant’s engagement. SU002, SU033
CU013 BlueVoyant migrated ODEON to Microsoft Sentinel, onboarded MDR for Microsoft, and added DFIR plus third-party risk management. SU002, SU033
CU014 ODEON’s case-study materials report a 98 percent reduction in alerts requiring review. SU002, SU033
CU015 ODEON’s BlueVoyant case study reports 30 critical or high third-party vulnerabilities resolved. SU002
CU016 Independent coverage quotes ODEON saying monthly alerts fell from hundreds to roughly 6 to 12 tickets. SU033
CU017 Snappi is described in multiple public sources as Greece’s first ECB-licensed neobank. SU003, SU034, SU035
CU018 Snappi used BlueVoyant and Veracloud to implement 24/7 SOC coverage, MDR, dark-web monitoring, and incident-response readiness within months of launch. SU003, SU034, SU035
CU019 Snappi’s public proof emphasizes board visibility, monthly SOC KPI reporting, tabletop exercises, and DORA readiness rather than conventional revenue or usage metrics. SU003, SU034
CU020 Beeks says BlueVoyant now supports a 24x7 end-to-end SOC for a platform serving capital-markets and financial-services customers. SU005, SU026
CU021 Beeks says BlueVoyant lowered alert fatigue, reduced data-ingestion costs, and was operational in less than three months. SU005, SU026
CU022 Beeks positions the partnership as a customer-acquisition differentiator because its own clients ask about cyber resilience. SU005, SU026
CU023 NAVSEA awarded a three-year Phase III contract and delivery orders to BlueVoyant Government Solutions for industrial-base resilience and supply-chain illumination work. SU019, SU020
CU024 BlueVoyant Government Solutions said in April 2025 that its SCD-G platform had been added to Carahsoft’s SCRIPTS BPA vehicle. SU031
CU025 BlueVoyant Government Solutions said its platform currently identifies critical risks for more than 4 million suppliers. SU031
CU026 Carahsoft distributes BlueVoyant through SEWP V, ITES-SW2, NASPO ValuePoint, and California CMAS procurement routes. SU024, SU030
CU027 BlueVoyant’s partner program offers co-selling, training, account support, and marketing tooling across channel, tech-alliance, and OEM relationships. SU004
CU028 Carahsoft says its reseller ecosystem includes more than 10,000 government contractors, VARs, solution providers, integrators, and MSPs. SU032
CU029 AWS Marketplace shows BlueVoyant selling a private-offer MDR service with 24x7 SOC support. SU025
CU030 BlueVoyant’s public financial-services evidence includes named work with Snappi, Beeks, and ClearBank plus sector materials featuring Fiserv and JP Morgan participants. SU003, SU005, SU006, SU008, SU014, SU026
CU031 BlueVoyant’s public government evidence includes California SOCaaS, NAVSEA supply-chain work, Carahsoft distribution, and contract-vehicle access. SU001, SU019, SU024, SU030, SU031, SU037
CU032 BlueVoyant actively markets to energy and legal buyers, but the reviewed corpus does not show equally deep named production proofs for those sectors. SU015, SU016
CU033 BlueVoyant’s 2024 MDR TEI summary claims 210 percent three-year ROI, 90 percent fewer escalated alerts per month, and 70 percent faster mean time to resolve for a composite customer. SU017
CU034 BlueVoyant’s supply-chain-defense TEI summary claims nearly 300 percent ROI, 65 percent better monitoring efficiency, 70 percent fewer suppliers above risk threshold, and 60 percent faster remediation of critical risks. SU011
CU035 BlueVoyant’s 2025 supply-chain survey says it captured 1,800 executives across financial services, healthcare, pharma, utilities, energy, retail, manufacturing, and defense. SU012
CU036 BlueVoyant said in May 2025 that it was trusted by more than 1,000 clients globally and had guided thousands of clients on Microsoft Security. SU018
CU037 FeaturedCustomers shows BlueVoyant with 9 reviews, 5 case studies, and a 4.7 out of 5 reference rating across 133 total customer references. SU021, SU022
CU038 PeerSpot describes BlueVoyant deployments across finance, healthcare, and manufacturing and says licensing typically includes annual or multi-year agreements. SU023
CU039 The reviewed AWS Marketplace and Slashdot pages both show zero visible customer ratings or reviews for BlueVoyant. SU025, SU029
CU040 None of the reviewed public customer sources disclose NRR, GRR, churn, or cohort renewal performance. SU001, SU002, SU003, SU005, SU014, SU021, SU022, SU023
CU041 None of the reviewed public customer sources break out top-customer concentration or contract-duration exposure by revenue. SU001, SU002, SU003, SU005, SU014, SU019, SU021, SU023
CU042 The strongest public outcomes cluster around Microsoft-centered operations, managed detection and response, and supply-chain risk use cases rather than broad attach-rate disclosure across all product lines. SU001, SU002, SU003, SU005, SU014, SU017, SU031
CU043 Most quantified customer proof is vendor-authored or partner-authored rather than independently audited, so deployment outcomes are visible but durability evidence remains thin. SU001, SU002, SU003, SU005, SU022, SU028, SU029, SU033, SU034
CR001 BlueVoyant markets itself as a Microsoft security specialist across Sentinel, Defender, Purview, and Copilot-readiness work. SR002, SR003
CR002 BlueVoyant says its MDR for Microsoft offer combines BlueVoyant AI with an elite 24x7 SOC and security operations team. SR003, SR018
CR003 BlueVoyant says it works with Microsoft product teams on Sentinel scenarios, operations feedback, API extensibility, and Security Copilot agents. SR013, SR028
CR004 BlueVoyant says it won the 2024 Microsoft Worldwide Security Partner of the Year Award and additional U.S. and Canada security partner awards. SR010, SR014
CR005 BlueVoyant and Micah Heaton were recognized in the 2025 Microsoft Security Excellence Awards as Security Trailblazer and Security Changemaker winners. SR009, SR017, SR027
CR006 BlueVoyant’s Sentinel eBook says it summarizes 16 anonymized case studies drawn from hundreds of hands-on Microsoft Sentinel deployments. SR033
CR007 Protiviti describes BlueVoyant’s Microsoft offering as combining advanced AI with expert human insight in a joint services stack. SR018
CR008 BlueVoyant launched BlueVoyant AI on 2026-06-09 as an AI-native Agentic SecOps platform. SR004, SR032
CR009 BlueVoyant AI is offered in both fully managed and enterprise SaaS deployment models. SR004, SR032
CR010 BlueVoyant says its AI workflows keep humans at the center of the strategy even when automated response actions occur at machine speed. SR004, SR032
CR011 BlueVoyant’s Cork SOC announcement says the site provides 24x7 monitoring for Irish and EU clients. SR008, SR015
CR012 BlueVoyant links its Cork expansion to NIS2 and DORA-driven customer demand and says local revenue grew 70% in 2024. SR008, SR015
CR013 BlueVoyant changed CEOs in May 2026 when John Hernandez succeeded co-founder Jim Rosenthal. SR006
CR014 BlueVoyant’s 2023 CPO appointment was framed as a move to unify product lines and expand share in cybersecurity. SR007
CR015 BlueVoyant’s privacy notice says BlueVoyant LLC is the controller of personal data collected through its website. SR001
CR016 BlueVoyant’s privacy notice says personal information may be shared with affiliate companies unless prohibited by law or other regulatory requirements. SR001
CR017 PacerMonitor shows Steward Health filed an adversary complaint against Bluevoyant LLC in July 2025. SR020
CR018 The public Steward docket describes avoidance and recovery claims under bankruptcy preference and fraudulent-transfer theories. SR020
CR019 The DoD CIO CMMC page says Phase 1 implementation runs from 2025-11-10 to 2026-11-09 and focuses on Level 1 and Level 2 self-assessments. SR022, SR023
CR020 The DoD CIO CMMC page reminds contractors to submit affirmations with CMMC assessments in SPRS. SR022
CR021 The DoD CMMC 2.0 page says contracting officers now include the new CMMC requirements in new solicitations and contracts. SR023
CR022 NIST SP 800-171 says its security requirements are intended for use in contractual vehicles and agreements between federal agencies and nonfederal organizations handling CUI. SR021
CR023 BlueVoyant Government Solutions markets supply-chain visibility and expert-led threat remediation at scale for mission assurance. SR011
CR024 BlueVoyant’s government customer page targets intelligence, federal civilian, acquisition, cybersecurity, and supply-chain risk-management use cases. SR012
CR025 Carahsoft lists BlueVoyant on NASA SEWP V through 2026-09-30. SR019
CR026 Carahsoft also lists ITES-SW2 through 2030-08-30 and SCRIPTS BPA through 2030-03-30 for BlueVoyant. SR019
CR027 Pavilion says BlueVoyant Government Solutions includes CMMC and NIST 800-171 compliance management. SR029
CR028 SAM.gov says contract-award search now supports filtering by keyword, agency, and legal business name. SR030
CR029 USAspending says it is the official open data source for federal awards, including contracts, grants, and loans. SR031
CR030 BlueVoyant said it raised more than $140 million in Series E funding to support the Conquest Cyber acquisition. SR005
CR031 BlueVoyant said Conquest Cyber had traction in the U.S. Defense Industrial Base and government organizations. SR005
CR032 PM Insights exposes only delayed preview data and gated institutional datasets for BlueVoyant valuation, secondary activity, and cap-table details. SR024
CR033 SourceForge presents BlueVoyant alongside many alternative cyber platforms in 2026, underscoring a crowded competitive set. SR025
CR034 PeerSpot describes BlueVoyant as spanning MDR, digital risk protection, and supply-chain defense with advanced analytics and a 24x7 SOC. SR026
CR035 Microsoft’s 2021 security blog framed customer need around tech sprawl and positioned BlueVoyant as an optimizer of Microsoft security services. SR016
CR036 Finance Yahoo and PR Newswire say BlueVoyant is building analytics, playbooks, hunting queries, notebooks, and Security Copilot agents on top of Sentinel. SR013, SR028
CR037 BlueVoyant’s Microsoft page markets cost-of-adoption assessments for Sentinel, Defender for Cloud, Microsoft 365 E5, data security, and Copilot readiness. SR002
CR038 BlueVoyant’s Sentinel eBook says customers use the company to optimize costs and migrate from other SIEMs. SR033
CR039 BlueVoyant’s Gartner-market-guide blog cites rising third-party breach pressure and presents AI-driven assessment plus expert remediation as its TPRM answer. SR034
CR040 Independent coverage of the BlueVoyant AI launch repeats the company’s claim that the platform delivers autonomous speed, precision, and control at scale. SR032
CR041 BlueVoyant’s 2024 Microsoft award release says the company’s Microsoft customer base has grown over the past three years. SR010, SR014
CR042 Microsoft’s 2025 awards page independently confirms BlueVoyant was among recognized security-ecosystem winners. SR017
CR043 Protiviti says it and BlueVoyant jointly deliver Microsoft security, compliance, and identity solutions. SR018
CR044 The PR Newswire UK Cork release says BlueVoyant’s EMEA build-out reflects a multi-million-Euro investment since 2017. SR015
CR045 BlueVoyant’s Cork release says the company had local employees in Ireland before opening the permanent office. SR008
CR046 BlueVoyant’s go-to-market and product differentiation are tightly coupled to Microsoft roadmap, pricing, and channel behavior. SR002, SR003, SR013, SR028
CR047 The shift from managed MDR into agentic SOC software increases execution complexity around packaging, pricing, support, and quality control. SR004, SR006, SR007, SR032
CR048 BlueVoyant’s public-sector motion is compliance-gated because the company markets CMMC and NIST support while DoD rules are now flowing into contracts. SR021, SR022, SR023, SR027, SR029
CR049 Public-sector concentration is material but still unquantified because contract vehicles are visible while agency-level award mix and renewal concentration are not publicly disclosed. SR019, SR030, SR031
CR050 The Steward complaint is the clearest company-specific adverse signal in the public record and should be diligenced for amount, defenses, and insurance coverage. SR020
CR051 Competitive risk is elevated because BlueVoyant competes at once in Microsoft services, MDR, TPRM, and supply-chain defense against more specialized vendors. SR025, SR026, SR034
CR052 Financing risk remains material because the public file shows a 2023 private raise and gated secondary-market previews, but not current ARR, runway, or valuation terms. SR005, SR024
CR053 The highest-likelihood near-term risks are Microsoft-feature dependence and managed-service staffing drift because both sit inside BlueVoyant’s daily delivery loop. SR003, SR008, SR013, SR018
CR054 The highest-impact downside risks are compliance slippage, financing opacity, and any legal escalation because those could impair growth or capital access quickly. SR020, SR022, SR023, SR024
CR055 If Microsoft economics worsen or BlueVoyant AI underdelivers, BlueVoyant would likely feel the damage first in customer ROI and renewal confidence before financing flexibility changes. SR003, SR004, SR013, SR024
CR056 Missing public metrics on SLA attainment, MTTR, analyst-to-customer ratios, agency concentration, and capital structure reduce confidence in residual-risk scoring. SR024, SR030, SR031
CV001 BlueVoyant announced on November 29, 2023 that it raised more than $140 million to accompany its acquisition of Conquest Cyber. SV002, SV032
CV002 BlueVoyant said Liberty Strategic Capital and ISTARI led the November 2023 funding round. SV002, SV032
CV003 BlueVoyant's February 23, 2022 Series D raised $250 million. SV003, SV011
CV004 BlueVoyant named Liberty Strategic Capital, ISTARI, Eden Global Partners, and 8VC as participants in the Series D round. SV003, SV011, SV008
CV005 Caplight currently shows BlueVoyant's last round as Series E on November 29, 2023 with an estimated valuation of $1 billion. SV004
CV006 Forge shows BlueVoyant's last known valuation as $1 billion dated February 23, 2022. SV006
CV007 Caplight, CB Insights, and GetLatka each report BlueVoyant total funding at $665.5 million. SV004, SV009, SV027
CV008 Tracxn reports BlueVoyant total funding at $696 million across six rounds. SV008
CV009 CB Insights classifies BlueVoyant as Series E | Alive and lists the last raise as $140 million. SV027
CV010 The SEC browse result for BlueVoyant shows Form D notices dated 2017-08-04, 2019-04-25, and 2020-07-08. SV012
CV011 The retained SEC browse result does not surface later BlueVoyant financing filings, leaving the 2022 and 2023 round terms undisclosed in public filing search results. SV012
CV012 BlueVoyant's February 2023 growth release said the company had more than 900 clients in 40-plus countries and nearly 1,000 clients globally. SV001
CV013 BlueVoyant's February 2023 growth release said recurring revenue grew 80% in 2022 and 108% on average since 2018. SV001
CV014 GetLatka estimates BlueVoyant's 2025 revenue at $213.5 million and employee count at about 650. SV009
CV015 BlueVoyant's public materials position the company around MDR, TPRM, digital risk protection, and professional services on one platform. SV001, SV010
CV016 Caplight tags BlueVoyant with MDR, third-party risk management, SOC-as-a-Service, supply chain risk management, and digital risk protection keywords. SV004
CV017 Notice titles BlueVoyant at $1.36 per share. SV005
CV018 Notice's page markup shows the current Notice Price at a 39% discount to the last round. SV005
CV019 Forge labels BlueVoyant market activity as limited and shows no Forge Price. SV006
CV020 Hiive's page data shows no daily price history and sets displayChart to false for BlueVoyant. SV007
CV021 PM Insights' public preview exposes sections for secondary-market ROI, bid-ask ratios, mutual-fund NAV, and cap-table details, but not the underlying numbers. SV026
CV022 Windsor Drake says the public cybersecurity median trades at roughly 6.0x to 6.5x NTM revenue in Q2 2026. SV018
CV023 Windsor Drake says managed security services compress to roughly 3x to 5x revenue in 2026. SV018
CV024 Tablestat shows median enterprise cybersecurity EV/revenue at 8.4x for 2025E and 6.8x for 2026E. SV020
CV025 CrowdStrike trades at 34.30x EV/revenue on 5.09B of trailing revenue and about 178.47B of market cap. SV013, SV021
CV026 Palo Alto Networks trades at 23.28x EV/revenue on 10.61B of trailing revenue and about 247.92B of market cap. SV028, SV030
CV027 Fortinet trades at 15.20x EV/revenue on 7.11B of trailing revenue and about 110.88B of market cap. SV029, SV031
CV028 SentinelOne trades at 4.61x EV/revenue on 1.05B of trailing revenue and about 5.45B of market cap. SV014, SV022
CV029 Qualys trades at 5.73x EV/revenue on 684.86M of trailing revenue and about 4.34B of market cap. SV017, SV025
CV030 Tenable trades at 3.32x EV/revenue on 1.02B of trailing revenue and about 3.33B of market cap. SV016, SV024
CV031 Rapid7 trades at 0.93x EV/revenue on 859.23M of trailing revenue and about 508.58M of market cap. SV015, SV023
CV032 multiples.vc describes CrowdStrike and SentinelOne as security-operations platforms and Rapid7, Qualys, and Tenable as exposure, XDR/SIEM, and compliance platforms, supporting their use as BlueVoyant comparables. SV019
CV033 BlueVoyant's homepage advertises 24x7 in-region SOC monitoring, 1,200-plus Microsoft Sentinel deployments, and 1,600-plus vulnerabilities remediated in the last 30 days. SV010
CV034 A $1 billion valuation on the $213.5 million ARR proxy implies roughly 4.7x ARR. SV004, SV009
CV035 A 4.7x ARR multiple sits below the 2026 public cyber median and near SentinelOne, Qualys, and Tenable. SV018, SV022, SV024, SV025
CV036 Because BlueVoyant mixes software with managed services and professional services, it should not command CrowdStrike-, Palo Alto-, or Fortinet-level software multiples without disclosed margin proof. SV010, SV018, SV020
CV037 The bull thesis rests on real scale, broad cyber-risk product breadth, and historical triple-digit recurring-revenue growth. SV001, SV010, SV032
CV038 The clearest anti-thesis is that public secondary data show a 39% discount, limited visible liquidity, and no obvious public valuation step-up after 2022. SV004, SV005, SV006
CV039 Caplight still showing a $1 billion estimate and Forge still showing a $1 billion last-known mark suggest no public upward valuation reset despite the 2023 Series E. SV004, SV006
CV040 Public sources disagree on exact capital raised, ranging from $665.5 million to $696 million, which signals data-room opacity rather than a clean public funding ledger. SV004, SV008, SV027
CV041 A base-case valuation band of roughly $0.85 billion to $1.1 billion is supportable by applying 4.0x to 5.0x to the $213.5 million ARR proxy. SV009, SV018, SV022
CV042 An upside range of roughly $1.2 billion to $1.5 billion requires sustained growth and a mix shift toward higher-margin platform revenue that would justify 5.5x to 7.0x multiples. SV018, SV020, SV028, SV029
CV043 A downside range of roughly $0.6 billion to $0.8 billion is consistent with the Notice discount to the last round and the managed-security/services range. SV005, SV018
CV044 The public evidence does not support a buy call because downside is observable in secondary signals while the upside case still depends on undisclosed margin, retention, and share-count data. SV005, SV006, SV012, SV026
CV045 BlueVoyant is large enough and strategically relevant enough that the correct recommendation is research-more rather than avoid. SV001, SV010, SV032
CV046 Confidence should be medium because the multiple work is directionally coherent, but the core ARR and liquidity inputs come from third-party datasets rather than audited disclosure. SV009, SV026, SV027
CV047 Risk rating should remain high because private-market liquidity appears thin and the current mark could compress if growth or margin quality undershoots. SV005, SV006, SV007
CV048 Valuation stance is fair rather than attractive because the $1 billion mark can be justified on the ARR proxy but leaves limited margin of safety against secondary discounts. SV005, SV009, SV018, SV022
CV049 Hiive states that BlueVoyant remains privately held and pre-IPO access is limited to accredited investors via secondary marketplaces. SV007
CV050 The highest-value diligence asks are current ARR and gross-margin mix, cap table and share count, actual secondary-clearing prices, and confirmation of any post-2023 financing terms. SV007, SV012, SV026, SV027
来源
编号出版方标题引文
SO001 BlueVoyant Company Founded in 2017... Headquartered in New York City, the company has over 600 employees... spanning five continents.
SO002 BlueVoyant Leadership
SO003 BlueVoyant Contact Us More Than 1,000 Customers in 45 Countries
SO004 BlueVoyant BlueVoyant Cyber Defense Platform
SO005 BlueVoyant Managed Detection & Response
SO006 BlueVoyant Third-Party Risk Management (TPRM)
SO007 BlueVoyant Partners
SO008 BlueVoyant BlueVoyant & Microsoft
SO009 BlueVoyant Awards
SO010 BlueVoyant Careers
SO011 BlueVoyant Born in the SOC, Not in a Lab | Webinar
SO012 BlueVoyant Next Era of Cyber Defense with BlueVoyant AI BlueVoyant today announced BlueVoyant AI, an innovative Agentic SecOps platform that fundamentally redefines how modern enterprises prevent, detect, investigate, and stop cyber threats.
SO013 BlueVoyant BlueVoyant Raises $250 Million Series D Led by Liberty Strategic Capital Liberty Strategic Capital... led the $250-million round with participation from... ISTARI... Eden Global Partners... and 8VC.
SO014 BlueVoyant BlueVoyant and Auto-ISAC Partner to Elevate TPRM in Automotive
SO015 BlueVoyant BlueVoyant Welcomes Michael Montoya as COO Michael Montoya has joined the company as Chief Operating Officer (COO)... overseeing the technology, product, and operations organizations.
SO016 PR Newswire John Hernandez Joins BlueVoyant as CEO to Accelerate AI-Driven Cybersecurity Platform and Global Growth John Hernandez will succeed Jim Rosenthal as Chief Executive Officer (CEO).
SO017 PR Newswire Liberty Strategic Capital Leads Investment Round in BlueVoyant, an Industry-Leading Cyber Defense Platform
SO018 PR Newswire BlueVoyant Acquires Conquest Cyber to Meet Market Need for Comprehensive Managed Detection and Response and Cyber Risk Posture Solutions
SO019 PR Newswire BlueVoyant and Auto-ISAC Partner to Elevate Third-Party Cyber Risk Management Across the Automotive Industry
SO020 TechCrunch BlueVoyant nabs $250M to help enterprises nab malicious hackers and stop security breaches
SO021 SecurityWeek BlueVoyant Raises $250 Million to Boost Technical Capabilities, Global Expansion
SO022 CRN BlueVoyant Acquires Conquest Cyber In Deal That Reshapes Microsoft Security Landscape
SO023 GovCon Wire BlueVoyant Purchases Conquest Cyber, Raises Over $140M in Series E Funding Round
SO024 BankInfoSecurity BlueVoyant Raises $140M, Buys Resilience Firm Conquest Cyber
SO025 iTWire BlueVoyant Ignites the Next Era of Cyber Defence with Launch of BlueVoyant AI
SO026 UK Tech News BlueVoyant Ignites the Next Era of Cyber Defence with Launch of BlueVoyant AI
SO027 Enterprise IT World BlueVoyant Appoints John Hernandez as CEO to Drive AI-Led Cybersecurity Growth
SO028 Unify Employee Data and Trends for Bluevoyant
SO029 GetLatka BlueVoyant Revenue 2025: $213.5M ARR, $1B Valuation
SO030 Caplight BlueVoyant | Valuation, Funding Rounds & Stock Price
SO031 UpGuard BlueVoyant Security Rating, Vendor Risk Report, and Data Breaches The Content Security Policy is implemented with unsafe-eval, reducing protection against XSS attacks.
SO032 Cyber Insurance News BlueVoyant Warns Supply Chain Breaches Soar as Cyber Liability Insurance Requirements Shape Risk Strategy
SO033 The SaaS News BlueVoyant Raises $140 Million in Series E
SM001 BlueVoyant Managed Detection & Response Protect your internal network, cloud instances, containers, and endpoints from unknown threat actors, and strengthen your utilization of existing EDR, SIEM, and cloud security tools.
SM002 BlueVoyant Third-Party Risk Management (TPRM) BlueVoyant Third-Party Risk Management (TPRM) is a fully managed solution that identifies, validates, and resolves critical cybersecurity issues in your third-party ecosystem.
SM003 BlueVoyant Continuous Monitoring & Remediation
SM004 BlueVoyant AI-Driven Cyber Defense
SM005 BlueVoyant Fourth-Party Identification and Analytics
SM006 Precedence Research Managed Detection and Response (MDR) Market Size to Hit USD 13.90 Bn by 2035
SM007 Mordor Intelligence Managed Detection and Response Market Size & Trends, 2031
SM008 The Business Research Company Managed Detection And Response Market Insights 2026 to 2035
SM009 Grand View Research Third-party Risk Management Market Size Report, 2030
SM010 Next Move Strategy Consulting Third-Party Risk Management Market Analysis | 2025-2030
SM011 The Business Research Company Third-party Risk Management Market Growth Report 2026
SM012 KPMG The 2026 KPMG Global Third-Party Risk Management Survey This is not the time for incremental improvements or fragmented approaches.
SM013 Marsh Rising third-party risks and persistent ransomware threats drive increased cybersecurity investments in 2026 | Marsh 70% of organizations experienced at least one material third-party cyber incident in the past year.
SM014 Panorays 200 CISOs Reveal the Truth About Third-Party Cyber Risk 85% of CISOs surveyed admitted they do not have full visibility across their entire supply chain.
SM015 National Institute of Standards and Technology Cybersecurity Framework
SM016 Securities and Exchange Commission Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure For domestic registrants, this disclosure must be filed on Form 8-K within four business days of determining that a cybersecurity incident is material.
SM017 European Commission NIS2 Directive: securing network and information systems The NIS2 Directive establishes a unified legal framework to uphold cybersecurity in 18 critical sectors across the EU.
SM018 Gartner Gartner Identifies the Top Cybersecurity Trends for 2026 The chaotic rise of AI, geopolitical tensions, regulatory volatility and an accelerating threat landscape are the driving forces behind the top cybersecurity trends for 2026.
SM019 CyberProof Mapping the Managed Detection and Response (MDR) Market for 2026 Gartner has cautioned that many providers misusing the “MDR” label offer only tool-centric monitoring (e.g. managed EDR) without the critical human analysis and incident response leadership.
SM020 Mordor Intelligence GRC Software Market Size, Share & 2031 Growth Trends Report
SM021 Black Kite 2026 Third-Party Breach Report | Black Kite Supply Chain Risk Data For every single vendor breached, an average of 5.28 downstream companies were publicly compromised.
SM022 CRC Group 2026 Cyber + Technology State of the Market at a Glance
SM023 Cybersecurity and Infrastructure Security Agency Information and Communications Technology Supply Chain Risk Management | CISA If vulnerabilities in the ICT supply chain—composed of hardware, software, and managed services from third-party vendors, suppliers, service providers, and contractors—are exploited, the consequences can affect all users of that technology or service.
SM024 Cybersecurity and Infrastructure Security Agency ICT Supply Chain Risk Management Task Force | CISA The ICT SCRM Task Force—a public-private partnership charged with identifying challenges and developing actionable solutions to enhance global ICT supply chain resilience.
SM025 PeerSpot Top Rated Managed Detection and Response (MDR) Vendors
SP001 BlueVoyant MDR, TPRM, Digital Risk Protection | BlueVoyant Agentic SecOps, MDR, and TPRM to protect your entire attack surface.
SP002 BlueVoyant Company Founded in 2017... the company has over 600 employees across offices... spanning five continents.
SP003 BlueVoyant Managed Detection & Response 50+ certified Microsoft Delivery & SOC Engineers
SP004 BlueVoyant Government Solutions BlueVoyant Government Solutions | Supply Chain Defense BlueVoyant Government Solutions operationalizes mission assurance with deep supply chain risk visibility and expert-led threat remediation at scale.
SP005 BlueVoyant Government Solutions Products More than 70,000 unique proprietary, open-source, and commercially-available data feeds
SP006 PR Newswire BlueVoyant Ignites the Next Era of Cyber Defense with Launch of BlueVoyant AI BlueVoyant AI provides both with its fully managed service... or as an enterprise-grade SaaS platform.
SP007 Palo Alto Networks Explore Cortex XSIAM Security Analytics Every SOC capability on one platform.
SP008 Palo Alto Networks About Us 16K+ Employees | 70K+ Customers Globally | ~$100B Market Cap
SP009 CrowdStrike 24/7 Expert Protection | CrowdStrike Falcon® Complete Next-Gen MDR 1min Median time-to-contain (MTTC)
SP010 Arctic Wolf Managed Detection and Response (MDR) | Arctic Wolf The SOC uses trusted datasets drawn from 14+ years of security operations and insights from 10,000+ global customers, and 1,000+ security engineers.
SP011 Arctic Wolf A Higher Standard of Security Operations | Arctic Wolf Trusted by over 10,000 customers worldwide
SP012 Arctic Wolf Why Arctic Wolf? As the pioneer of the first open XDR platform that makes security work, the Aurora® Superintelligence Platform leverages AI to enable cyber defense at an unprecedented capacity and scale.
SP013 Rapid7 About Rapid7 - Cybersecurity Company Rapid7 unifies exposure and detection to transform the cybersecurity operations of more than 11,500 customers worldwide.
SP014 Rapid7 Incident Command: AI Powered Next-Gen SIEM | Rapid7 Incident Command delivers a new standard for detection and response built for scale, speed, and clarity across your entire threat landscape.
SP015 ReliaQuest About Us ReliaQuest exists to Make Security Possible, allowing enterprise security teams to detect, contain and respond to threats within minutes—anytime, anywhere—using the GreyMatter agentic AI security operations platform.
SP016 ReliaQuest Home | ReliaQuest GreyMatter: The Agentic AI Security Operations Platform for Agentic Defense 50K+ alerts processed daily; 255+ Technology Partners with security technologies; 99.4% accuracy of AI investigations.
SP017 ReliaQuest ReliaQuest GreyMatter Integrations: Your Environment + Agentic AI Powered Security Operations Your environment + agentic AI powered security operations
SP018 eSentire Managed Detection and Response Services & Security Operations Platform Protecting 2,000+ Customers Across 35+ Industries
SP019 eSentire XDR Extended Detection & Response Solutions Our distributed platform easily integrates with your existing security investments.
SP020 eSentire eSentire MDR vs the Competition The Atlas Platform connects to ANY SIGNAL, whether that's Endpoint, Network, Logs, Cloud, Vulnerability scanner, Browser, or Identity provider.
SP021 SecurityScorecard SecurityScorecard | Supply Chain & Third-Party Risk Platform The world’s first AI-powered platform for continuous, threat-informed third-party risk management
SP022 SecurityScorecard Company - SecurityScorecard 3,300+ global organizations... 12M+ organizations monitored and rated
SP023 SecurityScorecard Third-Party Risk Management (TPRM) | SecurityScorecard Validate Questionnaires with Technical Ground Truth
SP024 Bitsight Cyber Risk Intelligence Platform A dynamic map of assets and vulnerabilities, prioritized by real-time threat intelligence, across your enterprise and supply chain.
SP025 Bitsight Third Party Risk Management Solutions 75K+ Mapped vendor profiles in the Bitsight Vendor Network
SP026 Bitsight Bitsight Named a Leader in Cybersecurity Risk Ratings, Praised By Customers for the Utility of its Data | Bitsight With more than 3,500 customers and over 68,000 organizations active on its platform
SP027 Gartner Peer Insights Best Managed Detection and Response Reviews 2026 | Gartner Peer Insights MDR offers outcome-driven security incident management... and the delivery of active threat disruption and containment actions.
SP028 PeerSpot BlueVoyant CORE Reviews, Competitors and Pricing As of June 2026, the mindshare of BlueVoyant CORE in the Managed Detection and Response (MDR) category stands at 0.9%, down from 1.2% compared to the previous year.
SP029 PeerSpot Compare BlueVoyant CORE vs CrowdStrike Falcon Complete MDR BlueVoyant is ranked #34, while CrowdStrike is ranked #2... BlueVoyant holds a 0.9% mindshare in MDR, compared to CrowdStrike’s 5.4% mindshare.
SP030 Ciphers Security Best Vendor Risk Management Platforms In 2026 Two fundamentally different approaches dominate this market... Security ratings platforms... assess vendors from the outside in.
SP031 Decryption Digest Best MDR Services 2026: CrowdStrike vs Arctic Wolf vs Huntress Compared MSSPs monitor firewall and SIEM alerts and deliver notifications... not meaningful security improvement.
SP032 CRN Managed Security Firm Arctic Wolf Raises $60 Million In Pursuit Of IPO Arctic Wolf has closed a $60 million funding round to help the managed detection and response vendor prepare for an IPO.
SP033 SC Media Arctic Wolf backs off IPO talk, looks to scale business with latest acquisition the company – which was reportedly valued at $4.3 billion – planned for an IPO this year. But he made no commitments
SP034 Help Net Security eSentire launches new Atlas AI Operatives for autonomous threat detection and response - Help Net Security The Atlas Platform... operates vendor-independently across any integration.
SI001 BlueVoyant MDR, TPRM, Digital Risk Protection | BlueVoyant BlueVoyant packages Agentic SecOps, MDR, TPRM, DRP, and professional services with 1,200+ Microsoft Sentinel deployments and 24x7 monitoring.
SI002 BlueVoyant Company Headquartered in New York City, the company has over 600 employees across offices spanning five continents.
SI003 BlueVoyant Channel Partners Operational cybersecurity demands collaboration, and BlueVoyant highlights partners including GuidePoint Security and CDW.
SI004 BlueVoyant Build Your Own SOC or Partner with an MSSP The annual cost of setting up your own 24/7/365 SOC can add up to more than $1.2 million.
SI005 BlueVoyant BlueVoyant Enters 2022 With Triple Digit Growth Momentum and More Than 700 Global Customers Customer count increased by more than 80%, with more than 700 customers globally in 30 countries worldwide.
SI006 BlueVoyant BlueVoyant Raises $250 Million Series D Led by Liberty Strategic Capital Since 2018, BlueVoyant has grown annual recurring revenues at 117% on average.
SI007 BlueVoyant BlueVoyant Acquires Conquest Cyber BlueVoyant raised more than $140 million in Series E funding to accompany the acquisition of Conquest Cyber.
SI008 BlueVoyant BlueVoyant Welcomes Timothy Yost as Chief Financial Officer Tim will focus on setting and managing the company’s financial and strategic plans and continue to build BlueVoyant’s world-class global finance organization.
SI009 BlueVoyant New Security Operations Centre in Cork, Ireland BlueVoyant serves over 1,000 customers in more than 45 countries, and local revenue grew 70% in 2024.
SI010 BlueVoyant Total Economic Impact™ of BlueVoyant MDR Services The commissioned Forrester TEI study cites 210% ROI over three years.
SI011 BlueVoyant Total Economic Impact™ of BlueVoyant Supply Chain Defense Report The Forrester TEI study cites nearly 300% return and a 62% reduction in time to remediate critical risks.
SI012 BlueVoyant Snappi Neobank: Enterprise-Grade Security from Day One Snappi built 24/7 SOC coverage within months by partnering with Veracloud and BlueVoyant.
SI013 BlueVoyant ODEON Cinemas Group ODEON consolidated security across 8 countries and 280+ cinemas while cutting alert volume by 98%.
SI014 BlueVoyant BlueVoyant TPRM Is on Google Cloud Marketplace Making BlueVoyant TPRM available on GCP Enterprise Agreement eligibility removes procurement friction.
SI015 BlueVoyant Maximizing Security ROI A recent BlueVoyant analysis found that an enterprise organization can have an annual cost of up to $750,000 to optimize its Microsoft security stack internally.
SI016 BlueVoyant Successful Deployments of Microsoft Sentinel eBook The eBook summarizes insights from hundreds of hands-on deployments and 16 anonymized case studies.
SI017 BlueVoyant ClearBank's Journey with BlueVoyant | Webinar BlueVoyant says it optimized ClearBank’s existing Microsoft Security investment for better outcomes.
SI018 GovConWire BlueVoyant Purchases Conquest Cyber, Raises Over $140M in Series E Funding Round The acquisition coincided with a Series E funding round that raised over $140 million from BlueVoyant’s existing investors.
SI019 FinTech Global BlueVoyant bags $140m Series E and snaps up cybersecurity firm This substantial investment was led by existing investors Liberty Strategic Capital and ISTARI.
SI020 Pulse 2.0 BlueVoyant: Conquest Cyber Acqusition And Over $140 Million In Series E Funding BlueVoyant also raised over $140 million in Series E funding to accompany the acquisition of Conquest Cyber.
SI021 The SaaS News BlueVoyant Raises $140 Million in Series E Funding details listed a $140.0M Series E in November 2023 led by Liberty Strategic Capital and ISTARI.
SI022 Private Equity Insights BlueVoyant raises $250m in funding round led by Steven Mnuchin-backed PE firm The firm intends to use the capital raised to ramp up the development of its products and expand into new international markets.
SI023 CB Insights BlueVoyant Stock Price, Funding, Valuation, Revenue & Financial Statements CB Insights says BlueVoyant has raised $665.5M over 9 rounds and estimated 2024 revenue at $750M.
SI024 GetLatka BlueVoyant Revenue 2025: $213.5M ARR, $1B Valuation In 2025, BlueVoyant's revenue reached $213.5M and the profile estimated roughly 650 employees.
SI025 Origin by Dialectica BlueVoyant: Ownership, Revenue & Funding Data Dialectica lists BlueVoyant as PE-backed with 653 employees and Liberty Strategic Capital as investor.
SI026 Clay How Much Did BlueVoyant Raise? Funding & Key Investors Clay lists total amount raised at $665.5 million, 11 investors, and over 1,000 customers across 45 countries.
SI027 Tracxn BlueVoyant Tracxn reports BlueVoyant has raised a total of $696M over 6 funding rounds.
SI028 PitchBook BlueVoyant Company Profile: Valuation & Investors | PitchBook The accessible PitchBook snapshot showed 363 employees, a $30M latest deal amount, and a historical Debt - PPP entry dated 27-Apr-2020.
SI029 Companies House BLUEVOYANT UK LIMITED filing history - Find and update company information BlueVoyant UK Limited filed full accounts made up to 31 December 2024 on 30 Sep 2025.
SI030 Companies House BLUEVOYANT LTD filing history - Find and update company information BlueVoyant Ltd filed full accounts made up to 31 December 2024 on 30 Sep 2025.
SI031 Indeed via Wayback Working at BlueVoyant: Employee Reviews A featured review warned that BlueVoyant was extremely top heavy with consistent bi-yearly layoffs and limited resources in some business units.
SE001 BlueVoyant MDR, TPRM, Digital Risk Protection | BlueVoyant
SE002 BlueVoyant BlueVoyant Cyber Defense Platform Seamlessly integrated MDR, TPRM, and DRP.
SE003 BlueVoyant BlueVoyant AI | Agentic SecOps Platform AI that knows where to act and when to ask.
SE004 BlueVoyant Managed Detection & Response
SE005 BlueVoyant MDR for Microsoft 24/7 detection and response across your full Microsoft security stack.
SE006 BlueVoyant Continuous Optimization for Microsoft Solutions
SE007 BlueVoyant Continuous Optimization for Microsoft Security
SE008 BlueVoyant Third-Party Risk Management (TPRM)
SE009 BlueVoyant Continuous Monitoring & Remediation
SE010 BlueVoyant Questionnaire Management
SE011 BlueVoyant Digital Risk Protection (DRP)
SE012 BlueVoyant Brand Protection
SE013 BlueVoyant Dark Web Watcher
SE014 BlueVoyant Executive Cyber Guard
SE015 BlueVoyant Comprehensive Third-Party Cyber Risk Management Solution
SE016 BlueVoyant BlueVoyant Acquires Conquest Cyber Conquest Cyber's SaaS technology modernizes risk management with a platform that unifies an organization's entire cyber risk management program.
SE017 BlueVoyant BlueVoyant Trust Center BlueVoyant delivers a comprehensive cloud-native security operations platform that provides real-time threat monitoring for networks, endpoints, and supply chains, extending to the clear, deep, and dark web.
SE018 GitHub Bluevoyant
SE019 GitHub Bluevoyant
SE020 GitHub GitHub - Bluevoyant/BV-Security-Copilot: Public Content for Copilot for Security Public Content for Copilot for Security.
SE021 PR Newswire BlueVoyant Unveils Leading-Edge Security Operations Platform The platform integrates internal, external, and supply chain defense solutions into a single, cloud-native platform.
SE022 PR Newswire BlueVoyant Ignites the Next Era of Cyber Defense with Launch of BlueVoyant AI BlueVoyant AI brings true AI-native Security Operations Center (SOC) capabilities to life, delivering real-time, deterministic decision-making, automated response, and faster containment.
SE023 PR Newswire BlueVoyant Expands Offerings to Establish the Only Comprehensive Third-Party Cyber Risk Management Solution
SE024 PR Newswire BlueVoyant Acquires Conquest Cyber to Meet Market Need for Comprehensive Managed Detection and Response and Cyber Risk Posture Solutions
SE025 PeerSpot BlueVoyant CORE Reviews, Competitors and Pricing
SE026 Cyber Magazine BlueVoyant Launch Platform to Tackle Supplier Attack Surface
SE027 SecuritySenses BlueVoyant Unveils Leading-Edge Security Operations Platform
SE028 Gartner Peer Insights BlueVoyant Reviews, Ratings & Features 2026 | Gartner Peer Insights
SE029 Gartner Peer Insights BlueVoyant Digital Risk Protection Reviews & Ratings 2026 | Gartner Peer Insights Effective detection and ticket management with occasional takedown challenges
SE030 Spiceworks Community BlueVoyant | Thoughts, opinions, experiences? They are a startup, which is concerning ... I believe the back-end is Splunk.
SE031 InNetwork Tech BlueVoyant Core: MDR for Microsoft (Managed Detection and Response) BlueVoyant’s service allows you to keep your security data in your own environment, reducing cost and ensuring stronger compliance.
SE032 Microsoft How to order the SWAG as part of attending "BLUEVOYANT Shadow Hunter -Security Immersion Workshop - Microsoft Q&A
SU001 BlueVoyant California’s Innovative Cybersecurity Initiative 70% Reduction in Mean Time to Detect (MTTD); 60% Reduction in Mean Time to Respond (MTTR); $2.1 Million annual personnel cost savings/entity utilizing SOCaas
SU002 BlueVoyant ODEON Cinemas Group 98% reduction in alerts requiring InfoSec or Regional IT review
SU003 BlueVoyant Snappi Neobank: Enterprise-Grade Security from Day One 24/7 SOC coverage operational from the outset
SU004 BlueVoyant Partners
SU005 BlueVoyant Beeks Group Selects BlueVoyant to Strengthen its 24x7 SOC
SU006 BlueVoyant Maximizing Your Investment with Microsoft Security | Webinar
SU007 BlueVoyant Digital Brand Protection for Financial Institutions
SU008 BlueVoyant Financial Exchanges - External Cyber Defense for When Your Attack…
SU009 BlueVoyant Securing State and Local Governments from Threats
SU010 BlueVoyant Avoiding the Government Third-Party Risk Domino Effect
SU011 BlueVoyant Total Economic Impact™ of BlueVoyant Supply Chain Defense Report
SU012 BlueVoyant The State of Supply Chain Defense: Annual Global Insights Report 2025
SU013 BlueVoyant BlueVoyant and Carahsoft Partnership
SU014 BlueVoyant ClearBank's Journey with BlueVoyant | Webinar
SU015 BlueVoyant Protecting the Grid: The Evolving Threat Landscape and Proactive…
SU016 BlueVoyant Defending Law Firms from Cyber Threats
SU017 BlueVoyant Total Economic Impact™ of BlueVoyant MDR Services
SU018 BlueVoyant Microsoft Security Excellence Award Winners
SU019 Navy SBIR/STTR Program Success Story In October 2021, Naval Sea Systems Command (NAVSEA) ... awarded a three-year single-award indefinite delivery contract to BlueVoyant Government Solutions
SU020 PR Newswire BlueVoyant's 202 Group Expands its Supply Chain Risk Management Solutions and Rebrands as BlueVoyant Government Solutions
SU021 FeaturedCustomers 14 BlueVoyant Customer Reviews & References
SU022 FeaturedCustomers 9 BlueVoyant Customer Reviews & References
SU023 PeerSpot BlueVoyant CORE Reviews, Competitors and Pricing
SU024 Carahsoft BlueVoyant and Carahsoft Partner to Defend Public Sector from Cyber Threats | Carahsoft
SU025 AWS Marketplace MDR for Splunk Cloud. Please contact BlueVoyant for Private Offer.
SU026 Beeks Group Beeks Group Collaborating With BlueVoyant | Beeks Group
SU027 Intelligence Community News BlueVoyant and Carahsoft announce partnership - Intelligence Community News
SU028 UpGuard BlueVoyant Security Rating, Vendor Risk Report, and Data Breaches | UpGuard
SU029 Slashdot Compare BitSight vs. BlueVoyant in 2026
SU030 Carahsoft BlueVoyant Government IT Procurement Contracts | Carahsoft
SU031 BlueVoyant Government Solutions SCRM Solutions Offered on GSA's SCRIPTS BPA via Carahsoft
SU032 Carahsoft Technology Reseller Partner Program | Carahsoft
SU033 Intelligent CISO BlueVoyant strengthens cyber defence for ODEON Cinemas Group across eight countries – Intelligent CISO
SU034 Veracloud How Snappi Built Enterprise-Grade Cybersecurity from Day One with Veracloud and BlueVoyant
SU035 MaltaCEOs Veracloud brings operational security to Greece’s first neobank
SU036 California Department of Technology Security Operations Center as a Service (SOCaaS)
SU037 California Department of Technology How California is Centralizing Public Sector Cybersecurity
SU038 MSSP Alert MSSP BlueVoyant Launches SOCaaS Powered by Microsoft Azure Sentinel -
SR001 BlueVoyant Privacy Policy & Legal Notice BlueVoyant LLC is the controller of your personal data and may share personal information with affiliate companies unless prohibited by law.
SR002 BlueVoyant BlueVoyant & Microsoft Streamline security with Microsoft XDR/E5 and Sentinel, delivering unified threat detection, response, and monitoring across your environment.
SR003 BlueVoyant MDR for Microsoft - Manage & Monitor Harness the full power of Microsoft Security with our elite 24x7 SOC and security operations team backed by BlueVoyant AI.
SR004 BlueVoyant Next Era of Cyber Defense with BlueVoyant AI BlueVoyant AI provides both with its fully managed service - supported 24/7 with BlueVoyant’s elite SOC team - or as an enterprise-grade SaaS platform.
SR005 BlueVoyant BlueVoyant Acquires Conquest Cyber BlueVoyant raised more than $140 million in Series E funding to accompany the acquisition of Conquest Cyber.
SR006 BlueVoyant John Hernandez Joins BlueVoyant as CEO John Hernandez will succeed Jim Rosenthal as Chief Executive Officer with a focus on scaling an AI-driven cybersecurity platform.
SR007 BlueVoyant BlueVoyant Welcomes New Chief Product Officer Amit Jasuja will guide BlueVoyant’s strategic product direction, aiming to unify product lines and expand the company’s share of the cybersecurity market.
SR008 BlueVoyant New Security Operations Centre in Cork, Ireland The new SOC will provide 24x7 monitoring of Irish and EU clients’ networks and digital ecosystems.
SR009 BlueVoyant Microsoft Security Excellence Award Winners BlueVoyant also won the Security Trailblazer award.
SR010 BlueVoyant 2024 Microsoft Worldwide Security Partner of the Year BlueVoyant announced it has won the 2024 Microsoft Worldwide Security Partner of the Year Award.
SR011 BlueVoyant Government Solutions BlueVoyant Government Solutions | Supply Chain Defense BlueVoyant Government Solutions operationalizes mission assurance with deep supply chain risk visibility and expert-led threat remediation at scale.
SR012 BlueVoyant Government Solutions Customers Supporting federal government agencies with end-to-end cyber supply chain risk management.
SR013 PR Newswire BlueVoyant is a proud participant in the Microsoft Sentinel partner ecosystem BlueVoyant is working with Microsoft product teams to shape Sentinel product development.
SR014 PR Newswire BlueVoyant Recognized as the Winner of 2024 Microsoft Worldwide Security Partner of the Year The company has additionally been named the Microsoft United States Security Partner of the Year for the third consecutive time.
SR015 PR Newswire UK BlueVoyant Expands in EU with New Cutting-Edge Security Operations Centre in Cork, Ireland With cyber security teams grappling with the enforcement of new EU regulations such as NIS 2 and DORA, clients now require a holistic, next-generation managed security service.
SR016 Microsoft Security Blog BlueVoyant optimizes customer security with Microsoft security services BlueVoyant speaks with a lot of companies about their security technology deployment and one of the main trends found is tech sprawl.
SR017 Microsoft Security Blog Microsoft announces the 2025 Security Excellence Awards winners The Microsoft Security Excellence Awards honor outstanding contributions across several categories.
SR018 Protiviti BlueVoyant Partnership | Protiviti US The platform integrates advanced AI technology with expert human insight to offer extensive protection and swift threat mitigation.
SR019 Carahsoft BlueVoyant Government IT Procurement Contracts | Carahsoft Carahsoft lists NASA SEWP V, ITES-SW2, SCRIPTS BPA, and CMAS contract access for BlueVoyant.
SR020 PacerMonitor Steward Health Care System LLC, et al., v. Bluevoyant LLC Complaint to (I) Avoid and Recover Avoidable Transfer(s) and (II) Disallow Claims by Steward Health Care System LLC against Bluevoyant LLC.
SR021 National Institute of Standards and Technology Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations The security requirements are intended for use by federal agencies in contractual vehicles or other agreements established between those agencies and nonfederal organizations.
SR022 U.S. Department of Defense CIO CIO - CMMC Resources & Documentation CMMC Phase 1 Implementation (Nov 10, 2025 - Nov 9, 2026) focuses primarily on CMMC Level 1 and Level 2 self-assessments.
SR023 U.S. Department of Defense CMMC 2.0 Details and Links to Key Resources Beginning November 10, contracting officers will include the new CMMC requirements in new solicitations and contracts.
SR024 PM Insights BlueVoyant Valuation | PM Insights Sample data shown with delay for preview purposes. Real-time, institutional-grade datasets available to subscribers.
SR025 SourceForge Best BlueVoyant Alternatives & Competitors SourceForge ranks the best alternatives to BlueVoyant in 2026.
SR026 PeerSpot BlueVoyant CORE Reviews, Competitors and Pricing Their MDR service offers 24/7 monitoring and threat hunting by a team of experts, utilizing advanced analytics and machine learning.
SR027 SecuritySenses BlueVoyant Recognised as Microsoft Security Excellence Award Winners BlueVoyant also won the Security Trailblazer award.
SR028 Yahoo Finance BlueVoyant is a proud participant in the Microsoft Sentinel partner ecosystem BlueVoyant is building on it with custom analytics, Copilot-ready content, and lessons tested in the field.
SR029 Pavilion BlueVoyant Government Solutions Government Contracts | Pavilion BlueVoyant provides government-focused supply chain risk management and cybersecurity services, including CMMC + NIST 800-171 compliance management.
SR030 SAM.gov Contract Award Data in SAM.gov The contract award search function in SAM.gov allows users to search federal procurement data and to filter by keyword, agency, and legal business name.
SR031 USAspending Government Spending Open Data | USAspending USAspending is the official open data source of federal spending information, including information about federal awards such as contracts, grants, and loans.
SR032 SecuritySenses BlueVoyant Ignites the Next Era of Cyber Defence with Launch of BlueVoyant AI BlueVoyant AI brings true AI-native Security Operations Centre capabilities to life.
SR033 BlueVoyant Successful Deployments of Microsoft Sentinel eBook This eBook summarizes the guide’s 16 real world anonymized case studies based on hundreds of hands-on deployments.
SR034 BlueVoyant BlueVoyant Recognized in Gartner’s Market Guide for Third-Party Risk Management The percentage of cyber breaches involving third parties doubled over the past year to 30% according to Verizon’s 2025 DBIR.
SV001 BlueVoyant BlueVoyant Enters 2023 with Momentous Growth Growing annual recurring revenues at an average of 108% since 2018, with recurring revenue growing 80% in 2022.
SV002 PR Newswire / BlueVoyant BlueVoyant Acquires Conquest Cyber to Meet Market Need for Comprehensive Managed Detection and Response and Cyber Risk Posture Solutions BlueVoyant raised more than $140 million in Series E funding to accompany the acquisition.
SV003 PR Newswire / BlueVoyant BlueVoyant Raises $250 Million Series D Led by Liberty Strategic Capital Liberty Strategic Capital ... led the $250-million round with participation from ... ISTARI ... Eden Global Partners ... and 8VC.
SV004 Caplight BlueVoyant | Valuation, Funding Rounds & Stock Price | Caplight Last Round Series E ... Nov 29, 2023 ... Est. Valuation $1B ... Total Funding Raised $665.5M.
SV005 Notice.co BlueVoyant Stock $1.36 | How to Buy, Valuation, Stock Price, IPO | Notice.co The current Notice Price premium (+) or discount (-) to the last round ... -39%.
SV006 Forge Invest and Sell BlueVoyant Stock - Forge Market activity ... Limited ... Forge Price $-- Not yet available ... Last known valuation $1B 2/23/2022.
SV007 Hiive BlueVoyant Stock | Invest or Sell Buy and sell BlueVoyant stock. Get stock prices & access to pre-IPO shares in one place at Hiive.
SV008 Tracxn BlueVoyant - 2026 Funding Rounds & List of Investors BlueVoyant has raised a total of $696M over 6 funding rounds.
SV009 GetLatka BlueVoyant Revenue 2025: $213.5M ARR, $1B Valuation In 2025, BlueVoyant's revenue reached $213.5M.
SV010 BlueVoyant MDR, TPRM, Digital Risk Protection | BlueVoyant Agentic SecOps, MDR, and TPRM to protect your entire attack surface.
SV011 Eden Global Partners BlueVoyant Raises $250 Million Series D Led by Liberty Strategic Capital BlueVoyant Raises $250 Million Series D Led by Liberty Strategic Capital.
SV012 U.S. Securities and Exchange Commission EDGAR Search Results — BlueVoyant Acc-no: 0000950103-20-013356 ... 2020-07-08 ... Acc-no: 0000950103-19-005109 ... 2019-04-25 ... Acc-no: 0000950103-17-007618 ... 2017-08-04.
SV013 CompaniesMarketCap CrowdStrike (CRWD) - Market capitalization As of June 2026 CrowdStrike has a market cap of $178.47 Billion USD.
SV014 CompaniesMarketCap SentinelOne (S) - Market capitalization As of June 2026 SentinelOne has a market cap of $5.43 Billion USD.
SV015 CompaniesMarketCap Rapid7 (RPD) - Market capitalization As of June 2026 Rapid7 has a market cap of $0.51 Billion USD.
SV016 CompaniesMarketCap Tenable (TENB) - Market capitalization As of June 2026 Tenable has a market cap of $3.33 Billion USD.
SV017 CompaniesMarketCap Qualys (QLYS) - Market capitalization As of June 2026 Qualys has a market cap of $4.34 Billion USD.
SV018 Windsor Drake Cybersecurity Valuations: Q2 2026 The public cybersecurity median is 6.0x–6.5x NTM revenue ... managed security services to 3x–5x.
SV019 multiples.vc Largest Cybersecurity Public Companies CrowdStrike ... endpoint, cloud workload, identity, and security operations ... Rapid7 ... expanded its portfolio to provide extended detection and response, SIEM ...
SV020 Tablestat Valuation Trading Multiples & Precedent Transactions: Enterprise Cybersecurity Software Providers Revenue growth Median 15.7% 2025E 16.0% 2026E ... 8.4x ... 6.8x.
SV021 Yahoo Finance CrowdStrike Holdings, Inc. (CRWD) Stock Price, News, Quote & History - Yahoo Finance Enterprise Value/Revenue 34.30 ... Revenue (ttm) 5.09B.
SV022 Yahoo Finance SentinelOne, Inc. (S) Stock Price, News, Quote & History - Yahoo Finance Enterprise Value/Revenue 4.61 ... Revenue (ttm) 1.05B.
SV023 Yahoo Finance Rapid7, Inc. (RPD) Stock Price, News, Quote & History - Yahoo Finance Enterprise Value/Revenue 0.93 ... Revenue (ttm) 859.23M.
SV024 Yahoo Finance Tenable Holdings, Inc. (TENB) Stock Price, News, Quote & History - Yahoo Finance Enterprise Value/Revenue 3.32 ... Revenue (ttm) 1.02B.
SV025 Yahoo Finance Qualys, Inc. (QLYS) Stock Price, News, Quote & History - Yahoo Finance Enterprise Value/Revenue 5.73 ... Revenue (ttm) 684.86M.
SV026 PM Insights BlueVoyant Valuation | PM Insights BlueVoyant Secondary Market ROI ... BlueVoyant Bid-Ask Volume Ratios ... BlueVoyant Mutual Fund Valuations (NAV) ... BlueVoyant Funding Rounds & Cap Table Details.
SV027 CB Insights BlueVoyant - Products, Competitors, Financials, Employees, Headquarters Locations Stage Series E | Alive ... Total Raised $665.5M ... Last Raised $140M.
SV028 Yahoo Finance Palo Alto Networks, Inc. (PANW) Stock Price, News, Quote & History - Yahoo Finance Enterprise Value/Revenue 23.28 ... Revenue (ttm) 10.61B.
SV029 Yahoo Finance Fortinet, Inc. (FTNT) Stock Price, News, Quote & History - Yahoo Finance Enterprise Value/Revenue 15.20 ... Revenue (ttm) 7.11B.
SV030 CompaniesMarketCap Palo Alto Networks (PANW) - Market capitalization As of June 2026 Palo Alto Networks has a market cap of $247.92 Billion USD.
SV031 CompaniesMarketCap Fortinet (FTNT) - Market capitalization As of June 2026 Fortinet has a market cap of $110.88 Billion USD.
SV032 SiliconANGLE BlueVoyant acquires cyber defense company Conquest Cyber, raises $140M Including the new funding, BlueVoyant has raised about $646 million to date, according to data from Tracxn.