New York, NY, USA
2017
  |  By Taylor Fletcher
When a vendor’s risk score changes, a TPRM team can see what issues were flagged, why they matter, and what remediation steps are recommended next. But improving a vendor’s risk posture is not always as simple as working through each risk finding one by one. Sometimes the bigger pattern sits at the asset level.
  |  By BlueVoyant Risk Operations Center
Foreign Ownership, Control, or Influence (FOCI) risk is often discussed as an ownership problem. Who owns the supplier? Who sits on the board? Is there a parent company tied to a foreign government? Does that relationship trigger CFIUS, export controls, sanctions, or a facility clearance review? These questions matter, but they do not capture the full risk picture. For C-SCRM program stakeholders, the most important word in FOCI is not ownership or control — it is influence.
  |  By BlueVoyant
Deployment services to help Microsoft 365 E5, E7 and Microsoft Defender Suite customers build the foundation for an agentic SOC.
  |  By Micah Heaton
Cost pressure can decide what your security team gets to see. A useful log source gets left out. Investigation history gets shortened. Analysts work with the evidence the organization could afford to keep. That is the part of Microsoft's Integrated Security Operations Center, or ISOC, announcement I keep coming back to. Bringing SIEM capabilities into the Defender experience, using native security data, and changing the economics gives customers a reason to revisit those decisions.
  |  By BlueVoyant and Microsoft
As you’re reading this, it’s possible an agent you’ve never heard of is reading your files. But where did it come from? What systems can it access? And who’s responsible for its oversight? Today, employees are using AI and agents to expand what they can accomplish and how work gets done. And the barriers to innovation have never been lower — with natural language and no-code tools, anyone in your organization can build a new agent in the span of an afternoon.
  |  By John Hernandez
Since joining BlueVoyant in May, I’ve spent my first 100 days listening. I've had conversations with nearly 50 customers and partners across industries and geographies, as well as the broader security industry, engaging with leaders at Black Hat last month. What I heard reinforced something I believe strongly: the security challenges organizations face today are changing faster than the traditional enterprise security model was designed to handle.
Ransomware and ransomware-style attacks can have a catastrophic impact within healthcare, where disruption directly impacts safety and continuity. Today's ransomware groups increasingly operate as sophisticated criminal enterprises, sharing tools, infrastructure, and expertise through ransomware-as-a-service (RaaS) models. This lowers the barrier to entry for cybercriminals while allowing experienced threat actors to focus their efforts on identifying and exploiting high-value targets.
  |  By Tom Moore, Director of Forensics
As regulators tighten expectations and cyber attacks increasingly exploit supply chains, organisations must shift from periodic vendor assessments to continuous third-party cyber resilience. For years, third-party cyber risk management focused primarily on vendor due diligence and annual security assessments. The objective was simple: determine whether a supplier met an acceptable level of security at a specific point in time.
  |  By BlueVoyant and Rolls Royce
Over recent months, our Microsoft Managed Detection and Response (MDR) service, powered by the Threat Fusion Cell, has observed a sharp increase in sophisticated attack campaigns attributed to offshoots of threat brand Vocal Brigantine, who ceased operations in Spring 2026.
Ransomware attacks no longer rely on traditional encryption methods. With today's advanced technology, threat actors are developing 'encryption-less extortion', focusing solely on data exfiltration and the threat of leaking or selling stolen sensitive information. Often used as part of double and even triple extortion strategies, ransomware has now evolved into a fragmented, competitive, and increasingly strategic threat landscape that employs divergent attack strategies, laser-focused on high-value targets.
  |  By BlueVoyant
Discover BlueVoyant's highly customizable, AI-driven questionnaire platform that automates assessment creation and distribution.
  |  By BlueVoyant
BlueVoyant has guided hundreds of clients to assess, deploy, and optimize their Microsoft security products. Our sessions are personalized one-on-one engagements where we analyze your unique environment, provide insights and guidance, and help you make data-backed decisions about your next Microsoft Security investment. Optimize security and potentially save up to 60% - Consolidate your solutions with Microsoft, get more out of E5, leverage compliance and security add-ons.
  |  By BlueVoyant
Secure your vendor and partner ecosystem in five easy steps with BlueVoyant Supply Chain Defense.
  |  By BlueVoyant
In today's increasingly hostile threat landscape, organizations are grappling with a lack of resources and overworked security operations teams, making effective, full-coverage threat detection and response a significant challenge. BlueVoyant Managed Detection & Response provides a cloud-native solution that offers end-to-end consulting, implementation, and managed security services with 24x7 security threat detection and response.
  |  By BlueVoyant
The BlueVoyant Cyber Defense Platform helps secure Azure, Microsoft 365, and hybrid cloud environments. We're trusted by more than 1,000 clients in 40-plus countries.
  |  By BlueVoyant
Identify gaps and achieve NIS2 readiness with BlueVoyant.
  |  By BlueVoyant
Discover how to unleash the full capabilities of your Microsoft Security tools and optimize your Copilot experience with BlueVoyant.
  |  By BlueVoyant
Seamlessly integrate internal, supply chain, and external cyber defenses.
  |  By BlueVoyant
Discover how supply chain cyber breaches are impacting global organizations in BlueVoyant's fourth annual survey into supply chain cyber risk management.
  |  By BlueVoyant
Businesses operating within the EU must prepare to comply with the stringent requirements of NIS2. Failure to do so could result in significant penalties, highlighting the urgency for organisations to act swiftly. NIS2 introduces new requirements in areas such as risk management, corporate accountability, reporting obligations, and business continuity.
  |  By BlueVoyant
In today's connected world, there's no shortage of entry points into financial institutions. From online banking websites to mobile apps, these crucial parts of a business are also easy targets. Taking a proactive approach to protect your customers' assets and your brand is the answer, but where do you start?
  |  By BlueVoyant
Your business is your castle. Once upon a time, you could keep it safe by constructing strong walls, posting a few guards at the door, raising the drawbridge, and digging a deep moat around it. That's now the stuff of fairy tales. Today's networks simply can't be locked down due to the nature of business itself. The perimeter that was once contained to a single building now spreads as far as your furthest third-party connection or remote employee. And while your business benefits from this greater flexibility and increased operational efficiency, so do the cybercriminals.
  |  By BlueVoyant
When it comes to designing or improving upon your organization's security program, one key area to focus on and include is cyber resilience. Either as a complementary stand-alone program or embedded into an existing cyber defense program, cyber resilience refers to a company's ability to continue business operations and outcomes in spite of cyber attacks or events.
  |  By BlueVoyant
In the past few years, third-party cyber attacks have imparted financial and reputational damage to every sector, from banks to healthcare systems to governments. The average cost of a third-party data breach in 2021 was $4.33 million, according to a report from IBM and the Ponemon Institute. While CISOs are well aware of the potential supply chain devastation from attacks, preventing them has been a challenge. In this white paper, we'll walk through three third-party breach scenarios, including real-world examples, offering practical solutions to prevent such attacks.

A comprehensive security operations platform empowered by AI to enable uninterrupted protection against potential threats.

BlueVoyant combines internal and external cyber defense capabilities into outcomes-based, cloud-native cybersecurity solution by continuously monitoring your network, endpoints, attack surface, and supply chain, as well as the clear, deep, and dark web for threats.

BlueVoyant Cyber Defense Platform:

  • Detection & Response: Protect your endpoints, network, and cloud from sophisticated threats while leveraging your existing security tool investments — EDR, SIEM, others.
  • Supply Chain Defense: Rapidly identify and drive remediation of critical cybersecurity issues in your third-party ecosystem, including zero-day and emerging vulnerabilities.
  • Digital Risk Protection: Detect and eliminate cyber threats originating in the clear, deep, and dark web before they impact your business and customers.
  • Cyber Posture Management: Systematic approach that involves the continuous measurement, management, and mitigation of cyber risk.
  • Proactive Defense: Collaborative and holistic approach to attack surface management that includes vulnerability management, penetration testing, phishing awareness, dark web threat research, and configuration management.

Seamless AI-driven internal, external, and supply chain cyber defense, all within one powerful Security Operations Platform.