BlueVoyant provides cyber defense solutions via a cloud-native platform that combines internal and external security operations to protect networks, endpoints, and the digital attack surface. It continuously monitors environments and uses threat detection and analytics to give real-time visibility. A major focus is supply chain security, using machine-learning automation and human expertise to identify, validate, and mitigate threats across complex third-party networks by monitoring domains, websites, social media, and applications. It also offers specialized Microsoft Security tools services and serves commercial and government clients, aiming to reduce digital risk and enable proactive defense across on-premises and cloud environments.
Company Size
501-1,000
Company Stage
Series E
Total Funding
$695.5M
Headquarters
New York City, New York
Founded
2017
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Flexible Work Hours
Remote Work Options
BlueVoyant launches solution to accelerate agentic security adoption of Microsoft's new Integrated Security Operations Center. Sep 23, 2026, 12:30 ET Deployment services to help Microsoft 365 E5, E7 and Microsoft Defender Suite customers build the foundation for an agentic SOC NEW YORK, Sept. 23, 2026 /PRNewswire/ - BlueVoyant, a leading cybersecurity company, today announced its Microsoft Defender XDR ISOC Deployment Service, one of the first deployment solutions in the market built to help enterprises adopt the newly announced Integrated Security Operations Center (ISOC) in Microsoft Defender. ISOC in Microsoft Defender brings security information and event management (SIEM) and extended detection and response (XDR) together in the Defender portal, providing a shared foundation of signals, context and controls for security teams and AI agents. "The pattern we see most often is a gap between the security technology customers own and what they can actually put to work," said Micah Heaton, Executive Director, Microsoft Product and Innovation Strategy at BlueVoyant. "ISOC helps close that gap by bringing security data, context and response workflows together in Microsoft Defender. The economics matter too. Cost pressure should not decide which evidence an analyst gets to see. Our role is to help customers assess readiness, activate the capabilities that matter and put them to work through deployment and managed services. That gives customers a practical foundation for adopting agents with the right context and controls." Preparing Customers for the Agentic Era of Security Operations Built on BlueVoyant's long-standing expertise as a premier Microsoft Security partner, the new Microsoft Defender XDR ISOC Deployment Service expands BlueVoyant's solution to cover the full scope of ISOC readiness. Customers and prospects can begin with BlueVoyant's ISOC Readiness Assessment, which is a no-cost engagement to prepare for ISOC deployment. The program provides a starting point to discuss the organization's environment and prepare for scoped ISOC deployment support, which includes: * Defender deployment and configuration across Endpoint, Identity, Office 365, Cloud Apps and Entra ID Identity Protection * Walkthroughs of ISOC custom detections, workbooks, automation, and user and entity behavior analytics (UEBA) * Use-case engineering to develop and refine detection rules, workbooks and automations BlueVoyant's depth across the full Microsoft security stack - Microsoft Sentinel, Microsoft Defender, Microsoft Entra and Microsoft Purview - positions the company to guide customers through every phase of Microsoft's rollout. "ISOC in Microsoft Defender represents an important evolution in how organizations defend against modern threats," said Naseem Tuffaha, Corporate Vice President, Customer Value Creation at Microsoft. "Our security partners like BlueVoyant play a critical role in helping customers bring these capabilities together, operationalize them in their environments, and turn Microsoft's security innovation into meaningful outcomes. ISOC is built for agentic security, and the combination of technology and operational experience will be essential to helping customers realize its full value." "We're proud to be one of the first Microsoft partners to help customers deploy Microsoft's new integrated security operations center," said John Hernandez, CEO at BlueVoyant. "ISOC gives customers an opportunity to improve how they run security operations and prepare for teams and AI agents to work from shared data and context. Customers need a practical path from deployment to day-to-day operations, which is exactly where BlueVoyant's expertise comes in - we don't just help stand it up, we help run it." Availability BlueVoyant's Microsoft Defender XDR ISOC Deployment Service is available now, with implementation aligned to customer eligibility, agreed scope and Microsoft's phased rollout. Current customers and prospects can request the no-cost ISOC Readiness Assessment Security Diagnostic here or register for an upcoming webinar, Defend Like a Pro on September 29 at 2 P.M. ET, to learn more about preparing for ISOC in Microsoft Defender. About BlueVoyant BlueVoyant defends organizations against cyber threats across any attack surface. BlueVoyant AI, our Agentic SecOps Platform, pairs a decade of frontline expertise with intelligent automation to help security teams detect, investigate and respond faster and more consistently. Our integrated capabilities span Managed Detection and Response (MDR), Third-Party Risk Management (TPRM) and Digital Risk Protection (DRP). A premier Microsoft Security partner, BlueVoyant supports more than 2,500 customer deployments in Microsoft-native environments worldwide. Learn more at bluevoyant.com. SOURCE BlueVoyant
Former FBI cyber veteran Milan Patel joins Sophos to lead MDR Services; Lisa Moorhead promoted to Chief Digital and Information Officer. The company's leadership appointments extend Sophos' agentic AI leadership across security operations and the enterprise August 10, 2026 OXFORD, U.K. Sophos, a global cybersecurity leader, today announced two senior leadership appointments across agentic security operations and enterprise technology: Milan Patel has joined as Global Head of MDR Services, and Lisa Moorhead has been promoted to Chief Digital and Information Officer (CDIO). Both report to CEO Joe Levy as part of the senior management team. Patel brings more than two decades of leadership across cybersecurity, national security, and managed detection and response (MDR), and will advance Sophos' agentic security operations center (SOC). Leading MDR Operations, Professional Services, and Advisory Services, his team defines and executes the global strategy for Sophos managed security services, including the continued advancement of Sophos' agentic operating model and the commercialization of emerging AI capabilities across the services portfolio. "Milan is a rare leader who has built and scaled an AI-powered MDR business from the ground up while operating at the highest levels of national cybersecurity," said Joe Levy, CEO, Sophos. "His appointment reinforces its commitment to managed services and the critical role they play in its growth strategy, as Sophos Group accelerate innovation across the world's largest agentic SOC. Sophos MDR defends more than 40,000 customers worldwide, delivering a fully automated response to threats in 89 seconds, with 52% of MDR cases closed end-to-end by AI. Patel's remit includes scaling that model and reinforcing the human-on-the-loop governance behind Sophos' use of agentic AI in production. "The agentic SOC is the most significant shift in managed security since MDR itself, and Sophos has built the operating model that defines it," said Milan Patel, global head of MDR services, Sophos. "I've spent my career at the intersection of advanced threats, national security, and managed services, and Sophos has the scale, architecture, and discipline to apply agentic AI to strengthen defense for customers against faster moving threats. I look forward to building on that foundation." Patel joins Sophos from BlueVoyant, where he was Global Head of MDR and Chief Revenue Officer. Earlier, he spent more than a decade as a Special Agent in the FBI, including as a Supervisor at FBI Headquarters and as a field Agent on landmark investigations such as Silk Road, Anonymous, and Operation Ghost Click, one of the largest cyber takedowns in history. Patel has also served as a member of the FBI's counter terrorism efforts overseas supporting Joint Special Operations Command, in addition to an operator on the FBI's elite Special Weapons and Tactics Team (SWAT). Patel co-led the Joint Requirements Team under the White House National Security Council's Cyber Security Directorate, where he helped authored the first cyber incident severity framework endorsed across U.S. government and intelligence agencies. Extending AI across the business. Sophos also promoted Lisa Moorhead to Chief Digital and Information Officer. Moorhead succeeds Tony Young, who is leaving Sophos after a transformational 10 years with the company. As CDIO, Moorhead owns the company's enterprise AI strategy, accelerating the speed and intelligence of go-to-market and business operations and raising the value Sophos delivers to customers and partners. Sophos is applying the same agentic AI discipline inside its own operations. By adopting agentic data engineering across its enterprise data platform, Sophos now delivers data pipelines four times faster across the full lifecycle. Proof-of-concept pipelines that once took two to three days are now produced in under an hour. The company is modernizing more than 800 production pipelines behind revenue forecasting, HR operations, and business analytics, with full standards compliance and a first-time deployment success rate above 95%, with governance enforced during the build by design. "In promoting Lisa Moorhead to CDIO, we are placing enterprise-wide AI adoption in the hands of a proven leader who has spent her career turning technology into measurable business outcomes," Levy said. "The trust our customers place in us depends on adopting AI both aggressively and responsibly, and Lisa has consistently shown she can move fast while delivering the architectures that trust requires." Moorhead was formerly Senior Vice President of IT Applications at Sophos, leading a global organization spanning enterprise architecture, development, and QA across the company's core business systems. She previously led Cloud Infrastructure Services and founded the company's IT Business Operations function. Before Sophos, she established the Office of the CIO at GoPro and held several IT leadership positions at Informatica. "This is one of the most exciting moments I've seen in enterprise technology, with AI driving rapid progress in areas that historically moved slowly," said Lisa Moorhead, chief digital and information officer, Sophos. "My focus is embedding AI across the business so our go-to-market, operations, and customer- and partner-facing teams move faster and make better-informed decisions. In IT, we hold a dual mandate to innovate and to protect the business from risk, and our discipline is making sure governance and guardrails keep pace with that adoption." About Sophos. Sophos, a global cybersecurity leader, defends more than 625,000 organizations worldwide with Sophos Fusion, the industry's first and most complete AI-native cybersecurity defense system: a single, connected architecture where every control point operates as one. Powered by agentic AI and elite human expertise, Sophos detects, investigates, and neutralizes threats before they become business-disrupting events. Working alongside a global ecosystem of managed service providers, resellers, and technology partners, Sophos compounds intelligence from every threat encountered and every environment defended to make every customer's defense stronger than the last. Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com.
BlueVoyant announced its Microsoft 365 E7 readiness bundle, combining BlueVoyant AI with deployment support for Microsoft Purview, Security Copilot, and Agent 365. The bundle helps organisations secure AI adoption through Microsoft 365 E7. The package addresses data security and agentic identity as enterprises expand their attack surface with E7 adoption. BlueVoyant AI brings continuous optimisation for Purview directly into its managed detection and response engine, treating Purview alerts, data leaks, and policy violations with automated enrichment and correlation. BlueVoyant's Entra ID Protection capability now extends to AI agents running across Microsoft environments. The company frames the offering around two foundations: data security through Microsoft Purview, and agentic identity through Entra ID Protection and Agent 365, now integrated within BlueVoyant AI's platform.
BlueVoyant, a leader in AI-driven security operations platforms, has appointed Ravi Subramanian as chief financial officer and Jamie Coleman as chief customer officer. Subramanian, who joined BlueVoyant in 2017 and previously served as acting CFO, will oversee global financial strategy and operations. Coleman brings over 20 years of experience building customer organisations across enterprise software and cybersecurity. The appointments support BlueVoyant's expansion as it serves more than 1,000 customers across 45 countries. Coleman previously led a global team of over 400 professionals at Quest Software and One Identity, managing a $60 million customer portfolio. He will focus on accelerating customer time-to-value and improving retention whilst strengthening customer outcomes across BlueVoyant's AI-driven cyber defence platform.
BlueVoyant launches first dedicated AI agent security service for Microsoft environments. Jennifer Smith, Content Manager | Published 6 July 2026 The first security service built to govern AI agent identities, permissions, and behaviour before they become a liability BlueVoyant, a leading cybersecurity company, today announced the availability of its Microsoft Agent 365 Security Deployment Service, the first professional services program to help enterprises discover, govern, and secure the AI agents running across their Microsoft environment. The service launches as organisations worldwide race to adopt AI agents faster than their security teams can govern them. Enterprises are integrating AI agents (including Microsoft 365 Copilot, Copilot Studio, Azure AI Foundry, and third-party agents) into critical business workflows at an unprecedented pace. But these agents represent a fundamentally new class of non-human identity. These agents can read sensitive data, call external tools and MCP servers, and act autonomously on behalf of users and organisations. Most enterprises have no inventory of which agents exist, no identity or access policies applied to them, and limited ability to detect or respond to agent-related threats. "AI agents are the fastest-growing attack surface that most security teams aren't watching," said John Hernandez, CEO at BlueVoyant. "The question isn't whether enterprises are running agents. They are. The question is whether those agents are governed. Right now, for most organisations, the answer is no." A Control Plane for the Agentic Enterprise The BlueVoyant Microsoft Agent 365 Security Deployment Service addresses this gap by establishing Microsoft Agent 365 as a centralised control plane for AI agent governance. The engagement configures Agent 365 alongside the Microsoft security stack (Microsoft Entra, Microsoft Defender for AI, and Microsoft Purview) so that AI agents are governed with the same rigour as any other identity in the enterprise. Over the course of a guided, approximately 90-day engagement, BlueVoyant's experts work directly within the client's Microsoft tenant to deliver: * Agent inventory and registry: A view into which agents exist, who owns them, what data they can access, and what tools they can invoke - including shadow AI detection for agents deployed without IT knowledge. * Identity and access controls: Agent Conditional Access and Identity Protection policies configured in Microsoft Entra, treating agent authentication with the same scrutiny as human user authentication. * Threat detection and response: Microsoft Defender Security for AI enabled and integrated with Defender XDR, providing detection and response capabilities specific to agent-related threats. * Data protection policies: Microsoft Purview DLP and Insider Risk Management extended to AI agents, reducing exposure from data oversharing and unauthorised access. * Client-owned configuration: All configuration lives within the client's tenant. BlueVoyant delivers the expertise and the blueprint; the client retains full ownership at engagement close. Addressing a Market Gap with Microsoft The service is designed to attach directly to Microsoft 365 E7 and Agent 365 deployments and is aligned with AI Cloud Partner Program incentives. It positions BlueVoyant as one of the first security partners with a defined, repeatable AI-agent security offer - a strategic advantage as the agentic AI market matures. "At the conclusion of the engagement, clients will have clear answers to the foundational questions every security leader should be asking today: What AI agents do we have? Who owns them? How are they governed? And what happens when one is compromised" said Sebastian Sobolev, Chief Product Officer at BlueVoyant. The Microsoft Agent 365 Security Deployment Service is available immediately. Clients must have Microsoft E5 or E7 licensing with the Agent 365 add-on to be eligible.