Rapid7, Inc., a company specialising in AI-driven managed cybersecurity, has unveiled enhanced cloud security features within its Exposure Command product. These advancements include runtime validation and Data Security Posture Management (DSPM), offering organisations the ability to identify, confirm, and prioritise exploitable risks based on actual attack scenarios and their potential business impact.
As organisations adopt hybrid and multi-cloud systems, their security measures need to transition from reactive assessments to continuous validation. Rapid7's latest updates aim to facilitate this shift by moving from simply assessing security to proactively mitigating risks across diverse environments. Runtime validation identifies which vulnerabilities and misconfigurations can be actively exploited, while DSPM provides essential context by connecting sensitive data and identity access with real attack scenarios.
Addressing complex cloud risks
Craig Adams, Rapid7's Chief Product Officer, commented, "True cloud risk happens at the intersection of vulnerabilities, identities, and sensitive data in production. By embedding runtime validation and data context into Exposure Command, we enable security teams to identify the exposures that pose the greatest risk and prioritise remediation earlier, strengthening resilience before those risks translate into breach impact."
New Capabilities for Cloud Security
The latest capabilities within Rapid7’s Exposure Command include:
- Continuous runtime visibility: This feature enables the analysis of live cloud workloads, identifying which vulnerabilities and misconfigurations are currently exploitable. Using eBPF-based sensors and AI, the system correlates runtime signals with baseline attitudes and business context.
- Monitoring AI-driven workloads: The solution continuously observes AI agents in unpredictable cloud settings, moving past static vulnerability scoring to verify active exposures within AI workloads.
- Automated incident response: Upon threat identification and verification, automatic remediation actions are executed, such as pausing or isolating processes to control and neutralise potential threats.
- Data-aware risk prioritisation: By aligning sensitive data insight with attacker accessibility, the system continuously discovers and classifies sensitive data, mapping identity access across cloud, SaaS, and hybrid systems. This approach enables remediation prioritisation based on the potential impact of a breach rather than just vulnerability severity.
Advancing threat remediation
Combining runtime validation and DSPM elevates Exposure Command's capacity to pinpoint and prioritise exploitable risks, allowing organisations to detect and address active threats before they escalate into genuine dangers. Rapid7 will showcase these new capabilities, alongside recent innovations in their Managed Detection and Response (MDR) service, at the RSAC 2026 Conference in San Francisco, from March 23 to 26 at booth #S-3201.
The company will hold sessions addressing critical topics in cybersecurity, including "Exploiting Cellular IoT Pathways to Compromise Trusted Access," led by Principal Security Researcher Deral Heiland on March 24, and "Sleeper Cells in the Telecom Backbone: Covert Ops," presented by VP of Cyber Intelligence Christiaan Beek on March 26.
Rapid7, Inc., a pioneer in AI-powered managed cybersecurity operations, announced new cloud security capabilities within Exposure Command, its industry-pioneer exposure management solution. The introduction of runtime validation and Data Security Posture Management (DSPM) enables organisations to identify, validate, and prioritise exploitable risk based on real-world attack paths and business impact.
As organisations scale hybrid and multi-cloud environments, security programs must move beyond reactive models built on assessment alone. With runtime validation and DSPM, Rapid7 advances Exposure Command from continuous assessment to continuous validation, enabling proactive exposure reduction across hybrid environments. Runtime validation determines which vulnerabilities and misconfigurations are actively exploitable, while DSPM provides critical context by mapping sensitive data and identity access to real-world attack paths that increase risk.
Unpredictable cloud environments
“True cloud risk happens at the intersection of vulnerabilities, identities, and sensitive data in production,” said Craig Adams, chief product officer at Rapid7. “By embedding runtime validation and data context into Exposure Command, we enable security teams to identify the exposures that pose the greatest risk and prioritise remediation earlier, strengthening resilience before those risks translate into breach impact.”
Rapid7’s new cloud security capabilities in Exposure Command include:
- Continuous visibility at runtime: Analyse live cloud workloads and validate which vulnerabilities and misconfigurations are actively exploitable. Leveraging eBPF-based sensors and AI-to-baseline application behaviour, the solution correlates runtime signals with posture findings and business context.
- Continuous monitoring of AI-driven workloads: Detect and neutralise deviations in highly complex, unpredictable cloud environments by continuously monitoring AI agents. Going beyond static vulnerability scoring, this validates which exposures are active across AI workloads.
- Automated cloud incident response: Initiate automated remediation actions once a threat is detected and validated. Steps include pausing, quarantining, or killing processes to neutralise and reduce the blast radius of any attack.
- Data aware risk prioritisation: Align sensitive data intelligence with attacker reachability to continuously discover and classify sensitive data and map identity access across cloud, SaaS, and hybrid environments. This shows whether high-value data is realistically reachable through real-world attack paths, enabling remediation decisions based on breach impact rather than vulnerability severity alone.
Remediate active exposures
Together, runtime validation and DSPM enhance Exposure Command’s ability to identify and prioritise exploitable risk, enabling organisations to continuously detect and remediate active exposures before they become legitimate threats.
Rapid7 will be demonstrating the new cloud security capabilities, recent innovations in our Managed Detection and Response (MDR) service, and the full capabilities of Exposure Command live at the RSAC 2026 Conference in San Francisco, March 23-26, booth #S-3201.
Rapid7 will also present the following sessions at the conference:
- Exploiting Cellular IoT Pathways to Compromise Trusted Access -Deral Heiland, Principal Security Researcher, IoT - March 24, 1:15 PM - 2:05 PM PDT, Moscone West 2020
- Sleeper Cells in the Telecom Backbone: Covert Ops - Christiaan Beek, VP of Cyber Intelligence - March 26, 12:20 PM - 1:10 PM PDT, Moscone West 2018