Skip to main content

Cyber Monitoring - Supplier FAQs

Everything you need to understand and use Cyber Monitoring in one place

All Your Questions Answered

Browse the sections below to quickly find answers to common supplier questions about the Cyber Monitoring feature, how BlueVoyant works and what it means for your organisation.

Can’t find what you need? Your local Supplier Support team is here to help: https://hellios.com/contact-and-locations.


01 Popular Questions

What is BlueVoyant? What is cyber monitoring?

BlueVoyant is an independent cyber risk monitoring organisation. Their platform continuously analyses information that is publicly visible about organisations on the internet and produces a risk score based on its findings. This should be understood as a continuous assessment of how an organisation’s external digital presence appears to third parties. It is not an examination of internal systems or infrastructure.

Hellios has integrated BlueVoyant data directly into its community platforms to provide Buyers with an independent, consistently applied view of cyber risk across their supply chain, and to ensure that suppliers have full visibility of the information their Buyers are able to access, enabling them to identify and address any issues proactively.

Why is Hellios introducing this?

Cyber risk within supply chains is a significant and growing concern for organisations of all sizes. While the Hellios platform provides a robust framework for supplier assessment through structured questionnaires, BlueVoyant complements this by providing an independently generated, continuously updated view of each supplier’s external cyber posture, adding an objective, externally observed dimension to the assurance information already gathered through the Hellios assessment process.

BlueVoyant provides an externally generated, objective assessment that is applied consistently across an entire supplier community. Hellios is integrating this capability to provide Buyers with a more reliable and comprehensive picture of supply chain cyber risk, and to ensure that suppliers have full visibility of the information their Buyers can access.

How is our organisation’s score generated?

BlueVoyant’s automated scanning examines signals associated with an organisation’s external digital footprint, principally its registered domains and the services, subdomains, and IP addresses linked to them. The assessment considers factors such as exposed or misconfigured services, software with known and unpatched vulnerabilities visible from the internet, SSL/TLS certificate issues, email security misconfigurations, and whether the organisation’s domain or associated email addresses appear in known data breach or dark web datasets.

Each finding is assigned a severity classification, and these are aggregated to produce an overall risk score. The same methodology is applied to every organisation BlueVoyant monitors, ensuring scores are directly comparable across a community.

Will BlueVoyant monitoring cost us anything as a supplier?

Access to BlueVoyant cyber monitoring is included within your annual subscription for registration on the Hellios platform. There is no additional cost to you as a supplier. Your score and findings will be accessible through the platform as part of your existing membership.

How can my organisation use it?

You can use the information provided by BlueVoyant to identify your organisation’s externally visible vulnerabilities, prioritise remediation activities, and support transparent conversations with your customers. The platform provides clear details of each finding together with targeted remediation guidance to help you address identified issues.

What are the benefits to my organisation?

Cyber monitoring provides visibility of externally visible cyber risks that would typically require significant investment to identify independently. By helping your organisation identify and address these risks, it can strengthen your cyber resilience and support greater confidence between you and your customers.

What will I see when I log in?

From the Cyber tab in your Hellios account, you’ll be able to view an overall cyber profile score, a breakdown of findings by risk category, ranked findings with clear details, and remediation guidance to help you address identified issues.

Are our Buyers able to view our BlueVoyant data?

Yes. Buyers who are members of the same Hellios community have access to BlueVoyant scores and findings for all published suppliers within that community.

Suppliers’ access to their own data ensures transparency. Traditionally Buyers may have monitored suppliers without a supplier being aware until an issue has been flagged with them. You are able to view the same information your Buyers can access and take appropriate action to address any issues before they potentially become a concern within the commercial relationship.

Who should we contact if we have further questions?

The Hellios Supplier Support team is the appropriate first point of contact for questions relating to the platform, data access, false positive disputes, or escalations to BlueVoyant. For questions regarding how your Buyers are utilising this data or any specific expectations they may have, we recommend engaging directly with your relevant Buyer contacts.


02 How BlueVoyant Works

Does BlueVoyant use artificial intelligence?

Yes. BlueVoyant uses AI-driven analytics to power its continuous monitoring by automatically ingesting and analysing large volumes of external threat intelligence and supply chain data in real time. Its machine-learning models continuously evaluate digital footprints, detect emerging threats across the open and dark web, and prioritise risks, reducing false positives and alert fatigue while ensuring attention is focused on the most critical issues. Overall, AI enables faster, more accurate threat identification and improved security outcomes at scale.

Does BlueVoyant access our internal systems or confidential data?

No. BlueVoyant operates exclusively using publicly available information. Its scanning methodology analyses data that is already visible on the public internet, the same information that any external party, including a malicious actor, could access without the organisation’s knowledge or consent. No connection is made to internal networks, no software installation is required, and no credentials or access permissions are requested from the supplier.

How does BlueVoyant compare to a penetration test?

BlueVoyant cyber monitoring is neither a penetration test nor an intrusive network scan. It is an external cyber risk monitoring service that analyses only what is publicly visible about an organisation from the internet, the same information an attacker could access from the outside.

No active probing, exploitation attempts, or aggressive scanning is performed. All data collection is passive and designed to have no impact whatsoever on supplier systems. The most accurate description is continuous, external cyber risk monitoring, sometimes referred to as outside-in monitoring or attack surface monitoring.

What domains and assets does BlueVoyant monitor?

BlueVoyant monitors assets associated with an organisation’s known external digital footprint, principally its registered primary domain(s) and the IP addresses, services, and subdomains linked to them. Where an organisation operates multiple trading entities, subsidiaries, or acquired businesses with separate domains, coverage may vary accordingly.

If it is believed that assets have been omitted or incorrectly attributed to your organisation, this should be raised through the Hellios portal for investigation.

What types of issues are typically identified by BlueVoyant?

Common findings include: open or misconfigured ports and services that should not be publicly accessible; expired, invalid, or insufficiently secure SSL/TLS certificates; software or systems with known and publicly disclosed vulnerabilities that are detectable from the internet; email security misconfigurations, including absent or incorrectly configured SPF, DKIM, or DMARC records; and references to the organisation’s domain or employee email addresses identified in known data breach or dark web datasets.

Findings are categorised by severity to assist in prioritisation.

Our organisation holds ISO 27001, Cyber Essentials, or equivalent certifications. Why is a BlueVoyant score still applicable?

Security certifications confirm that an organisation met a defined standard of internal controls and processes at the point of assessment. BlueVoyant monitors what is externally detectable about an organisation’s infrastructure on a continuous, ongoing basis. These are distinct forms of assurance, each revealing information the other does not.

It is entirely possible for an organisation holding a current certification to have externally visible issues, such as an overlooked exposed service, a lapsed certificate, or a misconfigured cloud resource, that fall outside the scope or timing of the most recent audit. Maintaining both recognised certifications and a strong BlueVoyant score represents the most comprehensive assurance position.

Our organisation is relatively small. Does this monitoring apply to us?

Yes. BlueVoyant monitoring applies to all suppliers within a Hellios community, irrespective of organisational size. Smaller organisations frequently have a more limited external digital footprint, which can simplify the process of identifying and addressing individual findings. No specialist internal security function is required to review or act on the findings. The BlueVoyant information is designed to present results in accessible language.

How does BlueVoyant handle our subsidiaries or group companies?

BlueVoyant’s monitoring incorporates corporate hierarchy data to accurately map parent companies and their subsidiaries. The digital footprinting process uses advanced attribution techniques to identify assets belonging to each entity while avoiding misattribution between related organisations. This ensures that findings are tied to the correct legal entity. If you believe your subsidiaries or group companies have been incorrectly attributed or omitted, please raise this through your Hellios portal.


03 Your Data and Access

What data relating to our organisation is accessible within the platform?

You are able to view your organisation’s current overall cyber risk score, the individual findings that contribute to it, the severity classification of each finding, and a description of what has been detected and why it is considered a risk. As a supplier, you do not have access to the data of other organisations within your community - only your own.

Which individuals within our organisation have access to our data in Hellios?

Access is determined by your organisation’s existing Hellios user permissions. Any individual within your organisation who holds access to the community portal will be able to view the BlueVoyant data. If there is uncertainty regarding which personnel currently hold access, this should be confirmed with your organisation’s Hellios administrator or the Hellios Supplier Support team.

Are we able to view BlueVoyant data for other suppliers in our community?

No. Supplier access within the platform is restricted to each organisation’s own data. Access to data across all suppliers within a community is reserved exclusively for Buyers. This access boundary is fixed within the platform architecture.

How frequently is our data updated?

BlueVoyant performs continuous monitoring. Scores and findings are updated daily on an ongoing basis and reflect a near-real-time view of an organisation’s external cyber posture. The data is not a static snapshot. Changes made to external infrastructure and any findings that are remediated will be identified and reflected accordingly in the score.

Are we automatically scanned once we are registered and published on the platform?

Once published on the Hellios platform, your organisation’s company name and primary domain will be passed to BlueVoyant to determine the digital footprint and initiate the analytic and scoring runs. This process may take a short period, typically two to three days, depending on whether BlueVoyant is already monitoring your organisation. No action is required from you as a supplier.

Does the BlueVoyant score link to or validate our questionnaire responses?

The BlueVoyant monitoring data and your Hellios questionnaire responses address different but complementary dimensions of cyber security. Where your questionnaire responses indicate that certain controls are in place, BlueVoyant provides an independent, ongoing check on whether those controls are reflected in your organisation’s external posture.

For example, if you have confirmed that email security controls such as SPF, DKIM, and DMARC are correctly configured, or that known vulnerabilities are remediated promptly, BlueVoyant will independently verify whether this is visible in your external-facing systems, providing objective corroboration of your self-reported position.

Is our data shared with any third parties beyond Buyers within our community?

Your BlueVoyant data within Hellios is accessible only to authorised users, i.e. your own organisation (subject to appropriate permissions) and Buyers within your community. It is not shared with other suppliers, other Hellios communities, or external third parties beyond those involved in the operation and support of the platform. Detailed information regarding data access and retention is available in Hellios’ data processing documentation, or may be obtained from the Hellios Supplier Support team.


04 Acting on Findings

What steps should we take to act on any findings and to improve our score?

A useful starting point is to review your individual findings in detail, rather than focusing solely on your headline score. Findings classified as critical or high severity warrant particular attention, as these represent the most material external risks and are most likely to be of concern to your Buyers.

The specific findings can be shared with your IT function or external IT provider, with a request to review and remediate each item identified. It is worth noting that scores are updated automatically as BlueVoyant detects changes to your organisation’s external posture. They are not manually adjusted. An improving score trajectory over time is a recognised indicator of active risk management, and represents a considerably stronger position than a score that remains static.

What guidance does BlueVoyant provide within each finding to help us remediate?

Each finding surfaced by BlueVoyant includes a description of the issue identified, an explanation of the security risk it poses, and specific guidance on the steps required to address it. The level of detail provided is designed to give your IT function or provider the information needed to take direct action. Where further assistance is required, BlueVoyant also offers a managed remediation service as detailed below.

Is a managed remediation service available, and how would we access it?

BlueVoyant offers a managed remediation service that sits outside the scope of the cyber monitoring services provided through Hellios. This service is available for Buying organisations to discuss directly with BlueVoyant.

Our organisation does not have a dedicated IT or security function. How should we approach this?

A dedicated internal security team is not a prerequisite for understanding and acting on BlueVoyant findings. The information is designed to present findings in accessible language, including an explanation of why each issue is considered a risk.

The recommended approach is to begin with the highest-severity findings and provide the detailed descriptions to whoever is responsible for managing IT, whether an internal colleague, an external IT support provider, or a hosting provider. The majority of findings are specific and directly actionable.

How quickly should we expect our score to reflect remediation activity?

The timeframe varies depending on the nature of the finding. Changes that are immediately detectable externally, such as the closure of an open port, renewal of an SSL certificate, or an update to exposed software, are typically reflected within BlueVoyant’s subsequent scan cycle. Findings associated with data breaches or dark web exposure may take longer to clear, as resolution is dependent on the underlying data rather than a directly actionable technical change.

We believe a finding is inaccurate or incorrectly attributed to our organisation. What is the process?

BlueVoyant data is recognised for its high levels of accuracy, and false positive findings are uncommon.

Where a finding is believed to have been incorrectly attributed, this should be raised using the “Challenge” button in the portal for Hellios and BlueVoyant to investigate. Findings confirmed as incorrectly attributed may be removed, and the score will be updated accordingly.

If BlueVoyant confirms that the finding is correct, no change will be made to the score.

What if we have open ports or exposed services that are intentional and legitimate - will these always count against our score?

BlueVoyant’s scoring is designed to account for context and legitimacy, recognising that not all findings represent unmanaged risk. Where there are genuine business or technical reasons for an exposure (e.g. an intentional Honeypot has been set up), this context can be taken into account through the “Challenge” process. The aim is to ensure your score reflects actual risk rather than simply the presence of observable configurations, so your organisation is not unfairly penalised for acceptable, well-managed, or intentional setups.

If you believe a specific finding relates to a legitimate and intentional configuration, please raise this using the “Challenge” button in the portal with a supporting explanation.

Our organisation uses third-party managed services or cloud infrastructure. Could this affect our score?

BlueVoyant monitors assets associated with an organisation’s domain and known external infrastructure. In shared or managed hosting environments, certain findings may relate to the provider’s broader infrastructure rather than the organisation’s specific deployment. Where this is believed to be the case, the matter should be raised using the “Challenge” button in the portal for Hellios and BlueVoyant to investigate.

It should also be noted that where an organisation’s data or services are hosted within an environment with known vulnerabilities — even where technical responsibility lies with the provider — Buyers may reasonably consider this to represent a risk to their supply chain.

Engaging with the provider to address shared infrastructure issues where practicable is therefore advisable.

Should we communicate proactively with our Buyers regarding our score or findings?

As Buyers have direct access to your score and findings within the platform, it is not necessary to share the underlying data. However, proactive communication may be beneficial, particularly where a score is low, where material findings are being remediated, or where contextual information would assist a Buyer’s understanding, such as findings relating to infrastructure that is in the process of being decommissioned.

An organisation that proactively communicates its awareness of identified issues and the steps being taken to address them is likely to be regarded more favourably than one that does not engage with the data. This approach reflects positively on the organisation’s security culture and its commitment to transparency.

Could a low score adversely affect our commercial relationships with Buyers?

The consequences of a low score are determined by each Buyer’s own risk management and procurement policies, which Hellios does not prescribe. Some Buyers may operate formal thresholds or remediation requirements; others may treat the data as one component of a broader risk assessment without automatic commercial implications.

The most effective course of action is to maintain awareness of your score, understand the factors contributing to it, and be in a position to demonstrate active management of the identified issues. A low score accompanied by a clear and progressing remediation plan is a materially different position from one where no action has been taken.


05 Privacy, Consent and Data Governance

Did our organisation consent to being monitored by BlueVoyant?

BlueVoyant’s monitoring is conducted exclusively using publicly available information. There is no legal requirement for consent in order to scan data that is already publicly accessible on the internet. This is the same information that any external party may access without an organisation’s knowledge or permission. No installation of software is required, and no credentials or access permissions are sought. The integration of BlueVoyant data into the Hellios platform is governed by Hellios’ terms of service applicable to community members.

Does the use of BlueVoyant data comply with GDPR and applicable UK data protection legislation?

BlueVoyant monitors organisational rather than personal data, principally domain names, IP addresses, and publicly exposed services associated with the organisation. As such, the majority of data involved does not constitute personal data for the purposes of GDPR. However, findings relating to dark web datasets may on occasion reference individual email addresses or credentials, which may constitute personal data in certain circumstances. Hellios and BlueVoyant operate in accordance with applicable data protection legislation.

Is it possible to opt out of BlueVoyant monitoring or the sharing of our data with Buyers?

As BlueVoyant monitors only publicly available information, it is not possible to prevent the monitoring itself. The same data is accessible to any party with internet access. What organisations are able to control is their external posture: by identifying and addressing findings, the information visible externally is reduced and the score improved accordingly.

While we understand your preference to have the score removed, our current system does not allow for selective visibility.

How secure will my information be?

All supplier information is stored in secure Tier 4, SSAE18 SOC2 Type II certified data centres, with data hosted in the UK, EU or Australia depending on the Hellios community. Encryption to the latest industry standards is employed, along with cyber security measures such as regular security scans and penetration testing. Hellios ensures that the limited amount of personal data collected is handled in accordance with applicable data protection legislation. Hellios is certified to ISO 27001 and Cyber Essentials Plus, demonstrating our commitment to recognised information security and cyber security standards.


06 Common Technical Terms

Email Authentication & Anti-Spoofing (SPF, DKIM, DMARC)

Your domain name (for example, yourcompany.com) is used to send and receive email through one or more mail servers, referred to as your “MX domain”. Alongside your domain, organisations publish DNS records — small pieces of text, stored centrally on the internet, that any other computer can look up (DNS is often compared to a phone book for the internet).

SPF, DKIM and DMARC are three DNS records that work together to prove an email genuinely came from your organisation, and to stop “spoofing” — where a criminal disguises an email to make it look like it was sent by you.

Vulnerability & Patch Management (CVEs and CVSS Scores)

Software — including the operating systems and applications running on your servers — is regularly found to contain security weaknesses. When one of these becomes publicly known, it is catalogued as a CVE (Common Vulnerabilities and Exposures): an official, shared record of a known flaw, given a reference number (for example, CVE-2024-12345) so it can be tracked and fixed.

Software vendors typically release a “patch” — an update — to close the gap once a CVE is identified. Because thousands of CVEs are published every year, the security industry rates how serious each one is using CVSS (the Common Vulnerability Scoring System): a standardised score from 0 to 10, grouped into four severity bands, used to help organisations decide what to prioritise.

Exposed Network Services

Every server connected to the internet has a number of “ports” — think of them as individual doors into the system, each used for a specific purpose (for example, port 443 is normally used for secure website traffic).

A service is “exposed” when its door is open and reachable by anyone on the internet, rather than only from trusted locations such as your internal office network.

Website & Server Certificates (SSL/TLS)

When your browser connects securely to a website (shown by the padlock icon and “https://” in the address bar), that connection is encrypted using an SSL/TLS certificate.

A certificate does two jobs: it scrambles the data travelling between the visitor and the server so it cannot be read if intercepted, and - when issued by a recognised, independent Certificate Authority - it proves to the visitor that they really are talking to your organisation and not an impersonator.

DNS Configuration

DNS (the Domain Name System) is often described as the internet's phone book: it translates human-readable domain names (like yourcompany.com) into the technical addresses, called IP addresses, that computers use to find and connect to one another.

Your organisation publishes DNS “records” - individual entries in that phone book - to direct traffic to the right place, such as your website or email servers.

Signs of Active Targeting (Threat Intelligence Findings)

As well as checking your configuration, BlueVoyant's monitoring can pick up on real-world activity directed at your organisation's systems, drawn from threat intelligence sources. Unlike the findings above, these describe things that are actually happening, rather than a setting that needs changing.


07 Further Help

Is assistance available to help our organisation improve its score?

The findings and remediation guidance presented on your profile within the platform represent the most direct starting point. They identify specifically what is externally visible and what action is required to address it. Your existing IT provider or managed service should be equipped to act on the specific findings identified.

For broader cyber security improvement guidance, a range of publicly available resources are accessible through:

• UK: National Cyber Security Centre (NCSC)

• European Union: European Union Agency for Cybersecurity (ENISA)

• United States: Cybersecurity Infrastructure Security Agency (CISA)

• Canada: Canadian Centre for Cyber Security (CCCS)

• Australia: Australian Cyber Security Centre (ACSC)

If you require additional specialist support, BlueVoyant also offers cyber security services separately, including:

• Cyber remediation and security consultancy

• Penetration testing and vulnerability services

• Managed security services

• Incident response

You can contact BlueVoyant at hellios@bluevoyant.com to discuss your requirements.

Any additional services provided by BlueVoyant would be separate from the BlueVoyant Cyber Monitoring service provided through Hellios. Any engagement, including its scope, terms and fees, would be agreed directly between your organisation and BlueVoyant, and Hellios would not be a party to that engagement.

Did this answer your question?