BlueVoyant
网络防御平台具备 MDR 与 TPRM 规模,但私募市场信息仍不透明
BlueVoyant 是可信的后期网络安全平台,MDR 和 TPRM 已有真实规模,受监管行业定位有差异化,也能借 Microsoft 生态放大;但私营公司不透明,加上估值和收入冲突未解,更适合观察而不是确信买入。
封面要素
公司概况
BlueVoyant 成立于 2017 年,总部位于纽约市。公司公开材料将其定位为统一网络防御平台,覆盖 MDR、第三方风险管理、数字风险防护和专业服务,并且与 Microsoft 安全工具深度绑定,在政府及其他受监管行业有明显足迹。公司已有可信商业规模——45 个国家超过 1,000 家客户、600 多名员工,并在 2022 年完成 $250M Series D、跨过 $1B 独角兽门槛后,于 2023 年公开宣布超过 $140M 的 Series E。不过,当前估值、ARR 质量、利润率结构和所有权结构在公开数据中仍只露出一部分,限制了承销信心。
- 创始人
- Jim Rosenthal, Tom Glocer
- 创立地点
- New York, New York, USA
- 总部
- New York, New York, USA (6 East 45th Street, Floor 17)
- 产品
- BlueVoyant 销售一套网络防御平台,覆盖托管检测与响应、第三方风险管理 / 供应链防御、数字风险防护和专业服务。当前路线图强调 AI-native SecOps、Microsoft-native 部署和持续供应商风险修复,而不是一次性评估。
- 客户
- 大型企业、金融服务机构、政府机构、国防工业基础实体,以及其他需要托管 SOC 覆盖、Microsoft 安全优化和跨供应商第三方网络风险管理的受监管组织。
- 商业模式
- 围绕 MDR、TPRM、DRP 以及咨询 / 响应服务的经常性托管安全与软件收入,并借助 Microsoft 生态工作、公共部门项目和渠道伙伴做交叉销售。
- 阶段
- Series E (private unicorn)
- 融资情况
- 公开资本历史包括 2022 年 2 月由 Liberty Strategic Capital 领投的 $250M Series D,以及 2023 年 11 月与收购 Conquest Cyber 同时宣布的超过 $140M Series E。第三方数据集将总融资额置于约 $665.5M 至 $696M。
执行摘要
主要优势
- BlueVoyant 在一个平台里覆盖 MDR、TPRM、DRP 和服务,销售的是统一网络防御,而不是单点控制。
- 公司已有可信企业规模:在 45 个国家超过 1,000 名客户、600 多名员工,并在公共部门和受监管行业拿到有分量的进展。
- BlueVoyant 的 Microsoft 专长是耐久的 go-to-market 优势,大量部署、认证合作伙伴身份和客户 ROI 研究共同强化了这一点。
- Liberty Strategic Capital、ISTARI、Temasek 相关资本和其他投资人的资金支持,让公司即便处在艰难私募市场背景下仍有战略可信度。
主要风险
- 公开财务能见度差:经审计 ARR、增长、毛利率、烧钱速度、NRR 和股权结构条款都未披露,公开收入估计还彼此冲突很大。
- 最后一个清晰的独角兽估值锚已经过期,私募市场数据也无法干净、高置信地读出当前企业价值或清算优先权。
- BlueVoyant 在拥挤的 MDR 和网络风险市场竞争,对手包括 Palo Alto Networks、CrowdStrike、Rapid7、Arctic Wolf 等更大平台,以及 BitSight、SecurityScorecard 这类风险专攻者。
- 业务模式仍实质依赖服务交付和 Microsoft 生态执行,可能压住利润率扩展,并放大平台依赖风险。
- 2026 年 AI 产品再定位抬高了执行风险:公司必须证明差异化不只是营销,同时还要在不断扩大的平台上守住服务质量。
未决问题
- 经审计 ARR、收入增长、毛利率、NRR、烧钱速度和现金余额。
- 完全摊薄股权结构表、优先股条款、清算优先权和任何老股交易细节。
- 2023 年 11 月 Series E 的精确当前估值,以及 2026 年老股成交是否验证或折价独角兽标记。
- MDR、TPRM、DRP、专业服务和政府项目之间的收入组合。
- 按垂直行业拆分的客户集中度和留存,尤其是政府和金融服务。
- 2026 年 6 月 BlueVoyant AI 发布后,AI 产品采用、定价和转化影响的独立证据。
目录
01公司概览
1.1 身份、总部与商业模式
BlueVoyant 将自己呈现为一家网络防御平台公司,成立于 2017 年,总部在纽约。其官方公司页和联系页把当前足迹锚定在曼哈顿,同时也显示出更广的跨国运营基础。公司称拥有 600 多名员工、45 个国家超过 1,000 家客户;即便不看第三方估算,也已越过创业孵化阶段,进入有规模的私营公司区间。产品上,BlueVoyant 并不把自己描述为单点工具厂商。其平台结合托管检测与响应、第三方风险管理、数字风险防护和专业服务,收入看起来来自经常性软件模块以及分析师主导的托管运营。所审阅材料始终把 BlueVoyant 放在企业、政府和关键基础设施用例中,而不是狭窄的 SME 或消费者路径。这一组合会影响后续尽调:它意味着更长销售周期、更重服务导入,以及对受监管或任务关键买家的差异化敞口。[CO001, CO002, CO003, CO004, CO005, CO006]
| 指标 | 数值 / 状态 | 日期 | 置信度 | 缺口 / 备注 |
|---|---|---|---|---|
| 成立 | 2017 | 2017 | 高 | 官方和独立来源相互印证 |
| 总部 | 6 East 45th Street, Floor 17, New York, NY 10017(总部地址) | 2026-06-29 | 高 | 官方领导层 / 联系页面 |
| 官方员工披露 | 600+ 名员工 | 2026-06-29 | 中 | 公司口径;第三方估算更高 |
| 客户披露 | 45 个国家的 1,000+ 名客户 | 2026-06-29 | 中 | 公司在联系页披露 |
| 核心平台 | MDR + TPRM + DRP + 专业服务 | 2026-06-29 | 高 | 官方套件页面 |
| 最近一次公开确认融资 | > $140M Series E,伴随收购 Conquest Cyber | 2023-11-29 | 高 | 已审阅公开记录未显示后续具名融资轮 |
| 第三方总融资估算 | ~$665.5M | 2025-11-28 | 中 | 私募市场数据库估算,未经审计 |
| 第三方估值估算 | ~$1B | 2025-11-28 | 中 | 未披露官方当前估值 |
| 现任 CEO | John Hernandez | 2026-05-05 | 高 | 接替联合创始人 Jim Rosenthal |
| 近期产品发布 | BlueVoyant AI | 2026-06-09 | 高 | AI 原生 / agentic SecOps 定位 |
| Microsoft 认可 | 2024 Worldwide + U.S. + Canada 年度安全合作伙伴荣誉 | 2024 | 高 | 历史奖项信号,不是当前财务指标 |
融资、估值和外部员工数混合了官方披露与私募市场或监测估算;非官方数值行应视为方向性信息,而非审计数据。
[CO001, CO002, CO003, CO004, CO005, CO016]BlueVoyant 把创始人塑造的治理层,连到一体化网络安全平台、Microsoft 生态杠杆、全球客户足迹,以及经济指标仍未公开的私募资本基础。
[CO005, CO017, CO028, CO032, CO035, CO043]最清晰的公开信号指向一家已有规模的私营网络安全平台,生态认可度强,但经济指标仍未公开。
融资和估值是第三方私募市场估算;客户和员工数字使用公司自行披露的最低门槛,而非精确审计数量。
[CO003, CO004, CO015, CO028]1.2 领导层、治理与关键人物风险
BlueVoyant 当前公开领导层图谱由近期交接塑造。John Hernandez 现任 CEO,联合创始人 Jim Rosenthal 转任主席,联合创始人 Thomas Glocer 仍任副主席。当前运营班底足以覆盖财务、产品、技术、信息安全、人力资源、政府解决方案、区域销售和伙伴关系,降低了对任何单一职能副手的依赖。即便如此,创始人影响力仍然重要,因为 Rosenthal 与 Glocer 仍是核心治理人物,公司的公开叙事也仍高度依赖创始人身份。这个组合指向一种显著但可管理的关键人物风险:BlueVoyant 已完成最高层交接,但其公共可信度、投资者连续性和战略叙事仍穿过创始人。此前公开任命 Michael Montoya 为 COO,也说明 BlueVoyant 在规模化阶段愿意刷新董事会以下的运营层。[CO009, CO010, CO011, CO012, CO013, CO014]
| 人物 | 职务 | 背景 / 公开语境 | 职能覆盖 / 创始人-市场匹配 | 关键人物依赖 |
|---|---|---|---|---|
| John Hernandez | 首席执行官 | 2026 年 5 月获任 CEO,负责在全球扩展 AI 驱动的网络安全平台 | 现任运营负责人,承接创始人主导阶段后的转折点 | 中 |
| James Rosenthal | 联合创始人;董事会主席 | 联合创始人、前 CEO;CEO 交接后仍是治理锚点 | 在战略、投资者连续性和董事会影响力上具备高创始人-市场匹配 | 高 |
| Thomas Glocer | 联合创始人;董事会副主席 | 联合创始人,曾任 Thomson Reuters 首席执行官 | 在纯网络安全履历之外,增加企业运营和董事会可信度 | 中 |
| Ravi Subramanian | 首席财务官 | 现任领导层页面公开列出的财务负责人 | 覆盖规划、财务和投资者准备职能 | 中 |
| Sebastian Sobolev | 首席产品官 | 领导层页面列出的现任产品负责人 | 负责平台 / AI 演进的路线图和打包 | 中-高 |
| Jim Bieda | 全球首席技术官 | 领导层页面列出的现任技术负责人 | 覆盖技术架构和平台可信度 | 中-高 |
| John Harbaugh | 首席信息安全官 | 领导层页面列出的现任安全负责人 | 支撑信任、安全态势和企业可信度 | 中 |
| Lonny Anderson | BlueVoyant Government Solutions 总裁 | 面向政府业务线的公开负责人 | 对公共部门和受监管环境 GTM 很重要 | 中 |
本表仅反映 BlueVoyant 页面和 CEO 交接报道中公开出现并得到印证的领导者;私人公司委员会结构和完整董事会名单仍不完整。
[CO009, CO010, CO011, CO012, CO013, CO042]1.3 融资历史、投资者与所有权可见度
BlueVoyant 公开可见的资本故事有两个主要拐点。第一,公司在 2022 年 2 月完成由 Liberty Strategic Capital 领投的 $250 million Series D,ISTARI、Eden Global Partners 和 8VC 参投。第二,2023 年 11 月,公司把 Conquest Cyber 收购与超过 $140 million 的 Series E 绑定披露,领投方为既有投资者 Liberty Strategic Capital 和 ISTARI。第三方市场数据平台目前聚集在约 $665.5 million 累计融资和估算 $1 billion 估值,但这些数字是数据库估算,不是公司认证的财务披露。因此,证据支持其资本基础强、机构背书可信,却不能给出现时精确估值。公开材料对董事会委员会、保护性条款、债务、老股转让和股权结构集中度也很薄,所以下方投资者地图应被视为尽调脚手架,而不是完全验证的控制权图。[CO020, CO021, CO023, CO026, CO027, CO028]
| 利益相关方 | 角色 | 控制 / 经济重要性 | 公开支持 | 尽调问题 |
|---|---|---|---|---|
| Liberty Strategic Capital | 2022 Series D 领投方;2023 Series E 共同领投方 | 锚定型机构赞助方;官方来源把该基金与近期两次主要融资都关联起来 | Liberty 2022 年披露 $125M 投资;2023 年融资中再次出现 | 确认董事席位、保护性条款和任何 step-up 权利 |
| ISTARI(Temasek 创立的网络安全投资者 / 顾问) | Series D 参与方;Series E 共同领投方 | 战略网络安全投资者,可能具备信息权相关性 | 在 2022 和 2023 年公司相关融资报道中被点名 | 确认持股比例、董事会观察员权利和战略商业联系 |
| Eden Global Partners / Eden Global Capital Partners(资本方) | Series D 参与方和战略顾问;关联方为 2023 年交易提供顾问服务 | 增长股权和配售支持,而非清晰披露的控制权 | 在 2022 年官方发布和 2023 年交易报道中被点名 | 澄清顾问角色是否带有任何持续治理权 |
| 8VC | Series D 参与方 | 显示风险投资参与 2022 年扩张轮 | 在 2022 年官方融资报道中被点名 | 确认后续跟投和当前持股比例 |
| James Rosenthal | 联合创始人;主席 | 可能拥有有意义的内部人持股,并在 CEO 交接后保持治理连续性 | 公开材料显示其继续担任董事会职务,但未披露股数 | 要求提供当前 cap table 和投票控制摘要 |
| Thomas Glocer | 联合创始人;副主席 | 董事会层面的战略影响力和声誉资本 | 公开确认其为联合创始人和副主席 | 确认股权比例和任何保留同意权 |
| Conquest Cyber 资产 / 团队 | 被收购的战略平台延伸 | 对受监管、政府和 DIB 产品扩张很重要,而不是单纯所有权控制 | 2023 年 11 月随 Series E 宣布收购 | 审查整合里程碑、earnouts 和客户留存假设 |
公开来源确认了轮次领投方和战略角色,但未披露持股比例、清算栈、债务或观察员权利;因此各行强调尽调问题,而不是推断控制权。
[CO020, CO023, CO025, CO026, CO028, CO042]1.4 平台演进、生态系统与商业定位
BlueVoyant 的定位不只是检测威胁,而是把多条网络安全工作流包进托管平台叙事。其 Microsoft 页面和获奖历史显示出异常强的生态对齐,包括多次获得安全伙伴认可,并围绕 Sentinel、Defender、Purview 以及 Copilot 时代安全运营做服务打包。伙伴计划也表明,其上市路径依赖渠道,而非纯直销。产品侧,公司已把叙事从托管网络防御扩展到更宽的 AI-native 或 agentic SecOps,并以 2026 年 6 月 BlueVoyant AI 发布作为节点。2023 年 11 月收购 Conquest Cyber 正处在这一演进中段,为受监管和政府敏感环境补上 SaaS-heavy 能力。Auto-ISAC 伙伴关系又把第三方风险叙事延伸进一个具名垂直行业。合起来看,公司更像是在复杂账户中加深钱包份额,而不是单纯增加 logo。[CO015, CO016, CO017, CO018, CO019, CO023]
1.5 里程碑、规模信号与不利考量
公开里程碑显示,BlueVoyant 从 2017 年创立故事进入资本密集扩张期,随后拓宽平台并完成管理层交接。到 2026 年,公司按官方页面描述,已经是全球化、对齐 Microsoft 且 AI-forward 的公司,拥有超过 1,000 家客户和 600 多名员工。与此同时,尽调不应过度精确。第三方员工数信号明显高于官方披露,估值和收入数字也主要来自私募市场数据库而非审计报告。保留信源中最强的公开不利信号是 UpGuard 2026 年 6 月外部风险报告,指出 CSP 弱点和 unsafe-eval 使用等具体网站安全加固问题。这不是足以推翻投资论点的事件,但值得注意,因为 BlueVoyant 销售的是安全结果。结合稀疏的公开治理和财务披露,尽调应把清晰运营动能与仍属私有的经济质量分开看。[CO021, CO028, CO029, CO030, CO031, CO032]
| 日期 | 事件 | 类型 | 金额 / 估值 / 状态 | 参与方 | 含义 |
|---|---|---|---|---|---|
| 2017 | BlueVoyant 在 New York 成立 | 成立 | 公司启动 | 包括 James Rosenthal 和 Thomas Glocer 在内的创始人 | 确立公司作为 2016 年后网络防御新进入者,并带有创始人主导治理根基 |
| 2022-02-23 | Series D 完成 | 融资 | $250M | Liberty Strategic Capital、ISTARI、Eden Global Partners、8VC 等 | 面向技术能力和全球扩张的主要扩张轮 |
| 2022-02 | BlueVoyant 被公开描述为网络安全独角兽 | 规模 | > $1B 估值;迄今总融资 $525M | SecurityWeek / TechCrunch 公开报道 | 外部市场验证了 2022 年融资拐点 |
| 2023-11-29 | Conquest Cyber 收购随 Series E 融资宣布 | 产品 | > $140M Series E | BlueVoyant、Conquest Cyber、Liberty Strategic Capital、ISTARI 参与 | 拓宽平台深度,并增加受监管环境 SaaS 能力 |
| 2023-11-29 | 收购被定位为面向高度受监管和政府环境 | 监管 | 战略扩张 | BlueVoyant、Conquest Cyber | 显示公司有意转向国防工业基础和受监管买方相关场景 |
| 2024 | 奖项页面突出 Microsoft 安全合作伙伴奖项 | 合作 | Worldwide + U.S. + Canada 荣誉 | BlueVoyant、Microsoft | 强化生态可信度和渠道定位 |
| 2025-09-24 | Auto-ISAC 战略合作宣布 | 合作 | TPRM 协作 | BlueVoyant、Auto-ISAC | 为供应链网络产品增加具名汽车垂直切口 |
| 2026-05-05 | John Hernandez 接替 Jim Rosenthal 出任 CEO | 治理 | 领导层交接 | John Hernandez、Jim Rosenthal、BlueVoyant 董事会 | 标志运营从创始人主导转向外聘 CEO 扩张阶段 |
| 2026-06-09 | BlueVoyant AI 发布 | 产品 | AI 原生 / agentic SecOps 平台 | BlueVoyant | 围绕 AI 主导的 SOC 工作流重新定位公司 |
| 2026-06-29 | UpGuard 供应商风险报告标记网站安全加固问题 | 负面 | CSP / unsafe-eval 发现 | UpGuard | 构成保留来源集中最清晰的公开负面信号 |
时间线混合了公司官方公告和高信号第三方印证;由于 BlueVoyant 是私人公司,后续融资和治理细节仍不完整。
[CO001, CO016, CO020, CO021, CO023, CO025]公开记录显示,BlueVoyant 从 2017 年创立,走到 2022 年融资扩张、2023 年平台拓宽,并在 2026 年完成管理层和 AI 产品重新定位。
[CO016, CO020, CO021, CO023, CO032, CO036]1.6 图表
02市场分析
2.1 市场边界与相邻支出
BlueVoyant 应被框定在托管检测与响应和网络安全导向第三方风险管理的交集,而不是泛化网络安全厂商,也不是广义 GRC 套件。MDR 页面强调在既有 EDR、SIEM、云和 Microsoft 安全栈之上补充 24x7 监控、事件响应和自动化。TPRM 页面强调持续监控、分析师引导修复、问卷工作流、零日告警和第四方映射。边界很重要,因为它定义了核心机会中应计入哪些支出。纳入的支出,是安全运营和供应商风险预算中用于持续检测、验证、修复和外部依赖可见性的部分。相邻支出位于 GRC、董事会汇报和更广的韧性工作流,主要替代方案仍是自建 SOC、定期问卷、电子表格驱动的供应商审查,以及只解决单层问题的点产品。[CM001, CM002, CM003, CM004, CM005, CM006]
| 细分 / 品类 | 纳入支出 | 排除支出 | 买方 / 付款方 | 相关性 |
|---|---|---|---|---|
| MDR 叠加 / 托管 SecOps | 24x7 监控、威胁分诊、事件响应、现有 EDR、SIEM、云和 Microsoft 安全工具调优 | 独立端点许可证、防火墙或通用网络硬件 | CISO、SOC 负责人、安全运营预算 | BlueVoyant MDR 核心边界 |
| 网络安全聚焦 TPRM | 持续监控、供应商网络安全发现、分析师主导补救、问卷工作流、zero-day 告警 | 通用供应商主数据和非网络安全采购管理 | CISO、第三方风险负责人、合规、采购 | BlueVoyant TPRM 核心边界 |
| 第四方与集中度分析 | 依赖映射、nth-party 可见性、what-if 分析、集中度暴露管理 | 不做依赖映射的一次性纯评估 | 企业风险、韧性、安全、采购 | 供应链网络风险中的重要扩张切口 |
| AI 辅助网络安全分诊 | 攻击面监控、威胁情报补强、漏洞优先级排序、自动化分诊支持 | 未整合安全工作流的通用 AI 工具 | 安全运营和网络防御团队 | 支撑 MDR 和数字风险相邻业务 |
| GRC / 董事会报告相邻业务 | 控制报告、治理工作流、可提交董事会的网络风险摘要、政策证据管理 | 宽泛的法律、审计、HR 和非网络安全治理套件 | 合规、审计、董事会、企业风险 | 相邻支出,不应计入纯 BlueVoyant 核心 TAM |
| 现状和替代动作 | 内部 SOC、电子表格驱动的供应商审查、年度问卷、狭窄点工具、手工补救邮件 | N/A | 现有流程负责人 | 解释为什么转化是渐进且多步骤的 |
边界是托管 SecOps 与网络安全聚焦供应商风险监控的交集。通用 GRC 和独立安全控制是相邻领域,不是直接核心 TAM。
[CM001, CM002, CM003, CM004, CM005, CM006]2.2 规模测算视角——TAM、SAM 与互相矛盾的公开估算
BlueVoyant 的市场可以测算,但只能用分层逻辑,不能只看一个 headline TAM。MDR 估算从 Precedence Research 的 2026 年 $3.92B,到 Mordor 的 $5.09B,The Business Research Company 则为 $4.16B。TPRM 对定义更敏感:TBRC 直接给出 2026 年 $8.09B,NextMSC 的 2025 年基线和 Grand View Research 的 2023 年基线则隐含接近 $11B 的标准化 2026 年数值。这些矛盾不是噪音,而是反映了各方对软件与服务、合规工作流与网络监控、相邻 GRC 范围的处理不同。对 BlueVoyant 而言,把 MDR 与 TPRM 公开基线合并、扣除重叠前,合理的 2026 年核心市场总天花板约为 $12–16B。更实际的 SAM 在套用大型企业、受监管买家和西方市场过滤后收窄到约 $5–8B。公开数据无法支持精确到美元的 SOM,因为 BlueVoyant 不披露分模块收入或胜率,所以 SOM 应被视为受证据约束,而不是被编造出来。[CM009, CM010, CM011, CM012, CM013, CM014]
| 视角 | 发布方 | 年份 / 期间 | 地区 | 数值 | CAGR / 份额 | 方法 | 置信度 | 局限 |
|---|---|---|---|---|---|---|---|---|
| MDR 公开基准 | Precedence Research | 2026 to 2035 | 全球 | 2026 年 USD 3.92B -> 2035 年 USD 13.90B | 15.12% | MDR 市场品类预测 | 中 | 周期很长,且品类定义取决于发布方 |
| MDR 另一公开基准 | Mordor Intelligence | 2026 to 2031 | 全球 | 2026 年 USD 5.09B -> 2031 年 USD 13.45B | 21.45% | 当前品类市场规模测算,包含细分份额 | 中 | 服务范围比部分同行更宽 |
| MDR 第三方公开基准 | The Business Research Company | 2026 to 2030 | 全球 | 2026 年 USD 4.16B -> 2030 年 USD 8.57B | 19.8% | MDR 市场标题预测 | 中 | 时间窗口和范围不同于 Precedence 与 Mordor |
| TPRM 直接 2026 基准 | The Business Research Company | 2026 to 2030 | 全球 | 2026 年 USD 8.09B -> 2030 年 USD 15.45B | 17.6% | TPRM 市场标题预测 | 中 | 可能包含 BlueVoyant 网络安全特定切口之外的解决方案和服务层 |
| TPRM 2026 代理值,来自 2025 基准 | NextMSC | 2025 to 2030 | 全球 | 2025 年 USD 9.71B;折算 2026 年约 USD 11.02B;2030 年 USD 18.28B | 13.48% | 将 2025 基准向前推一年,以便与 2026 口径可比 | 低 | 2026 数字由 2025 基准转换而来 |
| 基于 2023 年基准的 TPRM 2026 年代理值 | Grand View Research | 2023 年至 2030 年 | 全球 | 2023 年为 USD 7.42B;标准化到 2026 年约 USD 11.49B;2030 年达 USD 20.59B | 15.7% | 为保证 2026 年口径可比,将 2023 年基准向前复合推算 | 低 | 2026 年数字由 2023 年基线转换而来 |
| 相邻 GRC 参照 | Mordor Intelligence | 2026 年至 2031 年 | 全球 | 2026 年为 USD 23.32B -> 2031 年达 USD 39.01B | 10.84% | 更宽口径的治理、风险与合规软件市场 | 中 | 可作相邻参照,但口径太宽,不能计入 BlueVoyant 直接核心 TAM |
| BlueVoyant 2026 年核心总天花板 | 分析师基于 MDR + TPRM 基线综合估算 | 2026 年代理值 | 全球 | 约 USD 12.0B 至 USD 16.6B | n/a | 低端和高端分别相加已发布 MDR 与标准化 TPRM 基线,尚未扣除重叠 | 低 | 部分预算重叠被重复计算,且未纳入定价 / 模块组合细节 |
| BlueVoyant 可服务 SAM | 分析师基于品类筛选综合估算 | 2026 年代理值 | 受监管大型企业;北美 / 欧洲权重更高 | 约 USD 5B 至 USD 8B | n/a | 在核心天花板上套用大型企业、受监管买方和西方市场筛选 | 低 | 需要管理层提供地区、细分市场和模块组合数据来验证 |
| BlueVoyant 公开数据下的 SOM | 公开数据视角 | 2026 | BlueVoyant 目标账户 | 公开数据无法支撑 | n/a | 没有公开披露细分收入或模块份额 | 低 | 需要管理层披露收入组合、胜率和客户集中度 |
刻意保留相互矛盾的分析师估计。TPRM 2026 代理行把较早基线转换成统一的 2026 年视角;SAM 和 SOM 行是分析师推导视角,不是公司披露数字。
[CM009, CM010, CM011, CM012, CM013, CM014]从邻近治理语境到 BlueVoyant 更窄的实际 SAM,形成三层视角。
顶层使用 Mordor 的 2026 年 GRC 估算。中层是在重叠扣除前,公开 MDR 和标准化 TPRM 基线的中点。底层是在大型企业、受监管买方和西方市场过滤后的低信心 SAM 中点;它不是公司披露数字。
[CM017, CM018, CM019]以 USD 十亿美元展示低 / 高区间,说明在公司特定过滤之前,已发布的 2026 年市场基线分歧有多大。
MDR 低 / 高值直接来自 Precedence 和 Mordor 的 2026 年基线。TPRM 高值用 Grand View 的 2023 年基数和其披露 CAGR 换算为 2026 年代理值,TPRM 低值使用 TBRC 直接给出的 2026 年数值。核心上限行把重叠前的公开类别区间相加;SAM 是过滤后的估算,不是公司报告数字。
[CM012, CM016, CM018, CM019]2.3 买方、预算所有者与采用路径
买方地图是跨职能的。MDR 侧,经济买方通常是 CISO 或安全负责人,已经掌握 SIEM、EDR 和 Microsoft 安全预算,但需要更好的响应覆盖、更好调优或更多 24x7 产能。TPRM 侧,日常操作者常是供应商风险或合规团队,但付款权可能落在安全、采购、企业风险或受监管业务线负责人手上,取决于供应商敞口在哪里被衡量。采用触发点通常不是抽象的「网络成熟度」,而是近期事件、监管期限、反复问卷疲劳、供应商范围内的零日敞口,或内部意识到第四方风险基本不可见。BlueVoyant 官方界面暗示的采用路径,是先在既有工作流中叠加 MDR 或 TPRM 监控;当领导层判断人工流程太慢后,再扩展到修复、第四方分析和更广的韧性报告。[CM021, CM022, CM023, CM024, CM025, CM026]
| 细分市场 | 买方 | 用户 | 付款方 | 工作流 | 预算负责人 | 采用触发因素 |
|---|---|---|---|---|---|---|
| 大型企业 SOC 现代化 | CISO 或安全副总裁 | SOC 分析师、检测工程师、IR 团队 | 安全运营预算 | 在现有 EDR / SIEM / Microsoft 技术栈上叠加 24x7 监控与响应 | CISO,CIO / CFO 可见 | 告警疲劳、工具蔓延、人手短缺、近期事件 |
| 上市公司第三方网络安全项目 | CISO、第三方风险负责人、审计发起人 | 供应商风险分析师、合规团队、整改协调人 | 安全或 GRC 预算 | 收集证据,持续监控供应商,升级重大发现,支撑董事会报告 | CISO / CRO / 首席合规官 | SEC 治理压力、反复问卷负担、供应商事件 |
| 欧盟或受监管金融韧性项目 | 运营韧性或安全负责人 | 风险团队、韧性办公室、采购、安全运营 | 风险、合规或受监管业务线预算 | 梳理关键供应商,验证网络安全状态,支撑韧性测试和整改 | CRO、CISO、受监管实体高管 | NIS2 式截止期限、关键供应商依赖关系梳理 |
| Microsoft 重度安全环境 | 安全平台负责人或 CISO | Sentinel、Defender、M365 与云安全管理员 | 现有 Microsoft 和安全平台预算 | 调优告警,扩大自动化覆盖,在不替换技术栈的情况下增加托管覆盖 | CISO / 平台负责人 | Microsoft 安全投入利用不足、需要更快响应、内部调优能力有限 |
| 采购与供应商准入项目 | 采购或供应商管理负责人,安全团队共同发起 | 供应商准入分析师、业务负责人、风险评审人 | 采购 / 运营预算,安全团队参与 | 问卷管理、供应商分层、整改跟进、例外追踪 | 采购负责人,安全团队签字 | 供应商准入积压、合同条款执行、跨供应商零日暴露 |
各行混合 MDR 和 TPRM 采购中心,因为 BlueVoyant 同时覆盖两种销售动作。预算归属基于产品适配度和调研证据推断,不是 BlueVoyant 披露的管线数据。
[CM021, CM022, CM023, CM024, CM027, CM029]定性展示 BlueVoyant 的 MDR 和 TPRM 动作中,不同买方画像的权力、预算和触发逻辑如何变化。
单元格为定性内容,综合自 BlueVoyant 的产品表面,以及关于谁感到痛点、谁控制预算的调查证据。这是一张决策地图展项,不是公司披露的细分表。
[CM024, CM025, CM026, CM029, CM030]从最初的网络安全痛点,到在 MDR 和 TPRM 工作流中更广泛采用 BlueVoyant 的典型路径。
该流程为定性内容。它综合触发事件的调查证据和 BlueVoyant 的模块结构;不是已披露的漏斗转化图。
[CM027, CM029, CM037, CM047, CM048, CM049]2.4 增长驱动、监管与类别扩张
2026 年最强需求驱动来自监管、已被证明的第三方事件痛点,以及在技能人才不足下运营碎片化安全项目的成本上升。SEC 披露规则把网络治理和事件重大性纳入美国上市公司董事会流程。NIS2 把欧盟网络义务扩展到 18 个关键行业。CISA 和 NIST 将供应链网络风险定义为正式韧性问题,横跨硬件、软件和托管服务。这套政策栈遇到真实运营痛点:Marsh 报告称,过去一年 70% 的组织经历过重大第三方网络事件,66% 计划增加网络投资;Panorays 则显示多数 CISO 仍缺乏完整供应链可见性和正式泄露响应预案。BlueVoyant 的定位与这些压力吻合,因为它把内部防御和外部供应商敞口中的监控、验证、修复和 AI 辅助分诊组合在一起。[CM025, CM026, CM027, CM028, CM031, CM032]
| 驱动因素 / 约束 | 方向 | 时点 | 对 BlueVoyant 的含义 | 尽调问题 |
|---|---|---|---|---|
| SEC 网络安全披露治理 | 驱动因素 | 当前 | 买方从 SOC 团队扩展到审计、法务和董事会利益相关方;这些人需要有证据支撑的网络安全工作流 | 询问管理层,管线中有多少比例与上市公司治理要求挂钩 |
| NIS2 及更广泛的欧盟网络安全义务 | 驱动因素 | 当前至 2026 年执法周期 | 覆盖行业更急于掌握供应商网络安全状态并提交韧性报告 | 量化 BlueVoyant 对 NIS2 覆盖行业和欧盟总部账户的暴露 |
| CISA / NIST 供应链正式化 | 驱动因素 | 结构性 | 把网络供应链风险确认为一门韧性学科,范围横跨硬件、软件和托管服务 | 测试买方把 SCRM 定义为韧性而非采购合规时,BlueVoyant 是否仍能赢单 |
| 第三方事件频率 | 驱动因素 | 立即 | 真实事件会催生应急预算,用于持续监控、整改和依赖关系梳理 | 要求提供供应商事件加快采购时点的案例 |
| 第四方盲区与集中度风险 | 驱动因素 | 立即且持续扩大 | 强化对依赖关系梳理和直接供应商之外情景分析的需求 | 核实第四方分析有多常扩展既有 TPRM 交易 |
| AI 辅助分诊与 Microsoft 优化 | 驱动因素 | 近期 | 支撑 MDR 向 Microsoft 重度环境加售,也降低服务成本叙事 | 要求独立证明告警量下降和整改时间改善 |
| 工具蔓延与集成薄弱 | 约束 | 持续存在 | 买方工作流彼此断开,会拖慢 MDR 与 TPRM 模块的交叉销售和标准化 | 要求提供因平台重叠或内部集成问题受阻交易的赢单 / 输单数据 |
| MDR 标签混乱与评估拥挤 | 约束 | 当前 | 买方困惑会抬高举证门槛,也更偏向品类归属更清晰或打包能力更强的厂商 | 询问 BlueVoyant 如何对托管 EDR 和更大型 XDR 平台做差异化 |
| 保险价格走软与预算审查 | 约束 | 当前 | 保险价格下行可能削弱一个紧迫性杠杆,即便索赔严重度仍然较高 | 测试网络保险定价走软时,管线质量是否变化 |
| 没有公开披露 SOM | 约束 | 当前 | 市场份额承销因此不精确,仅靠公开证据也难以支撑估值信心 | 要求提供模块级收入组合、ACV 区间和续约 / 交叉销售指标 |
时点和战略含义综合自监管、市场调研和 BlueVoyant 产品定位。约束行和驱动因素行一样,对估值判断很重要。
[CM027, CM031, CM032, CM033, CM034, CM035]2.5 约束、不利信号与估值相关性
市场论点不错,但并非没有摩擦。KPMG 显示,大多数项目仍只与企业风险部分整合,端到端托管服务采用率仍低,这意味着买方常用割裂工具、局部试点或狭窄用例接近 TPRM 与 MDR。CyberProof 警告,一些供应商滥用 MDR 标签,只提供托管 EDR 或工具中心监控,却没有完整的人类响应领导,这制造买方混淆并拖慢类别转化。PeerSpot 拥挤的 MDR 类别和 CRC 关于网络保险定价走软的证据,也强化了一个判断:即使索赔严重性继续上升,预算紧迫感也会回落。估值上,正确结论是 BlueVoyant 所在市场足够大、痛点足够重,但估值倍数压缩仍取决于公司能否把跨类别故事转化为可衡量的模块渗透、更低买方混淆,以及公开数据可支撑的 SOM。[CM036, CM039, CM040, CM041, CM042, CM043]
2.6 图表
03竞争对手
3.1 竞争格局与买方替代方案
BlueVoyant 并不处在一个干净的单一市场盒子里。Gartner 的 2026 年 MDR 市场定义,将托管检测与响应视为供应商运营的一站式 SOC 能力,并强调主动遏制,而非只做告警监控;BlueVoyant 自己的主页则同时营销四个相邻产品:MDR、第三方风险管理、数字风险防护和专业服务。这让竞争场比普通 MDR 候选清单更宽。一侧,BlueVoyant 面对 CrowdStrike、Palo Alto Networks、Arctic Wolf、Rapid7、ReliaQuest 和 eSentire 等直接 MDR 对手。另一侧,它面对 SecurityScorecard、BitSight 等 TPRM 与网络评级平台,也面对 OneTrust 或 ProcessUnity 风格的供应商风险项目和内部 SOC 现状等工作流导向替代方案。实际含义是:当买方想要一个伙伴同时覆盖 SOC 运营和供应商网络防御时,BlueVoyant 可以胜出;当预算所有者把问题收窄为平台原生 MDR 或采购中心的供应商风险自动化时,它可能被替代。[CP001, CP002, CP005, CP027, CP029, CP033]
| 竞争对手 | 品类 | 规模 / 融资信号 | 买方甜蜜点 | 关键差异化 | 相比 BlueVoyant 的主要限制 |
|---|---|---|---|---|---|
| BlueVoyant | 混合 MDR + TPRM / C-SCRM | 600+ 名员工;1,200+ 个 Sentinel 部署;保留的 2026 年来源未更新私募融资 | Microsoft 重度企业、受监管买方、政府供应链 | 结合 MDR、TPRM、DRP 和服务,Microsoft 交付深度强 | MDR 可见度低于最大的平台原生对手;公开融资 / 定价细节偏少 |
| Palo Alto Networks Unit 42 / Cortex XSIAM(平台) | 平台原生 MDR / SOC | 16K+ 名员工;全球 70K+ 客户 | 已标准化 Palo Alto 的大型企业 | 统一 AI SOC 平台,加上 Unit 42 服务和深度一方遥测 | 最佳经济性和结果绑定 Palo Alto 技术栈;TPRM 重叠有限 |
| CrowdStrike Falcon Complete | 平台原生 MDR | 上市公司规模;每月整改 2.7M 次检测;中位遏制时间 1 分钟 | 愿意标准化 Falcon 的企业和安全成熟中型市场客户 | 原生端点、身份、云与 SIEM 遥测,叠加自主和人工响应 | 相比 BlueVoyant 或 ReliaQuest,平台锁定更强,开放技术栈灵活性更低 |
| Arctic Wolf | 开放 XDR MDR | 10K+ 客户;1,000+ 名安全工程师;历史报道 $60M Series D 轮融资和约 $4.3B 估值 | 希望共管结果的中大型企业到企业级买方 | Concierge 交付、开放 XDR、保修和安全旅程模型 | TPRM 和供应链网络防御不是核心采购动作 |
| Rapid7 | 平台主导的托管运营 | 全球 11,500+ 客户;上市公司规模 | 希望统一暴露管理和检测的大型 SMB、中型市场和企业级买方 | Command Platform 连接暴露管理、遥测和托管运营 | 服务身份相比 BlueVoyant 差异化较弱;TPRM 重叠有限 |
| ReliaQuest | 开放平台企业 SecOps | 每天处理 50K+ 告警;255+ 技术合作伙伴;保留页面未披露客户数 | Fortune 1000 和工具异构企业 | 任意来源标准化、智能体 AI 队友和广泛集成深度 | 公开规模和定价披露有限;没有 TPRM 专属数据网络护城河 |
| eSentire | 厂商独立 MDR | 2,000+ 客户,覆盖 35+ 行业;300+ 集成 | 受监管中型市场、私募股权组合公司和高端中型企业团队 | 人工主导遏制,叠加多信号 XDR 和无限狩猎 / 事件处理叙事 | 品牌规模低于最大上市套件,TPRM 也不是核心 |
| SecurityScorecard | 威胁情报驱动的 TPRM / 供应链检测 | 3,300+ 客户组织;12M+ 被监控和评级组织 | 供应商风险、网络保险、采购和董事会报告项目 | 持续评级,加上 AI 评估自动化、第 N 方可见性和整改工作流 | 托管 SOC 深度弱于 BlueVoyant MDR;外部视角方法不能替代内部遥测 |
| BitSight | 网络风险情报 / TPRM | 3,500+ 客户;68K+ 活跃组织;75K+ 已映射供应商画像 | 以评级为中心的企业风险和供应链项目 | 大规模已映射供应链数据集、独立验证的评级主张和强分析师认可 | MDR 不是核心,客户可能仍需要单独的工作流或服务层 |
| 内部 SOC / 仅工作流项目 | 现状 / 替代方案 | 买方自筹人员、工具或 GRC 套件预算 | 超大型企业或合规主导的采购团队 | 如果已有工作流套件,可获得最大控制权或最低增量支出 | 相比完整 MDR,人手负担最高或威胁响应结果更弱 |
规模信号混合了员工、部署、客户数、供应商画像和历史私募融资标记;这些指标只看方向,不能直接类比收入。
[CP002, CP005, CP011, CP012, CP014, CP017]基于证据的竞争者开放度与预算宽度序位视图;y 值越高,说明在 SOC、采购、保险或供应链工作流中的重叠越广。
坐标轴是根据留存产品页面和市场指南推导的序位评分,而非经审计市场份额数据。X = 技术栈开放度 / 工具中立性,从 1(封闭套件)到 5(开放生态)。Y = 预算宽度,从 1(仅 SOC)到 5(SOC 加供应链 / 采购 / 保险相关性)。
[CP001, CP002, CP014, CP021, CP027, CP032]3.2 MDR 正面对比:平台套件 vs 开放栈供应商
BlueVoyant 周围的 MDR 市场分成两类经济属性不同的竞争者。Palo Alto Networks 和 CrowdStrike 把托管响应作为更大专有平台的延伸来销售;它们的卖点是自动化深度、原生遥测和捆绑经济性。Palo Alto 在 Cortex XSIAM 的统一 SIEM、SOAR、EDR、NDR 和 CDR 栈之上叠加 Unit 42 服务;CrowdStrike 的 Falcon Complete 强调一分钟中位遏制时间、每月数百万次修复,以及来自 Falcon 生态的端点、身份、云和第三方深度遥测。Arctic Wolf、ReliaQuest、Rapid7 和 eSentire 从相反方向进攻:它们把自己定位为更开放、服务更重的伙伴,可跨既有工具资产工作。Arctic Wolf 主打 concierge 交付和开放 XDR;ReliaQuest 主打任意来源归一化和广泛集成;Rapid7 主打暴露管理加检测;eSentire 主打厂商无关 XDR 和人类主导遏制。运营上,BlueVoyant 更接近第二阵营,但比多数同类对手拥有更强的 Microsoft-specific 服务身份。[CP003, CP004, CP009, CP010, CP011, CP012]
| 采购标准 | BlueVoyant | Palo Alto | CrowdStrike | Arctic Wolf | Rapid7 | ReliaQuest | eSentire | SecurityScorecard | BitSight |
|---|---|---|---|---|---|---|---|---|---|
| 动手托管响应权限 | 高 | 高 | 高 | 高 | 中 | 高 | 高 | 低 | 低 |
| 专有平台锁定压力 | 中 | 高 | 高 | 低 | 中 | 低 | 低 | 低 | 低 |
| Microsoft 生态深度 | 高 | 中 | 中 | 中 | 中 | 中 | 中 | 低 | 低 |
| EDR / SIEM 开放性 | 中 | 低 | 低 | 高 | 中 | 高 | 高 | 低 | 低 |
| 第三方 / 供应链网络监控 | 高 | 低 | 低 | 低 | 低 | 低 | 低 | 高 | 高 |
| 董事会 / 采购 / 保险报告效用 | 中 | 中 | 中 | 中 | 中 | 中 | 中 | 高 | 高 |
| 公开传递的 AI / 智能体路线图 | 高 | 高 | 高 | 高 | 高 | 高 | 高 | 高 | 高 |
| 混合工具企业最佳适配 | 中 | 低 | 低 | 高 | 中 | 高 | 高 | 低 | 低 |
高 / 中 / 低由作者根据留存的公开产品页面和独立买家指南判断;这些评级反映公开披露的能力和运营模式,不代表经审计的基准性能。
[CP003, CP009, CP012, CP014, CP016, CP020]压缩能力地图,展示 BlueVoyant 与 MDR 套件厂商、TPRM 平台的重叠位置。
高 / 中 / 低取值是作者基于留存公开文档和买方指南来源作出的评估;它们展示公开能力叙事,不是经审计功能同等性。
[CP003, CP006, CP013, CP023, CP025, CP028]3.3 供应链与 TPRM 竞争
BlueVoyant 的供应链防御带来一组不同于 MDR 对手的买方替代方案。SecurityScorecard 和 BitSight 是最清晰的重叠者,因为两者都把网络风险框定为对供应商敞口的持续、由外向内视图,再把数据连接到董事会报告、采购监督、保险工作流和修复项目。SecurityScorecard 进一步把自己呈现为供应链检测与响应,具备问卷自动化、nth-party 可见性和 AI 辅助修复。BitSight 则把大型映射供应商网络、Forrester 认可的评级可信度,以及覆盖数千万家受监控公司的网络风险情报数据集组合起来。独立市场指南也指出,许多买方不会止步于评级工具;他们会把评级工具与 ProcessUnity、OneTrust、Venminder 或内部问卷项目等工作流中心平台搭配使用。对 BlueVoyant 来说,这很重要,因为其由外向内 C-SCRM 主张不只与竞争数据网络竞争,也与工作流软件竞争;除非 BlueVoyant 证明修复更快、分析师参与更强,否则独立情报层容易显得可替换。[CP006, CP007, CP021, CP022, CP023, CP024]
3.4 BlueVoyant 差异化、打包方式与可能胜区
BlueVoyant 最有特色的公开故事,是 Microsoft-heavy MDR、由外向内供应商防御和相邻数字风险服务的组合,而不是宣称自己是最佳端点或评级厂商。其保留页面强调 1,200 多个 Microsoft Sentinel 部署、24x7 区域 SOC 覆盖、50 多名认证 Microsoft 交付和 SOC 工程师,以及一个政府产品:无需专有供应商数据,就能用 70,000 多个数据源映射数万家供应商。2026 年 6 月 BlueVoyant AI 发布增加了第二个重要角度:管理层正试图从纯服务走向 agentic SecOps 平台,既可作为托管服务消费,也可作为 self-service SaaS 使用。这让 BlueVoyant 在受监管、Microsoft-heavy 环境中有可信胜区,尤其当买方想用一个供应商覆盖托管 SOC 运营和第三方网络防御时。若买方想在单一专有安全套件内把调查负担降到最低,或采购主导的 TPRM 项目已经偏好评级厂商加工作流软件,BlueVoyant 就不那么合适。[CP003, CP004, CP006, CP007, CP008, CP027]
| 厂商 | 公开价格可见度 | 合约 / 打包信号 | 公开重点 | 竞争含义 |
|---|---|---|---|---|
| BlueVoyant | 留存页面未公开标价 | 平台与托管服务按报价打包 | MDR、TPRM、DRP 与专业服务一起销售 | 交叉销售灵活性是优势,但外部买家无法靠公开页面对标标价 ACV |
| CrowdStrike Falcon Complete | 留存页面未公开标价 | Falcon 平台上的按报价 MDR | 智能体式 MDR、确定性自动化和广泛原生遥测 | 已使用 Falcon 的客户可以把支出纳入更大的平台合约 |
| Palo Alto Networks | 留存页面未公开标价 | 按报价销售 XSIAM 与 Unit 42 托管服务 | 统一 SOC 技术栈和托管服务 | 在大型套件客户中,打包经济性可能压低服务驱动型挑战者的空间 |
| Arctic Wolf | 留存页面未公开标价 | 安全运营包,配套礼宾式交付和保障 | 结果导向的托管服务,而不是工具采购 | 吸引想外包结果的买家,但公开可比性仍然偏低 |
| Rapid7 | 留存页面未公开标价 | 平台订阅加托管运营 | 暴露面管理 + SIEM + 托管运营 | Rapid7 客户有自然扩张路径,但公开定价不透明仍需尽调 |
| ReliaQuest | 留存页面未公开标价 | 企业平台,部署高度依赖集成 | GreyMatter 支持任意来源运营和集成 | 最适合复杂企业,但采购很可能仍是定制化、服务占比高 |
| eSentire | 留存页面未公开标价 | 托管 MDR / XDR 服务合约 | 强调不限次数威胁狩猎和事件处置 | 适合结果导向买家,但早期筛选名单的成本比较不够透明 |
| SecurityScorecard / BitSight | 留存页面未公开标价 | 评级 / TPRM 项目按报价销售 | 持续监控、问卷、AI 摘要、供应商网络情报 | 预算路径通常走采购、风险或保险,而不是 SOC |
本表只比较价格可见度和打包信号。留存的官方页面通常不披露企业标价,因此合约金额和实际折扣仍是尽调缺口。
[CP041, CP042, CP043, CP044]六项公开指标概括 BlueVoyant 截至 2026 年 6 月的竞争位置,同时纳入优势和反向信号。
[CP003, CP005, CP007, CP008, CP034, CP040]3.5 弱点、不利证据与护城河持久性
最重要的反证并不是 BlueVoyant 缺少产品宽度,而是更大竞争者可以用更强市场可见度或更低运营摩擦来框定同一项工作。PeerSpot 2026 年 6 月评论页显示,BlueVoyant 的 MDR mindshare 仅 0.9%,低于一年前的 1.2%;其直接对比页将 BlueVoyant 排在第 34 位,而 CrowdStrike 第 2 位,并指出 BlueVoyant 报告定制较弱、配置可能更重。Daylight 的 2026 年买方指南更直白:它把 BlueVoyant 归入 MSSP-style MDR 供应商,买方选择它是为获得广泛安全伙伴关系,但其工作流比 AI-native 或 XDR-extended 替代方案更依赖分析师工时。TPRM 侧,BlueVoyant 还必须防御 SecurityScorecard 和 BitSight 规模大得多的外部数据网络。几乎所有保留竞品页面都缺乏公开定价,加剧了挑战,因为从外部很难基准化既有套件捆绑和多产品折扣。因此,BlueVoyant 在跨预算服务宽度上有真实护城河,但在类别可见度、数据网络规模或平台锁定上,护城河并不显然持久。[CP017, CP018, CP034, CP035, CP036, CP037]
| 护城河或风险判断 | 主要威胁 | 严重度 | 当前缓释信号 | 尽调问题 |
|---|---|---|---|---|
| Microsoft 专项 MDR 深度 | CrowdStrike、Palo Alto 和 Microsoft 原生替代方案能提供更强原生自动化或打包经济性 | 高 | BlueVoyant AI 发布和 1,200+ 个 Sentinel 部署强化了专项能力叙事 | 拆分 Microsoft 重度客户与非 Microsoft 客户的收入结构 |
| 跨预算的 MDR + TPRM + DRP 定位 | 买家可能仍会拆分 SOC 与供应商风险预算,分别选择最佳单点工具 | 高 | BlueVoyant 将四条销售动线一起推广,政府 C-SCRM 又拓宽了叙事 | 衡量多产品附加率,以及从 MDR 扩张到 TPRM 的情况 |
| 由外向内的供应商照明 | SecurityScorecard 和 BitSight 运营规模大得多的公开数据网络,评级品牌也更强 | 高 | BlueVoyant 增加分析师主导的整改和政府任务框架,而不只卖评级 | 对标评级厂商,测试供应商覆盖、误报和整改速度 |
| 服务驱动型交付模式 | AI 原生和平台原生 MDR 能把更多调查负担转给软件和自动化 | 高 | BlueVoyant AI 推动模式转向智能体式 SecOps 和自助式 SaaS | 测试 BlueVoyant AI 部署前后的分析师 / 客户杠杆率和升级负载 |
| 公开定价不透明 | 套件厂商可以把折扣藏进更大的合约,使单独比较更难 | 中 | 买家想要单一合作伙伴时,BlueVoyant 可以把 MDR 和 TPRM 打包 | 尽调中获取口径一致的 ACV、爬坡和续约基准 |
| MDR 市场能见度较低 | PeerSpot 心智份额和排名显示,进入短名单的吸引力弱于 CrowdStrike 或品类领导者 | 中 | BlueVoyant 可以瞄准受监管或 Microsoft 主导的用例,而不是泛化 MDR 比拼 | 按垂直行业验证企业品牌认知和 RFP 入围率 |
严重度是作者基于留存公开证据的判断。尽调问题指向需要哪些私有数据,才能测试已观察到的护城河或风险是否持久。
[CP017, CP018, CP034, CP035, CP036, CP037]04财务
4.1 收入模式与变现可见度
BlueVoyant 的公开商业界面看起来像一套围绕 MDR、TPRM、DRP 和专业服务包装的经常性网络安全平台,而不是一次性项目业务。主页和产品材料强调持续监控、响应、修复和下架工作;客户证明和 TEI 研究也强化了订阅或 retainer 式价值主张。话虽如此,公开记录在结果上远强于变现细节。BlueVoyant 披露部署数量、ROI 主张和 marketplace 采购路径,但不发布核心产品标准标价,也不展示实际成交价、折扣或经常性托管服务与项目型工作的收入组合。结果是,营收机制清晰,但收入质量和各收入流贡献利润率仍不完整。[CI001, CI002, CI003, CI004, CI005, CI006]
| 收入流 | 机制 | 公开证据 | 变现可见度 | 质量 / 注意事项 | 尽调问题 |
|---|---|---|---|---|---|
| 托管检测与响应 | 经常性托管监控和响应 | 1,200+ 个 Sentinel 部署;24x7 SOC 覆盖 | 合约制 / 经常性,但标价不公开 | 需求代理指标强;定价透明度弱 | 索取合约条款、按席位 / 设备计费口径,以及按客户分群的毛利率 |
| 第三方风险管理 | 经常性监控、验证和整改支持 | 整改速度快 18x;准确率 98%;GCP 市场渠道 | 经常性 / 可走企业采购 | 结果数据强;收入兑现不透明 | 索取按供应商计价、整改费用和附加率 |
| 数字风险防护 | 持续监控和下架服务 | 两年下架 50,000 个域名;社交和网站下架成功率 | 可能是经常性服务包 | 活动信号强;未披露价格 | 索取按受保护品牌 / 账号计价,以及下架经济性 |
| 专业服务 / DFIR | 项目、长期服务合约和咨询收入 | 主页和案例研究把事件响应、战略服务与 MDR 并列定位 | 项目 / 长期服务合约组合未披露 | 相比 MDR / TPRM,收入最可能更波动 | 索取长期服务合约附加率和服务利用率数据 |
官方页面清楚展示了收入机制,但没有对收入流组合、实际定价或收入流层面的利润率做勾稽。
[CI001, CI002, CI004, CI005, CI006, CI007]| 产品 / 渠道 | 公开定价信号 | 实际定价可见度 | 采购路径 | 收入含义 |
|---|---|---|---|---|
| MDR / SOC 外包 | 自建与购买对比页面提出自建成本 >$1.2M,MSSP 替代方案 <25% | 未公开合约价格或单端点费率 | 直销和合作伙伴 | 价值主张明确,但实际 ASP 和毛利率未知 |
| GCP Marketplace 上的 TPRM | 市场上架信息公开;未披露数字标价 | 未公开净价、折扣或最低承诺 | 云市场 / 企业协议 | 应能降低采购摩擦并缩短渠道周期 |
| Microsoft 优化服务 | 博客称内部优化每年最高可花 $750k | 未披露 BlueVoyant 服务价目表 | 企业直销,可能偏咨询式销售 | 支撑咨询式追加销售逻辑,但不代表 BlueVoyant 实际定价兑现 |
| 合作伙伴辅助成交 | 2021 年合作伙伴贡献新业务的 50% | 未披露渠道折扣和收入分成 | 经销商、咨询公司和技术合作伙伴 | 可能提升漏斗前端效率,同时压缩实际成交价格 |
| 客户案例扩张 | Odeon 和 Snappi 展示多产品落地后扩张路径 | 未披露合约金额 | 直销 / 合作伙伴混合 | 支撑钱包份额叙事,但没有给出单账户 ARR |
本表把公开采购路径与缺失的实际价格数据分开;公开记录展示买家如何购买,不展示实际支付金额。
[CI012, CI013, CI017, CI034, CI035, CI038]BlueVoyant 把直销需求、伙伴需求和云市场入口转成经常性托管安全收入,外加一层规模较小的专业服务;但公开材料没有披露到可量化已实现毛利的程度。
这张桥接图是定性的:公开材料给出了上市路径和结果,却没有披露已实现收入结构,也没有按收入流拆出毛利率。
[CI001, CI011, CI017, CI034, CI038, CI060]4.2 GTM 动作与销售效率代理指标
BlueVoyant 似乎依靠直销企业、伙伴带动需求和低摩擦云 marketplace 采购的混合模式扩张。公司明确表示,伙伴在 2021 年贡献了全部新业务的一半;渠道页面也显示,经销商和咨询关系是核心,而非附带。这很重要,因为伙伴杠杆可以抵消 24x7 托管服务通常伴随的人力密度。BlueVoyant 还营销相对自建 SOC 的硬成本节省,声称自建每年可超过 $1.2 million,而 MSSP 成本可低于该水平的四分之一。客户价值研究提供了更多证据,尽管由公司赞助:Forrester TEI 材料、ODEON 成果和 Sentinel 案例研究指南都指向显著运营节省,但仍未给出真正的 CAC、回本周期或实际毛利率数据。[CI011, CI012, CI013, CI017, CI029, CI030]
| 代理指标 | 公开数值 / 状态 | 置信度 | 重要性 | 尽调问题 |
|---|---|---|---|---|
| 2018 年以来 ARR 增长 | 声称平均增长 117% | 中 | 如果方向仍然成立,说明收入端动能强 | 索取按年份审计的 bookings / ARR 桥表 |
| 合作伙伴来源新业务 | 2021 年新业务的 50% | 中 | 显示直销人头之外的分销杠杆 | 索取合作伙伴来源管线、胜率和利润分成 |
| 自建与购买替代成本 | >$1.2M 自建年度 SOC 成本 | 中 | 界定客户 ROI 和支付意愿上限 | 索取 ROI 模型假设和真实竞争胜负数据 |
| 外包 SOC 节省成本说法 | <25% 的内部 SOC 成本 | 中 | 支撑回本叙事,但不代表实际成交价 | 索取合约样本和客户回本模型 |
| MDR TEI 价值代理指标 | 210% ROI;升级告警减少 90%;MTTR 加快 70% | 中 | 如果样本有代表性,支撑留存和扩张判断 | 索取客户分群方法和非赞助客户推荐 |
| 供应链防御价值代理指标 | ~300% ROI;关键风险整改快 62% | 中 | 显示 TPRM 经济性可能高于纯合规工具 | 索取 TPRM 账户的客户留存和扩张指标 |
这些是销售效率和价值代理指标,不是闭环单位经济;公开证据偏方向性,且大多由公司赞助。
[CI017, CI018, CI029, CI030, CI031, CI032]BlueVoyant 给出了较强的客户价值代理指标和外包经济性,但公开证据链在 CAC、回本周期和利润率可直接测算之前就断开了。
节点概括的是证据质量,不是隐藏的内部遥测;下游经济性输出仍有意保持未解。
[CI012, CI013, CI017, CI029, CI030, CI031]4.3 公开规模信号与运营杠杆代理指标
BlueVoyant 官方规模叙事在增长方向上强且内部一致,但对当前精确规模不够一致,无法无保留承销。官方新闻稿从 2022 年初 30 个国家超过 700 家客户,推进到 2024 年中 900 多家全球客户,再到 2025 年 3 月 45 个以上国家超过 1,000 家客户。员工数信号更不均:BlueVoyant 称拥有 600 多名员工,GetLatka 估约 650 人,Dialectica 列出 653 人,一个可访问的历史 PitchBook 快照仅显示 363 名员工。这个跨度太大,不能忽略,尤其是收入 / 员工和销售效率代理指标会随分母不同而显著改变。谨慎解读是:BlueVoyant 具备真实企业规模和国际交付覆盖,但公开数据库在精确运营基线上仍陈旧或不一致。[CI010, CI014, CI015, CI016, CI020, CI025]
| 指标 | 2022 信号 | 2024 信号 | 2025 / 数据库信号 | 注意事项 |
|---|---|---|---|---|
| 客户数量 | >700 个客户,覆盖 30 个国家 | >900 个全球客户 | >1,000 个客户,覆盖 >45 个国家 | 增长路径方向上强劲,但当前精确数量仍是公司口径 |
| 员工数 | Series D 时 >560 名员工 | 公司页面显示 >600 名员工 | 650 (GetLatka); 653 (Dialectica); 363 (历史 PitchBook) | 私有数据库互相不一致,部分快照已经过时 |
| 合作伙伴杠杆 | 合作伙伴贡献新业务的 50% | 官方网站上的渠道名单变宽 | TPRM 新增市场采购路径 | GTM 信号好,但披露的经济性弱 |
| 交付规模 | 1,200+ 个 Sentinel 部署;24x7 SOC | ODEON 覆盖 8 个国家和 280+ 家影院 | 指南显示数百个部署 / 16 个案例研究 | 规模已有证明,但并非所有部署都会转化为可比 ARR |
| EMEA 投资 | 2021 年扩张到 >10 个国家 | 2024 年搭建财务职能并推进收购整合 | Cork 启动,本地收入 2024 年 +70% | 规模信号支撑增长,不支撑盈利能力 |
这些代理指标混合了官方披露和私有数据库快照;它们适合判断趋势方向,不适合作为干净的单期经营基线。
[CI010, CI015, CI016, CI017, CI020, CI021]4.4 资本基础、投资者财团与互相冲突的私营公司信号
BlueVoyant 资本历史明确包括两轮大型后期融资:2022 年 $250 million Series D,以及 2023 年与 Conquest Cyber 收购绑定的超过 $140 million Series E。Liberty Strategic Capital 和 ISTARI 是该投资者基础中的反复锚点,Eden Global Partners 也多次以顾问或参与方身份出现。除此之外,第三方数据库开始分歧。CB Insights 和 Clay 都报告累计融资约 $665.5 million,Tracxn 则报告 $696 million;投资者数量从历史 PitchBook 快照的 9 家,到 Clay 的 11 家和 CB Insights 的 15 家不等。收入信号分歧更大:GetLatka 给出 2025 年 $213.5 million 估算,CB Insights 则给出 2024 年 $750 million。这些矛盾不能证明任何单一来源是错的,但足以说明,公开 / 私有数据尾迹没有充分对齐,若无管理层确认,不足以支持投资承销。[CI019, CI021, CI022, CI023, CI024, CI041]
| 维度 | 公开信号 | 有来源支持的数值 / 状态 | 承销含义 | 尽调问题 |
|---|---|---|---|---|
| Series D 股权资本 | 大型后期融资 | 2022 年 Series D,$250M,Liberty Strategic Capital 领投 | 为规模扩张和招聘提供实质性资产负债表支持 | 索取投后现金桥表和资金用途 |
| Series E + 收购资本 | 与收购挂钩的增长资金 | 2023 年伴随 Conquest 收购完成 > $140M Series E | 显示投资人持续支持,也显示 M&A 意愿 | 索取整合预算和 Conquest 收入贡献 |
| 投资人基础深度 | 战略赞助方重复出资 | Liberty、ISTARI/Temasek、Eden、8VC,加上各数据库不一的投资人数量 | 财团质量看起来强,但确切广度不一致 | 索取当前股权结构表和按轮次的所有权 |
| 债务 / 杠杆信号 | 仅留存历史公开债务痕迹 | PitchBook 快照显示 2020 年 Debt-PPP 条目;未留存当前债务额度 | 当前杠杆可能为零、温和,或只是未披露 | 索取债务明细、贷款人名称和契约包 |
| 现金 / 烧钱 / 资金续航期 | 未公开披露 | 截至运行日,没有留存公开来源验证这些指标 | 这是最大的承销障碍 | 索取最新现金余额、烧钱和资金续航模型 |
| 区域扩张承诺 | EMEA 搭建和 SOC 扩张可见 | Cork 开业绑定数百万欧元投资和 70% 本地收入增长 | 即使没有现金披露,扩张仍说明支出还在继续 | 索取 EMEA 招聘计划、opex 和预期回本 |
历史融资时间线放在公司概览中;本表聚焦未来充足性和承销所需的当前盲点。
[CI019, CI022, CI023, CI026, CI028, CI041]| 指标 | 来源 A | 来源 B | 来源 C | 冲突原因 / 使用方式 |
|---|---|---|---|---|
| 累计融资 | CB Insights: 9 轮融资 $665.5M | Clay: 累计融资 $665.5M | Tracxn: 6 轮融资 $696M | 共识大致落在 $600M 中段,但轮次数和处理口径不同;管理层应提供股权结构表 |
| 收入 / ARR | GetLatka: 2025 年 $213.5M | CB Insights: 2024 年 $750M | 没有官方收入披露 | 这些数字无法直接勾稽,可能分别反映 ARR、更广义收入或过时估算 |
| 员工 | 公司页面: >600 | GetLatka: 650; Dialectica: 653 | PitchBook 快照: 363 | 较新来源集中在 600+,可访问的 PitchBook 快照看起来过时或不完整 |
| 投资人数量 | Clay: 11 名投资人 | CB Insights: 15 名投资人 | PitchBook 快照: 9 名投资人 | 数据库覆盖不同;应使用公开轮次公告并索取股权结构表,而不是依赖单一数量 |
| 最新交易历史 | 官方 / 新闻来源显示 2023 年 Series E $140M | 可访问的 PitchBook 快照显示最新交易金额为 $30M | PitchBook 还显示历史 Debt-PPP 条目 | 过时或归档的画像可能大幅扭曲当前融资和杠杆假设 |
重点不是选择偏好的数据库,而是在管理层勾稽之前保留相互矛盾的估算。
[CI042, CI043, CI044, CI045, CI046, CI047]公开浮现的融资、收入、客户和员工数字跨度很大,因为公司仍是私有企业,各数据库快照也不一致。
区间刻意保留年份和来源方法之间的矛盾,而不是把它们压成一个虚假的点估计。
[CI042, CI044, CI045, CI046, CI047, CI049]4.5 财务结论与尽调阻塞项
保留证据支持这样一家公司:真实经常性需求、充足私募资本背书,以及足够重要的企业客户宽度。但证据并不支持干净的财务承销案例。现金、烧钱速度、runway、债务义务、实际定价、毛利率、留存、CAC 和回本周期仍在公开记录之外。历史 PPP 债务信号和英国备案轨迹显示有公司文件活动,但无法回答当前杠杆或流动性问题。不利的员工评论没有推翻增长叙事,却提示资源约束可能与收购式扩张和高管扩编并存。因此,正确财务结论是建设性但仅凭公开证据不可投资:BlueVoyant 看起来具备商业意义,但仍需要管理层数据来判断收入质量、运营杠杆和下一轮融资依赖。[CI026, CI028, CI053, CI054, CI055, CI056]
| 缺失指标 | 重要性 | 当前代理指标 | 具体尽调路径 |
|---|---|---|---|
| 账上现金 / 资金续航期 | 决定融资依赖和下一轮融资紧迫性 | 只有历史大型融资和持续扩张可作代理 | 索取当前资产负债表、现金预测和董事会资金续航情景材料 |
| 月度烧钱和招聘计划 | 显示增长是自我供血还是消耗现金 | Cork 扩张、CFO 搭建和客户增长是间接代理 | 索取月度烧钱桥表、招聘计划和预算差异 |
| 按产品线拆分毛利率 | 需要把软件式经常性经济性和人力密集型服务经济性拆开 | TEI 和案例研究展示结果,不展示毛利 | 要求提供 MDR、TPRM、DRP 和服务的毛利率与利用率 |
| 实际成交价格 / 折扣 | 需要判断价格纪律和续约质量 | 公开材料只呈现 marketplace 路径和自建 / 外购框架 | 要求提供价格手册、折扣审批记录和近期合同样本 |
| 债务期限表和契约 | 需要理解杠杆、限制条款和再融资风险 | 直接浮现的只有 2020 年 Debt-PPP 历史痕迹 | 要求提供贷款人协议、契约包和任何并购相关借款 |
此处的 null 是有意保留的尽调阻断项,不是格式遗漏;它们标出承销所需的最低数据集。
[CI052, CI058, CI059, CI060, CI061, CI062]4.6 图表
05产品与技术
5.1 平台定义与融合架构
BlueVoyant 现在营销自己时,较少说成独立 MDR 供应商,更多说成统一网络防御操作系统。主页、Cyber Defense Platform 页面和 2024 年发布材料一致描述了一个 cloud-native 平台,横跨内部防御、第三方风险和外部数字风险监控。这很重要,因为产品定义贴着客户工作流:安全团队可以在同一运营模型下运行内部 SOC 分诊、供应商修复以及品牌或凭证下架,而不必把分散点工具拼起来。公司较新的 AI 层强化了这一融合论点,而不是取代它;BlueVoyant AI 被描述为一个控制平面,用来决定何时把工作路由给确定性自动化、何时调用人类分析师、何时让 agents 行动。尽调正面结论是,产品组合打包有一致性。尽调保留意见是,除少数 Microsoft-specific 文档外,公开架构仍停留在营销层深度。[CE001, CE003, CE004, CE005, CE006, CE007]
| 模块 / 资产 | 主要买方或用户 | 当前公开成熟度 | 差异化信号 | 尽调缺口 |
|---|---|---|---|---|
| Cyber Defense Platform(网络防御平台) | CISO、SOC 负责人、安全运营团队 | 当前伞形产品 | 在一个云原生界面上汇聚 MDR、TPRM、DRP 和服务 | 没有公开架构文件展示共享 schema、租户或数据路由细节 |
| BlueVoyant AI | BlueVoyant SOC 或客户 SOC | 2026 年新发布 / 正在推向市场 | Agentic 模型把人工判断、确定性自动化和 AI agents 组合起来,既支持托管部署,也支持自助部署 | 没有公开基准包说明误报下降、MTTR 变化或模型治理细节 |
| MDR for Microsoft(托管检测与响应) | Microsoft 原生安全团队 | 核心产品,证据很扎实 | 组合中最具体的技术证据,包括租户内数据处理和具体 Microsoft 技术栈覆盖 | Microsoft 工具之外的广度仍只在更高层级描述 |
| Continuous Optimization for Microsoft Solutions(持续优化) | 安全工程、合规和平台运维团队 | 当前模块 / 咨询加软件层 | 从监控延伸到 Sentinel、Defender、M365 和 Purview 优化 | 商业包装、可重复性和自动化深度未公开拆分 |
| Third-Party Risk Management / Supply Chain Defense(第三方风险 / 供应链防御) | 供应商风险、采购和网络风险团队 | 当前产品,公开材料显示功能完整 | 结合连续监控、修复、问卷和咨询工作,而不只是被动评分 | 软件贡献和分析师人力贡献未公开量化 |
| Digital Risk Protection | 品牌保护、欺诈和外部风险团队 | 当前产品,模块化 | 覆盖 web、社交、app、暗网和高管保护工作流,并披露下架指标 | 结果质量取决于外部平台和合作伙伴响应速度 |
| Conquest 增强的合规与态势层 | 国防、政府和受监管买方 | 整合阶段的能力扩展 | 增加风险成熟度、态势和合规映射,对 CMMC 密集环境有用 | 公开来源没有说明 Conquest 工作流现在多大程度嵌入核心 BlueVoyant UX |
各行把当前营销中的模块,与并购扩展而来、仍主要靠发布材料佐证的态势 / 合规层分开。
[CE001, CE003, CE007, CE011, CE019, CE025]公开产品叙事可拆成五层栈:从信号采集,到 AI 编排,再到分析师驱动的结果。
该图综合了当前产品页、发布稿、信任中心元数据和 Microsoft 材料,并非复制供应商发布的系统图。
[CE004, CE005, CE006, CE007, CE016, CE030]5.2 Microsoft-centric MDR 与 agentic SOC 运营
最具体的技术深度在 BlueVoyant 的 Microsoft 生态故事里。MDR 套件明确嵌入 MDR for Microsoft 和 Continuous Optimization for Microsoft Solutions,Microsoft-specific 页面也比泛平台文案更精确。BlueVoyant 公开声称覆盖 Microsoft 安全栈的 24/7 防护,拥有多个伙伴称号和专业化认证,围绕 Sentinel 与 Defender 有大型参与基础,并采用一种交付模式:客户安全数据可留在客户 tenant 内,而不是导出到 MSSP 控制的数据湖。2026 年 BlueVoyant AI 发布通过描述自动遏制动作、托管或 self-service 部署选择,以及用多年 Microsoft-native 运营历史训练的模型,扩展了这一位置。实践中,这意味着 BlueVoyant 最强技术护城河不是广泛开放集成目录,而是围绕 Microsoft 环境的流程深度、调优、自动化和分析师工作流。[CE002, CE006, CE007, CE008, CE009, CE010]
| 用户任务 | 当前工作流问题 | BlueVoyant 方案 | 已披露收益或运营信号 | 局限 |
|---|---|---|---|---|
| Microsoft SOC 分诊和遏制 | Sentinel、Defender、身份、终端和云界面上的告警太多 | MDR for Microsoft 加 BlueVoyant AI | 明确营销 24/7 监控、自动响应动作和高保真告警 | 公开证据最强的是主张本身,不是独立衡量的结果 |
| Microsoft 成本和态势优化 | 客户为 Sentinel、Defender、M365 和 Purview 支付过多,或配置不足 | Continuous Optimization for Microsoft Solutions(持续优化) | BlueVoyant 称有 1,000+ 次项目,并提供许可和 Sentinel 消耗的成本控制指导 | 节省方法和客户实际分布未公开 |
| 第三方关键发现修复 | 供应商风险团队能发现问题,但难以推动闭环 | Continuous Monitoring & Remediation | ROC 分析师验证发现,并直接联系第三方 | 没有按客户分层披露闭环率分布 |
| 供应商评估运营 | 问卷靠人工,速度慢,也难验证 | Questionnaire Management 平台和托管服务 | 自动化加供应商主张验证被呈现为差异化点 | 公开材料没有展示与客户 GRC 技术栈的集成 |
| 品牌冒充下架 | 钓鱼网站、假页面和恶意 app 在多个平台上快速迁移 | Brand Protection | 营销材料称支持无限下架和覆盖 300+ app store,首页披露了成功指标 | 下架成功仍取决于注册商、社交平台或 app store 配合 |
| 凭据、欺诈和泄露监控 | 安全团队看不见地下社区和泄露数据 | Dark Web Watcher | 材料描述了地下来源连续监控,以及账号接管和泄露处理工作流 | 公开证据没有展示信噪比或发现时间分布 |
| 面向高管的攻击预防 | VIP 在核心 IT 控制之外面临个人数据暴露和账号接管风险 | Executive Cyber Guard | 实时告警和阻断攻击的工具属于营销中的工作流 | 公开材料未量化采用情况或衡量后的高管风险下降 |
本表聚焦用户任务和运营工作流,不聚焦合同 SKU 或内部包名。
[CE007, CE008, CE012, CE015, CE021, CE023]BlueVoyant 偏 Microsoft 的工作流从遥测和身份信号开始,随后进入 AI 辅助分诊、人工验证,以及遏制或优化动作。
该流程突出以 Microsoft 为中心的 MDR 路径,因为这部分公开证据最具体。
[CE007, CE008, CE012, CE015, CE016, CE018]5.3 第三方风险与供应链工作流
BlueVoyant 的供应链防御材料足够具体,可以把 TPRM 视为产品化工作流,而不是围绕外部评级的咨询包装。当前 TPRM 概览、持续监控页面和 2023 年扩张发布对齐在同一运营模型上:按风险对供应商监控分层,BlueVoyant 分析师在 Risk Operations Center 内验证发现,修复直接与供应商推进,而不是完全留给客户。问卷管理也被描述为软件和托管服务兼具,这符合 BlueVoyant 的整体模式:在工作流混乱处,把自动化与劳动密集执行结合。公开来看,最有证据支撑的差异点是分析师引导修复、零日告警、基于 AI/ML 的业务风险监控,以及把持续监控与定期尽职评估结合的能力。剩余尽调问题是,其中多少来自可重复软件杠杆,多少来自专家配置和服务流程纪律带来的规模。[CE019, CE020, CE021, CE022, CE023, CE024]
| 层 / 组件 | 作用 | 关键依赖 | 主要风险 |
|---|---|---|---|
| 客户遥测和资产界面 | 向平台输入内部、外部和供应商信号 | 客户租户、云工作负载、终端、供应商和暗网监控访问 | 公开材料没有解释标准化、留存或跨域 schema 设计 |
| Microsoft 原生数据平面 | 为 MDR 工作流提供 Sentinel、Defender、身份和合规上下文 | Microsoft 生态深度,以及持续 API / 功能访问 | 如果买方想要更广的异构技术栈透明度,重度集中在 Microsoft 会带来集中度风险 |
| AI 和确定性自动化层 | 以机器速度丰富、分诊,并可触发自动遏制动作 | 模型调优、playbook、审批逻辑和数据质量 | 公开证据没有揭示模型治理、评估或回滚控制 |
| 人类分析师层 | SOC 和 ROC 专家验证告警、调优逻辑,并与客户或供应商沟通 | 熟练人力供给和可重复流程 | 规模扩大时,服务质量可能变得人力密集 |
| 第三方风险分析层 | 监控供应商、风险事件、问卷和修复工作流 | 大规模外部数据源覆盖,加客户供应商清单 | 没有公开文档说明客户侧如何集成采购或 GRC 系统 |
| 外部下架和监控网络 | 执行品牌、app、社交和凭据修复结果 | 注册商、社交平台、app store 和地下来源访问 | 结果质量会随外部平台响应速度而变化 |
| Conquest 态势和合规层 | 把平台延伸到态势、成熟度和面向政府的合规工作流 | 并购后产品整合成功 | 公开来源没有说明 UX 已完全统一,还是仍停留在组合层面 |
该架构由已审阅的产品页面、发布材料和 Microsoft 宣传资料综合而来,而不是来自供应商发布的工程图。
[CE004, CE006, CE015, CE016, CE021, CE022]5.4 数字风险防护与外部依赖链
平台的外部风险侧被组织成清晰的三模块结构:Brand Protection、Dark Web Watcher 和 Executive Cyber Guard。这些模块映射到具体用户任务,而不是抽象威胁情报 buzzwords。BlueVoyant 声称可在网站、社交和 rogue-app 渠道做品牌下架;监控 dark-web 中的欺诈、泄露凭证和暴露数据;并监控高价值账号被攻陷或个人数据暴露等高管风险。公司也至少发布了一些可衡量的 DRP 表现信号,包括网站和社交媒体下架成功率,以及服务器级下架中位时间。不过在运营上,这条产品线最明显依赖外部平台和对手方:注册商、社交网络、应用商店、地下监控访问和客户响应预案都位于结果链条中。这让 DRP 具有战略重要性,但也高度依赖外部环节,因此 Gartner 评论标题中关于偶发下架挑战的提醒值得关注。[CE025, CE026, CE027, CE028, CE029, CE030]
BlueVoyant 的产品结果依赖一串技术和生态对手方,尤其是 Microsoft,以及外部下架和供应商响应渠道。
依赖图聚焦抓取来源中可见的对手方;未披露的内部基础设施供应商被有意省略。
[CE021, CE027, CE028, CE030, CE033, CE035]5.5 信任控制、能力扩张与产品风险
BlueVoyant 公开信任与路线图证据足以支撑企业尽调,但不足以消除买方追问。Trust Center 确认公司希望被视为 cloud-native、AI-plus-human 平台,拥有超过 1,000 名客户;Microsoft 和 Conquest 材料则显示其明确对齐合规要求重的环境。Conquest 尤其重要,因为它把 BlueVoyant 从检测和风险可见性扩展到风险成熟度映射、态势管理,以及 CMMC 和 FedRAMP-adjacent 环境等政府导向合规工作流。与此同时,公开开发者界面很薄:GitHub 只显示一个可见公开仓库,且该仓库被标为 Copilot for Security 内容,而不是核心平台代码或可复用集成。独立评论和社区来源也浮现真实警示信号——偶发 DRP 下架摩擦、围绕专有深度的长期疑问,以及非 Microsoft 集成、SLA 或独立审计产品表现的公开证据有限。[CE016, CE031, CE032, CE033, CE034, CE035]
| 控制 / 信号 | 状态 | 范围 | 缺口 |
|---|---|---|---|
| Trust Center 存在 | 已验证 | Vanta 托管的公开 Trust Center 称 BlueVoyant 是云原生、AI 加人工,并拥有 1,000+ 客户 | 抓取到的公开界面没有以可读文本披露完整证书和报告清单 |
| 租户内 Microsoft 数据处理 | 宣传资料已验证 | MDR for Microsoft PDF 称客户可把安全数据留在自有环境 | 证据来自合作伙伴宣传资料,不是公开架构或数据处理白皮书 |
| Microsoft 合作伙伴认可和专业化 | 已验证的公司主张 | MDR for Microsoft 页面列出合作伙伴奖项、资质和安全专业化 | 奖项更能证明交付可信度,而不是平台控制成熟度 |
| CMMC / FedRAMP / 国防环境相关性 | 通过 Conquest 并购已验证 | 发布材料把 Conquest 和 BlueVoyant 与 CMMC RPO 认证、DIB 使用场景,以及 FedRAMP marketplace 上的 ARMED ATK 联系起来 | 公开来源仍未把这些控制详细映射到主商业平台 |
| DRP 执行的独立评价信号 | 混合 | Gartner 界面显示一条正面的 DRP 评价标题,但仍提示偶发下架挑战 | 单条公开评价标题不足以承销广泛可靠性 |
| 公开开发者透明度 | 低 | GitHub 显示一个可见公开仓库,聚焦 Copilot for Security 内容 | 开源证据太薄,无法评估连接器深度、发布节奏或规模化工程复用 |
本表把抓取来源中直接可见的信任信号,与仍需私下尽调的更大控制清单分开。
[CE016, CE017, CE031, CE032, CE035, CE036]| 日期 / 阶段 | 功能 / 里程碑 | 状态 | 含义 | 来源 |
|---|---|---|---|---|
| 2023-03 合作伙伴培训 | BlueVoyant Shadow Hunter Microsoft Security Immersion Workshop(安全沉浸式工作坊) | 历史 / 合作伙伴赋能 | 说明在更广的平台汇聚叙事完全公开前,Microsoft 从业者互动已存在 | SE032 |
| 2023-09 产品扩展 | 全面的第三方网络风险管理扩展 | 已发布 | 为 Supply Chain Defense 增加问卷管理、多层级监控、零日告警和咨询工作流 | SE015/SE023 |
| 2023-11 并购 | Conquest Cyber 并购 | 已交割 / 正在整合 | 用风险成熟度视角扩展态势、合规和政府国防能力 | SE016/SE024 |
| 2024-07 平台发布 | BlueVoyant Cyber Defense Platform(网络防御平台) | 已发布 | 建立一个覆盖内部、外部和供应链防御的云原生伞形平台 | SE021/SE026/SE027 |
| 2025-09 开发者信号 | BV-Security-Copilot 仓库在 GitHub 公开更新 | 可见但狭窄 | 显示公司产出了一些面向从业者的资料,但没有广泛公开工程透明度 | SE018/SE019/SE020 |
| 2026 当前市场推广 | MDR for Microsoft 和 Continuous Optimization 是平台内上线模块 | 当前 | 确认该产品既作为运营覆盖销售,也围绕 Microsoft 安全支出和控制做优化销售 | SE005/SE006/SE007 |
| 2026 AI 发布 | BlueVoyant AI agentic SecOps platform(智能体 SecOps 平台) | 已发布 | 路线图从汇聚界面推进到面向托管和自助 SOC 的 AI 原生编排层 | SE022 |
BlueVoyant 不发布公开 changelog,因此路线图证据由发布材料、宣传资料、GitHub 活动和当前方案页面重建。
[CE004, CE007, CE015, CE024, CE033, CE034]公开证据最能支撑 Microsoft 交付深度和模块广度;在开放工程透明度、非 Microsoft 集成和硬运营基准测试上较弱。
[CE015, CE022, CE035, CE036, CE037, CE039]5.6 图表
06客户
6.1 客户分层与买方结构
BlueVoyant 的公开客户文件指向企业和政府买方:它们安全运营复杂、监管敞口明显,或拥有大型第三方生态,而不是广泛 SMB 基础。买方通常是 CISO、信息安全办公室、安全架构负责人或基础设施所有者;日常用户是 SOC 或 IT 运营团队;付款方通常是机构采购预算、受监管企业安全预算,或由伙伴支持的合同工具。最强的可见细分是公共部门和金融服务:一侧是 California OIS、NAVSEA 以及 Carahsoft 支持的政府路径,另一侧是 Snappi、Beeks、ClearBank 和面向金融服务的 Microsoft 内容。ODEON 把客户文件拓宽到多国消费者运营,但模式仍是复杂、高风险环境。能源和法律显然是目标垂直行业,但所审阅语料没有同等强度的具名生产引用。[CU001, CU002, CU003, CU004, CU030, CU031]
| 分层 / 群组 | 买方 / 用户 / 付款方 | 代表性公开证据 | 证据证明什么 | 主要缺口 |
|---|---|---|---|---|
| 州和地方政府 | 买方:OIS/CISO;用户:SOC 和 IT 团队;付款方:机构或全州网络安全预算 | California OIS SOCaaS 和 CDT SOCaaS 页面 | BlueVoyant 能支持资源受限公共实体的共享服务监控 | 公开证据集中在 California,且不披露合同经济性 |
| 联邦国防和采购 | 买方:项目 / 采购负责人;用户:供应链和安全分析师;付款方:联邦合同工具 | NAVSEA / 202 Group Phase III 工作,以及 SCRIPTS BPA 可用性 | BlueVoyant 在供应链风险使用场景中具备真实联邦采购牵引力 | 项目和供应商覆盖证据强于终端用户采用细节 |
| 数字银行和受监管金融 | 买方:CISO / 董事会 / 安全负责人;用户:SOC 和合规团队;付款方:企业安全预算 | Snappi 和 ClearBank 公开材料 | 韧性、报告和 Microsoft 运营重要时,BlueVoyant 有吸引力 | 公开材料中的具名银行名单仍偏少 |
| 资本市场基础设施 | 买方:CISO / IT 负责人;用户:SOC 分析师;付款方:平台运营方预算 | Beeks Group 客户表述 | BlueVoyant 能支持面向客户的金融基础设施,并安抚下游客户 | 关于初始部署之外扩展的公开证据很少 |
| 多站点商业运营商 | 买方:中央 InfoSec / 云服务;用户:区域安全团队;付款方:公司安全预算 | ODEON 案例研究和独立报道 | BlueVoyant 能统一嘈杂的多国环境,并增加第三方风险可见性 | 公开商业证据由一个旗舰娱乐业客户背书主导 |
| 能源和法律行业市场动作 | 买方:行业 CISO 或 IT / 安全负责人;用户:安全团队;付款方:企业安全预算 | 能源 webinar 和律所方案 spotlight | BlueVoyant 正积极瞄准银行和政府之外的其他受监管行业 | 已审阅来源没有在这些垂直领域列出可比的生产客户 |
各行把有具名证据的分层,与当前主要由方案营销或思想领导力支持的行业分开。
[CU001, CU002, CU003, CU004, CU030, CU031]可见买方旅程通常从合规或告警疲劳痛点开始,经由伙伴或 Microsoft 主导的导入,扩展到全天候运营和第三方风险可见度。
[CU001, CU002, CU026, CU027, CU030, CU042]6.2 具名生产证明与买方结果
BlueVoyant 最强公开客户证据来自少量具名引用,并附带具体运营结果。California OIS 给出最清晰的州政府证明,展示以 Microsoft 为中心的 SOCaaS 部署,带来更快检测与响应以及预算节省。ODEON 增加了一个跨国商业引用,包含量化的告警噪音降低、第三方漏洞解决,以及从碎片化工具迁移到 Sentinel 加 MDR 的更详细技术叙事。Snappi 在数字 ROI 上较弱,但在受监管银行准备度上很强:上线数月内获得 24/7 SOC 覆盖、董事会汇报、桌面演练验证的响应,以及 DORA 准备。Beeks 是最好的金融市场证明,因为客户自己表示 BlueVoyant 降低了告警疲劳、降低数据摄取成本,并在不到三个月内上线。NAVSEA 和 BlueVoyant Government Solutions 材料证明其具备真实联邦部署意义,尽管这些证据更偏项目和合同驱动,而不是席位数或续约驱动。[CU005, CU006, CU007, CU008, CU009, CU010]
| 日期 / 信号 | 公开指标或证明点 | 来源 | 解读 | 注意事项 |
|---|---|---|---|---|
| 2025 年 5 月 | 全球超过 1,000 家客户信任 | BlueVoyant Microsoft awards 新闻稿 | 显示公司愿意在近期公开材料中提出四位数客户数主张 | 公司整体主张未按产品、地域或收入规模拆分 |
| 2025 年 6 月 | California SOCaaS 保护 112 个公共部门组织,合计节省超过 $54 million | California Department of Technology 新闻室 | 显示一个有意义的全州规模公共部门生产项目 | CDT 没有拆分当前项目有多少具体归因于 BlueVoyant |
| 2025 年 4 月 | SCD-G 目前为超过 4 million 家供应商识别关键风险 | BlueVoyant Government Solutions SCRIPTS BPA 新闻稿 | 证明政府供应链防御中的大型受监控生态规模 | 供应商覆盖是平台范围,不是客户数指标 |
| 2026 年评价界面 | FeaturedCustomers 显示 133 条客户参考的总体评分为 4.7/5 | FeaturedCustomers 证言页面 | 第三方评价界面暗示存在相当规模的客户参考存量 | 参考平台不是经审计的留存或使用披露 |
| 2026 年 marketplace 可见性 | 已审阅的 AWS Marketplace 和 Slashdot 页面显示 0 条客户评价或评分 | AWS Marketplace 和 Slashdot 对比页面 | 一些面向买方界面上的独立公开评价密度仍较浅 | 无评价不证明采用率低,主要说明可见反馈量低 |
本表混合公司宣称规模、项目规模和第三方可见性代理指标,因为 BlueVoyant 不发布完整公开客户 cohort 序列。
[CU009, CU025, CU036, CU037, CU039]| 客户 / 项目 | 分层 | 部署状态 | 公开报告的结果 | 证明什么 | 局限 |
|---|---|---|---|---|---|
| California OIS SOCaaS | 州政府 | 生产共享服务项目 | MTTD 降低 70%,MTTR 降低 60%,每个参与实体每年节省 $2.1M 人员成本 | BlueVoyant 能支持大型、基于 Microsoft 的公共部门运营模型 | 已审阅语料没有显示合同价值或续约机制 |
| ODEON Cinemas Group | 娱乐 / 多站点运营 | 生产级跨国部署 | 需审查告警减少 98%,已解决 30 个关键 / 高危第三方漏洞 | BlueVoyant 能在分布式环境中降噪,并增加供应商风险可见性 | 大部分证据仍由供应商或合作伙伴撰写,而非 ODEON 审计 |
| Snappi | 数字银行 / neobank | 生产发布阶段部署 | 24/7 SOC、DORA 就绪、董事会级 KPI 报告、经桌面演练验证的事件响应 | BlueVoyant 能帮助受监管银行快速上线安全运营 | 证据更强调韧性就绪,而不是商业或用户量结果 |
| Beeks Group | 资本市场基础设施 | 生产客户部署 | 不到三个月上线,告警疲劳和数据摄取成本同步下降 | 客户面向外部的金融平台需要网络信任支撑获客,BlueVoyant 能强化这一环 | 公开证据没有量化续约、扩张或合同规模 |
| NAVSEA / BlueVoyant Government Solutions | 联邦国防供应链 | 政府生产项目 | Phase III 合同、交付订单,以及当前平台覆盖超过 4M 家供应商的说法 | BlueVoyant 已在联邦供应链场景落地,也具备采购相关性 | 项目级证据强于常规 SaaS 账户指标 |
行项目聚焦已审阅材料中最深入的具名证据,并把运营里程碑与传统 SaaS 留存指标分开。
[CU005, CU006, CU007, CU008, CU011, CU013]少数具名引用的证据质量最强;但即便量化结果很强,留存可见度仍然偏弱。
[CU005, CU011, CU018, CU020, CU023, CU039]6.3 政府与金融服务深度
政府和金融服务是 BlueVoyant 公开客户故事中最可辩护的部分。政府侧,公司可以指向 California 全州 SOCaaS 模式、通过 202 Group 继承的 NAVSEA 供应链工作,以及经 Carahsoft、SEWP、ITES-SW2、NASPO、CMAS 和 SCRIPTS BPA 扩大的采购足迹。这不只是 logo 证据,而是显示真实合同路径和运营用例。金融服务侧,证明更窄但仍可信。Beeks 提供资本市场基础设施证明,并有直接客户表述。Snappi 展示一家新受监管银行从第一天起就用 BlueVoyant 建立网络运营,ClearBank 则表明 BlueVoyant 可与一家成熟英国银行客户公开谈 Microsoft 优化。需要谨慎的是,公开深度最强处围绕 Microsoft-centric 托管安全和韧性主题,而不是一长串具名银行或保险公司。[CU003, CU004, CU017, CU018, CU020, CU021]
6.4 渠道与采购路径
BlueVoyant 的上市路径显然刻意偏重伙伴。公司宣传正式伙伴计划,包含联合销售、赋能、账户规划和 OEM / 技术联盟支持。Carahsoft 是公共部门需求最清晰的渠道放大器,因为它让 BlueVoyant 接入既有经销商网络和合同工具,而不是逐个机构强推直接采购。BlueVoyant Government Solutions 又通过 SCRIPTS 和供应链防御动作增加了一条更专门的联邦路径。AWS Marketplace 提供另一条采购路径,尽管所审阅 listing 偏 private-offer,外部反馈很少。实际含义是,扩张可能既来自伙伴和平台生态,也来自净新增直销。对 Microsoft-centric 买方尤其高效,但也意味着客户可见度可能落后于上市路径宽度,因为部分胜单通过分销商、网络研讨会或伙伴页面浮现,而不是通过详细独立案例研究出现。[CU024, CU025, CU026, CU027, CU028, CU029]
| 路径 | 买方或用户类型 | 公开证据 | 可实现的能力 | 限制 |
|---|---|---|---|---|
| 以 Microsoft 为中心的企业直销 | CISO / SOC / 云安全团队 | ODEON、Snappi、Beeks、ClearBank、California OIS 等客户 | 支持快速接入 Sentinel、Defender、MDR 和报告工作流 | 公开证据在 Microsoft 已具战略地位的场景最强 |
| Carahsoft 公共部门分销 | 联邦、州、地方、部落、教育、医疗买方 | Carahsoft 合作伙伴关系和合同页面 | 让机构通过既有经销渠道和合同载体采购 | 间接路径会降低终端客户经济性的可见度 |
| SCRIPTS BPA / BlueVoyant Government Solutions(政府解决方案) | DoD 和 FCEB 供应链风险买方 | BlueVoyantGov SCRIPTS BPA 新闻稿 | 简化联邦项目获取 SCD-G 和分析师支持的路径 | 项目规模不会自动转化为商业 SaaS 式留存数据 |
| AWS Marketplace 私有报价 | 云优先安全买方 | AWS Marketplace MDR 列表 | 通过 AWS 账单和 marketplace 工作流完成采购 | 已审阅列表仍显示无客户评论,并要求私有报价 |
| 合作伙伴主导的外部背书 | 合作伙伴、分销商和客户引用生态 | 合作伙伴页面、Carahsoft 经销商页面、Beeks 和 Veracloud 外部案例 | 把触达和可信度延伸到 BlueVoyant 自有渠道之外 | 路径广度超过独立可见续约证据的深度 |
这张补充表把采购机制与客户结果分开,避免把合作伙伴和合同路径误当作留存证据。
[CU026, CU027, CU028, CU029, CU030, CU031]BlueVoyant 的公开部署通常先拿到采购入口,再进入以 Microsoft 为中心的导入,随后转向持续运营和伙伴可见的扩张。
[CU013, CU018, CU021, CU026, CU029, CU042]6.5 留存、集中度与可见度风险
BlueVoyant 客户文件中最大的缺口不是没有参考账户,而是没有耐久性披露。所审阅来源均未提供 NRR、GRR、流失率、logo 留存、队列续约曲线或按客户划分的收入集中度。PeerSpot 暗示年度或多年协议较常见,但这仍是泛化第三方评论,而非公司验证的队列证据。独立评论界面只能部分帮上忙。FeaturedCustomers 显示有一定数量参考和正面评分,但 AWS Marketplace 和 Slashdot 页面在所审阅 listing 上仍显示零公开评分。多数量化证明由厂商或伙伴撰写,有助于看到部署结果,却不足以承销集中度和续约风险。因此尽调结论是混合的:BlueVoyant 拥有可信标杆证明和受监管行业相关性,但买方仍需 top-customer 敞口、扩张率、续约率和分部经济性的私有数据,才能把公开客户故事视为完全承销。[CU037, CU038, CU039, CU040, CU041, CU042]
| 指标 / 代理指标 | 公开数值 | 细分 | 置信度 | 尽调事项 |
|---|---|---|---|---|
| 净收入留存率(NRR) | 整体客户群 | 低 | 索取过去八个季度按产品线和客户细分拆分的 NRR | |
| 总留存 / Logo 留存 | 整体客户群 | 低 | 索取 Logo 留存和总美元留存 cohort | |
| 流失率 | 整体客户群 | 低 | 索取总流失和净流失,并列出前 20 大客户贡献 | |
| 合同期限 / 续约结构 | PeerSpot 提到年度或多年期协议 | 企业细分混合 | 低 | 按细分获取订单表样本、续约日期和终止权 |
| 公开满意度 / 可见度代理指标 | FeaturedCustomers 评分 4.7/5,含 133 条引用;但审阅页面显示 AWS 评论为 0、Slashdot 评分为 0 | 公开证据表面 | 中 | 将公开评论密度与真实续约和支持 KPI 对齐核验 |
Null 表示已审阅材料未公开该指标;可见评论和合同信号只是代理指标,不能替代留存数据。
[CU037, CU038, CU039, CU040]| 扩张驱动或集中风险 | 公开证据显示什么 | 对投资判断的影响 | 尽调路径 |
|---|---|---|---|
| 以 Microsoft 为中心的交叉销售 | California、ODEON、Snappi、Beeks 和 ClearBank 都把 BlueVoyant 与以 Microsoft 为中心的安全运营紧密绑定 | Microsoft 重度账户内的扩张逻辑很强,但该技术栈之外的产品广度不够可见 | 索取按产品拆分的 ARR、挂载率,以及 Microsoft 主导部署之外的胜率 |
| 公共部门合同路径依赖 | Carahsoft、SEWP、ITES-SW2、CMAS 和 SCRIPTS 带来有意义的政府准入 | 有助于放大分销,但采购节奏和渠道执行可能塑造收入集中度 | 索取按直销与渠道、合同载体拆分的 bookings |
| 金融服务合规拉动 | Snappi、Beeks 以及金融服务内容显示需求由合规驱动,并强调运营韧性价值 | 行业适配度好,但具名银行深度仍有限 | 索取头部金融服务账户、pipeline 转化,以及按子细分拆分的可背书程度 |
| 旗舰客户引用集中 | 公开证据由少数深度案例主导,而不是一组同样细致的广泛引用 | 如果长尾部署更浅,少数旗舰账户可能高估整体部署深度 | 索取前 10 大客户收入占比,以及超过重要 ARR 门槛的客户数量 |
| 耐久性可见度缺口 | 未发现公开 NRR、GRR、流失、续约或头部客户集中度披露 | 这是承保客户质量时最大的剩余尽调障碍 | 在 NDA 下获取 cohort 表、续约仪表盘和集中度明细 |
该图表同时列出上行空间和风险,因为 BlueVoyant 的公开材料最擅长说明客户为什么购买,却最缺少这些客户能持续多久的证据。
[CU026, CU028, CU030, CU031, CU039, CU040]07风险
7.1 监管、隐私与不利信号
BlueVoyant 目前并未表现为处在大范围公开执法压力下的公司,但其可见运营界面仍带来真实的监管和法律暴露。公司的隐私和法律声明称,BlueVoyant LLC 是网站个人数据控制者,并可在法律未禁止时与关联方共享个人信息;这并不罕见,但对会审查控制者边界、关联方访问和全球数据处理的买方仍然重要。更大的外部约束来自公司贴近政府和国防的业务动作。BlueVoyant Government Solutions 明确向联邦和国防场景销售供应链防御、CMMC 支持和 NIST 800-171 合规管理,而 DoD 的 CMMC 推行已经进入实际合同。因此,风险不是抽象监管,而是能否按采购绑定的网络控制要求执行;如果 BlueVoyant 或其客户无法证明准备就绪,项目中标可能被拖延,甚至被取消资格。 当前公开材料里,最清晰的公司特定负面信号是 Steward Health 在 Texas bankruptcy court 对 Bluevoyant LLC 提起的对抗性申诉。仅靠公开案卷文字无法量化暴露、胜算或预期结果,但这是一个仍在推进的负面事项,需要直接尽调事实背景、保险、准备金处理,以及它是否反映计费、交付或供应商管理争议。另一个方面,SAM.gov 和 USAspending 让联邦授标数据可以公开追踪,这一点有用,因为 BlueVoyant 的合同工具覆盖面可见,但实际机构层面的集中度和续约依赖不可见。整体看,只有当公司能证明隐私治理克制、公共部门合规准备处在当下可用状态,并能给 Steward 事项一个边界清楚的解释时,法律和监管风险才算可控。[CR015, CR016, CR017, CR018, CR019, CR020]
| 规则 / 案件 / 控制 | 司法辖区 | 状态 | 可能性 | 严重性 | 缓释措施 | 剩余敞口 | 尽调路径 |
|---|---|---|---|---|---|---|---|
| 面向国防相关工作的 DoD CMMC 推进 | 美国 / DoD | Phase 1 自 2025-11-10 起生效,涵盖 Level 1 和 Level 2 自评 | 高 | 高 | 用现有 CMMC 和 NIST 支持定位证明准备度 | 高 — 认证证据缺失或薄弱会拖慢授标,或导致投标出局 | 获取内部 CMMC 等级映射、最新 SPRS 确认,以及与 CMMC 工作绑定的客户引用 |
| 合同执行中的 NIST SP 800-171 义务 | 美国 / 联邦采购 | 处理 CUI 的非联邦系统需遵守的持续基线控制框架 | 高 | 高 | 将交付流程映射到 800-171 控制覆盖 | 中高 — 控制缺口会变成采购、审计或整改负担 | 索取正式控制矩阵、继承模型和任何第三方评估 |
| Steward Health 对抗性诉状 | Texas Southern Bankruptcy Court | 截至 2026-06-26,公开案卷仍活跃 | 中 | 中高 | 如果敞口有限,可通过法律抗辩、保险和协商解决 | 中 — 仅凭公开案卷,事实敞口和金额敞口仍不清楚 | 审阅诉状、答辩、索赔金额、付款历史和任何保险公司往来 |
| 网站隐私治理和关联方共享 | 网站 / 跨境数据治理 | 隐私声明称 BlueVoyant LLC 为控制者,除非被禁止,否则可与关联方共享 | 中 | 中 | 在交易特定 DPA 中明确控制者边界、关联方访问和保留期限 | 中 — 如果数据流边界不清,买方尽调负担会上升 | 索取产品级 DPA、子处理方和区域数据流图 |
| 联邦授标透明度和机构审查 | 美国 / 采购数据 | SAM.gov 和 USAspending 让合同授标尽调可行,但公司组合未披露 | 中 | 中 | 在承保集中度前,预先搭建机构和合同载体分析 | 中 — 隐性集中可能在尽调后期浮出水面 | 按法定企业名称拉取机构级授标,并与管理层收入分部对账 |
各行仅用公开证据按剩余严重性排序;不能替代律师审阅或逐合同合规测试。
[CR015, CR016, CR017, CR018, CR019, CR020]7.2 Microsoft 生态系统与竞争平台风险
BlueVoyant 最强的公开优势,也正是其最大的战略依赖之一。公司把自己定位为 Microsoft 安全专家,覆盖 Sentinel、Defender、Purview、Copilot readiness 以及相邻的采用成本评估;Microsoft 和 BlueVoyant 的材料也共同强调,BlueVoyant 帮助塑造 Sentinel 用例、分析能力和 Security Copilot 内容。奖项和生态认可证明其渠道可信度真实存在,合作伙伴栈显然不是表面文章。但这也意味着,BlueVoyant 的差异化暴露在 Microsoft 路线图选择、定价变化、打包方式调整和原生功能扩张之下。如果 Microsoft 把更多工作流直接做进自家栈,BlueVoyant 就必须持续证明,其专家服务、内容和运营判断值得额外付费,而不是变成可选的外包人力。 竞争强度很高,因为 BlueVoyant 防守的不是一个狭窄切口。公开材料和评测目录把它放在 MDR、Microsoft 托管安全、数字风险、供应链防御和第三方风险管理等多个领域。多条进攻路径给了公司更多机会,但也意味着买方可以在每个品类里拿 BlueVoyant 与更专精的供应商对比。公司自己的 Sentinel case-study eBook 和 Gartner-market-guide 博客显示,BlueVoyant 的胜法是降低复杂度、帮助客户把风险运营起来,而不是拥有独一无二的底层平台。这很有价值,但一旦 Microsoft 伙伴激增、专注 MDR 的供应商在服务深度上胜出,或 best-of-breed TPRM 供应商把单一工作流执行得更好,防守难度就会上升。简言之,Microsoft 渠道实力降低了需求生成风险,同时也抬高了商品化和集中度风险。[CR001, CR002, CR003, CR004, CR005, CR006]
| 依赖 | 交易对手 / 生态 | 角色 | 集中度 | 失效场景 | 严重性 | 缓释措施 | 剩余敞口 |
|---|---|---|---|---|---|---|---|
| Microsoft 安全技术栈 | Microsoft | BlueVoyant 主要产品的核心遥测、工作流和服务底座 | 高 | Microsoft 原生能力改进,挤压 BlueVoyant 叠加服务的价值 | 高 | 持续证明差异化部署、内容和托管运营价值 | 高 |
| Microsoft 渠道可信度和奖项 | Microsoft / MISA 生态 | 面向 Microsoft 中心型买方的需求生成和信任信号 | 高 | 路线图、联合销售或合作伙伴计划变化削弱 pipeline 效率 | 高 | 将证据点扩展到奖项和纯 Microsoft 成功案例之外 | 中高 |
| Sentinel 合作伙伴生态建设 | Microsoft Sentinel 生态 | BlueVoyant 在 Sentinel 之上构建分析、playbook、查询和 Copilot agent | 高 | API、平台经济性或商店分发规则发生重大变化 | 高 | 贴近产品团队,并维护客户难以轻易复制的交付资产 | 高 |
| 公共部门采购载体 | Carahsoft 和政府承包渠道 | 进入机构和国防相邻买方的准入路径 | 中 | 载体准入存在,但底层授标组合集中在少数机构或项目 | 中高 | 承保前用 SAM.gov 和 USAspending 衡量真实集中度 | 中高 |
| 拥挤的网络风险品类 | MDR / TPRM / 供应链和数字风险市场 | 设定买方为 BlueVoyant 定价和比较时使用的基准 | 高 | 聚焦型厂商在单一工作流上执行更好,而 BlueVoyant 承担平台蔓延 | 中高 | 说明 BlueVoyant 哪些胜利来自运营结果,而不只是产品广度 | 中高 |
依赖风险由 Microsoft 集中度主导,但采购渠道和品类广度依赖同样重要,因为它们会塑造转化、续约和定价权。
[CR001, CR002, CR003, CR004, CR005, CR006]相比任何单一专有公开指标,BlueVoyant 更依赖 Microsoft、人工 SOC 人才、采购渠道和合规证据。
[CR001, CR002, CR003, CR007, CR021, CR022]7.3 人力服务交付与 AI 执行风险
BlueVoyant 正试图把一个以人为主导的托管安全业务,延展成 AI 原生产品叙事,同时不放弃专家监督的承诺。2026 年 6 月发布的 BlueVoyant AI 称,客户既可以买由 BlueVoyant 精英 SOC 团队支撑的全托管服务,也可以买把同样能力交到客户手里的 SaaS 平台。商业上这很有吸引力,但也提出了真实的运营挑战:公司现在必须在两种模式下同时交付高质量的分析师驱动服务、可信的自治工作流,以及一致的定价和打包。关于机器速度遏制、降低误报和确定性响应的公开说法都很激进。如果没有强护栏、人工接管流程和可衡量的质量结果支撑,BlueVoyant 可能招来更多审查,而不是更少,尤其是在受监管或高后果的客户环境里。 运营模式仍然偏重人力。BlueVoyant 依然强调 24x7 专家监控、全球 SOC 覆盖,以及 Cork 中心服务爱尔兰和欧盟客户等区域扩张。这些都是有意义的缓释因素,但也意味着即便公司在推自动化,招聘、培训、本地化和质量控制仍会持续消耗资源。领导层变化又增加了一层执行风险。John Hernandez 于 2026 年接任 CEO,带着 AI 增长使命;2023 年聘任 CPO 的目的也被明确表述为在产品线扩张后统一产品方向。风险不在于 BlueVoyant 缺乏野心,而在于公司可能要同时管理服务一致性、模型信任、分析师工作流和产品整合。公开评测和目录来源承认其能力覆盖面广,但没有给出 SLA、MTTR、人员配比或告警调优证据,无法完全消除执行风险。[CR008, CR009, CR010, CR011, CR012, CR013]
| 失效模式 | 可能性 | 严重性 | 缓释成熟度 | 剩余敞口 | 未解决缺口 |
|---|---|---|---|---|---|
| Agentic-AI 响应误判或人工兜底薄弱 | 中高 | 高 | 中 — 已有以人为中心的工作流表述,但硬质量指标未公开 | 高 | BlueVoyant AI 没有公开误报、漏报或干预率数据 |
| 托管服务与 SaaS 共存复杂度 | 高 | 高 | 中 — 一个平台 / 两种部署模式的叙事清楚,但打包方式和支持边界尚无公开证据 | 高 | 托管模式与自助模式之间没有公开定价架构或迁移路径 |
| 24x7 SOC 人员配置或分析师质量漂移 | 高 | 中高 | 中 — 区域 SOC 扩张可见,但人员比例和 SLA 不可见 | 高 | 没有公开 MTTR、人员配置或升级质量指标 |
| 区域合规和服务本地化负担 | 中 | 中高 | 中 — Cork 扩张为 EU 客户增加区域内覆盖 | 中高 | 没有公开多语言支持深度、本地数据边界设计或审计节奏证据 |
| MDR、TPRM 和供应链产品的功能蔓延 | 中 | 中高 | 中低 — 产品广度是销售资产,也带来协调负担 | 中高 | 没有公开路线图说明产品、服务和 AI 层如何排序或简化 |
运营风险被抬高,因为公司既要守住人工交付质量,又要同时扩展平台广度和 AI 自动化叙事。
[CR008, CR009, CR010, CR011, CR012, CR013]7.4 公共部门暴露、领导层与融资不透明
BlueVoyant 的公共部门定位同时带来韧性和集中度风险。积极一面是,公司通过 Carahsoft 出现在多个合同工具上,并围绕供应链防御、网络安全和合规支持提出政府专属价值主张。由于这些工作对应真实采购和任务需求,而不是可有可无的试验,需求可能更耐久。负面一面是,政府相关收入通常推进更慢、合规门槛更高,也比普通商业 SaaS 更依赖认证证据和合同执行。BlueVoyant 的公开材料没有披露政府或国防客户贡献多少收入、哪些机构最关键,或续约如何分布在各项目之间。因此,公开记录能确认暴露存在,却无法确认分散度。 融资能见度同样不完整。当前材料里最清晰的资本事实,是 2023 年公告称 BlueVoyant 为支持收购 Conquest Cyber 完成超过 $140 million 的 Series E 融资。PM Insights 显示,围绕公司的二级市场和估值监测至少存在一定活动,但公开预览有意保持很薄,无法提供可承销的当前指标。这里没有引用任何关于 ARR、烧钱、runway、杠杆、清算优先权或当前估值的公开披露。这并不证明公司承压,但意味着后期私募市场风险真实存在:如果增长、Microsoft 经济性或公共部门中标率走弱,外部投资者将不得不给一家关键运营指标仍基本私有的公司定价。[CR011, CR012, CR013, CR014, CR023, CR024]
| 角色 / 职能 | 依赖或缺口 | 可能性 | 严重性 | 缓释措施 | 尽调路径 |
|---|---|---|---|---|---|
| 首席执行官领导力 | AI 叙事和全球规模同步推进时,创始人领导过渡到 John Hernandez 这位运营型 CEO | 中 | 高 | 新任 CEO 经验丰富,具备企业平台背景 | 审阅第一年运营优先级、销售生产率和领导团队稳定性 |
| 产品领导力和整合 | CPO 职权意味着收购线和传统业务线仍需持续产品统一 | 中 | 中高 | 专职产品负责人具备大型供应商和产品组合经验 | 索取当前产品地图、弃用政策和整合里程碑跟踪 |
| MDR 分析师队伍 | 即便 AI 发布后,24x7 专家监控仍是核心 | 高 | 高 | 区域 SOC 布局和托管服务历史 | 获取分析师与客户比例、流失率、认证覆盖和升级协议 |
| 区域支持和本地化 | Cork 扩张和 EU 服务增加人员、合规与时区复杂度 | 中 | 中高 | 区域内 SOC 投资和本地招聘 | 按地域验证人员爬坡、语言覆盖和客户支持边界 |
| 政府和合规专家 | 公共部门动作依赖稀缺的网络安全 / 合规人才,需要能讲清 CMMC、NIST、采购和整改 | 中 | 中高 | 专门的政府业务和合作伙伴渠道 | 审阅公共部门账户的投标支持、合规专家和续约责任归属 |
执行风险更多来自同时协调服务人力、产品整合、区域支持和公共部门专业化,而不是创始人可信度本身。
[CR011, CR012, CR013, CR014, CR023, CR024]7.5 监测触发器、缓释成熟度与数据缺口
缓释图景可信,但不完整。BlueVoyant 的确有真实强项:多年获得 Microsoft 认可、可见的公共部门合同入口、不断扩大的 EMEA SOC 足迹,以及横跨托管检测、第三方风险和供应链防御的产品组合。这些不是装饰性信号。但公司的关键剩余风险,只能被公开证据部分缓释。Microsoft 依赖被渠道实力削弱了,但没有消失。BlueVoyant AI 可能改善单位经济性和服务质量,但同一次发布也扩大了执行范围。政府暴露能创造耐久需求,也会提高合规证据和采购纪律门槛。融资风险仍很难打分,因为公开披露远远没有达到衡量稀释或退出风险所需的指标粒度。 因此,更合适的看法是:BlueVoyant 拥有真实战略资产,但执行容错空间很窄。最可操作的否决标准都可以观察:Microsoft 功能商品化压缩服务差异化;AI 质量或人工接管证据薄弱;在公共部门竞标中无法证明 CMMC/NIST 准备就绪;Steward 事项出现不利进展;或新的融资事件暗示压力而非选择权。公开材料还在集中度、服务质量和资本结构上留下实质性尽调缺口。这些遗漏不会否定业务,但会让剩余风险评分保持偏高。除非管理层能拿出客户组合、续约耐久性、SOC 质量和资本条款的硬指标,审慎的承销立场应是:BlueVoyant 具备战略吸引力,但对执行高度敏感。[CR004, CR005, CR008, CR010, CR017, CR021]
| 风险 | 可监控触发因素 | 阈值 / 事件 | 行动含义 |
|---|---|---|---|
| Microsoft 生态依赖 | 证据显示 Microsoft 原生功能吸收 BlueVoyant 的服务内容或经济性 | 续约异议围绕在 Microsoft 支出之上继续为合作伙伴叠加层付费而上升 | 下调差异化和毛利率耐久性评估 |
| AI 执行质量 | BlueVoyant AI 的人工兜底、误报和遏制质量证据 | 管理层无法为自主工作流提供可信质量指标或客户引用 | 将 AI 发布视为增加风险,而不是降低风险 |
| 公共部门合规准备度 | CMMC、NIST 和授标级尽调产出 | 缺少 SPRS 确认、控制映射薄弱,或与合规准备度相关的机构推进停滞 | 假设政府增长更慢,获胜成本更高 |
| 法律 / 负面信号控制 | Steward 诉讼、保险和准备金姿态的直接事实 | 诉状实质扩张、损害赔偿看起来重大,或管理层无法清楚叙述争议 | 上调法律风险评级,并重审交易对手 / 流程尽调 |
| 融资不透明 | 当前 ARR、burn、现金 runway,以及任何新资本事件 | 下一轮显示压力、惩罚性优先权,或在没有明确运营加速时大幅稀释 | 降低对入场价格的信心,并要求更强下行保护 |
这些否决标准把柔性的公开信号转成明确尽调测试,避免把渠道强度和新闻稿误当作风险已经关闭。
[CR017, CR021, CR030, CR032, CR036, CR037]影响最大的残余风险集中在 Microsoft 依赖、融资不透明、公共部门合规,以及托管加 AI 运营模型质量。
[CR046, CR047, CR048, CR049, CR050, CR051]平台、合规或执行失误很可能先打到客户信任,然后才体现为融资或估值压力。
[CR046, CR047, CR048, CR049, CR052, CR053]08估值
8.1 投资论点与反论点
BlueVoyant 已有足够规模和品类宽度,只要价格合适,就具备可投资性。公司官方材料描述的是一个统一平台,覆盖 MDR、TPRM、数字风险防护和专业服务,而不是单点工具。这种宽度很重要,因为它支撑了比纯 MDR 更宽的可比公司集合,也让 BlueVoyant 能以多个产品切口进入企业和公共部门预算。2023 年增长公告也显示出有意义的商业验证:超过 900 家客户、覆盖 40 多个国家,并且自 2018 年以来经常性收入曾保持三位数扩张。如果第三方给出的 2025 年 ARR 代理值 $213.5 million 大体方向正确,BlueVoyant 已是一家有规模的网络安全供应商,而不是仍在收入前阶段押注的独角兽。 反论点在于估值质量,而不是公司是否存在。本章最关键的反证信号来自公开二级市场证据:Notice 显示较上一轮折价 39%,Forge 称市场活动有限,Hiive 的公开挂牌页没有可见价格历史。这些信号意味着私募市场要么流动性不足,要么态度谨慎,或两者兼有。同时,公司仍未公开当前毛利率、留存、服务收入占比、稀释后股数,以及 2023 年之后任何融资条款。尽管核心业务看起来可信,这组因素仍把正确结论留在继续研究,而不是买入。 [CV012, CV013, CV015, CV016, CV017, CV018]
| 维度 | 取值 | 理由 |
|---|---|---|
| 建议 | 继续研究 | 公开证据支持一个看似合理、但尚未明显错价的 $1B 估值;缺失的私有指标仍然关键。 |
| 信心 | 中 | 多项交叉验证彼此吻合,但核心 ARR 和流动性输入来自第三方数据供应商。 |
| 风险评级 | 高 | 二级市场折价、可见流动性稀薄,以及未披露的股数和利润率数据,都会带来真实的下行情景敏感性。 |
| 估值立场 | 合理 | 隐含约 4.7x ARR 代理值落在混合型网络安全可比公司的区间内,但还不够便宜,无法抵消披露缺口。 |
| 决策含义 | 尽调后再接受价格 | 只有管理层证明软件收入占比、利润率质量和近期成交价之后,才上调判断。 |
截至 2026-06-29 的公开资料视角;估值使用第三方 ARR 和二级市场预览,而非经审计财务披露。
[CV041, CV044, CV045, CV046, CV047, CV048]| 立场 | 论点 | 什么会改变判断 |
|---|---|---|
| 投资论点 | BlueVoyant 覆盖 MDR、TPRM、DRP 和专业服务,拓宽了钱包份额,也提升了可比性。 | 如果能证明平台模块正在贡献更高收入占比,正面案例会更强。 |
| 投资论点 | 官方来源显示公司已有可观商业规模:超过 900 名客户、覆盖 40 多个国家,并曾实现经常性收入三位数增长。 | 可信的 2026 年客户数、ARR 质量和留存更新,会让规模论点更站得住。 |
| 投资论点 | 如果 $213.5M ARR 代理值大体正确,$1B 仅相当于约 4.7x ARR,明显低于高溢价网络安全龙头。 | 披露毛利率和软件收入占比,可能支持向更高质量的平台倍数靠拢。 |
| 反论点 | Notice 显示相对上一轮有 39% 折价,意味着二级市场买家可能以显著低于头部估值的价格成交。 | 近期经纪商报价单或接近、超过 $1B 的已执行交易,可以直接反驳折价信号。 |
| 反论点 | Forge 显示交易活动有限,且没有可见 Forge Price,削弱了对当前流动性的信心。 | 可见的买卖盘深度或撮合完成的二级市场成交,可降低流动性折价。 |
| 反论点 | 公开来源对累计融资额说法不一,也没有披露当前稀释、利润率或 2023 年之后的融资条款。 | 清晰的股权结构表、股数、优先权堆栈和当前财务包,会把案例从叙事推进到可承销。 |
这些论点刻意围绕价格敏感性展开:正面案例真实存在,但反论点扎根于可观察的二级市场和披露缺口。
[CV007, CV008, CV012, CV013, CV015, CV018]决策流从规模和可比公司支撑出发,经过二级市场谨慎信号和披露缺口,最后落到继续研究的判断。
这只是逻辑决策架构;它概括公开证据的权重,而不是正式评分模型。
[CV034, CV037, CV038, CV044, CV045, CV048]8.2 融资历史、披露质量与二级市场信号
BlueVoyant 的公开融资历史在标题层面清楚,但在影响定价纪律的细节上模糊。保留来源确认,2022 年 2 月有 $250 million Series D,2023 年 11 月有超过 $140 million 新融资,但公开申报轨迹并不完整。SEC 浏览结果只显示 2017、2019 和 2020 年的 Form D 通知,没有显示后续融资条款。Caplight、CB Insights 和 GetLatka 都指向 $665.5 million 总融资额,Tracxn 报告六轮合计 $696 million,SiliconANGLE 则引用 Tracxn 称 2023 年那轮后约为 $646 million。这不是致命问题,但说明投资者用的是供应商摘要,而不是清晰的公开账本。 二级市场平台进一步加深了这种谨慎。Caplight 仍把 BlueVoyant 锚定在估算 $1 billion,并显示上一轮为 2023 年 11 月 29 日的 Series E。Forge 仍显示上一轮已知估值为 2022 年 2 月的 $1 billion,称当前市场活动有限,且不公布 Forge Price。PM Insights 和 Hiive 都确认二级交易基础设施存在,但公开预览没有给出足够实时深度,无法承销一个精确清算价格。换句话说,市场提供了方向上有用的信号,但透明流动性不足;没有直接经纪商数据,很难把这些信号转化为确信度。 [CV001, CV002, CV003, CV004, CV005, CV006]
8.3 公开可比公司与倍数分析
BlueVoyant 的合适公开可比公司集合本来就应是混合型。高增长一端,CrowdStrike、Palo Alto Networks 和 Fortinet 代表有规模的安全平台,具备强安全运营业务和明显更高的软件质量。相对温和的一端,SentinelOne、Qualys、Tenable 和 Rapid7 更适合作为参考,因为 BlueVoyant 的混合模式仍更接近运营安全和风险管理,而不是纯云安全赢家通吃叙事。Windsor Drake 的 2026 年行业框架是关键宏观锚点:公开网络安全公司约按 6.0x 到 6.5x NTM 收入交易,而托管安全服务约低在 3x 到 5x。 按 2025 年 ARR 代理值计算,BlueVoyant 隐含 4.7x 倍数,落在这片区间的中低位置。它远低于 CrowdStrike 的 34.3x 和 Palo Alto 的 23.28x,也低于 Fortinet 的 15.2x,更接近 SentinelOne 的 4.61x、Qualys 的 5.73x 和 Tenable 的 3.32x。如果 BlueVoyant 的收入组合包含有意义的服务成分,且平台自动化优势尚未转化为已披露的类软件利润率,这个位置在方向上合理。因此,可比公司结论需要保留层次:从收入倍数看,$1 billion 并不显然过高,但折价也不足以构成一个公开证据清晰支持的入场机会。 [CV015, CV016, CV022, CV023, CV024, CV025]
| 可比公司 | 细分视角 | 市值 | 收入(ttm) | EV/收入 | 与 BlueVoyant 的相关性 | 关键限制 |
|---|---|---|---|---|---|---|
| CrowdStrike | 安全运营 / XDR 龙头 | $178.47B | $5.09B | 34.30x | 软件 / 安全运营的上限参照。 | 软件属性过纯、溢价过高,无法直接作为基准情景锚点。 |
| Palo Alto Networks | 含运营能力的综合安全平台 | $247.92B | $10.61B | 23.28x | 展示成熟平台宽度可以获得的估值。 | 比 BlueVoyant 成熟且盈利能力强得多。 |
| Fortinet | 具有运营敞口的安全平台 | $110.88B | $7.11B | 15.20x | 是低于 PANW/CRWD 的有用高端基准。 | 质量仍显著更高,硬件 / 订阅收入也更分散。 |
| SentinelOne | MDR / 端点平台 | $5.45B | $1.05B | 4.61x | 最接近的公开市场倍数校验,适用于成长型但非高溢价安全平台。 | 纯端点 / 软件组合仍比 BlueVoyant 更清晰。 |
| Qualys | 风险 / 合规 / 漏洞 | $4.34B | $684.86M | 5.73x | 可作为风险与合规邻近领域参照。 | 不是服务占比较高的 MDR 业务。 |
| Tenable | 暴露管理 / 漏洞 | $3.33B | $1.02B | 3.32x | 可作为风险导向网络安全的低端区间参照。 | 产品组合和 GTM 与 MDR 加服务不同。 |
| Rapid7 | XDR / SIEM / 暴露管理 | $0.51B | $859.23M | 0.93x | 展示公开市场折价质量和增长时的估值底部。 | 除非利润率或增长严重不及预期,否则对 BlueVoyant 可能过于惩罚。 |
市值和收入数字来自 2026-06-29 访问的 Yahoo Finance 和 CompaniesMarketCap 截图;EV/收入取自 Yahoo Finance。这些值是方向性的公开市场参照,不是私募市场成交价。
[CV022, CV023, CV024, CV025, CV026, CV027]将不同 ARR 倍数应用于 $213.5M 的 2025 年 ARR 代理值,得到以百万美元计的示意企业价值。
数值按第三方 $213.5M ARR 代理值测算,并四舍五入至最接近的百万美元;它们不是经纪商报价。
[CV022, CV023, CV034, CV035, CV041, CV042]8.4 牛市、基准与熊市估值情景
情景框架从真正可观察的内容出发。基准情景下,BlueVoyant 以 $213.5 million ARR 代理值计,应获得约 4.0x 到 5.0x 倍数,对应大约 $0.85 billion 到 $1.1 billion。这个区间既符合公司的真实规模和产品宽度,也反映了对混合利润率和有限流动性的谨慎。牛市情景下,如果管理层证明近期增长可持续、软件和平台层扩张快于服务,并且近期二级或一级价格发现支持更高质量的网络安全倍数,BlueVoyant 可上探约 $1.2 billion 到 $1.5 billion。因此,牛市情景依赖执行和披露改善,而不只是市场倍数扩张。 熊市情景已经可见。Notice 较上一轮折价 39%,Forge 又没有价格信号;如果下一次真实清算事件低于标题估值,或投资者认为 BlueVoyant 应归入 3x 到 4x 托管安全区间而非平台溢价桶,下行区间大约在 $0.6 billion 到 $0.8 billion。偏度很关键:公开证据并没有强烈显示估值过高,但已经显示部分下行可以被发现,而上行仍依赖市场尚未共享的私有事实。 [CV018, CV019, CV022, CV023, CV034, CV035]
| 情景 | 关键假设 | 隐含倍数 | 估值区间(USD B) | 概率信号 | 关键风险 |
|---|---|---|---|---|---|
| 牛市 | 增长保持强劲,软件收入占比扩大,且尽调支持更高质量的平台画像。 | ARR 倍数 5.5x–7.0x | 1.2–1.5 | 需要私有证据压过二级市场折价。 | 没有利润率证明,或成交价偏弱,都会打破该案例。 |
| 基准 | ARR 代理值大体正确,BlueVoyant 被市场认可为混合型网络安全平台,并带有中等服务折价。 | ARR 倍数 4.0x–5.0x | 0.85–1.10 | 与留存的公开证据最一致。 | 如果 ARR 质量弱于代理值,即便基准情景也会被压缩。 |
| 熊市 | 下一次真实成交事件验证二级市场折价,并把 BlueVoyant 推向托管安全或服务类公司的估值区间。 | ARR 倍数 3.0x–3.8x | 0.60–0.80 | 与 Notice 折价和可见流动性稀薄一致。 | 新资本以更低估值进入,或利润率不佳,都会加速下行。 |
情景区间是使用公开 ARR 代理值作出的 USD 十亿美元口径分析估算;它们不是管理层指引,也不是经纪商报价。
[CV018, CV023, CV034, CV041, CV042, CV043]| 触发器 | 阈值 / 事件 | 如何传导到论点 | 行动含义 |
|---|---|---|---|
| 二级市场折价扩大 | 相对上一轮的可观察折价超过约 50%,或新一轮定价低于 $0.8B。 | 这意味着市场认为质量或流动性明显弱于基准情景假设。 | 暂停,并按熊市情景水平重新承销。 |
| 服务型经济特征得到确认 | 毛利率或收入结构显示业务的服务占比显著高于隐含水平。 | 合理倍数会被压到更接近托管安全区间。 | 将立场从合理转向偏贵。 |
| 没有真实价格发现 | 下一轮尽调周期内没有出现经纪商背书的二级市场成交、买盘或股权结构证据。 | 流动性折价仍未解决,市场无法验证头部估值。 | 保持继续研究,或下调建议。 |
| 2023 年后融资不透明 | 管理层无法提供任何 2023 年后融资条款、股数或优先权堆栈文件。 | 没有稀释机制,即便企业价值看起来合理,回报测算也不可靠。 | 没有股权结构包之前,不投入资本。 |
| 增长质量转弱 | ARR 代理值被证明高估,或留存 / 扩张指标低于软件型门槛。 | 打破了 BlueVoyant 至少应获得混合型平台倍数的基准假设。 | 立即重估至熊市区间。 |
这些阈值是尽调触发器,不是合同契约;它们把公开市场证据转化成具体终止标准。
[CV018, CV019, CV023, CV036, CV038, CV041]各情形估值区间以百万美元计,并与当前 $1B 的公开标记对比。
区间为分析师估算,依据保留下来的公开证据、二级市场预览和可比倍数区间得出。
[CV041, CV042, CV043, CV048]8.5 建议、退出纪律与最终尽调问题
仅从公开证据看,建议是继续研究。BlueVoyant 看起来是一家合法且有规模的网络安全平台,当前 $1 billion 标题估值也没有明显脱离保留的 ARR 代理值。但这不等于估值有吸引力。公开市场只提供预览级二级信号,其中最强的一个还是负面信号。此外,保留来源没有披露当前稀释后股数、利润率画像、留存指标,或 2023 年 11 月之后任何融资条款。缺少这些事实,买方可以解释为什么 $1 billion 说得通,但还不能解释为什么它明显对自己有利地错价。 公开证据中的退出准备度也有限。Hiive 称 BlueVoyant 仍为私人持有,合格投资者只能通过二级市场在 IPO 前获得访问;没有任何保留来源显示 IPO 进程、战略出售进程或新的估值重置。可操作路径很直接:拿到当前 ARR 结构、毛利率、NRR 或客户留存、cap table 和优先权栈,以及经纪商或管理层给出的近期真实二级成交。如果这些数据确认类软件经济性,且二级价格稳定或改善,评级可以上调。若它们反而确认收入偏服务、二级交易继续折价,合理标签就会滑向估值偏紧。 [CV021, CV033, CV041, CV042, CV043, CV044]
| 主题 | 缺失证据 | 重要性 | 负责人 / 尽调路径 |
|---|---|---|---|
| 2026 年 ARR 质量 | 当前 ARR、经常性收入与服务收入占比,以及 2023 至 2026 年 ARR 桥接。 | 决定 2025 年 ARR 代理值是否真实,也决定 4.7x 倍数是合理还是偏高。 | 要求提供当前董事会材料或 CFO 经营包。 |
| 利润率和留存画像 | 按主要产品线列示的毛利率、调整后 EBITDA、总留存和 NRR。 | 需要判断 BlueVoyant 应得混合服务倍数,还是软件平台倍数。 | 管理层尽调会,加上队列级留存展项。 |
| 股权结构和摊薄后股数 | 最新完全摊薄股数、优先权堆栈、期权池和清算瀑布。 | 稀释不透明时,每股回报可能与企业价值测算大幅背离。 | 数据室股权结构导出,或律师准备的摘要。 |
| 实际二级市场成交价 | 来自股权结构管理方或交易平台的近期经纪商报价单、撮合交易和买卖盘历史。 | 最好的公开二级市场信号偏负面;真实成交可以验证或反驳该折价。 | 直接做经纪商尽调,并调取 Forge / Notice / 公司管理记录。 |
| 2023 年后任何融资条款 | Series E 轮之后的债务、结构化融资或附函证据。 | 后续资本结构变化会改变下行保护、优先级和估值解读。 | CFO / 法务确认,并提供融资文件。 |
每项要求都对应公开记录中的当前卡点,而不是泛泛的尽调愿望清单。
[CV011, CV021, CV044, CV046, CV047, CV048]按 IC 视角给六个维度打分,这些维度最影响 BlueVoyant 当前估值判断。
分数是分析性、相对性的判断,供 IC 讨论使用,不是模型机械推导出的结果。
[CV037, CV038, CV044, CV046, CV047, CV048]免责声明
本报告仅供尽调和信息参考,不构成投资、法律、会计或税务建议。BlueVoyant 是私营公司,公开记录中的多项数字仍是估算值, 彼此冲突或已经过时。任何投资决定都应基于对管理层的直接尽调、客户访谈、经审计财务和最终法律文件,而不能只依赖公开来源汇总。
证据索引
| 编号 | 陈述 | 可信度 | 来源 |
|---|---|---|---|
| CO001 | BlueVoyant was founded in 2017. | 高 | SO001, SO020, SO021 |
| CO002 | BlueVoyant's current headquarters is 6 East 45th Street, Floor 17, New York, NY 10017. | 高 | SO002, SO003 |
| CO003 | BlueVoyant officially says it has over 600 employees. | 中 | SO001 |
| CO004 | BlueVoyant officially says it has more than 1,000 customers in 45 countries. | 中 | SO003 |
| CO005 | BlueVoyant's core platform spans managed detection and response, third-party risk management, digital risk protection, and professional services. | 高 | SO004, SO005, SO006 |
| CO006 | BlueVoyant's MDR offering covers internal networks, cloud instances, containers, and endpoints and advertises 500+ Microsoft Sentinel deployments. | 中 | SO005 |
| CO007 | BlueVoyant describes its TPRM product as a fully managed service in which ROC experts review, validate, and help remediate third-party findings. | 中 | SO006 |
| CO008 | BlueVoyant presents itself as an AI-driven provider of internal, external, and supply-chain cyber defense. | 中 | SO012, SO029 |
| CO009 | John Hernandez is BlueVoyant's current chief executive officer. | 高 | SO002, SO016, SO027 |
| CO010 | James Rosenthal is a co-founder and now serves as chairman of BlueVoyant's board. | 高 | SO002, SO016, SO027 |
| CO011 | Thomas Glocer is a co-founder and vice chairman of BlueVoyant's board. | 高 | SO002, SO001 |
| CO012 | BlueVoyant's public executive bench includes Ravi Subramanian (CFO), Sebastian Sobolev (CPO), Jim Bieda (Global CTO), John Harbaugh (CISO), and Sangya Sharma (CHRO). | 中 | SO002 |
| CO013 | BlueVoyant's leadership page also lists solution and regional leaders including Ron Feler, Austin Berglas, Chris Teekema, Michael Spencer, Robert Hannigan, Lonny Anderson, Justin Staffel, Holly Steele, and Patrick Shea. | 中 | SO002 |
| CO014 | BlueVoyant published a COO appointment for Michael Montoya, stating that he would oversee technology, product, and operations. | 中 | SO015 |
| CO015 | BlueVoyant says it has received more than 60 awards and nominations since 2019. | 高 | SO009, SO001 |
| CO016 | BlueVoyant's awards materials say it won Microsoft's 2024 Worldwide Security Partner of the Year and 2024 U.S. and Canada Security Partner of the Year honors. | 高 | SO009, SO008 |
| CO017 | BlueVoyant markets itself as a Microsoft security expert with 10x recognition and dedicated service packaging around Sentinel, Defender, Purview, and Copilot-era security operations. | 高 | SO008, SO009 |
| CO018 | BlueVoyant's partner program emphasizes end-to-end platform resale and 24x7 access to sales, marketing, training, and certification resources. | 中 | SO007 |
| CO019 | BlueVoyant says it is a member of the ISTARI Collective. | 中 | SO007 |
| CO020 | On 2022-02-23 BlueVoyant closed a $250 million Series D led by Liberty Strategic Capital with participation from ISTARI, Eden Global Partners, and 8VC. | 高 | SO013, SO017, SO021 |
| CO021 | Independent 2022 coverage said BlueVoyant's Series D valued the company at over $1 billion and brought total funding to $525 million at that time. | 高 | SO021, SO020 |
| CO022 | TechCrunch described BlueVoyant's pre-Series-D offering as a mix of proprietary technology, third-party best-in-class tools, and professional services for internal and external cyber risk. | 中 | SO020 |
| CO023 | BlueVoyant announced on 2023-11-29 that it acquired Conquest Cyber and paired the transaction with more than $140 million in Series E funding. | 中 | SO018, SO023, SO033 |
| CO024 | CRN reported that the combined BlueVoyant-Conquest proposition was aimed at customers securing Microsoft environments across both commercial and government sectors. | 中 | SO022, SO024 |
| CO025 | GovConWire and BankInfoSecurity framed the Conquest acquisition as expanding BlueVoyant's reach into highly regulated, U.S. government, and defense-industrial-base environments. | 中 | SO023, SO024, SO018 |
| CO026 | Caplight lists BlueVoyant's last round as a Series E on 2023-11-29, with an estimated $1 billion valuation and $665.5 million of total funding raised. | 中 | SO030 |
| CO027 | GetLatka lists a 2025 revenue estimate of $213.5 million, $665.5 million of total funding, a $1 billion valuation, and a team size near 650 for BlueVoyant. | 低 | SO029 |
| CO028 | Third-party private-market datasets in the reviewed set cluster around roughly $665.5 million of total funding and a $1 billion valuation, but those figures remain unaudited estimates rather than company disclosure. | 中 | SO029, SO030 |
| CO029 | The reviewed official company sources do not publish current ARR, GAAP revenue, gross margin, or profitability. | 中 | SO001, SO013, SO018 |
| CO030 | Public headcount signals diverge: BlueVoyant officially says it has over 600 employees, while third-party datasets in the retained set range from about 649-650 to 750. | 中 | SO001, SO029, SO030, SO031 |
| CO031 | UpGuard's June 29, 2026 vendor risk report lists BlueVoyant with 750 employees and says its assessment is based on continuous external monitoring across five risk categories. | 中 | SO031 |
| CO032 | UpGuard flags CSP allowing insecure active sources and use of unsafe-eval on BlueVoyant's web estate, creating the clearest adverse public signal in the retained source set. | 中 | SO031 |
| CO033 | BlueVoyant's contact page lists offices in New York, Leeds, London, Tel Aviv, Makati, and Bogotá plus SOC locations in Riverdale and Cork. | 中 | SO003 |
| CO034 | BlueVoyant's company overview page separately describes offices or support presence in College Park, Washington, D.C., London, Leeds, Cork, Toronto, Tel Aviv, Bogota, Manila, and Singapore across five continents. | 中 | SO001 |
| CO035 | Taken together, BlueVoyant's official pages support a globally distributed operating footprint rather than a single-office New York vendor. | 高 | SO001, SO003 |
| CO036 | BlueVoyant launched BlueVoyant AI on 2026-06-09 as an AI-native or agentic SecOps platform for both managed and self-service SOCs. | 高 | SO012, SO025, SO026 |
| CO037 | The 2026 AI launch extends BlueVoyant's existing Microsoft and SOC positioning rather than creating a wholly new category. | 中 | SO012, SO008, SO011 |
| CO038 | On 2025-09-24 BlueVoyant and Auto-ISAC announced a strategic engagement to elevate third-party cyber risk management across the automotive industry. | 高 | SO014, SO019 |
| CO039 | BlueVoyant's careers page emphasizes mission-driven culture, a large proprietary dataset, automation playbooks, and continual training as part of its employment brand. | 中 | SO010 |
| CO040 | BlueVoyant explicitly markets to companies, government entities, and critical-infrastructure organizations rather than to a narrow single vertical. | 中 | SO001, SO018 |
| CO041 | Cyber Insurance News summarized BlueVoyant's 2025 State of Supply Chain Defense report as showing 97% of surveyed organizations suffered negative impact from at least one supply-chain cyber breach, reinforcing the demand case behind its TPRM positioning. | 中 | SO032, SO014 |
| CO042 | PRNewswire and Enterprise IT World show a May 2026 CEO transition from co-founder Jim Rosenthal to John Hernandez while Rosenthal remained chairman. | 高 | SO016, SO027, SO002 |
| CO043 | The CEO handoff reduces single-person operating dependence, but founder-linked governance and brand concentration remain meaningful because Rosenthal and Glocer continue in chair and vice-chair roles. | 中 | SO002, SO016, SO027 |
| CO044 | BlueVoyant's public leadership materials foreground founders in governance or advisory roles rather than as the day-to-day executive bench. | 中 | SO002 |
| CO045 | Caplight characterizes BlueVoyant's customer profile as a B2B mix of subscription SaaS, services and consulting, and government contracts. | 中 | SO030 |
| CO046 | Caplight tags BlueVoyant around threat intelligence, incident response, vulnerability management, cloud security, and compliance or risk workflows. | 中 | SO030 |
| CO047 | The combination of MDR, TPRM, and professional-services pages indicates BlueVoyant monetizes both recurring software modules and analyst-led managed services. | 中 | SO005, SO006, SO030 |
| CO048 | In the reviewed public source set, the last specifically dated financing event is the more-than-$140 million Series E announced on 2023-11-29 alongside the Conquest acquisition. | 中 | SO018, SO023, SO030, SO033 |
| CM001 | BlueVoyant markets MDR as protection for internal networks, cloud instances, containers, and endpoints that augments existing EDR, SIEM, and cloud security tools. | 中 | SM001 |
| CM002 | BlueVoyant markets TPRM as a fully managed solution that identifies, validates, and resolves critical cybersecurity issues in a third-party ecosystem. | 高 | SM002, SM003 |
| CM003 | BlueVoyant's TPRM module set includes continuous monitoring and remediation, questionnaire management, point-in-time risk assessments, and program consulting. | 中 | SM002 |
| CM004 | BlueVoyant's continuous-monitoring workflow includes analyst-directed remediation, business risk monitoring, tiered vendor analysis, zero-day alerting, fourth-party analytics, and APIs/integrations. | 中 | SM003 |
| CM005 | BlueVoyant's fourth-party analytics motion goes beyond direct-vendor questionnaires into fourth- and nth-party dependency mapping and what-if analysis. | 中 | SM005 |
| CM006 | BlueVoyant's AI positioning emphasizes augmenting human judgment in attack-surface monitoring, threat detection, and vulnerability analysis instead of promising a fully autonomous cyber workflow. | 中 | SM001, SM004 |
| CM007 | BlueVoyant's direct market boundary is the overlap between managed SecOps and cyber-focused third-party risk management rather than generic GRC or stand-alone security controls. | 高 | SM001, SM002, SM003, SM005 |
| CM008 | The most relevant adjacent budget pools are GRC, board reporting, and resilience workflows, but those categories should remain outside BlueVoyant's direct core TAM. | 中 | SM015, SM020, SM023 |
| CM009 | Precedence Research sizes the MDR market at USD 3.92B in 2026 and USD 13.90B by 2035, implying 15.12% CAGR from 2026 to 2035. | 中 | SM006 |
| CM010 | Mordor Intelligence sizes the MDR market at USD 5.09B in 2026 and USD 13.45B by 2031, implying 21.45% CAGR. | 中 | SM007 |
| CM011 | The Business Research Company sizes the MDR market at USD 4.16B in 2026 and USD 8.57B by 2030, implying 19.8% CAGR. | 中 | SM008 |
| CM012 | Published MDR baselines conflict materially, with 2026 starting values ranging from USD 3.92B to USD 5.09B and growth assumptions ranging from 15.12% to 21.45% CAGR. | 中 | SM006, SM007, SM008 |
| CM013 | Grand View Research sizes TPRM at USD 7.42B in 2023 and USD 20.59B by 2030 at 15.7% CAGR, with North America holding more than 38% of revenue in 2023. | 中 | SM009 |
| CM014 | NextMSC says the TPRM market reached USD 9.71B by end-2025 and will reach USD 18.28B by 2030 at 13.48% CAGR, with large enterprises expected to dominate demand. | 中 | SM010 |
| CM015 | The Business Research Company says the TPRM market will grow from USD 8.09B in 2026 to USD 15.45B by 2030 at 17.6% CAGR. | 中 | SM011 |
| CM016 | Published TPRM baselines also conflict materially, with direct and normalized 2026 values ranging from roughly USD 8.09B to USD 11.49B depending on methodology and category scope. | 中 | SM009, SM010, SM011 |
| CM017 | The broader adjacent GRC software market is much larger than BlueVoyant's direct wedge, at an estimated USD 23.32B in 2026 growing to USD 39.01B by 2031. | 中 | SM020 |
| CM018 | Combining MDR and TPRM published baselines suggests a gross 2026 core-market ceiling for BlueVoyant of roughly USD 12.0B to USD 16.6B before removing overlap. | 低 | SM006, SM007, SM008, SM009, SM010, SM011 |
| CM019 | Applying large-enterprise, regulated-buyer, and western-market filters to the gross ceiling yields a practical BlueVoyant SAM of roughly USD 5B to USD 8B. | 低 | SM007, SM009, SM010, SM011 |
| CM020 | Public data does not support a precise dollar SOM for BlueVoyant because the company does not disclose module-level revenue or the split between MDR, TPRM, Microsoft-managed services, and adjacent offerings. | 低 | SM001, SM002, SM003, SM004, SM005 |
| CM021 | MDR spending is enterprise-skewed: Mordor says large enterprises accounted for 57.65% of 2025 MDR spend, while TBRC lists major adopters across BFSI, IT, government, and energy verticals. | 中 | SM007, SM008 |
| CM022 | BlueVoyant's practical SAM is likely western-market skewed because Mordor assigns North America 45.78% of MDR revenue in 2025 and Grand View gives North America more than 38% of TPRM revenue. | 低 | SM007, SM009 |
| CM023 | Large enterprises dominate public TPRM demand because they manage extensive vendor ecosystems, global supply chains, and complex regulatory requirements. | 中 | SM010 |
| CM024 | BlueVoyant's TPRM workflow implies a buying committee that spans security, vendor-risk operations, compliance, procurement, and resilience owners rather than a single budget line. | 中 | SM002, SM003, SM005 |
| CM025 | Panorays says 85% of CISOs lack full supply-chain visibility and only 41% monitor fourth parties, validating a core buyer pain point for BlueVoyant's dependency-mapping and monitoring wedge. | 中 | SM014, SM005 |
| CM026 | Panorays says 62% of CISOs saw regulatory pressure increase and only 22% feel fully prepared, showing that buyer urgency is rising even where operating readiness remains low. | 中 | SM014 |
| CM027 | Marsh says 70% of organizations experienced at least one material third-party cyber incident in the past year and 66% plan to increase cybersecurity investment in the coming year. | 中 | SM013 |
| CM028 | KPMG says regulatory compliance and cyber risk are now the primary drivers shaping TPRM strategy globally. | 中 | SM012 |
| CM029 | BlueVoyant's MDR positioning is an overlay and optimization motion for existing security tooling, not a pure rip-and-replace platform sale. | 中 | SM001, SM004 |
| CM030 | BlueVoyant's TPRM positioning suggests payer logic often extends from security into procurement and enterprise-risk owners because remediation and onboarding workflows sit outside the SOC. | 中 | SM002, SM003 |
| CM031 | SEC cybersecurity disclosure rules require public companies to disclose material cyber incidents within four business days and to describe cybersecurity risk management, strategy, and governance. | 中 | SM016 |
| CM032 | NIS2 creates a unified EU cybersecurity framework across 18 critical sectors, expanding the set of organizations that must take supplier and operational cyber risk seriously. | 中 | SM017 |
| CM033 | CISA defines ICT supply-chain cyber risk as spanning hardware, software, and managed services from third-party vendors, suppliers, service providers, and contractors. | 高 | SM023, SM024 |
| CM034 | NIST CSF 2.0 and CISA's SCRM materials show that cyber supply-chain risk is now treated as a formal management and resilience discipline rather than a narrow procurement checklist. | 高 | SM015, SM023, SM024 |
| CM035 | Gartner says AI, geopolitical tension, regulatory volatility, and an accelerating threat landscape are the forces shaping cybersecurity buying priorities in 2026. | 中 | SM018 |
| CM036 | KPMG says only about one in five organizations have achieved full TPRM integration with ERM and only 5% have adopted end-to-end managed-service models. | 中 | SM012 |
| CM037 | Black Kite says that in 2025 each vendor breach compromised an average of 5.28 downstream companies, which makes fourth-party and concentration analysis commercially relevant. | 中 | SM021 |
| CM038 | BlueVoyant claims its TPRM monitoring uses AI/ML across more than 50,000 data sources and can issue zero-day alerts in as little as 90 minutes, aligning the product with continuous-risk rather than periodic-review buying criteria. | 中 | SM003, SM005 |
| CM039 | CyberProof says Gartner has warned that some providers misuse the MDR label by offering managed EDR or other tool-centric monitoring without full human-led incident-response leadership. | 中 | SM019 |
| CM040 | CyberProof says MDR has moved toward mainstream adoption, citing projections that half of organizations would use MDR services for 24x7 monitoring, detection, and containment. | 低 | SM019 |
| CM041 | KPMG says most organizations still rely on a patchwork of disconnected tools, which constrains category standardization and slows end-to-end TPRM adoption. | 中 | SM012 |
| CM042 | Panorays' data implies that many buyers still operate with major blind spots beyond direct vendors, so category adoption is limited as much by process maturity as by software availability. | 中 | SM014 |
| CM043 | CRC says global cyber-insurance pricing fell about 7% in Q4 2025 as market capacity improved, which can soften one urgency lever for cyber-spend escalation. | 中 | SM022 |
| CM044 | CRC says ransomware remained the primary driver of business interruption claims and that supply-chain and vendor risk stayed a central underwriting focus in 2026. | 中 | SM022 |
| CM045 | PeerSpot's MDR category page shows that buyers actively compare many vendors and still ask what differentiates MDR from a traditional SOC, reinforcing category crowding and education friction. | 中 | SM025 |
| CM046 | BlueVoyant's market should not be equated with generic GRC because BlueVoyant sells cyber monitoring, validation, remediation, and dependency visibility rather than broad policy-and-audit software alone. | 中 | SM002, SM003, SM020 |
| CM047 | BlueVoyant's strongest valuation support comes from cross-sell between independently growing MDR and TPRM categories that are both being pulled forward by regulation and operating pain. | 中 | SM006, SM007, SM011, SM013, SM018 |
| CM048 | The main market risk is not whether the categories exist, but whether BlueVoyant can win inside crowded, definition-sensitive categories where buyer confusion, tool sprawl, and budget scrutiny can slow conversion. | 中 | SM012, SM019, SM022, SM025 |
| CM049 | BlueVoyant's differentiated TPRM wedge appears to be analyst-led remediation plus fourth-party mapping, not just questionnaire automation. | 中 | SM002, SM003, SM005, SM014 |
| CM050 | BlueVoyant's differentiated MDR wedge appears to be overlaying and optimizing existing Microsoft, EDR, and SIEM environments with 24x7 monitoring and automation rather than selling a stand-alone security control. | 中 | SM001, SM004 |
| CP001 | Gartner defines MDR as a provider-operated, outcome-driven SOC service that includes active disruption and containment rather than alerting alone. | 中 | SP027 |
| CP002 | BlueVoyant publicly positions itself across MDR, TPRM, digital risk protection, and professional services rather than as a single-product MDR vendor. | 中 | SP001 |
| CP003 | BlueVoyant highlights 1,200+ Microsoft Sentinel deployments, 10 Microsoft security awards, and 24x7 in-regional SOC monitoring across Europe and the US. | 中 | SP001 |
| CP004 | BlueVoyant’s MDR page advertises 50+ certified Microsoft Delivery and SOC engineers plus unlimited remote incident-response lifecycle support. | 中 | SP003 |
| CP005 | BlueVoyant says it was founded in 2017 and has over 600 employees across offices on five continents. | 中 | SP002 |
| CP006 | BlueVoyant Government’s C-SCRM product says it uses more than 70,000 unique proprietary, open-source, and commercial data feeds without requiring agency or vendor proprietary data. | 中 | SP005 |
| CP007 | BlueVoyant Government says it can map, monitor, and mitigate risk for tens of thousands of suppliers at once and validate 100% of supplier risk events. | 中 | SP005 |
| CP008 | BlueVoyant’s June 2026 launch of BlueVoyant AI signals a strategic move toward agentic SecOps that can be consumed either as a fully managed SOC or a self-service SaaS platform. | 中 | SP006 |
| CP009 | Palo Alto positions Cortex XSIAM as a unified AI-driven SOC platform spanning SIEM, SOAR, EDR, NDR, and CDR. | 中 | SP007 |
| CP010 | Palo Alto advertises 10,000+ detections, 2,600+ analytics models, and Unit 42-managed services on top of XSIAM. | 中 | SP007 |
| CP011 | Palo Alto says it has 16K+ employees and 70K+ customers globally, giving it distribution scale that BlueVoyant cannot match publicly. | 中 | SP008 |
| CP012 | CrowdStrike Falcon Complete advertises a one-minute median time-to-contain and 2.7 million detections remediated monthly. | 中 | SP009 |
| CP013 | CrowdStrike frames Falcon Complete as agentic MDR that combines deterministic automation, adaptive AI agents, human-in-the-loop experts, and native visibility across endpoint, identity, cloud, and third-party data. | 中 | SP009 |
| CP014 | Arctic Wolf positions around a fully managed agentic SOC with 10,000+ customers, 1,000+ security engineers, and 200+ integrations. | 中 | SP010, SP011 |
| CP015 | Arctic Wolf says its proactive MDR can reduce attack frequency and impact by up to 90% and completed more than 74,000 security posture reviews in 2025. | 低 | SP010 |
| CP016 | Arctic Wolf’s value proposition centers on concierge delivery, open XDR, security-journey guidance, and warranty coverage rather than a single endpoint platform. | 中 | SP010, SP012 |
| CP017 | CRN reported that Arctic Wolf raised $60 million in Series D to help the company prepare for IPO-related thresholds. | 中 | SP032 |
| CP018 | SC Media reported that Arctic Wolf was valued at roughly $4.3 billion while management avoided committing to an IPO timeline. | 中 | SP033 |
| CP019 | Rapid7 says it serves more than 11,500 customers worldwide and positions itself as a leader in AI-powered managed cybersecurity operations. | 中 | SP013 |
| CP020 | Rapid7’s Incident Command platform ties exposure management, endpoint and cloud telemetry, third-party sources, Rapid7 Labs intelligence, and 20 years of data into one detection-and-response workflow. | 中 | SP014 |
| CP021 | ReliaQuest describes GreyMatter as an agentic AI security operations platform that detects, contains, investigates, and responds regardless of data source. | 中 | SP015 |
| CP022 | ReliaQuest’s homepage says GreyMatter processes 50K+ alerts daily with 255+ technology partners and 99.4% AI investigation accuracy. | 中 | SP016 |
| CP023 | ReliaQuest’s integrations posture supports enterprises that want to keep existing SIEM, EDR, and cloud tools rather than replace them with one vendor stack. | 中 | SP017 |
| CP024 | eSentire says it protects 2,000+ customers across 35+ industries and pairs Atlas AI with 24/7 expert human SOC coverage. | 中 | SP018 |
| CP025 | eSentire’s XDR platform and third-party coverage claim a vendor-independent model with broad integrations and human-controlled AI response. | 中 | SP019, SP034 |
| CP026 | eSentire’s competitive messaging explicitly emphasizes unlimited threat hunting, unlimited incident handling, and any-signal integration breadth. | 中 | SP020 |
| CP027 | SecurityScorecard says 70% of the Fortune 100 trust its data, 3,300+ organizations use the platform, and 12M+ organizations are monitored and rated. | 中 | SP022 |
| CP028 | SecurityScorecard’s TPRM pitch combines questionnaire review, technical-ground-truth validation, continuous monitoring, nth-party visibility, remediation blueprints, and risk quantification. | 中 | SP021, SP023 |
| CP029 | SecurityScorecard publicly frames itself as supply-chain detection and response rather than only a passive cyber-ratings tool. | 中 | SP021, SP022 |
| CP030 | BitSight says its TPRM product includes 75K+ mapped vendor profiles and claims a 75% reduction in third-party breach probability for customers. | 低 | SP025 |
| CP031 | BitSight says it continuously monitors 40M+ companies and 250M+ digital assets and exposes cyber risk through APIs, integrations, and data feeds. | 中 | SP024, SP025 |
| CP032 | Bitsight’s April 2026 press release says it was named a Forrester Leader and had more than 3,500 customers plus over 68,000 organizations active on platform. | 中 | SP026 |
| CP033 | Gartner’s 2026 MDR market page lists 173 products and reiterates that immediate remote mitigative response is a mandatory MDR feature. | 中 | SP027 |
| CP034 | PeerSpot says BlueVoyant CORE held 0.9% MDR mindshare in June 2026, down from 1.2% the year before. | 中 | SP028 |
| CP035 | PeerSpot’s BlueVoyant-versus-CrowdStrike comparison ranks BlueVoyant #34 in MDR while CrowdStrike is ranked #2 and holds 5.4% mindshare versus BlueVoyant’s 0.9%. | 中 | SP029 |
| CP036 | PeerSpot says reviewers occasionally note limited reporting customization for BlueVoyant and characterize CrowdStrike as broader and faster to deploy. | 中 | SP029 |
| CP037 | Daylight’s 2026 buyer guide classifies BlueVoyant among MSSPs offering MDR that are chosen for broad security partnership but use more analyst-hours-intensive investigation workflows than AI-native or XDR-extended alternatives. | 中 | SP031 |
| CP038 | Ciphers Security says the TPRM market splits between outside-in security-ratings platforms and workflow-oriented lifecycle tools such as ProcessUnity, OneTrust, Venminder, and Prevalent. | 中 | SP030 |
| CP039 | The same Ciphers Security guide says ratings tools assess vendors from the outside in, while workflow platforms manage questionnaires and lifecycle tasks from the inside, so many buyers blend the two approaches. | 中 | SP030 |
| CP040 | BlueVoyant’s public combination of MDR, TPRM, digital-risk protection, and government C-SCRM gives it a cross-budget story that most MDR-only or ratings-only competitors do not present on one surface. | 中 | SP001, SP004, SP021, SP024 |
| CP041 | The retained official pages for BlueVoyant, CrowdStrike, Arctic Wolf, Rapid7, ReliaQuest, eSentire, SecurityScorecard, and BitSight do not disclose enterprise list pricing for their full offerings, implying quote-based sales motions and limited public comparability. | 中 | SP001, SP009, SP010, SP013, SP015, SP018, SP021, SP024 |
| CP042 | Platform-native competitors create bundling pressure because Palo Alto, CrowdStrike, and Rapid7 tie managed response to broader SOC, XDR, or SIEM suites with unified telemetry and automation. | 中 | SP007, SP009, SP014 |
| CP043 | Arctic Wolf, ReliaQuest, and eSentire represent a separate open-stack threat because all three publicly stress preserving the customer’s existing security tools while adding 24x7 expert operations. | 中 | SP010, SP017, SP019 |
| CP044 | BlueVoyant’s supply-chain defense competes against much larger publicly described data networks because SecurityScorecard and BitSight cite millions of monitored organizations or tens of thousands of mapped vendor profiles. | 中 | SP022, SP025, SP026 |
| CP045 | BlueVoyant is best aligned to Microsoft-heavy or regulated buyers that want managed SOC operations plus outside-in supplier defense rather than a single-vendor endpoint suite or a pure ratings tool. | 中 | SP001, SP003, SP005, SP006, SP021, SP024 |
| CP046 | Internal SOC build remains a substitute, but Gartner and Decryption Digest both frame outsourced MDR as a way to avoid the staffing and response burden of self-running security operations. | 中 | SP027, SP031 |
| CI001 | BlueVoyant publicly packages MDR, TPRM, DRP, and professional services as four core commercial solution families. | 中 | SI001 |
| CI002 | BlueVoyant claims more than 1,200 successful Microsoft Sentinel deployments. | 中 | SI001 |
| CI003 | BlueVoyant claims customers can reduce Sentinel costs by 40% without sacrificing coverage. | 中 | SI001 |
| CI004 | BlueVoyant claims it provides 24x7 in-regional SOC monitoring across Europe and the United States. | 中 | SI001 |
| CI005 | BlueVoyant claims its TPRM offer drives 18x faster remediation of critical issues. | 中 | SI001 |
| CI006 | BlueVoyant claims 98% accuracy for critical vulnerabilities identified in its TPRM motion. | 中 | SI001 |
| CI007 | BlueVoyant claims an average response time of 3.5 hours for recently disclosed zero-day vulnerabilities. | 中 | SI001 |
| CI008 | BlueVoyant claims it remediated more than 1,600 vulnerabilities on behalf of clients in the last 30 days. | 中 | SI001 |
| CI009 | BlueVoyant claims it completed 50,000 successful domain takedowns over the prior two years. | 中 | SI001 |
| CI010 | BlueVoyant says it has over 600 employees across offices spanning five continents. | 中 | SI002 |
| CI011 | BlueVoyant publicly positions channel partners such as GuidePoint Security and CDW as part of its distribution model. | 中 | SI003 |
| CI012 | BlueVoyant's build-versus-buy marketing says a self-built 24/7 SOC can cost more than $1.2 million annually. | 中 | SI004 |
| CI013 | The same BlueVoyant page says a partnered MSSP can cost less than 25% of the annual cost of building an internal SOC. | 中 | SI004 |
| CI014 | BlueVoyant said it added 299 new customers during 2021. | 中 | SI005 |
| CI015 | BlueVoyant said customer count exceeded 700 across 30 countries by early 2022. | 高 | SI005, SI006 |
| CI016 | BlueVoyant said its employee count increased by 130% during 2021. | 中 | SI005 |
| CI017 | BlueVoyant said partners contributed 50% of all new business in 2021. | 中 | SI005 |
| CI018 | BlueVoyant said annual recurring revenue had grown 117% on average since 2018. | 高 | SI005, SI006 |
| CI019 | BlueVoyant closed a $250 million Series D round led by Liberty Strategic Capital with participation from ISTARI, Eden Global Partners, and 8VC. | 高 | SI006, SI022 |
| CI020 | BlueVoyant said it had grown to more than 560 employees and more than 700 customers by the Series D announcement. | 中 | SI006 |
| CI021 | BlueVoyant said it expanded into more than 10 countries during 2021. | 中 | SI006 |
| CI022 | BlueVoyant acquired Conquest Cyber and raised more than $140 million of Series E funding alongside the deal. | 高 | SI007, SI018, SI019, SI020, SI021 |
| CI023 | The Series E funding was led by Liberty Strategic Capital and ISTARI, with Eden Global Capital Partners acting as strategic adviser. | 高 | SI007, SI018, SI019, SI020, SI021 |
| CI024 | BlueVoyant said Conquest Cyber added SaaS technology and FedRAMP Marketplace credentials for defense and government use cases. | 中 | SI007, SI020 |
| CI025 | BlueVoyant said it had more than 900 global customers when Timothy Yost joined as CFO in June 2024. | 中 | SI008 |
| CI026 | BlueVoyant framed the Timothy Yost hire as scaling the company's financial and strategic planning capability. | 中 | SI008 |
| CI027 | BlueVoyant said it served over 1,000 customers in more than 45 countries by March 2025. | 高 | SI009, SI026 |
| CI028 | BlueVoyant said local EMEA revenue grew 70% in 2024 and described Cork as part of a multi-million-euro regional investment program. | 中 | SI009 |
| CI029 | BlueVoyant's commissioned Forrester MDR study claims 210% ROI over three years. | 中 | SI010 |
| CI030 | The same MDR study claims a 90% reduction in total escalated alerts per month. | 中 | SI010 |
| CI031 | The same MDR study claims a 70% acceleration in mean time to resolve. | 中 | SI010 |
| CI032 | BlueVoyant's commissioned Supply Chain Defense study claims nearly 300% return on investment. | 中 | SI011 |
| CI033 | The same Supply Chain Defense study claims a 62% reduction in time to remediate critical risks. | 中 | SI011 |
| CI034 | BlueVoyant's Snappi case study says the customer achieved 24x7 SOC coverage within months instead of hiring across multiple vendors. | 中 | SI012 |
| CI035 | BlueVoyant's ODEON case study says the deployment spans 8 countries and more than 280 cinemas. | 中 | SI013 |
| CI036 | BlueVoyant's ODEON case study says the program cut alerts requiring InfoSec or regional IT review by 98%. | 中 | SI013 |
| CI037 | BlueVoyant's ODEON case study says the program resolved 30 critical or high third-party vulnerabilities. | 中 | SI013 |
| CI038 | BlueVoyant said Google Cloud Marketplace availability removes procurement friction for its TPRM offer. | 中 | SI014 |
| CI039 | BlueVoyant's Microsoft-security ROI blog says an enterprise can spend up to $750,000 annually to optimize the stack internally. | 中 | SI015 |
| CI040 | BlueVoyant's Sentinel deployment guide says its examples are drawn from hundreds of deployments and 16 anonymized case studies. | 中 | SI016 |
| CI041 | Private Equity Insights reported that BlueVoyant intended to use Series D proceeds for product development and international expansion. | 中 | SI022 |
| CI042 | CB Insights reported that BlueVoyant had raised $665.5 million over 9 rounds. | 中 | SI023 |
| CI043 | CB Insights reported a $1.0 billion valuation in February 2022. | 中 | SI023 |
| CI044 | CB Insights estimated BlueVoyant's 2024 revenue at $750 million, which conflicts with lower recurring-revenue estimates in other databases. | 低 | SI023 |
| CI045 | GetLatka estimated BlueVoyant's 2025 revenue at $213.5 million. | 低 | SI024 |
| CI046 | GetLatka estimated BlueVoyant employed about 650 people in 2025. | 低 | SI024 |
| CI047 | Clay reported $665.5 million of total funding and a latest funding date of 2023-11-01. | 中 | SI026 |
| CI048 | Clay reported 11 investors and over 1,000 customers across 45 countries. | 中 | SI026 |
| CI049 | Dialectica listed BlueVoyant at 653 employees and named Liberty Strategic Capital as an investor. | 中 | SI025 |
| CI050 | Tracxn reported $696 million of total funding across 6 rounds, conflicting with the $665.5 million totals cited by CB Insights and Clay. | 低 | SI027 |
| CI051 | PitchBook's accessible snapshot showed 363 employees and a $30 million latest deal amount, conflicting with the 600-plus employee signals from later sources. | 低 | SI028 |
| CI052 | PitchBook's accessible snapshot included a historical Debt - PPP financing entry dated 2020-04-27. | 中 | SI028 |
| CI053 | Companies House shows BlueVoyant UK Limited filed full accounts for the year ended 2024 on 2025-09-30. | 中 | SI029 |
| CI054 | Companies House shows a compulsory strike-off action against BlueVoyant UK Limited was discontinued in March 2025. | 中 | SI029 |
| CI055 | Companies House shows BlueVoyant Ltd also filed full accounts for the year ended 2024 on 2025-09-30. | 中 | SI030 |
| CI056 | An archived Indeed review described BlueVoyant as extremely top heavy with management. | 低 | SI031 |
| CI057 | The same archived review alleged consistent bi-yearly layoffs and resource cuts across some business units. | 低 | SI031 |
| CI058 | No retained public source verified current cash on hand, monthly burn, or runway as of 2026-06-29. | 中 | SI001, SI002, SI006, SI007, SI008, SI009, SI023, SI024, SI026, SI027, SI028 |
| CI059 | No retained public source disclosed realized contract pricing, discounting, gross margin, NRR, or CAC payback for BlueVoyant. | 中 | SI001, SI004, SI010, SI011, SI014, SI015, SI023, SI024, SI026 |
| CI060 | The public record supports a recurring managed-services model but does not reconcile the mix between software-like recurring revenue and project-based services. | 中 | SI001, SI005, SI006, SI007, SI010, SI011, SI012, SI013 |
| CI061 | Using GetLatka's $213.5 million revenue estimate and Dialectica's 653-employee estimate implies roughly $327,000 of revenue per employee. | 低 | SI024, SI025 |
| CI062 | Using the $665.5 million consensus total raised and GetLatka's $213.5 million revenue estimate implies cumulative funding of roughly 3.1x estimated annual revenue. | 低 | SI024, SI026 |
| CI063 | BlueVoyant's current public financial signal set is too contradictory to underwrite revenue quality or runway without management data. | 中 | SI023, SI024, SI025, SI026, SI027, SI028, SI029, SI030, SI031 |
| CE001 | BlueVoyant currently defines its customer-facing offer as Agentic SecOps, MDR, and TPRM that protect the full attack surface. | 中 | SE001 |
| CE002 | BlueVoyant publicly advertises Microsoft-focused scale signals including 1,200-plus Sentinel deployments, 24x7 in-regional SOC monitoring, and named cost savings. | 中 | SE001 |
| CE003 | The Cyber Defense Platform page organizes the portfolio into MDR, TPRM, DRP, and professional-services suites. | 中 | SE002 |
| CE004 | BlueVoyant’s 2024 platform launch describes a single cloud-native platform integrating internal, external, and supply-chain defense. | 高 | SE002, SE021 |
| CE005 | The platform is described as processing signals and alerts from internal networks, supply chains, and the clear, deep, and dark web. | 高 | SE021, SE027 |
| CE006 | BlueVoyant AI says the company matches human expertise, deterministic automation, and AI agents to the mission rather than treating AI as a universal substitute. | 高 | SE003, SE022 |
| CE007 | BlueVoyant AI is offered both as a fully managed service and as a SaaS platform for internal security teams. | 高 | SE003, SE022 |
| CE008 | BlueVoyant AI publicly claims automated response actions including device isolation, credential revocation, and malicious-email eradication. | 中 | SE022 |
| CE009 | BlueVoyant AI attributes its Microsoft advantage to almost ten years of operating experience and more than 2,500 Microsoft-native customer deployments. | 中 | SE022 |
| CE010 | BlueVoyant MDR is marketed as protecting internal networks, cloud instances, containers, and endpoints while strengthening existing EDR, SIEM, and cloud-security tools. | 中 | SE004 |
| CE011 | MDR for Microsoft and Continuous Optimization for Microsoft Solutions are first-class modules inside the MDR suite. | 高 | SE004, SE006 |
| CE012 | BlueVoyant promises 24/7 detection and response across the full Microsoft security stack. | 高 | SE005, SE031 |
| CE013 | The MDR for Microsoft page lists 2026 Data Security and Compliance Trailblazer recognition, 2024 Worldwide Security Partner of the Year, three-time US Security Partner of the Year, and MISA membership. | 中 | SE005 |
| CE014 | BlueVoyant claims Microsoft Solutions Partner designations in Security, Infrastructure (Azure), and Modern Work plus security specializations in Cloud Security, Identity and Access Management, and Threat Protection. | 中 | SE005 |
| CE015 | Continuous Optimization for Microsoft Solutions extends the offer into Sentinel, Defender, M365, and Purview configuration and optimization based on 1,000-plus engagements. | 高 | SE006, SE007 |
| CE016 | BlueVoyant’s MDR for Microsoft collateral says customers can keep security data in their own environment instead of sending it to MSSP-owned infrastructure. | 中 | SE031 |
| CE017 | The Microsoft collateral frames the service around Microsoft Sentinel and Microsoft 365 Defender as the core security stack. | 中 | SE031 |
| CE018 | The MDR for Microsoft deployment playbook explicitly includes infrastructure setup, log-source ingestion, alert and SOAR configuration, knowledge transfer, and initial alert tuning. | 中 | SE031 |
| CE019 | BlueVoyant describes TPRM as a fully managed solution that identifies, validates, and resolves critical cybersecurity issues in a third-party ecosystem. | 中 | SE008 |
| CE020 | BlueVoyant’s TPRM suite includes continuous monitoring and remediation, questionnaire management, point-in-time risk assessments, and vendor consulting. | 高 | SE008, SE015 |
| CE021 | The continuous-monitoring workflow says Risk Operations Center analysts validate findings and work directly with third parties on remediation. | 中 | SE009 |
| CE022 | BlueVoyant says its business-risk monitoring uses AI and machine learning across more than 50,000 data sources and eight risk categories. | 中 | SE009 |
| CE023 | The questionnaire-management module automates assessment creation and distribution while validating supplier statements against observed performance. | 中 | SE010 |
| CE024 | BlueVoyant’s 2023 supply-chain expansion added multi-tier continuous monitoring, questionnaire workflows, point-in-time assessments, rapid zero-day alerting, and advisory workshops. | 高 | SE015, SE023 |
| CE025 | BlueVoyant positions DRP as protection against threats emerging from the clear, deep, and dark web before they affect the business or customers. | 中 | SE011 |
| CE026 | BlueVoyant’s DRP modules are Brand Protection, Dark Web Watcher, and Executive Cyber Guard. | 中 | SE011 |
| CE027 | Brand Protection covers web, social-media, and app impersonation with unlimited takedowns and monitoring across more than 300 official and unofficial app stores. | 中 | SE012 |
| CE028 | Dark Web Watcher monitors underground communities for fraud campaigns, sold credentials, and data leakage. | 中 | SE013 |
| CE029 | Executive Cyber Guard focuses on executive-data exposure, stolen credentials, and account-takeover prevention for high-value individuals. | 中 | SE014 |
| CE030 | BlueVoyant’s differentiated product story is convergence: Microsoft-centric MDR on the inside, TPRM across the supply chain, and DRP on the external attack surface under one operating model. | 中 | SE002, SE004, SE008, SE011 |
| CE031 | The Trust Center describes BlueVoyant as a cloud-native security-operations platform combining advanced AI with expert human insight across networks, endpoints, supply chains, and web or dark-web monitoring. | 中 | SE017 |
| CE032 | The Trust Center says BlueVoyant is trusted by more than 1,000 clients globally. | 中 | SE017 |
| CE033 | Conquest Cyber adds SaaS technology that unifies security posture, compliance, detection, and response through a risk-maturity lens. | 高 | SE016, SE024 |
| CE034 | BlueVoyant planned to integrate Conquest technology into existing products and services to create internal and external cyber defense mapped to risk maturity. | 高 | SE016, SE024 |
| CE035 | Conquest brought DIB and government credentials, CMMC RPO accreditation, FedRAMP-marketplace presence for ARMED ATK, and additional Microsoft security capabilities into BlueVoyant’s platform story. | 高 | SE016, SE024 |
| CE036 | Public GitHub evidence shows only one visible BlueVoyant repository, BV-Security-Copilot, with the public pages pointing to a September 22, 2025 update. | 高 | SE018, SE019, SE020 |
| CE037 | The visible BlueVoyant GitHub repo is framed as public content for Copilot for Security, implying limited open-source transparency relative to the breadth of the marketed platform. | 中 | SE020 |
| CE038 | Microsoft Learn records a BlueVoyant Shadow Hunter Microsoft Security Immersion Workshop, showing practitioner-facing Microsoft training activity beyond static marketing pages. | 中 | SE032 |
| CE039 | Gartner’s DRP page surfaces a favorable review headline that still notes occasional takedown challenges, signaling that takedown execution remains a real operational risk area. | 中 | SE029 |
| CE040 | A 2019 Spiceworks thread shows buyer skepticism that BlueVoyant was a startup relying on established tools such as Splunk, highlighting a long-running diligence question about proprietary depth versus service orchestration. | 低 | SE030 |
| CE041 | PeerSpot describes BlueVoyant CORE as a combined MDR, digital-risk-protection, and supply-chain-defense suite backed by 24/7 monitoring and machine learning. | 中 | SE025 |
| CE042 | Cyber Magazine independently described the 2024 launch as a cloud-native platform specifically aimed at the supplier-driven attack surface. | 中 | SE026 |
| CE043 | BlueVoyant publicly reports a 99 percent website-takedown success rate, a 95 percent social-media-takedown success rate, and a 23-hour median server-level takedown time for DRP. | 中 | SE001 |
| CU001 | BlueVoyant’s visible customer base skews toward regulated or operationally complex organizations rather than broad SMB self-serve buyers. | 低 | SU001, SU002, SU003, SU005, SU014, SU019 |
| CU002 | The deepest named public proofs span state government, federal defense supply chains, digital banking, capital-markets infrastructure, and multinational entertainment operations. | 低 | SU001, SU002, SU003, SU005, SU019 |
| CU003 | Public financial-services proof is concentrated in Snappi, Beeks, ClearBank, and sector-specific Microsoft content rather than a long named roster of banks or insurers. | 低 | SU003, SU005, SU006, SU014, SU026 |
| CU004 | Public-sector proof is concentrated in California OIS, NAVSEA, and Carahsoft-enabled procurement routes rather than a broad public list of named agencies. | 低 | SU001, SU013, SU019, SU024, SU030, SU031 |
| CU005 | California OIS launched a cloud-based SOCaaS that integrated Microsoft Security with BlueVoyant’s MDR for Microsoft. | 中 | SU001 |
| CU006 | BlueVoyant’s California case study says the program reduced mean time to detect by 70 percent. | 中 | SU001 |
| CU007 | BlueVoyant’s California case study says the program reduced mean time to respond by 60 percent. | 中 | SU001 |
| CU008 | BlueVoyant’s California case study says participating entities saved about $2.1 million in annual personnel costs. | 中 | SU001 |
| CU009 | California’s Department of Technology said in June 2025 that SOCaaS protected 112 public-sector organizations and had produced more than $54 million of combined savings. | 中 | SU037 |
| CU010 | California CDT describes SOCaaS as a 24/7 continuous-monitoring service used to satisfy statewide monitoring requirements. | 中 | SU036, SU037 |
| CU011 | ODEON Cinemas Group runs more than 280 cinemas across eight countries. | 中 | SU002, SU033 |
| CU012 | ODEON’s public materials describe nearly 50 log sources and a previously fragmented, noisy security setup before BlueVoyant’s engagement. | 中 | SU002, SU033 |
| CU013 | BlueVoyant migrated ODEON to Microsoft Sentinel, onboarded MDR for Microsoft, and added DFIR plus third-party risk management. | 中 | SU002, SU033 |
| CU014 | ODEON’s case-study materials report a 98 percent reduction in alerts requiring review. | 中 | SU002, SU033 |
| CU015 | ODEON’s BlueVoyant case study reports 30 critical or high third-party vulnerabilities resolved. | 中 | SU002 |
| CU016 | Independent coverage quotes ODEON saying monthly alerts fell from hundreds to roughly 6 to 12 tickets. | 中 | SU033 |
| CU017 | Snappi is described in multiple public sources as Greece’s first ECB-licensed neobank. | 中 | SU003, SU034, SU035 |
| CU018 | Snappi used BlueVoyant and Veracloud to implement 24/7 SOC coverage, MDR, dark-web monitoring, and incident-response readiness within months of launch. | 中 | SU003, SU034, SU035 |
| CU019 | Snappi’s public proof emphasizes board visibility, monthly SOC KPI reporting, tabletop exercises, and DORA readiness rather than conventional revenue or usage metrics. | 中 | SU003, SU034 |
| CU020 | Beeks says BlueVoyant now supports a 24x7 end-to-end SOC for a platform serving capital-markets and financial-services customers. | 中 | SU005, SU026 |
| CU021 | Beeks says BlueVoyant lowered alert fatigue, reduced data-ingestion costs, and was operational in less than three months. | 中 | SU005, SU026 |
| CU022 | Beeks positions the partnership as a customer-acquisition differentiator because its own clients ask about cyber resilience. | 中 | SU005, SU026 |
| CU023 | NAVSEA awarded a three-year Phase III contract and delivery orders to BlueVoyant Government Solutions for industrial-base resilience and supply-chain illumination work. | 中 | SU019, SU020 |
| CU024 | BlueVoyant Government Solutions said in April 2025 that its SCD-G platform had been added to Carahsoft’s SCRIPTS BPA vehicle. | 中 | SU031 |
| CU025 | BlueVoyant Government Solutions said its platform currently identifies critical risks for more than 4 million suppliers. | 中 | SU031 |
| CU026 | Carahsoft distributes BlueVoyant through SEWP V, ITES-SW2, NASPO ValuePoint, and California CMAS procurement routes. | 中 | SU024, SU030 |
| CU027 | BlueVoyant’s partner program offers co-selling, training, account support, and marketing tooling across channel, tech-alliance, and OEM relationships. | 中 | SU004 |
| CU028 | Carahsoft says its reseller ecosystem includes more than 10,000 government contractors, VARs, solution providers, integrators, and MSPs. | 中 | SU032 |
| CU029 | AWS Marketplace shows BlueVoyant selling a private-offer MDR service with 24x7 SOC support. | 中 | SU025 |
| CU030 | BlueVoyant’s public financial-services evidence includes named work with Snappi, Beeks, and ClearBank plus sector materials featuring Fiserv and JP Morgan participants. | 低 | SU003, SU005, SU006, SU008, SU014, SU026 |
| CU031 | BlueVoyant’s public government evidence includes California SOCaaS, NAVSEA supply-chain work, Carahsoft distribution, and contract-vehicle access. | 低 | SU001, SU019, SU024, SU030, SU031, SU037 |
| CU032 | BlueVoyant actively markets to energy and legal buyers, but the reviewed corpus does not show equally deep named production proofs for those sectors. | 低 | SU015, SU016 |
| CU033 | BlueVoyant’s 2024 MDR TEI summary claims 210 percent three-year ROI, 90 percent fewer escalated alerts per month, and 70 percent faster mean time to resolve for a composite customer. | 中 | SU017 |
| CU034 | BlueVoyant’s supply-chain-defense TEI summary claims nearly 300 percent ROI, 65 percent better monitoring efficiency, 70 percent fewer suppliers above risk threshold, and 60 percent faster remediation of critical risks. | 中 | SU011 |
| CU035 | BlueVoyant’s 2025 supply-chain survey says it captured 1,800 executives across financial services, healthcare, pharma, utilities, energy, retail, manufacturing, and defense. | 中 | SU012 |
| CU036 | BlueVoyant said in May 2025 that it was trusted by more than 1,000 clients globally and had guided thousands of clients on Microsoft Security. | 中 | SU018 |
| CU037 | FeaturedCustomers shows BlueVoyant with 9 reviews, 5 case studies, and a 4.7 out of 5 reference rating across 133 total customer references. | 中 | SU021, SU022 |
| CU038 | PeerSpot describes BlueVoyant deployments across finance, healthcare, and manufacturing and says licensing typically includes annual or multi-year agreements. | 中 | SU023 |
| CU039 | The reviewed AWS Marketplace and Slashdot pages both show zero visible customer ratings or reviews for BlueVoyant. | 中 | SU025, SU029 |
| CU040 | None of the reviewed public customer sources disclose NRR, GRR, churn, or cohort renewal performance. | 低 | SU001, SU002, SU003, SU005, SU014, SU021, SU022, SU023 |
| CU041 | None of the reviewed public customer sources break out top-customer concentration or contract-duration exposure by revenue. | 低 | SU001, SU002, SU003, SU005, SU014, SU019, SU021, SU023 |
| CU042 | The strongest public outcomes cluster around Microsoft-centered operations, managed detection and response, and supply-chain risk use cases rather than broad attach-rate disclosure across all product lines. | 低 | SU001, SU002, SU003, SU005, SU014, SU017, SU031 |
| CU043 | Most quantified customer proof is vendor-authored or partner-authored rather than independently audited, so deployment outcomes are visible but durability evidence remains thin. | 低 | SU001, SU002, SU003, SU005, SU022, SU028, SU029, SU033, SU034 |
| CR001 | BlueVoyant markets itself as a Microsoft security specialist across Sentinel, Defender, Purview, and Copilot-readiness work. | 中 | SR002, SR003 |
| CR002 | BlueVoyant says its MDR for Microsoft offer combines BlueVoyant AI with an elite 24x7 SOC and security operations team. | 中 | SR003, SR018 |
| CR003 | BlueVoyant says it works with Microsoft product teams on Sentinel scenarios, operations feedback, API extensibility, and Security Copilot agents. | 中 | SR013, SR028 |
| CR004 | BlueVoyant says it won the 2024 Microsoft Worldwide Security Partner of the Year Award and additional U.S. and Canada security partner awards. | 高 | SR010, SR014 |
| CR005 | BlueVoyant and Micah Heaton were recognized in the 2025 Microsoft Security Excellence Awards as Security Trailblazer and Security Changemaker winners. | 高 | SR009, SR017, SR027 |
| CR006 | BlueVoyant’s Sentinel eBook says it summarizes 16 anonymized case studies drawn from hundreds of hands-on Microsoft Sentinel deployments. | 中 | SR033 |
| CR007 | Protiviti describes BlueVoyant’s Microsoft offering as combining advanced AI with expert human insight in a joint services stack. | 中 | SR018 |
| CR008 | BlueVoyant launched BlueVoyant AI on 2026-06-09 as an AI-native Agentic SecOps platform. | 高 | SR004, SR032 |
| CR009 | BlueVoyant AI is offered in both fully managed and enterprise SaaS deployment models. | 高 | SR004, SR032 |
| CR010 | BlueVoyant says its AI workflows keep humans at the center of the strategy even when automated response actions occur at machine speed. | 中 | SR004, SR032 |
| CR011 | BlueVoyant’s Cork SOC announcement says the site provides 24x7 monitoring for Irish and EU clients. | 中 | SR008, SR015 |
| CR012 | BlueVoyant links its Cork expansion to NIS2 and DORA-driven customer demand and says local revenue grew 70% in 2024. | 中 | SR008, SR015 |
| CR013 | BlueVoyant changed CEOs in May 2026 when John Hernandez succeeded co-founder Jim Rosenthal. | 中 | SR006 |
| CR014 | BlueVoyant’s 2023 CPO appointment was framed as a move to unify product lines and expand share in cybersecurity. | 中 | SR007 |
| CR015 | BlueVoyant’s privacy notice says BlueVoyant LLC is the controller of personal data collected through its website. | 中 | SR001 |
| CR016 | BlueVoyant’s privacy notice says personal information may be shared with affiliate companies unless prohibited by law or other regulatory requirements. | 中 | SR001 |
| CR017 | PacerMonitor shows Steward Health filed an adversary complaint against Bluevoyant LLC in July 2025. | 中 | SR020 |
| CR018 | The public Steward docket describes avoidance and recovery claims under bankruptcy preference and fraudulent-transfer theories. | 中 | SR020 |
| CR019 | The DoD CIO CMMC page says Phase 1 implementation runs from 2025-11-10 to 2026-11-09 and focuses on Level 1 and Level 2 self-assessments. | 高 | SR022, SR023 |
| CR020 | The DoD CIO CMMC page reminds contractors to submit affirmations with CMMC assessments in SPRS. | 中 | SR022 |
| CR021 | The DoD CMMC 2.0 page says contracting officers now include the new CMMC requirements in new solicitations and contracts. | 中 | SR023 |
| CR022 | NIST SP 800-171 says its security requirements are intended for use in contractual vehicles and agreements between federal agencies and nonfederal organizations handling CUI. | 中 | SR021 |
| CR023 | BlueVoyant Government Solutions markets supply-chain visibility and expert-led threat remediation at scale for mission assurance. | 中 | SR011 |
| CR024 | BlueVoyant’s government customer page targets intelligence, federal civilian, acquisition, cybersecurity, and supply-chain risk-management use cases. | 中 | SR012 |
| CR025 | Carahsoft lists BlueVoyant on NASA SEWP V through 2026-09-30. | 中 | SR019 |
| CR026 | Carahsoft also lists ITES-SW2 through 2030-08-30 and SCRIPTS BPA through 2030-03-30 for BlueVoyant. | 中 | SR019 |
| CR027 | Pavilion says BlueVoyant Government Solutions includes CMMC and NIST 800-171 compliance management. | 中 | SR029 |
| CR028 | SAM.gov says contract-award search now supports filtering by keyword, agency, and legal business name. | 中 | SR030 |
| CR029 | USAspending says it is the official open data source for federal awards, including contracts, grants, and loans. | 中 | SR031 |
| CR030 | BlueVoyant said it raised more than $140 million in Series E funding to support the Conquest Cyber acquisition. | 中 | SR005 |
| CR031 | BlueVoyant said Conquest Cyber had traction in the U.S. Defense Industrial Base and government organizations. | 中 | SR005 |
| CR032 | PM Insights exposes only delayed preview data and gated institutional datasets for BlueVoyant valuation, secondary activity, and cap-table details. | 中 | SR024 |
| CR033 | SourceForge presents BlueVoyant alongside many alternative cyber platforms in 2026, underscoring a crowded competitive set. | 中 | SR025 |
| CR034 | PeerSpot describes BlueVoyant as spanning MDR, digital risk protection, and supply-chain defense with advanced analytics and a 24x7 SOC. | 中 | SR026 |
| CR035 | Microsoft’s 2021 security blog framed customer need around tech sprawl and positioned BlueVoyant as an optimizer of Microsoft security services. | 中 | SR016 |
| CR036 | Finance Yahoo and PR Newswire say BlueVoyant is building analytics, playbooks, hunting queries, notebooks, and Security Copilot agents on top of Sentinel. | 中 | SR013, SR028 |
| CR037 | BlueVoyant’s Microsoft page markets cost-of-adoption assessments for Sentinel, Defender for Cloud, Microsoft 365 E5, data security, and Copilot readiness. | 中 | SR002 |
| CR038 | BlueVoyant’s Sentinel eBook says customers use the company to optimize costs and migrate from other SIEMs. | 中 | SR033 |
| CR039 | BlueVoyant’s Gartner-market-guide blog cites rising third-party breach pressure and presents AI-driven assessment plus expert remediation as its TPRM answer. | 中 | SR034 |
| CR040 | Independent coverage of the BlueVoyant AI launch repeats the company’s claim that the platform delivers autonomous speed, precision, and control at scale. | 中 | SR032 |
| CR041 | BlueVoyant’s 2024 Microsoft award release says the company’s Microsoft customer base has grown over the past three years. | 中 | SR010, SR014 |
| CR042 | Microsoft’s 2025 awards page independently confirms BlueVoyant was among recognized security-ecosystem winners. | 中 | SR017 |
| CR043 | Protiviti says it and BlueVoyant jointly deliver Microsoft security, compliance, and identity solutions. | 中 | SR018 |
| CR044 | The PR Newswire UK Cork release says BlueVoyant’s EMEA build-out reflects a multi-million-Euro investment since 2017. | 中 | SR015 |
| CR045 | BlueVoyant’s Cork release says the company had local employees in Ireland before opening the permanent office. | 中 | SR008 |
| CR046 | BlueVoyant’s go-to-market and product differentiation are tightly coupled to Microsoft roadmap, pricing, and channel behavior. | 中 | SR002, SR003, SR013, SR028 |
| CR047 | The shift from managed MDR into agentic SOC software increases execution complexity around packaging, pricing, support, and quality control. | 中 | SR004, SR006, SR007, SR032 |
| CR048 | BlueVoyant’s public-sector motion is compliance-gated because the company markets CMMC and NIST support while DoD rules are now flowing into contracts. | 中 | SR021, SR022, SR023, SR027, SR029 |
| CR049 | Public-sector concentration is material but still unquantified because contract vehicles are visible while agency-level award mix and renewal concentration are not publicly disclosed. | 中 | SR019, SR030, SR031 |
| CR050 | The Steward complaint is the clearest company-specific adverse signal in the public record and should be diligenced for amount, defenses, and insurance coverage. | 中 | SR020 |
| CR051 | Competitive risk is elevated because BlueVoyant competes at once in Microsoft services, MDR, TPRM, and supply-chain defense against more specialized vendors. | 中 | SR025, SR026, SR034 |
| CR052 | Financing risk remains material because the public file shows a 2023 private raise and gated secondary-market previews, but not current ARR, runway, or valuation terms. | 中 | SR005, SR024 |
| CR053 | The highest-likelihood near-term risks are Microsoft-feature dependence and managed-service staffing drift because both sit inside BlueVoyant’s daily delivery loop. | 中 | SR003, SR008, SR013, SR018 |
| CR054 | The highest-impact downside risks are compliance slippage, financing opacity, and any legal escalation because those could impair growth or capital access quickly. | 中 | SR020, SR022, SR023, SR024 |
| CR055 | If Microsoft economics worsen or BlueVoyant AI underdelivers, BlueVoyant would likely feel the damage first in customer ROI and renewal confidence before financing flexibility changes. | 中 | SR003, SR004, SR013, SR024 |
| CR056 | Missing public metrics on SLA attainment, MTTR, analyst-to-customer ratios, agency concentration, and capital structure reduce confidence in residual-risk scoring. | 中 | SR024, SR030, SR031 |
| CV001 | BlueVoyant announced on November 29, 2023 that it raised more than $140 million to accompany its acquisition of Conquest Cyber. | 高 | SV002, SV032 |
| CV002 | BlueVoyant said Liberty Strategic Capital and ISTARI led the November 2023 funding round. | 高 | SV002, SV032 |
| CV003 | BlueVoyant's February 23, 2022 Series D raised $250 million. | 高 | SV003, SV011 |
| CV004 | BlueVoyant named Liberty Strategic Capital, ISTARI, Eden Global Partners, and 8VC as participants in the Series D round. | 高 | SV003, SV011, SV008 |
| CV005 | Caplight currently shows BlueVoyant's last round as Series E on November 29, 2023 with an estimated valuation of $1 billion. | 中 | SV004 |
| CV006 | Forge shows BlueVoyant's last known valuation as $1 billion dated February 23, 2022. | 中 | SV006 |
| CV007 | Caplight, CB Insights, and GetLatka each report BlueVoyant total funding at $665.5 million. | 高 | SV004, SV009, SV027 |
| CV008 | Tracxn reports BlueVoyant total funding at $696 million across six rounds. | 中 | SV008 |
| CV009 | CB Insights classifies BlueVoyant as Series E | Alive and lists the last raise as $140 million. | 中 | SV027 |
| CV010 | The SEC browse result for BlueVoyant shows Form D notices dated 2017-08-04, 2019-04-25, and 2020-07-08. | 中 | SV012 |
| CV011 | The retained SEC browse result does not surface later BlueVoyant financing filings, leaving the 2022 and 2023 round terms undisclosed in public filing search results. | 中 | SV012 |
| CV012 | BlueVoyant's February 2023 growth release said the company had more than 900 clients in 40-plus countries and nearly 1,000 clients globally. | 中 | SV001 |
| CV013 | BlueVoyant's February 2023 growth release said recurring revenue grew 80% in 2022 and 108% on average since 2018. | 中 | SV001 |
| CV014 | GetLatka estimates BlueVoyant's 2025 revenue at $213.5 million and employee count at about 650. | 中 | SV009 |
| CV015 | BlueVoyant's public materials position the company around MDR, TPRM, digital risk protection, and professional services on one platform. | 高 | SV001, SV010 |
| CV016 | Caplight tags BlueVoyant with MDR, third-party risk management, SOC-as-a-Service, supply chain risk management, and digital risk protection keywords. | 中 | SV004 |
| CV017 | Notice titles BlueVoyant at $1.36 per share. | 中 | SV005 |
| CV018 | Notice's page markup shows the current Notice Price at a 39% discount to the last round. | 中 | SV005 |
| CV019 | Forge labels BlueVoyant market activity as limited and shows no Forge Price. | 中 | SV006 |
| CV020 | Hiive's page data shows no daily price history and sets displayChart to false for BlueVoyant. | 中 | SV007 |
| CV021 | PM Insights' public preview exposes sections for secondary-market ROI, bid-ask ratios, mutual-fund NAV, and cap-table details, but not the underlying numbers. | 中 | SV026 |
| CV022 | Windsor Drake says the public cybersecurity median trades at roughly 6.0x to 6.5x NTM revenue in Q2 2026. | 中 | SV018 |
| CV023 | Windsor Drake says managed security services compress to roughly 3x to 5x revenue in 2026. | 中 | SV018 |
| CV024 | Tablestat shows median enterprise cybersecurity EV/revenue at 8.4x for 2025E and 6.8x for 2026E. | 中 | SV020 |
| CV025 | CrowdStrike trades at 34.30x EV/revenue on 5.09B of trailing revenue and about 178.47B of market cap. | 中 | SV013, SV021 |
| CV026 | Palo Alto Networks trades at 23.28x EV/revenue on 10.61B of trailing revenue and about 247.92B of market cap. | 中 | SV028, SV030 |
| CV027 | Fortinet trades at 15.20x EV/revenue on 7.11B of trailing revenue and about 110.88B of market cap. | 中 | SV029, SV031 |
| CV028 | SentinelOne trades at 4.61x EV/revenue on 1.05B of trailing revenue and about 5.45B of market cap. | 中 | SV014, SV022 |
| CV029 | Qualys trades at 5.73x EV/revenue on 684.86M of trailing revenue and about 4.34B of market cap. | 中 | SV017, SV025 |
| CV030 | Tenable trades at 3.32x EV/revenue on 1.02B of trailing revenue and about 3.33B of market cap. | 中 | SV016, SV024 |
| CV031 | Rapid7 trades at 0.93x EV/revenue on 859.23M of trailing revenue and about 508.58M of market cap. | 中 | SV015, SV023 |
| CV032 | multiples.vc describes CrowdStrike and SentinelOne as security-operations platforms and Rapid7, Qualys, and Tenable as exposure, XDR/SIEM, and compliance platforms, supporting their use as BlueVoyant comparables. | 中 | SV019 |
| CV033 | BlueVoyant's homepage advertises 24x7 in-region SOC monitoring, 1,200-plus Microsoft Sentinel deployments, and 1,600-plus vulnerabilities remediated in the last 30 days. | 中 | SV010 |
| CV034 | A $1 billion valuation on the $213.5 million ARR proxy implies roughly 4.7x ARR. | 中 | SV004, SV009 |
| CV035 | A 4.7x ARR multiple sits below the 2026 public cyber median and near SentinelOne, Qualys, and Tenable. | 中 | SV018, SV022, SV024, SV025 |
| CV036 | Because BlueVoyant mixes software with managed services and professional services, it should not command CrowdStrike-, Palo Alto-, or Fortinet-level software multiples without disclosed margin proof. | 中 | SV010, SV018, SV020 |
| CV037 | The bull thesis rests on real scale, broad cyber-risk product breadth, and historical triple-digit recurring-revenue growth. | 中 | SV001, SV010, SV032 |
| CV038 | The clearest anti-thesis is that public secondary data show a 39% discount, limited visible liquidity, and no obvious public valuation step-up after 2022. | 中 | SV004, SV005, SV006 |
| CV039 | Caplight still showing a $1 billion estimate and Forge still showing a $1 billion last-known mark suggest no public upward valuation reset despite the 2023 Series E. | 中 | SV004, SV006 |
| CV040 | Public sources disagree on exact capital raised, ranging from $665.5 million to $696 million, which signals data-room opacity rather than a clean public funding ledger. | 中 | SV004, SV008, SV027 |
| CV041 | A base-case valuation band of roughly $0.85 billion to $1.1 billion is supportable by applying 4.0x to 5.0x to the $213.5 million ARR proxy. | 中 | SV009, SV018, SV022 |
| CV042 | An upside range of roughly $1.2 billion to $1.5 billion requires sustained growth and a mix shift toward higher-margin platform revenue that would justify 5.5x to 7.0x multiples. | 中 | SV018, SV020, SV028, SV029 |
| CV043 | A downside range of roughly $0.6 billion to $0.8 billion is consistent with the Notice discount to the last round and the managed-security/services range. | 中 | SV005, SV018 |
| CV044 | The public evidence does not support a buy call because downside is observable in secondary signals while the upside case still depends on undisclosed margin, retention, and share-count data. | 中 | SV005, SV006, SV012, SV026 |
| CV045 | BlueVoyant is large enough and strategically relevant enough that the correct recommendation is research-more rather than avoid. | 中 | SV001, SV010, SV032 |
| CV046 | Confidence should be medium because the multiple work is directionally coherent, but the core ARR and liquidity inputs come from third-party datasets rather than audited disclosure. | 中 | SV009, SV026, SV027 |
| CV047 | Risk rating should remain high because private-market liquidity appears thin and the current mark could compress if growth or margin quality undershoots. | 中 | SV005, SV006, SV007 |
| CV048 | Valuation stance is fair rather than attractive because the $1 billion mark can be justified on the ARR proxy but leaves limited margin of safety against secondary discounts. | 中 | SV005, SV009, SV018, SV022 |
| CV049 | Hiive states that BlueVoyant remains privately held and pre-IPO access is limited to accredited investors via secondary marketplaces. | 中 | SV007 |
| CV050 | The highest-value diligence asks are current ARR and gross-margin mix, cap table and share count, actual secondary-clearing prices, and confirmation of any post-2023 financing terms. | 中 | SV007, SV012, SV026, SV027 |
| 编号 | 出版方 | 标题 | 引文 |
|---|---|---|---|
| SO001 | BlueVoyant | Company | Founded in 2017... Headquartered in New York City, the company has over 600 employees... spanning five continents. |
| SO002 | BlueVoyant | Leadership | |
| SO003 | BlueVoyant | Contact Us | More Than 1,000 Customers in 45 Countries |
| SO004 | BlueVoyant | BlueVoyant Cyber Defense Platform | |
| SO005 | BlueVoyant | Managed Detection & Response | |
| SO006 | BlueVoyant | Third-Party Risk Management (TPRM) | |
| SO007 | BlueVoyant | Partners | |
| SO008 | BlueVoyant | BlueVoyant & Microsoft | |
| SO009 | BlueVoyant | Awards | |
| SO010 | BlueVoyant | Careers | |
| SO011 | BlueVoyant | Born in the SOC, Not in a Lab | Webinar | |
| SO012 | BlueVoyant | Next Era of Cyber Defense with BlueVoyant AI | BlueVoyant today announced BlueVoyant AI, an innovative Agentic SecOps platform that fundamentally redefines how modern enterprises prevent, detect, investigate, and stop cyber threats. |
| SO013 | BlueVoyant | BlueVoyant Raises $250 Million Series D Led by Liberty Strategic Capital | Liberty Strategic Capital... led the $250-million round with participation from... ISTARI... Eden Global Partners... and 8VC. |
| SO014 | BlueVoyant | BlueVoyant and Auto-ISAC Partner to Elevate TPRM in Automotive | |
| SO015 | BlueVoyant | BlueVoyant Welcomes Michael Montoya as COO | Michael Montoya has joined the company as Chief Operating Officer (COO)... overseeing the technology, product, and operations organizations. |
| SO016 | PR Newswire | John Hernandez Joins BlueVoyant as CEO to Accelerate AI-Driven Cybersecurity Platform and Global Growth | John Hernandez will succeed Jim Rosenthal as Chief Executive Officer (CEO). |
| SO017 | PR Newswire | Liberty Strategic Capital Leads Investment Round in BlueVoyant, an Industry-Leading Cyber Defense Platform | |
| SO018 | PR Newswire | BlueVoyant Acquires Conquest Cyber to Meet Market Need for Comprehensive Managed Detection and Response and Cyber Risk Posture Solutions | |
| SO019 | PR Newswire | BlueVoyant and Auto-ISAC Partner to Elevate Third-Party Cyber Risk Management Across the Automotive Industry | |
| SO020 | TechCrunch | BlueVoyant nabs $250M to help enterprises nab malicious hackers and stop security breaches | |
| SO021 | SecurityWeek | BlueVoyant Raises $250 Million to Boost Technical Capabilities, Global Expansion | |
| SO022 | CRN | BlueVoyant Acquires Conquest Cyber In Deal That Reshapes Microsoft Security Landscape | |
| SO023 | GovCon Wire | BlueVoyant Purchases Conquest Cyber, Raises Over $140M in Series E Funding Round | |
| SO024 | BankInfoSecurity | BlueVoyant Raises $140M, Buys Resilience Firm Conquest Cyber | |
| SO025 | iTWire | BlueVoyant Ignites the Next Era of Cyber Defence with Launch of BlueVoyant AI | |
| SO026 | UK Tech News | BlueVoyant Ignites the Next Era of Cyber Defence with Launch of BlueVoyant AI | |
| SO027 | Enterprise IT World | BlueVoyant Appoints John Hernandez as CEO to Drive AI-Led Cybersecurity Growth | |
| SO028 | Unify | Employee Data and Trends for Bluevoyant | |
| SO029 | GetLatka | BlueVoyant Revenue 2025: $213.5M ARR, $1B Valuation | |
| SO030 | Caplight | BlueVoyant | Valuation, Funding Rounds & Stock Price | |
| SO031 | UpGuard | BlueVoyant Security Rating, Vendor Risk Report, and Data Breaches | The Content Security Policy is implemented with unsafe-eval, reducing protection against XSS attacks. |
| SO032 | Cyber Insurance News | BlueVoyant Warns Supply Chain Breaches Soar as Cyber Liability Insurance Requirements Shape Risk Strategy | |
| SO033 | The SaaS News | BlueVoyant Raises $140 Million in Series E | |
| SM001 | BlueVoyant | Managed Detection & Response | Protect your internal network, cloud instances, containers, and endpoints from unknown threat actors, and strengthen your utilization of existing EDR, SIEM, and cloud security tools. |
| SM002 | BlueVoyant | Third-Party Risk Management (TPRM) | BlueVoyant Third-Party Risk Management (TPRM) is a fully managed solution that identifies, validates, and resolves critical cybersecurity issues in your third-party ecosystem. |
| SM003 | BlueVoyant | Continuous Monitoring & Remediation | |
| SM004 | BlueVoyant | AI-Driven Cyber Defense | |
| SM005 | BlueVoyant | Fourth-Party Identification and Analytics | |
| SM006 | Precedence Research | Managed Detection and Response (MDR) Market Size to Hit USD 13.90 Bn by 2035 | |
| SM007 | Mordor Intelligence | Managed Detection and Response Market Size & Trends, 2031 | |
| SM008 | The Business Research Company | Managed Detection And Response Market Insights 2026 to 2035 | |
| SM009 | Grand View Research | Third-party Risk Management Market Size Report, 2030 | |
| SM010 | Next Move Strategy Consulting | Third-Party Risk Management Market Analysis | 2025-2030 | |
| SM011 | The Business Research Company | Third-party Risk Management Market Growth Report 2026 | |
| SM012 | KPMG | The 2026 KPMG Global Third-Party Risk Management Survey | This is not the time for incremental improvements or fragmented approaches. |
| SM013 | Marsh | Rising third-party risks and persistent ransomware threats drive increased cybersecurity investments in 2026 | Marsh | 70% of organizations experienced at least one material third-party cyber incident in the past year. |
| SM014 | Panorays | 200 CISOs Reveal the Truth About Third-Party Cyber Risk | 85% of CISOs surveyed admitted they do not have full visibility across their entire supply chain. |
| SM015 | National Institute of Standards and Technology | Cybersecurity Framework | |
| SM016 | Securities and Exchange Commission | Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure | For domestic registrants, this disclosure must be filed on Form 8-K within four business days of determining that a cybersecurity incident is material. |
| SM017 | European Commission | NIS2 Directive: securing network and information systems | The NIS2 Directive establishes a unified legal framework to uphold cybersecurity in 18 critical sectors across the EU. |
| SM018 | Gartner | Gartner Identifies the Top Cybersecurity Trends for 2026 | The chaotic rise of AI, geopolitical tensions, regulatory volatility and an accelerating threat landscape are the driving forces behind the top cybersecurity trends for 2026. |
| SM019 | CyberProof | Mapping the Managed Detection and Response (MDR) Market for 2026 | Gartner has cautioned that many providers misusing the “MDR” label offer only tool-centric monitoring (e.g. managed EDR) without the critical human analysis and incident response leadership. |
| SM020 | Mordor Intelligence | GRC Software Market Size, Share & 2031 Growth Trends Report | |
| SM021 | Black Kite | 2026 Third-Party Breach Report | Black Kite Supply Chain Risk Data | For every single vendor breached, an average of 5.28 downstream companies were publicly compromised. |
| SM022 | CRC Group | 2026 Cyber + Technology State of the Market at a Glance | |
| SM023 | Cybersecurity and Infrastructure Security Agency | Information and Communications Technology Supply Chain Risk Management | CISA | If vulnerabilities in the ICT supply chain—composed of hardware, software, and managed services from third-party vendors, suppliers, service providers, and contractors—are exploited, the consequences can affect all users of that technology or service. |
| SM024 | Cybersecurity and Infrastructure Security Agency | ICT Supply Chain Risk Management Task Force | CISA | The ICT SCRM Task Force—a public-private partnership charged with identifying challenges and developing actionable solutions to enhance global ICT supply chain resilience. |
| SM025 | PeerSpot | Top Rated Managed Detection and Response (MDR) Vendors | |
| SP001 | BlueVoyant | MDR, TPRM, Digital Risk Protection | BlueVoyant | Agentic SecOps, MDR, and TPRM to protect your entire attack surface. |
| SP002 | BlueVoyant | Company | Founded in 2017... the company has over 600 employees across offices... spanning five continents. |
| SP003 | BlueVoyant | Managed Detection & Response | 50+ certified Microsoft Delivery & SOC Engineers |
| SP004 | BlueVoyant Government Solutions | BlueVoyant Government Solutions | Supply Chain Defense | BlueVoyant Government Solutions operationalizes mission assurance with deep supply chain risk visibility and expert-led threat remediation at scale. |
| SP005 | BlueVoyant Government Solutions | Products | More than 70,000 unique proprietary, open-source, and commercially-available data feeds |
| SP006 | PR Newswire | BlueVoyant Ignites the Next Era of Cyber Defense with Launch of BlueVoyant AI | BlueVoyant AI provides both with its fully managed service... or as an enterprise-grade SaaS platform. |
| SP007 | Palo Alto Networks | Explore Cortex XSIAM Security Analytics | Every SOC capability on one platform. |
| SP008 | Palo Alto Networks | About Us | 16K+ Employees | 70K+ Customers Globally | ~$100B Market Cap |
| SP009 | CrowdStrike | 24/7 Expert Protection | CrowdStrike Falcon® Complete Next-Gen MDR | 1min Median time-to-contain (MTTC) |
| SP010 | Arctic Wolf | Managed Detection and Response (MDR) | Arctic Wolf | The SOC uses trusted datasets drawn from 14+ years of security operations and insights from 10,000+ global customers, and 1,000+ security engineers. |
| SP011 | Arctic Wolf | A Higher Standard of Security Operations | Arctic Wolf | Trusted by over 10,000 customers worldwide |
| SP012 | Arctic Wolf | Why Arctic Wolf? | As the pioneer of the first open XDR platform that makes security work, the Aurora® Superintelligence Platform leverages AI to enable cyber defense at an unprecedented capacity and scale. |
| SP013 | Rapid7 | About Rapid7 - Cybersecurity Company | Rapid7 unifies exposure and detection to transform the cybersecurity operations of more than 11,500 customers worldwide. |
| SP014 | Rapid7 | Incident Command: AI Powered Next-Gen SIEM | Rapid7 | Incident Command delivers a new standard for detection and response built for scale, speed, and clarity across your entire threat landscape. |
| SP015 | ReliaQuest | About Us | ReliaQuest exists to Make Security Possible, allowing enterprise security teams to detect, contain and respond to threats within minutes—anytime, anywhere—using the GreyMatter agentic AI security operations platform. |
| SP016 | ReliaQuest | Home | ReliaQuest GreyMatter: The Agentic AI Security Operations Platform for Agentic Defense | 50K+ alerts processed daily; 255+ Technology Partners with security technologies; 99.4% accuracy of AI investigations. |
| SP017 | ReliaQuest | ReliaQuest GreyMatter Integrations: Your Environment + Agentic AI Powered Security Operations | Your environment + agentic AI powered security operations |
| SP018 | eSentire | Managed Detection and Response Services & Security Operations Platform | Protecting 2,000+ Customers Across 35+ Industries |
| SP019 | eSentire | XDR Extended Detection & Response Solutions | Our distributed platform easily integrates with your existing security investments. |
| SP020 | eSentire | eSentire MDR vs the Competition | The Atlas Platform connects to ANY SIGNAL, whether that's Endpoint, Network, Logs, Cloud, Vulnerability scanner, Browser, or Identity provider. |
| SP021 | SecurityScorecard | SecurityScorecard | Supply Chain & Third-Party Risk Platform | The world’s first AI-powered platform for continuous, threat-informed third-party risk management |
| SP022 | SecurityScorecard | Company - SecurityScorecard | 3,300+ global organizations... 12M+ organizations monitored and rated |
| SP023 | SecurityScorecard | Third-Party Risk Management (TPRM) | SecurityScorecard | Validate Questionnaires with Technical Ground Truth |
| SP024 | Bitsight | Cyber Risk Intelligence Platform | A dynamic map of assets and vulnerabilities, prioritized by real-time threat intelligence, across your enterprise and supply chain. |
| SP025 | Bitsight | Third Party Risk Management Solutions | 75K+ Mapped vendor profiles in the Bitsight Vendor Network |
| SP026 | Bitsight | Bitsight Named a Leader in Cybersecurity Risk Ratings, Praised By Customers for the Utility of its Data | Bitsight | With more than 3,500 customers and over 68,000 organizations active on its platform |
| SP027 | Gartner Peer Insights | Best Managed Detection and Response Reviews 2026 | Gartner Peer Insights | MDR offers outcome-driven security incident management... and the delivery of active threat disruption and containment actions. |
| SP028 | PeerSpot | BlueVoyant CORE Reviews, Competitors and Pricing | As of June 2026, the mindshare of BlueVoyant CORE in the Managed Detection and Response (MDR) category stands at 0.9%, down from 1.2% compared to the previous year. |
| SP029 | PeerSpot | Compare BlueVoyant CORE vs CrowdStrike Falcon Complete MDR | BlueVoyant is ranked #34, while CrowdStrike is ranked #2... BlueVoyant holds a 0.9% mindshare in MDR, compared to CrowdStrike’s 5.4% mindshare. |
| SP030 | Ciphers Security | Best Vendor Risk Management Platforms In 2026 | Two fundamentally different approaches dominate this market... Security ratings platforms... assess vendors from the outside in. |
| SP031 | Decryption Digest | Best MDR Services 2026: CrowdStrike vs Arctic Wolf vs Huntress Compared | MSSPs monitor firewall and SIEM alerts and deliver notifications... not meaningful security improvement. |
| SP032 | CRN | Managed Security Firm Arctic Wolf Raises $60 Million In Pursuit Of IPO | Arctic Wolf has closed a $60 million funding round to help the managed detection and response vendor prepare for an IPO. |
| SP033 | SC Media | Arctic Wolf backs off IPO talk, looks to scale business with latest acquisition | the company – which was reportedly valued at $4.3 billion – planned for an IPO this year. But he made no commitments |
| SP034 | Help Net Security | eSentire launches new Atlas AI Operatives for autonomous threat detection and response - Help Net Security | The Atlas Platform... operates vendor-independently across any integration. |
| SI001 | BlueVoyant | MDR, TPRM, Digital Risk Protection | BlueVoyant | BlueVoyant packages Agentic SecOps, MDR, TPRM, DRP, and professional services with 1,200+ Microsoft Sentinel deployments and 24x7 monitoring. |
| SI002 | BlueVoyant | Company | Headquartered in New York City, the company has over 600 employees across offices spanning five continents. |
| SI003 | BlueVoyant | Channel Partners | Operational cybersecurity demands collaboration, and BlueVoyant highlights partners including GuidePoint Security and CDW. |
| SI004 | BlueVoyant | Build Your Own SOC or Partner with an MSSP | The annual cost of setting up your own 24/7/365 SOC can add up to more than $1.2 million. |
| SI005 | BlueVoyant | BlueVoyant Enters 2022 With Triple Digit Growth Momentum and More Than 700 Global Customers | Customer count increased by more than 80%, with more than 700 customers globally in 30 countries worldwide. |
| SI006 | BlueVoyant | BlueVoyant Raises $250 Million Series D Led by Liberty Strategic Capital | Since 2018, BlueVoyant has grown annual recurring revenues at 117% on average. |
| SI007 | BlueVoyant | BlueVoyant Acquires Conquest Cyber | BlueVoyant raised more than $140 million in Series E funding to accompany the acquisition of Conquest Cyber. |
| SI008 | BlueVoyant | BlueVoyant Welcomes Timothy Yost as Chief Financial Officer | Tim will focus on setting and managing the company’s financial and strategic plans and continue to build BlueVoyant’s world-class global finance organization. |
| SI009 | BlueVoyant | New Security Operations Centre in Cork, Ireland | BlueVoyant serves over 1,000 customers in more than 45 countries, and local revenue grew 70% in 2024. |
| SI010 | BlueVoyant | Total Economic Impact™ of BlueVoyant MDR Services | The commissioned Forrester TEI study cites 210% ROI over three years. |
| SI011 | BlueVoyant | Total Economic Impact™ of BlueVoyant Supply Chain Defense Report | The Forrester TEI study cites nearly 300% return and a 62% reduction in time to remediate critical risks. |
| SI012 | BlueVoyant | Snappi Neobank: Enterprise-Grade Security from Day One | Snappi built 24/7 SOC coverage within months by partnering with Veracloud and BlueVoyant. |
| SI013 | BlueVoyant | ODEON Cinemas Group | ODEON consolidated security across 8 countries and 280+ cinemas while cutting alert volume by 98%. |
| SI014 | BlueVoyant | BlueVoyant TPRM Is on Google Cloud Marketplace | Making BlueVoyant TPRM available on GCP Enterprise Agreement eligibility removes procurement friction. |
| SI015 | BlueVoyant | Maximizing Security ROI | A recent BlueVoyant analysis found that an enterprise organization can have an annual cost of up to $750,000 to optimize its Microsoft security stack internally. |
| SI016 | BlueVoyant | Successful Deployments of Microsoft Sentinel eBook | The eBook summarizes insights from hundreds of hands-on deployments and 16 anonymized case studies. |
| SI017 | BlueVoyant | ClearBank's Journey with BlueVoyant | Webinar | BlueVoyant says it optimized ClearBank’s existing Microsoft Security investment for better outcomes. |
| SI018 | GovConWire | BlueVoyant Purchases Conquest Cyber, Raises Over $140M in Series E Funding Round | The acquisition coincided with a Series E funding round that raised over $140 million from BlueVoyant’s existing investors. |
| SI019 | FinTech Global | BlueVoyant bags $140m Series E and snaps up cybersecurity firm | This substantial investment was led by existing investors Liberty Strategic Capital and ISTARI. |
| SI020 | Pulse 2.0 | BlueVoyant: Conquest Cyber Acqusition And Over $140 Million In Series E Funding | BlueVoyant also raised over $140 million in Series E funding to accompany the acquisition of Conquest Cyber. |
| SI021 | The SaaS News | BlueVoyant Raises $140 Million in Series E | Funding details listed a $140.0M Series E in November 2023 led by Liberty Strategic Capital and ISTARI. |
| SI022 | Private Equity Insights | BlueVoyant raises $250m in funding round led by Steven Mnuchin-backed PE firm | The firm intends to use the capital raised to ramp up the development of its products and expand into new international markets. |
| SI023 | CB Insights | BlueVoyant Stock Price, Funding, Valuation, Revenue & Financial Statements | CB Insights says BlueVoyant has raised $665.5M over 9 rounds and estimated 2024 revenue at $750M. |
| SI024 | GetLatka | BlueVoyant Revenue 2025: $213.5M ARR, $1B Valuation | In 2025, BlueVoyant's revenue reached $213.5M and the profile estimated roughly 650 employees. |
| SI025 | Origin by Dialectica | BlueVoyant: Ownership, Revenue & Funding Data | Dialectica lists BlueVoyant as PE-backed with 653 employees and Liberty Strategic Capital as investor. |
| SI026 | Clay | How Much Did BlueVoyant Raise? Funding & Key Investors | Clay lists total amount raised at $665.5 million, 11 investors, and over 1,000 customers across 45 countries. |
| SI027 | Tracxn | BlueVoyant | Tracxn reports BlueVoyant has raised a total of $696M over 6 funding rounds. |
| SI028 | PitchBook | BlueVoyant Company Profile: Valuation & Investors | PitchBook | The accessible PitchBook snapshot showed 363 employees, a $30M latest deal amount, and a historical Debt - PPP entry dated 27-Apr-2020. |
| SI029 | Companies House | BLUEVOYANT UK LIMITED filing history - Find and update company information | BlueVoyant UK Limited filed full accounts made up to 31 December 2024 on 30 Sep 2025. |
| SI030 | Companies House | BLUEVOYANT LTD filing history - Find and update company information | BlueVoyant Ltd filed full accounts made up to 31 December 2024 on 30 Sep 2025. |
| SI031 | Indeed via Wayback | Working at BlueVoyant: Employee Reviews | A featured review warned that BlueVoyant was extremely top heavy with consistent bi-yearly layoffs and limited resources in some business units. |
| SE001 | BlueVoyant | MDR, TPRM, Digital Risk Protection | BlueVoyant | |
| SE002 | BlueVoyant | BlueVoyant Cyber Defense Platform | Seamlessly integrated MDR, TPRM, and DRP. |
| SE003 | BlueVoyant | BlueVoyant AI | Agentic SecOps Platform | AI that knows where to act and when to ask. |
| SE004 | BlueVoyant | Managed Detection & Response | |
| SE005 | BlueVoyant | MDR for Microsoft | 24/7 detection and response across your full Microsoft security stack. |
| SE006 | BlueVoyant | Continuous Optimization for Microsoft Solutions | |
| SE007 | BlueVoyant | Continuous Optimization for Microsoft Security | |
| SE008 | BlueVoyant | Third-Party Risk Management (TPRM) | |
| SE009 | BlueVoyant | Continuous Monitoring & Remediation | |
| SE010 | BlueVoyant | Questionnaire Management | |
| SE011 | BlueVoyant | Digital Risk Protection (DRP) | |
| SE012 | BlueVoyant | Brand Protection | |
| SE013 | BlueVoyant | Dark Web Watcher | |
| SE014 | BlueVoyant | Executive Cyber Guard | |
| SE015 | BlueVoyant | Comprehensive Third-Party Cyber Risk Management Solution | |
| SE016 | BlueVoyant | BlueVoyant Acquires Conquest Cyber | Conquest Cyber's SaaS technology modernizes risk management with a platform that unifies an organization's entire cyber risk management program. |
| SE017 | BlueVoyant | BlueVoyant Trust Center | BlueVoyant delivers a comprehensive cloud-native security operations platform that provides real-time threat monitoring for networks, endpoints, and supply chains, extending to the clear, deep, and dark web. |
| SE018 | GitHub | Bluevoyant | |
| SE019 | GitHub | Bluevoyant | |
| SE020 | GitHub | GitHub - Bluevoyant/BV-Security-Copilot: Public Content for Copilot for Security | Public Content for Copilot for Security. |
| SE021 | PR Newswire | BlueVoyant Unveils Leading-Edge Security Operations Platform | The platform integrates internal, external, and supply chain defense solutions into a single, cloud-native platform. |
| SE022 | PR Newswire | BlueVoyant Ignites the Next Era of Cyber Defense with Launch of BlueVoyant AI | BlueVoyant AI brings true AI-native Security Operations Center (SOC) capabilities to life, delivering real-time, deterministic decision-making, automated response, and faster containment. |
| SE023 | PR Newswire | BlueVoyant Expands Offerings to Establish the Only Comprehensive Third-Party Cyber Risk Management Solution | |
| SE024 | PR Newswire | BlueVoyant Acquires Conquest Cyber to Meet Market Need for Comprehensive Managed Detection and Response and Cyber Risk Posture Solutions | |
| SE025 | PeerSpot | BlueVoyant CORE Reviews, Competitors and Pricing | |
| SE026 | Cyber Magazine | BlueVoyant Launch Platform to Tackle Supplier Attack Surface | |
| SE027 | SecuritySenses | BlueVoyant Unveils Leading-Edge Security Operations Platform | |
| SE028 | Gartner Peer Insights | BlueVoyant Reviews, Ratings & Features 2026 | Gartner Peer Insights | |
| SE029 | Gartner Peer Insights | BlueVoyant Digital Risk Protection Reviews & Ratings 2026 | Gartner Peer Insights | Effective detection and ticket management with occasional takedown challenges |
| SE030 | Spiceworks Community | BlueVoyant | Thoughts, opinions, experiences? | They are a startup, which is concerning ... I believe the back-end is Splunk. |
| SE031 | InNetwork Tech | BlueVoyant Core: MDR for Microsoft (Managed Detection and Response) | BlueVoyant’s service allows you to keep your security data in your own environment, reducing cost and ensuring stronger compliance. |
| SE032 | Microsoft | How to order the SWAG as part of attending "BLUEVOYANT Shadow Hunter -Security Immersion Workshop - Microsoft Q&A | |
| SU001 | BlueVoyant | California’s Innovative Cybersecurity Initiative | 70% Reduction in Mean Time to Detect (MTTD); 60% Reduction in Mean Time to Respond (MTTR); $2.1 Million annual personnel cost savings/entity utilizing SOCaas |
| SU002 | BlueVoyant | ODEON Cinemas Group | 98% reduction in alerts requiring InfoSec or Regional IT review |
| SU003 | BlueVoyant | Snappi Neobank: Enterprise-Grade Security from Day One | 24/7 SOC coverage operational from the outset |
| SU004 | BlueVoyant | Partners | |
| SU005 | BlueVoyant | Beeks Group Selects BlueVoyant to Strengthen its 24x7 SOC | |
| SU006 | BlueVoyant | Maximizing Your Investment with Microsoft Security | Webinar | |
| SU007 | BlueVoyant | Digital Brand Protection for Financial Institutions | |
| SU008 | BlueVoyant | Financial Exchanges - External Cyber Defense for When Your Attack… | |
| SU009 | BlueVoyant | Securing State and Local Governments from Threats | |
| SU010 | BlueVoyant | Avoiding the Government Third-Party Risk Domino Effect | |
| SU011 | BlueVoyant | Total Economic Impact™ of BlueVoyant Supply Chain Defense Report | |
| SU012 | BlueVoyant | The State of Supply Chain Defense: Annual Global Insights Report 2025 | |
| SU013 | BlueVoyant | BlueVoyant and Carahsoft Partnership | |
| SU014 | BlueVoyant | ClearBank's Journey with BlueVoyant | Webinar | |
| SU015 | BlueVoyant | Protecting the Grid: The Evolving Threat Landscape and Proactive… | |
| SU016 | BlueVoyant | Defending Law Firms from Cyber Threats | |
| SU017 | BlueVoyant | Total Economic Impact™ of BlueVoyant MDR Services | |
| SU018 | BlueVoyant | Microsoft Security Excellence Award Winners | |
| SU019 | Navy SBIR/STTR Program | Success Story | In October 2021, Naval Sea Systems Command (NAVSEA) ... awarded a three-year single-award indefinite delivery contract to BlueVoyant Government Solutions |
| SU020 | PR Newswire | BlueVoyant's 202 Group Expands its Supply Chain Risk Management Solutions and Rebrands as BlueVoyant Government Solutions | |
| SU021 | FeaturedCustomers | 14 BlueVoyant Customer Reviews & References | |
| SU022 | FeaturedCustomers | 9 BlueVoyant Customer Reviews & References | |
| SU023 | PeerSpot | BlueVoyant CORE Reviews, Competitors and Pricing | |
| SU024 | Carahsoft | BlueVoyant and Carahsoft Partner to Defend Public Sector from Cyber Threats | Carahsoft | |
| SU025 | AWS Marketplace | MDR for Splunk Cloud. Please contact BlueVoyant for Private Offer. | |
| SU026 | Beeks Group | Beeks Group Collaborating With BlueVoyant | Beeks Group | |
| SU027 | Intelligence Community News | BlueVoyant and Carahsoft announce partnership - Intelligence Community News | |
| SU028 | UpGuard | BlueVoyant Security Rating, Vendor Risk Report, and Data Breaches | UpGuard | |
| SU029 | Slashdot | Compare BitSight vs. BlueVoyant in 2026 | |
| SU030 | Carahsoft | BlueVoyant Government IT Procurement Contracts | Carahsoft | |
| SU031 | BlueVoyant Government Solutions | SCRM Solutions Offered on GSA's SCRIPTS BPA via Carahsoft | |
| SU032 | Carahsoft | Technology Reseller Partner Program | Carahsoft | |
| SU033 | Intelligent CISO | BlueVoyant strengthens cyber defence for ODEON Cinemas Group across eight countries – Intelligent CISO | |
| SU034 | Veracloud | How Snappi Built Enterprise-Grade Cybersecurity from Day One with Veracloud and BlueVoyant | |
| SU035 | MaltaCEOs | Veracloud brings operational security to Greece’s first neobank | |
| SU036 | California Department of Technology | Security Operations Center as a Service (SOCaaS) | |
| SU037 | California Department of Technology | How California is Centralizing Public Sector Cybersecurity | |
| SU038 | MSSP Alert | MSSP BlueVoyant Launches SOCaaS Powered by Microsoft Azure Sentinel - | |
| SR001 | BlueVoyant | Privacy Policy & Legal Notice | BlueVoyant LLC is the controller of your personal data and may share personal information with affiliate companies unless prohibited by law. |
| SR002 | BlueVoyant | BlueVoyant & Microsoft | Streamline security with Microsoft XDR/E5 and Sentinel, delivering unified threat detection, response, and monitoring across your environment. |
| SR003 | BlueVoyant | MDR for Microsoft - Manage & Monitor | Harness the full power of Microsoft Security with our elite 24x7 SOC and security operations team backed by BlueVoyant AI. |
| SR004 | BlueVoyant | Next Era of Cyber Defense with BlueVoyant AI | BlueVoyant AI provides both with its fully managed service - supported 24/7 with BlueVoyant’s elite SOC team - or as an enterprise-grade SaaS platform. |
| SR005 | BlueVoyant | BlueVoyant Acquires Conquest Cyber | BlueVoyant raised more than $140 million in Series E funding to accompany the acquisition of Conquest Cyber. |
| SR006 | BlueVoyant | John Hernandez Joins BlueVoyant as CEO | John Hernandez will succeed Jim Rosenthal as Chief Executive Officer with a focus on scaling an AI-driven cybersecurity platform. |
| SR007 | BlueVoyant | BlueVoyant Welcomes New Chief Product Officer | Amit Jasuja will guide BlueVoyant’s strategic product direction, aiming to unify product lines and expand the company’s share of the cybersecurity market. |
| SR008 | BlueVoyant | New Security Operations Centre in Cork, Ireland | The new SOC will provide 24x7 monitoring of Irish and EU clients’ networks and digital ecosystems. |
| SR009 | BlueVoyant | Microsoft Security Excellence Award Winners | BlueVoyant also won the Security Trailblazer award. |
| SR010 | BlueVoyant | 2024 Microsoft Worldwide Security Partner of the Year | BlueVoyant announced it has won the 2024 Microsoft Worldwide Security Partner of the Year Award. |
| SR011 | BlueVoyant Government Solutions | BlueVoyant Government Solutions | Supply Chain Defense | BlueVoyant Government Solutions operationalizes mission assurance with deep supply chain risk visibility and expert-led threat remediation at scale. |
| SR012 | BlueVoyant Government Solutions | Customers | Supporting federal government agencies with end-to-end cyber supply chain risk management. |
| SR013 | PR Newswire | BlueVoyant is a proud participant in the Microsoft Sentinel partner ecosystem | BlueVoyant is working with Microsoft product teams to shape Sentinel product development. |
| SR014 | PR Newswire | BlueVoyant Recognized as the Winner of 2024 Microsoft Worldwide Security Partner of the Year | The company has additionally been named the Microsoft United States Security Partner of the Year for the third consecutive time. |
| SR015 | PR Newswire UK | BlueVoyant Expands in EU with New Cutting-Edge Security Operations Centre in Cork, Ireland | With cyber security teams grappling with the enforcement of new EU regulations such as NIS 2 and DORA, clients now require a holistic, next-generation managed security service. |
| SR016 | Microsoft Security Blog | BlueVoyant optimizes customer security with Microsoft security services | BlueVoyant speaks with a lot of companies about their security technology deployment and one of the main trends found is tech sprawl. |
| SR017 | Microsoft Security Blog | Microsoft announces the 2025 Security Excellence Awards winners | The Microsoft Security Excellence Awards honor outstanding contributions across several categories. |
| SR018 | Protiviti | BlueVoyant Partnership | Protiviti US | The platform integrates advanced AI technology with expert human insight to offer extensive protection and swift threat mitigation. |
| SR019 | Carahsoft | BlueVoyant Government IT Procurement Contracts | Carahsoft | Carahsoft lists NASA SEWP V, ITES-SW2, SCRIPTS BPA, and CMAS contract access for BlueVoyant. |
| SR020 | PacerMonitor | Steward Health Care System LLC, et al., v. Bluevoyant LLC | Complaint to (I) Avoid and Recover Avoidable Transfer(s) and (II) Disallow Claims by Steward Health Care System LLC against Bluevoyant LLC. |
| SR021 | National Institute of Standards and Technology | Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations | The security requirements are intended for use by federal agencies in contractual vehicles or other agreements established between those agencies and nonfederal organizations. |
| SR022 | U.S. Department of Defense CIO | CIO - CMMC Resources & Documentation | CMMC Phase 1 Implementation (Nov 10, 2025 - Nov 9, 2026) focuses primarily on CMMC Level 1 and Level 2 self-assessments. |
| SR023 | U.S. Department of Defense | CMMC 2.0 Details and Links to Key Resources | Beginning November 10, contracting officers will include the new CMMC requirements in new solicitations and contracts. |
| SR024 | PM Insights | BlueVoyant Valuation | PM Insights | Sample data shown with delay for preview purposes. Real-time, institutional-grade datasets available to subscribers. |
| SR025 | SourceForge | Best BlueVoyant Alternatives & Competitors | SourceForge ranks the best alternatives to BlueVoyant in 2026. |
| SR026 | PeerSpot | BlueVoyant CORE Reviews, Competitors and Pricing | Their MDR service offers 24/7 monitoring and threat hunting by a team of experts, utilizing advanced analytics and machine learning. |
| SR027 | SecuritySenses | BlueVoyant Recognised as Microsoft Security Excellence Award Winners | BlueVoyant also won the Security Trailblazer award. |
| SR028 | Yahoo Finance | BlueVoyant is a proud participant in the Microsoft Sentinel partner ecosystem | BlueVoyant is building on it with custom analytics, Copilot-ready content, and lessons tested in the field. |
| SR029 | Pavilion | BlueVoyant Government Solutions Government Contracts | Pavilion | BlueVoyant provides government-focused supply chain risk management and cybersecurity services, including CMMC + NIST 800-171 compliance management. |
| SR030 | SAM.gov | Contract Award Data in SAM.gov | The contract award search function in SAM.gov allows users to search federal procurement data and to filter by keyword, agency, and legal business name. |
| SR031 | USAspending | Government Spending Open Data | USAspending | USAspending is the official open data source of federal spending information, including information about federal awards such as contracts, grants, and loans. |
| SR032 | SecuritySenses | BlueVoyant Ignites the Next Era of Cyber Defence with Launch of BlueVoyant AI | BlueVoyant AI brings true AI-native Security Operations Centre capabilities to life. |
| SR033 | BlueVoyant | Successful Deployments of Microsoft Sentinel eBook | This eBook summarizes the guide’s 16 real world anonymized case studies based on hundreds of hands-on deployments. |
| SR034 | BlueVoyant | BlueVoyant Recognized in Gartner’s Market Guide for Third-Party Risk Management | The percentage of cyber breaches involving third parties doubled over the past year to 30% according to Verizon’s 2025 DBIR. |
| SV001 | BlueVoyant | BlueVoyant Enters 2023 with Momentous Growth | Growing annual recurring revenues at an average of 108% since 2018, with recurring revenue growing 80% in 2022. |
| SV002 | PR Newswire / BlueVoyant | BlueVoyant Acquires Conquest Cyber to Meet Market Need for Comprehensive Managed Detection and Response and Cyber Risk Posture Solutions | BlueVoyant raised more than $140 million in Series E funding to accompany the acquisition. |
| SV003 | PR Newswire / BlueVoyant | BlueVoyant Raises $250 Million Series D Led by Liberty Strategic Capital | Liberty Strategic Capital ... led the $250-million round with participation from ... ISTARI ... Eden Global Partners ... and 8VC. |
| SV004 | Caplight | BlueVoyant | Valuation, Funding Rounds & Stock Price | Caplight | Last Round Series E ... Nov 29, 2023 ... Est. Valuation $1B ... Total Funding Raised $665.5M. |
| SV005 | Notice.co | BlueVoyant Stock $1.36 | How to Buy, Valuation, Stock Price, IPO | Notice.co | The current Notice Price premium (+) or discount (-) to the last round ... -39%. |
| SV006 | Forge | Invest and Sell BlueVoyant Stock - Forge | Market activity ... Limited ... Forge Price $-- Not yet available ... Last known valuation $1B 2/23/2022. |
| SV007 | Hiive | BlueVoyant Stock | Invest or Sell | Buy and sell BlueVoyant stock. Get stock prices & access to pre-IPO shares in one place at Hiive. |
| SV008 | Tracxn | BlueVoyant - 2026 Funding Rounds & List of Investors | BlueVoyant has raised a total of $696M over 6 funding rounds. |
| SV009 | GetLatka | BlueVoyant Revenue 2025: $213.5M ARR, $1B Valuation | In 2025, BlueVoyant's revenue reached $213.5M. |
| SV010 | BlueVoyant | MDR, TPRM, Digital Risk Protection | BlueVoyant | Agentic SecOps, MDR, and TPRM to protect your entire attack surface. |
| SV011 | Eden Global Partners | BlueVoyant Raises $250 Million Series D Led by Liberty Strategic Capital | BlueVoyant Raises $250 Million Series D Led by Liberty Strategic Capital. |
| SV012 | U.S. Securities and Exchange Commission | EDGAR Search Results — BlueVoyant | Acc-no: 0000950103-20-013356 ... 2020-07-08 ... Acc-no: 0000950103-19-005109 ... 2019-04-25 ... Acc-no: 0000950103-17-007618 ... 2017-08-04. |
| SV013 | CompaniesMarketCap | CrowdStrike (CRWD) - Market capitalization | As of June 2026 CrowdStrike has a market cap of $178.47 Billion USD. |
| SV014 | CompaniesMarketCap | SentinelOne (S) - Market capitalization | As of June 2026 SentinelOne has a market cap of $5.43 Billion USD. |
| SV015 | CompaniesMarketCap | Rapid7 (RPD) - Market capitalization | As of June 2026 Rapid7 has a market cap of $0.51 Billion USD. |
| SV016 | CompaniesMarketCap | Tenable (TENB) - Market capitalization | As of June 2026 Tenable has a market cap of $3.33 Billion USD. |
| SV017 | CompaniesMarketCap | Qualys (QLYS) - Market capitalization | As of June 2026 Qualys has a market cap of $4.34 Billion USD. |
| SV018 | Windsor Drake | Cybersecurity Valuations: Q2 2026 | The public cybersecurity median is 6.0x–6.5x NTM revenue ... managed security services to 3x–5x. |
| SV019 | multiples.vc | Largest Cybersecurity Public Companies | CrowdStrike ... endpoint, cloud workload, identity, and security operations ... Rapid7 ... expanded its portfolio to provide extended detection and response, SIEM ... |
| SV020 | Tablestat | Valuation Trading Multiples & Precedent Transactions: Enterprise Cybersecurity Software Providers | Revenue growth Median 15.7% 2025E 16.0% 2026E ... 8.4x ... 6.8x. |
| SV021 | Yahoo Finance | CrowdStrike Holdings, Inc. (CRWD) Stock Price, News, Quote & History - Yahoo Finance | Enterprise Value/Revenue 34.30 ... Revenue (ttm) 5.09B. |
| SV022 | Yahoo Finance | SentinelOne, Inc. (S) Stock Price, News, Quote & History - Yahoo Finance | Enterprise Value/Revenue 4.61 ... Revenue (ttm) 1.05B. |
| SV023 | Yahoo Finance | Rapid7, Inc. (RPD) Stock Price, News, Quote & History - Yahoo Finance | Enterprise Value/Revenue 0.93 ... Revenue (ttm) 859.23M. |
| SV024 | Yahoo Finance | Tenable Holdings, Inc. (TENB) Stock Price, News, Quote & History - Yahoo Finance | Enterprise Value/Revenue 3.32 ... Revenue (ttm) 1.02B. |
| SV025 | Yahoo Finance | Qualys, Inc. (QLYS) Stock Price, News, Quote & History - Yahoo Finance | Enterprise Value/Revenue 5.73 ... Revenue (ttm) 684.86M. |
| SV026 | PM Insights | BlueVoyant Valuation | PM Insights | BlueVoyant Secondary Market ROI ... BlueVoyant Bid-Ask Volume Ratios ... BlueVoyant Mutual Fund Valuations (NAV) ... BlueVoyant Funding Rounds & Cap Table Details. |
| SV027 | CB Insights | BlueVoyant - Products, Competitors, Financials, Employees, Headquarters Locations | Stage Series E | Alive ... Total Raised $665.5M ... Last Raised $140M. |
| SV028 | Yahoo Finance | Palo Alto Networks, Inc. (PANW) Stock Price, News, Quote & History - Yahoo Finance | Enterprise Value/Revenue 23.28 ... Revenue (ttm) 10.61B. |
| SV029 | Yahoo Finance | Fortinet, Inc. (FTNT) Stock Price, News, Quote & History - Yahoo Finance | Enterprise Value/Revenue 15.20 ... Revenue (ttm) 7.11B. |
| SV030 | CompaniesMarketCap | Palo Alto Networks (PANW) - Market capitalization | As of June 2026 Palo Alto Networks has a market cap of $247.92 Billion USD. |
| SV031 | CompaniesMarketCap | Fortinet (FTNT) - Market capitalization | As of June 2026 Fortinet has a market cap of $110.88 Billion USD. |
| SV032 | SiliconANGLE | BlueVoyant acquires cyber defense company Conquest Cyber, raises $140M | Including the new funding, BlueVoyant has raised about $646 million to date, according to data from Tracxn. |