Rapid7 - Experts & Thought Leaders

Latest Rapid7 news & announcements

Rapid7 cloud security with exposure command

Rapid7, Inc., a pioneer in AI-powered managed cybersecurity operations, announced new cloud security capabilities within Exposure Command, its industry-pioneer exposure management solution. The introduction of runtime validation and Data Security Posture Management (DSPM) enables organisations to identify, validate, and prioritise exploitable risk based on real-world attack paths and business impact. As organisations scale hybrid and multi-cloud environments, security programs must move beyond reactive models built on assessment alone. With runtime validation and DSPM, Rapid7 advances Exposure Command from continuous assessment to continuous validation, enabling proactive exposure reduction across hybrid environments. Runtime validation determines which vulnerabilities and misconfigurations are actively exploitable, while DSPM provides critical context by mapping sensitive data and identity access to real-world attack paths that increase risk. Unpredictable cloud environments “True cloud risk happens at the intersection of vulnerabilities, identities, and sensitive data in production,” said Craig Adams, chief product officer at Rapid7. “By embedding runtime validation and data context into Exposure Command, we enable security teams to identify the exposures that pose the greatest risk and prioritise remediation earlier, strengthening resilience before those risks translate into breach impact.” Rapid7’s new cloud security capabilities in Exposure Command include: Continuous visibility at runtime: Analyse live cloud workloads and validate which vulnerabilities and misconfigurations are actively exploitable. Leveraging eBPF-based sensors and AI-to-baseline application behaviour, the solution correlates runtime signals with posture findings and business context. Continuous monitoring of AI-driven workloads: Detect and neutralise deviations in highly complex, unpredictable cloud environments by continuously monitoring AI agents. Going beyond static vulnerability scoring, this validates which exposures are active across AI workloads. Automated cloud incident response: Initiate automated remediation actions once a threat is detected and validated. Steps include pausing, quarantining, or killing processes to neutralise and reduce the blast radius of any attack. Data aware risk prioritisation: Align sensitive data intelligence with attacker reachability to continuously discover and classify sensitive data and map identity access across cloud, SaaS, and hybrid environments. This shows whether high-value data is realistically reachable through real-world attack paths, enabling remediation decisions based on breach impact rather than vulnerability severity alone. Remediate active exposures Together, runtime validation and DSPM enhance Exposure Command’s ability to identify and prioritise exploitable risk, enabling organisations to continuously detect and remediate active exposures before they become legitimate threats. Rapid7 will be demonstrating the new cloud security capabilities, recent innovations in our Managed Detection and Response (MDR) service, and the full capabilities of Exposure Command live at the RSAC 2026 Conference in San Francisco, March 23-26, booth #S-3201. Rapid7 will also present the following sessions at the conference: Exploiting Cellular IoT Pathways to Compromise Trusted Access -Deral Heiland, Principal Security Researcher, IoT - March 24, 1:15 PM - 2:05 PM PDT, Moscone West 2020 Sleeper Cells in the Telecom Backbone: Covert Ops - Christiaan Beek, VP of Cyber Intelligence - March 26, 12:20 PM - 1:10 PM PDT, Moscone West 2018

Rapid7 enhances partner alignment in 2026

Rapid7, a pioneer in AI-powered managed cybersecurity operations, announced 2026 updates to its PACT Partner Program designed to strengthen alignment between Rapid7 and its partner ecosystem and accelerate scalable growth through the channel. Rapid7 has long believed that tight Go-to-Market (GTM) alignment with partners is essential to delivering customer outcomes. The 2026 program updates introduce new partner tier differentiation, simplified deal motions, and enhanced program economics to make it easier for partners and Rapid7 teams to engage customers together and deliver value faster. Enhanced program economics As demand for AI-integrated cybersecurity operations and outcome-driven cybersecurity solutions continues to grow, organisations increasingly rely on trusted partners to help implement and operationalise security programs. The 2026 PACT updates reinforce Rapid7’s commitment to building a highly aligned partner ecosystem, where shared engagement models, clear attribution, and predictable economics enable partners and Rapid7 teams to win together. “Partners are central to how we go to market,” said Suzanne Swanson, vice president of global channel partnerships at Rapid7. “Our focus is on building tight alignment across engagement models, economics, and execution so partners can grow with us and deliver meaningful outcomes for customers. The 2026 PACT updates make it simpler and more predictable for partners to build and scale their security practices with Rapid7.” Recurring security services The new PACT framework supports partners delivering MDR and other recurring security services where consistency and margin clarity are critical. Additional key updates to the program include: Platinum Partner Tier: Introduces a top-tier designation for strategic partners that consistently deliver outstanding performance, customer impact, and engagement. Updated Deal Motions: Aligns the program around two primary deal motions: Deal Registration for partner-sourced opportunities and Co-Sell for Rapid7-sourced opportunities. Earlier partner engagement and clearer attribution reduce ambiguity and simplify execution. Improved Program Economics: Offers more competitive partner economics for partner-sourced deals. Supported by simplified deal motions, product category alignment, and faster quoting, these enhancements deliver greater predictability and stronger margins. Tech Champion Program: Establishes a structured enablement and engagement framework for partner sales engineers, including early roadmap visibility and technical collaboration to strengthen alignment in complex MDR and exposure management opportunities. Exposure management opportunities Together, these updates reinforce Rapid7’s commitment to building a channel ecosystem defined by simplicity, accountability, and shared long-term growth. Saepio is one of Rapid7’s inaugural platinum partners. Paul Mullen, cybersecurity vendor manager at Saepio, commented: “Being recognised as a Rapid7 Platinum Partner is a milestone that reflects the strength of our partnership over the past 8-plus years. Our relationship with Rapid7 has always been built on more than business performance. It is grounded in a strong cultural alignment, a shared strategic direction, and mutual ambitions for continued growth.”

Rapid7 and ARMO strengthen cloud security partnership

Rapid7, Inc., a pioneer in threat detection and exposure management, announced a strategic partnership with ARMO, the creators of the open-source cloud-native security platform Kubescape and Cloud Application Detection & Response (CADR) innovator, to bring full cloud and application runtime security to the Rapid7 Command platform. This partnership marks the continued evolution of Rapid7’s industry-pioneer approach to exposure management. With added cloud runtime visibility augmenting the broad attack surface coverage provided by Rapid7 today, organisations can reduce risk earlier, operate more efficiently, and build true cyber resilience. Dynamic cloud environments Modern cloud attacks often exploit small, interconnected gaps across dynamic cloud environments. By adding continuous anomaly detection and real-time threat detection and response (D&R) across active cloud assets and workloads, this new offering gives security, development, and IT teams unified, threat-prioritised insight and faster response. “By extending our exposure management leadership with runtime from ARMO, we’re giving organisations clearer visibility, faster response, and better security outcomes,“ said Corey Thomas, CEO at Rapid7. “This is another important step in our commitment to delivering unified, open security with exposure context that enables security teams to move from reactive defense to preemptive response.” More precise response By bringing true CADR to the Rapid7 Command platform, Rapid7 now enables security teams to: Detect active threats in real time with live attack awareness from application-level to cloud-level threats, API attacks, data exfiltration, and container breakout attempts. Correlate runtime events with misconfigurations, vulnerabilities, and identity risks to provide a single view of risk and active attacks to unlock faster and more precise response. Respond instantly by isolating compromised workloads or terminating malicious processes to stop lateral movement. Seamlessly integrate detection and response workflows with existing AWS, Azure, and multicloud environments. Proactive exposure management “Our team built ARMO to bring the most advanced runtime-powered, open-source first, behavioural Cloud Runtime Security to every Kubernetes and cloud-native environment,” said Shauli Rozen, co-founder and CEO of ARMO. “Rapid7 shares that philosophy. By combining their breadth—across exposure management, detection and response, and cloud security—with our runtime security technology, we are delivering the most advanced cloud defence solution that is both modern and practical. Together, we’re helping organisations detect real attacks as they happen and protect the infrastructure their businesses rely on.” “As enterprises face increasingly fragmented and complex cloud threats, the need for full visibility across all cloud environments continues to be paramount. Rapid7’s partnership with ARMO helps to meet that market need by connecting the dots between proactive exposure management and real-time threat detection & response,” said Philip Bues, senior research manager, IDC Security and Trust. “This addition to Rapid7’s capabilities enables security teams to better correlate exposures with active threats and prioritise remediation based on operational risk, supporting both security objectives and business continuity.”

Insights & Opinions from thought leaders at Rapid7

Amid interesting times, Hikvision’s outlook remains upbeat in the USA

Despite any negativity you may hear, Hikvision is optimistic about their role in the U.S. market. “We demonstrate that we can be trusted, and that we should be trusted,” says Jeffrey He, Vice President, Hikvision, and President, Hikvision USA and Hikvision Canada. “We have sound products and technology. Our mission in the security industry is to protect, not to harm. Otherwise why would we be in this industry?” Hikvision is committed to investing in the North American market, where there was ‘positive year-over-year growth’ in 2018 and ‘strong’ sales in Q1 this year, according to Eric Chen, General Manager of Hikvision USA and Hikvision Canada. HikCentral central management software The company’s U.S. focus is shifting from products to solution sales, with emphasis on ‘mid-market’ small- and medium-sized businesses (SMBs). The largest verticals are retail and education, and there are emerging opportunities in the cannabis market. Launch of the HikCentral central management software (CMS) is a component of the company’s solution-sales approach. Launch of the HikCentral central management software is a component of the company’s solution-sales approachMr. He acknowledges the growth of ‘anti-China sentiment’ in the United States and other parts of the world, which he says will impact Hikvision’s operations globally. Specifically, in the U.S., ‘political’ elements impacting Hikvision’s business include ongoing tariffs and a trade war, Congressional calls for export controls and sanctions, and a provision of the National Defense Authorization Act (NDAA) that bans use of Chinese video surveillance products in government applications. Specifying cybersecurity initiatives at ISC West In spite of it all, Hikvision’s message at the recent ISC West show was overwhelmingly positive, and the company also detailed cybersecurity initiatives they say put the Chinese company ahead of many competitors in the industry. Eric Chen came in as General Manager last year; he previously spent a decade working for Hikvision in China. Chen reports solid 18.8% year-over-year growth for Hikvision globally, totalling $7.4 billion last year. He notes the company saw 40% compounded growth between 2010 and 2018. Globally, there are 34,000 employees, 16,000 of whom are research and development (R&D) engineers. Hikvision’s expanding global footprint includes 46 international branches. There are three manufacturing facilities in China, in addition to one in India. HikRewards program for HDP customers At ISC West, Hikvision’s theme was ‘Focus on Your Success’, including introduction of the HikRewards program that provides rebates to HDP (Hikvision Dealer Partner) customers, their core dealer base. A new online Hikvision Knowledge Library for HDPs provides training and reference materials dealers can share with employees. A new tech centre, introduced in December, provides data sheets, product information, and support resources. There is also a North American R&D team headquartered in Montreal. At the industry’s largest U.S. trade show, Hikvision unveiled a brand-new booth with plenty of open space and video walls A customer satisfaction survey launched in March provided good feedback from customers. “They know who to call if they have a problem,” says Chen. “We want to focus on making customers successful.” The success theme also extends to Hikvision employees, who are featured in videos describing their jobs and enthusiasm for Hikvision. There are some 400 employees in the North American operation. At the industry’s largest U.S. trade show, Hikvision unveiled a brand-new booth with plenty of open space and video walls. Half of the booth was focussed on solutions, especially retail and education, and also gaming and commercial real estate. Security products displayed at ISC West A variety of devices, including access control, intercoms and cameras, are integrated using the HikCentral CMS systemProduct highlights at the ISC West booth included the 32-megapixel PanoVu multi-sensor dome camera, whose 180-degree panoramic image was displayed on a 65-inch monitor. A variety of devices, including access control, intercoms and cameras, are integrated using the HikCentral CMS system. Some products new to the North American market, including intercoms, turnstiles, emergency call stations, and under-vehicle inspection, were displayed. Hikvision’s deep learning products are moving into their second generation, including the ability to obscure private information on videos to comply with GDPR/privacy requirements (previewed at ISC West and released later in the year). Algorithm components of Hikvision’s DeepInMind artificial intelligence are being adapted into a platform called AcuSense for value-priced products, which can recognise a human or vehicle and help filter out false alarms. Also being adapted to products with lower price points are the ColorVu system that incorporates visible light LEDs to provide colour images at night, and DarkFighter low-light capabilities. Penetration testing of cameras and NVRs As a global manufacturer, Hikvision faces a high level of scrutiny about cybersecurity, which Mr. Chen says is “a good thing for us,” enabling them to highlight the steps they are taking to improve cybersecurity. Chuck Davis, Director of Cybersecurity, outlined specific milestones Hikvision has achieved in its quest to provide world-class cybersecurity. Chuck Davis, Director of Cybersecurity, outlined specific milestones Hikvision has achieved in its quest to provide world-class cybersecurity In September 2017, Hikvision began working with third parties (including Rapid7) for penetration testing (ethical hacking) of its cameras and recorders. That same month, Hikvision set up a Cybersecurity Hotline open to anyone with questions about cybersecurity, including white-hat hackers and researchers. Even before that, Hikvision had an open-door policy on cybersecurity and a program for patching and disclosing responsibility. In February of 2018, Hikvision released a 40-page Cybersecurity White Paper describing cybersecurity testing and processes built into the software development lifecycle. That same month, Hikvision launched an Opened Source Code Transparency Center and offered an open invitation to anyone wanting to inspect Hikvision’s source code and let them know of any vulnerabilities. FIPS 140-2 certification by NIST Hikvision has also become a Common Vulnerabilities and Exposures (CVE) Numbering Authority (CNA), which ensures their patching and incident reporting programs have been reviewed by a CNA partnering company. Hikvision's encryption module (HIKSSL) received Level 1 FIPS 140-2 certification to be used in both IP cameras and NVRsIn August, Hikvision received Federal Information Processing Standard (FIPS) 140-2 certification, a U.S. government encryption standard created by the National Institute of Standards and Technology (NIST). Hikvision's encryption module (HIKSSL) received Level 1 FIPS 140-2 certification to be used in both IP cameras and NVR products. Davis said the FIPS 140-2 certification process began before the NDAA ban on use of Hikvision products in the U.S. government, and in any case is a standard that ensures a high level of encryption. “We wanted to make sure we had the same level of technology,” he says. “It was not to win over the government.” Making industry more cybersecure “We are really trying to have third parties test and certify our equipment,” adds Davis. “We are trying to be open and transparent. Education and awareness are key.” “We need the trust of customers in the security community,” says Mr. He. “No matter what, we have to follow the highest standards to offset the concerns and accusations.” In April 2018, Davis became a member of the Security Industry Association (SIA) Cybersecurity Advisory Board to help make the entire industry more cybersecure through education, awareness and standards. Hikvision has also joined the Forum of Incident Response and Security Teams (FIRST at first.org), a global cybersecurity incident response consortium that cooperatively handles computer security incidents and promotes incident prevention programs. Davis has presented Cybersecurity Road Shows in 22 cities in the United States and Canada, and also in Australia and New Zealand. The 90-minute presentations focus on education awareness around cybersecurity and seek to get attendees engaged and aware about cybersecurity in business and also in their homes.