STOCK TITAN

Rapid7 Becomes First Major Security Operations Platform to Unite SecOps and GRC

(Moderate)
(Neutral)
Tags

Rapid7 (NASDAQ: RPD) announced the general availability of Rapid7 Cyber GRC, adding native governance, risk, and compliance capabilities to the Rapid7 Command Platform. The offering connects GRC workflows with live SecOps data to give security, risk, and compliance teams a unified, continuously updated view of controls, active threats, and organizational risk.

According to Rapid7, Cyber GRC enables continuous control validation using platform telemetry, automated audit readiness across multiple frameworks, AI-assisted third-party risk management, and policy and risk register management. It is positioned as part of Rapid7’s broader Preemptive Security strategy and is being showcased at Black Hat USA 2026.

Loading...
Loading translation...

Positive

  • None.

Negative

  • None.

Market Context

Rapid7’s prior Cyber GRC early-access announcement was followed by a -5.94% 24-hour reaction, giving...
Analysis

Rapid7’s prior Cyber GRC early-access announcement was followed by a -5.94% 24-hour reaction, giving this general-availability launch a directly comparable historical reference. That record adds execution and adoption context; moderate short positioning remained a risk to monitor.

Key Figures

Early access launch: May 2026 Platform innovations: four Company experience: 25 years +1 more
4 metrics
Early access launch May 2026 Rapid7 Cyber GRC
Platform innovations four Showcased at Black Hat USA 2026
Company experience 25 years Rapid7 expertise and innovation
Customers more than 11,500 Rapid7 managed detection and response customers worldwide

Historical Context

5 past events · Latest: Jul 14 (Neutral)
Pattern 5 events
Date Event Sentiment 24h Move Catalyst
Jul 14 Earnings date notice Neutral -5.5% Announced Q2 2026 results release date and conference call scheduling
Jun 15 Inducement grant Negative -3.4% Granted 525,000 restricted stock units to the chief product officer
Jun 01 Leadership change Positive +4.3% Appointed Wael Mohamed CEO and moved Corey Thomas to executive chairman
May 21 Threat landscape report Negative -3.1% Reported vulnerability exploitation as the leading initial access vector
May 13 Cyber GRC early access Positive -5.9% Launched Cyber GRC early access with 360 Advanced for continuous compliance

24h Move is the share-price change in the day after each event; other market factors may also have contributed.

Pattern Detected

Recent reactions were mixed, with the prior Cyber GRC early-access announcement followed by a negative reaction despite the product launch.

Key Terms

grc, secops, attack-surface visibility, managed detection and response, +1 more
5 terms
grc regulatory
"connect GRC workflows with live SecOps data"
GRC stands for Governance, Risk, and Compliance, a coordinated approach companies use to set rules, spot and manage threats, and follow laws and industry standards. Think of it as a company's operating manual and early-warning system—like household rules, smoke detectors, and a neighborhood code—that helps protect the business from legal fines, operational surprises, and reputational harm, which in turn reduces investor uncertainty and potential losses.
secops technical
"connect GRC workflows with live SecOps data"
SecOps is the ongoing practice of monitoring, detecting and responding to cybersecurity threats and vulnerabilities across a company’s systems, tools and networks. Think of it as a combined neighborhood watch and emergency response team for a business’s digital assets: it limits damage from hacks, prevents downtime, helps meet regulatory rules, and reduces the chance of costly breaches or reputational harm, all of which affect investor risk and value.
attack-surface visibility technical
"tying internal controls to current attack-surface visibility"
The extent to which a company can identify and monitor all the digital entry points—servers, devices, applications, cloud services, network connections and exposed APIs—where attackers could try to gain access. Investors care because clearer visibility helps assess cyber risk, potential exposure to breaches, regulatory gaps and likely remediation costs; think of it like knowing every door and window in a building when judging how easy it would be to break in.
managed detection and response technical
"recognized leader in preemptive managed detection and response (MDR)"
Managed detection and response (MDR) is a service where outside specialists continuously monitor a company’s digital systems, look for signs of cyberattacks, and take or recommend immediate action to contain and fix problems. Think of it as hiring a dedicated 24/7 security team and emergency response crew for a business’s IT systems; for investors, MDR matters because it reduces the risk of costly breaches, downtime, regulatory fines, and damage to reputation that can hurt revenue and share value.
pci approved scanning vendor regulatory
"optional PCI Approved Scanning Vendor scanning"
A PCI Approved Scanning Vendor (ASV) is an independent security company that performs external vulnerability scans of internet-facing systems to check compliance with the Payment Card Industry Data Security Standard (PCI DSS). Think of an ASV like a certified inspector who tests doors and windows for weaknesses; its scan reports and passing status help businesses demonstrate to payment card networks and auditors that their public-facing systems do not have known security flaws that could expose cardholder data.

AI-generated analysis. How Rhea-AI works. Not financial advice.

See more from StockTitan in Google Search and AI answers. Adds StockTitan as a preferred source · opens Google
Add on Google

New generally available offering makes Rapid7 the first major security operations platform to connect GRC workflows with live SecOps data in one platform

BOSTON, July 28, 2026 (GLOBE NEWSWIRE) -- Rapid7, Inc. (NASDAQ: RPD), a global leader in AI-powered managed cybersecurity operations, today announced the general availability of Rapid7 Cyber GRC, expanding the Rapid7 Command Platform with native governance, risk, and compliance (GRC) capabilities. The new offering helps organizations continuously understand cyber risk, validate control effectiveness, and simplify compliance by connecting GRC workflows with live security operations data. This shared data foundation gives security and compliance teams a unified, continuously updated view of control performance, active threats, and organizational risk.

With Rapid7 Cyber GRC, Rapid7 becomes the first major security operations platform to unify SecOps and GRC, extending its Preemptive Security strategy across risk, controls, and compliance.

Security operations and governance have historically evolved as separate disciplines, leaving organizations to reconcile security findings, compliance evidence, and business risk across disconnected systems. This fragmentation consumes valuable resources, slows decision-making, and leaves leaders without a current view of whether controls are working. Rapid7 Cyber GRC brings these functions together on a common operational foundation, uniting security operations and governance to support continuous assurance.

Rapid7 Cyber GRC closes that gap by connecting governance workflows directly to live security telemetry. By tying internal controls to current attack-surface visibility, Rapid7 gives security, risk, and compliance teams a shared view of control effectiveness, active threats, and organizational risk.

With Rapid7 Cyber GRC, organizations can:

  • Continuously validate security controls using live platform telemetry to identify control deficiencies and drift between formal assessments.
  • Automate audit readiness by collecting evidence and mapping controls across multiple compliance frameworks.
  • Streamline third-party risk management with an AI Assessment Assistant that accelerates vendor questionnaires and reviews.
  • Connect security action to measurable risk reduction by bringing active threats, exposures, and findings into year-round compliance workflows.

The Cyber GRC also uses AI-powered assistants for compliance workflows and third-party assessments. These capabilities support policy management, third-party risk management, risk registers, audit-ready reporting, and optional PCI Approved Scanning Vendor scanning.

“Preemptive security goes beyond detecting and responding to threats. Organizations need to continuously understand where risk exists, whether controls are working, and where action is needed before gaps become incidents,” said Corey Thomas, Executive Chairman of Rapid7. “By bringing GRC into our platform, Rapid7 Cyber GRC connects what teams detect, what they fix, and what they can prove, turning compliance from a point-in-time exercise into an active part of security operations.”

Since launching Cyber GRC in early access in May 2026, Rapid7 has advanced the offering through customer validation, commercial adoption, and an expanding assurance partner ecosystem. Early customers included GetWell Networks and SelectQuote Insurance Services, demonstrating demand among organizations seeking to connect security operations with continuous compliance.

"What excites me most about Rapid7 Cyber GRC is the ability to use the wealth of security data, asset inventories, and API connectivity already available to us to produce more accurate, timely, and defensible risk reporting,” said Bill Theissen, Managing Partner and Vice President of Consulting Services at Cyber Watch. “Just as important, the platform helps bridge the divide between security engineering and GRC teams through a shared view of risk and a common language for communicating it."

Rapid7 is also building an ecosystem of audit, assurance, and GRC partners that extends continuous assurance beyond the platform. Partners including HITRUST, Insight Assurance, and 360 Advanced help organizations support certification and compliance programs across frameworks such as SOC 2, ISO 27001, HITRUST, CMMC, and FedRAMP.

Cyber GRC is one of four platform innovations Rapid7 is showcasing at Black Hat USA 2026 as part of its broader Preemptive Security strategy, alongside:

  • AI-Accelerated Exposure Discovery & Visibility, which applies natural language querying and AI-generated summaries to help teams surface exposures faster, identify software risk across the full technology stack, and communicate risk posture clearly to the business.
  • Preemptive MDR Alerts, which surface high-confidence threats before they escalate into incidents
  • Agentic SOC, which applies AI agents to accelerate investigations and guide response while preserving analyst control over high-impact decisions.

Together, these innovations extend Rapid7’s vision for Preemptive Security; helping organizations anticipate risk, continuously validate defenses, and disrupt attacks before they become incidents.

Attendees can experience live demonstrations and expert-led sessions at Rapid7 Booth #2445 in the Black Hat USA Business Hall, as well as at the company’s private space at Border Grill in Mandalay Bay. Join Rapid7 at Black Hat 2026.

About Rapid7
Rapid7, Inc. (NASDAQ: RPD) is a global leader in AI-powered managed cybersecurity operations, trusted to advance organizations’ cyber resilience. Open and extensible, the Rapid7 Command Platform integrates security data, enriching it with AI, threat intelligence, and 25 years of expertise and innovation to reduce risk and disrupt attackers. As a recognized leader in preemptive managed detection and response (MDR), Rapid7 unifies exposure and detection to transform the cybersecurity operations of more than 11,500 customers worldwide. For more information, visit our website, check out our blog, or follow us on LinkedIn or X.

Media Contact
Christine Nurnberger
SVP Global Marketing and Growth
press@rapid7.com
(857) 216-7804

Rapid7 Investor Contact
Matt Wells
Vice President, Investor Relations
investors@rapid7.com
(617) 865-4277


FAQ

What is Rapid7 Cyber GRC and how does it expand the RPD Command Platform?

Rapid7 Cyber GRC is a governance, risk, and compliance solution embedded in the Rapid7 Command Platform. According to Rapid7, it connects GRC workflows with live security operations data, supporting continuous risk understanding, control validation, audit-ready reporting, and third-party risk management in one shared data foundation.

How does Rapid7 (RPD) Cyber GRC connect SecOps and GRC for security teams?

Rapid7 Cyber GRC links governance workflows directly to live security telemetry from the Rapid7 Command Platform. According to Rapid7, this ties internal controls to current attack-surface visibility, giving security, risk, and compliance teams a shared view of control effectiveness, active threats, and organizational cyber risk.

What key capabilities does Rapid7 Cyber GRC offer for compliance and audits?

Rapid7 Cyber GRC offers automated evidence collection, control mapping across multiple compliance frameworks, and audit-ready reporting. According to Rapid7, it supports policy management, risk registers, AI-powered compliance assistants, and optional PCI Approved Scanning Vendor scanning to help organizations simplify and streamline ongoing compliance efforts.

How does Rapid7 Cyber GRC help with third-party risk management for RPD customers?

Rapid7 Cyber GRC includes an AI Assessment Assistant to accelerate vendor questionnaires and reviews. According to Rapid7, this helps streamline third-party risk management by using platform data and AI to assess external partners more efficiently and support continuous assurance across the extended enterprise.

Which compliance frameworks can Rapid7 (RPD) Cyber GRC support through its partner ecosystem?

Rapid7 is working with partners such as HITRUST, Insight Assurance, and 360 Advanced to support various frameworks. According to Rapid7, Cyber GRC can help organizations with programs aligned to SOC 2, ISO 27001, HITRUST, CMMC, and FedRAMP certification and compliance efforts.