decryptingtech

Technology. Business models. Market debates.

Browse this section

Rapid7

Rapid7 is best understood as two businesses that grew from a single idea and are now being separated by force. The idea was that finding weaknesses and responding to attacks are the same discipline, and that a company which understood how software is exploited could sell both the search and the defence. For fifteen years that held. Today the company carries $824m of annual recurring revenue, of which a shrinking fifth is falling fast enough to drag the whole into decline, and a new chief executive is narrowing the portfolio to the two categories where a defensible position still exists. The investment case rests on whether a business that reached a ceiling can be cut back to the parts that still grow before its balance sheet flexibility is spent. If it succeeds, the result is a focused, cash-generative security platform with a genuine service moat trading at a fraction of the multiple its peers command. If it fails, the narrowing continues until what remains is a well-run services business with no growth and no cushion.

The franchise

Rapid7 was founded in Boston in 2000 around Nexpose, a vulnerability scanner. Its defining move came in 2009 with the acquisition of Metasploit, the open-source exploitation framework used by penetration testers and attackers alike. Rapid7 still stewards it. The commercial value is partly reputational, since owning the tool the security community uses buys credibility that marketing cannot, but the deeper value is intellectual. Metasploit taught the company the difference between a vulnerability that exists and a vulnerability that can actually be exploited, and that distinction is the thread running through everything Rapid7 has built since.

The company listed in 2015 and expanded from scanning into detection, response and a managed service. The resulting franchise is unusual in scaled cybersecurity because it is shaped around the middle of the market rather than the top. Rapid7 serves roughly 11,500 customers at an average of about $70,000 of annual recurring revenue each. Palo Alto Networks and CrowdStrike are built on far larger contracts with far larger organisations. Rapid7 sells to companies that have a security problem, a real budget, and nothing like the staff required to run a modern security programme.

That position is genuine rather than a consolation. A mid-sized company cannot staff a security operations centre; continuous monitoring requires eight to ten analysts before holiday cover is considered, which is out of reach for most organisations below a few thousand employees. Selling those companies an outcome rather than a tool is a durable proposition, and it is the reason the detection and response half of Rapid7 still grows.

The limitation is the same fact viewed from the other side. Mid-market budgets are smaller, more price-sensitive and more exposed to bundled alternatives arriving inside licences the customer already owns. There is no natural ladder from a $70,000 contract to an eight-figure enterprise agreement. Management argues that mid-market leadership demonstrates strength rather than marking a ceiling. That assertion is precisely what the last three years of numbers have been contesting.

Business model

Revenue is recurring and subscription-based, delivered through the cloud-native Insight platform, with a managed service layered on top. Customers subscribe by module, and expansion comes from adding products and coverage rather than from hardware refresh. Full-year 2026 revenue is guided to $837m to $841m with free cash flow of approximately $130m.

The critical structural point is that Rapid7 is not a pure software company. Managed detection and response is delivered by people, and people scale with customer count. Non-GAAP gross margin was 71.7% in the June quarter, down 215 basis points year on year, with the decline attributed to security operations centre staffing and cloud consumption. Scaled software peers run materially higher. This is not a failure of execution; it is the cost of the model, and it explains why automation is a financial question for Rapid7 rather than only a competitive one. Every analyst hour removed converts directly into gross margin.

Since August the company reports itself in two parts. Core Platform Solutions, comprising detection and response and exposure management, represent over 80% of ARR and grew approximately 1% year on year. Everything else, under 20% of ARR, is declining. That single split is the whole of the financial story: the core is roughly flat, the tail is falling, and total ARR contracted 2.0% in the June quarter as a result.

Exposure management: the founding category

Vulnerability management is the discipline of enumerating every asset an organisation runs, identifying the known software flaws present on each, and deciding which to fix first. It is unglamorous and mandatory, driven as much by audit and insurance requirements as by security teams themselves.

The category’s problem is volume. A large estate generates tens of thousands of findings, the overwhelming majority of which no attacker could realistically reach. Simply listing them transfers the work to the customer. The category has therefore evolved from enumeration to prioritisation and, more recently, to validation: establishing not merely that a flaw exists but that an attacker could actually get to it from the outside and reach something worth taking.

This is where Rapid7 has aimed. Exposure Command, the successor to InsightVM, adds attack-path analysis, cloud coverage, data security posture management to identify where sensitive data lives and who can access it, and attack validation to determine what is genuinely reachable in production. Management reports healthy adoption, driven both by new customers and by migration from the older vulnerability management base.

Nonetheless the segment is shrinking, and it is shrinking inside the part of the business management calls core. That is the single most important fact in the Rapid7 debate, because it is the one that does not fit the story being told. The competitive explanation is uncomfortable: scanning is being absorbed by vendors whose agents are already installed on every endpoint and who can therefore add the capability at close to zero marginal cost, while newer entrants price the enumeration layer towards nothing. Value is migrating to prioritisation and remediation, which is where Rapid7 says it intends to compete, but it has not yet arrived there in the numbers.

Detection and response: selling the outcome

Detection and response is roughly 55% of total ARR and grew approximately 5% year on year, making it the growing half of the company and the larger one. It combines InsightIDR, which collects and correlates security telemetry across endpoints, network, cloud and identity, with managed detection and response, in which Rapid7 analysts operate that platform on the customer’s behalf around the clock.

The proposition is straightforward. Rather than buying detection software and then hiring the team to run it, the customer buys the monitoring itself, delivered by people who watch thousands of environments and therefore see attack patterns before any single organisation would. For the mid-market this is not a convenience but the only realistic route to continuous coverage.

The differentiator management leans on hardest is vendor neutrality. Rapid7 monitors whatever endpoint, network, cloud and identity telemetry the customer already owns, and has no agent of its own to defend. Competitors moving into managed detection from an endpoint position cannot make the same offer without undermining the product they are really selling. Management’s argument that endpoint vendors entering this market lack the right to win is self-serving, but it identifies a real conflict, and vendor neutrality is a structural advantage rather than a feature, because copying it would require a competitor to devalue its own installed base.

The constraint is that growth consumes analysts. Unless automation absorbs alert volume faster than customers are added, expansion compresses gross margin. That is the financial problem the company’s AI investment is meant to solve.

The non-core portfolio: what is being wound down

Under 20% of ARR sits in products assembled over twenty-five years: application security testing, cloud security posture management, and security orchestration and automation, alongside older standalone tools. Each competes against a well-funded specialist that treats it as a primary business rather than a secondary one.

Management has stopped defending this portfolio. The stated position is that Rapid7 will not chase categories where the outcome has already been decided by pure plays, and will instead concentrate investment where it holds a leading position. Customers on non-core products will continue to be supported, some will be migrated into the core platform, and the remainder will be managed for margin.

The arithmetic consequence should be stated plainly, because the company does not state it directly. This tail is the entire source of the ARR decline. Core grew about 1%; total fell 2.0%. Total ARR will therefore keep declining until the shrinking portion becomes small enough that its contraction no longer outweighs modest core growth. This is a controlled run-off, and it takes several quarters by construction.

AI: the Kenzo bet and the margin question

Rapid7 acquired Kenzo Security in the March 2026 quarter, an agentic platform designed to run security operations autonomously. Its significance is architectural rather than promotional. Kenzo supplies a common data layer intended to move investigation away from a per-alert model, in which each alert consumes analyst time, towards a system-driven one in which coverage scales with the environment rather than with headcount.

For most security vendors an agentic strategy is a competitive story. For Rapid7 it is also a margin story, and that distinction matters. In a business where over half of ARR is delivered by people, automation that removes analyst hours flows straight to gross margin, which is why gross margin is the cleanest available read on whether the AI investment is producing anything real. Management has been explicit that the objective is to deliver services at scale with software-like economics.

The stated design principle is that the platform sits over the tools customers already run rather than requiring replacement, which is consistent with the vendor-neutral positioning, and that agents extend the reach of human analysts rather than substituting for their judgement. Management’s framing is that people decide and agents act.

The scepticism is warranted on scale rather than intent. Every scaled security vendor is now describing an autonomous security operations centre, and Rapid7 is pursuing one with the smallest research and development budget among them, while simultaneously removing 12% of its workforce and promising to reinvest part of the savings into the same product organisation. Both commitments cannot be met in full.

The moat

Rapid7’s moat is the managed service relationship rather than any individual product. A customer that has handed continuous monitoring to a provider has also handed over knowledge of its environment, tuned alerting thresholds, escalation paths and jointly written response procedures. Replacing that is not comparable to cancelling a software subscription; it means rebuilding operational muscle memory while remaining exposed throughout. Service relationships of this kind churn less than licences.

Vendor neutrality reinforces it, for the reason given above. The research organisation and continued stewardship of Metasploit supply threat intelligence and standing with practitioners that competitors cannot buy quickly. Twenty-five years of scanning has also produced deep familiarity with how enterprise estates are actually assembled, which matters in a market where most environments are hybrid and untidy.

The limits are severe and should not be understated. Rapid7 owns no control point. It does not own the endpoint agent, the network path, the identity provider or the cloud platform, which means the telemetry its competitors receive as a by-product of their core product must be obtained through integration. Palo Alto Networks sits in the network, CrowdStrike sits on the endpoint and Microsoft sits across identity and productivity; each generates its data for free. Rapid7 negotiates for the same data. Scale compounds the problem, since $824m of ARR funds a research budget an order of magnitude below the largest platform competitors, and in security that gap widens rather than closes.

Competitive landscape

Rapid7 competes on two fronts at once, against exposure management specialists in the category it helped create and against far larger platforms in detection and response. The contest is not decided by feature lists. It turns on whether a mid-sized organisation would rather buy security as an outcome from an independent provider or accept adequate coverage bundled inside something it already owns.

CompetitorWhere it is strongestRapid7 advantageRapid7 vulnerability
TenablePure-play exposure management with the largest vulnerability management installed basePairs exposure with a delivered response service that Tenable does not offerTenable grew revenue 8.6% in the June quarter while Rapid7 declined 1.5% in the same category
QualysCloud-native scanning at scale, strong compliance franchise and high marginsDetection and response provides a second engine that Qualys lacks entirelyQualys converts the same category into materially higher margins and cash generation
CrowdStrikeEndpoint control point, telemetry, brand and balance sheetVendor neutrality: monitors whatever the customer already runsCan attach exposure management to an agent already deployed, at close to zero marginal cost
MicrosoftIdentity, endpoint, cloud and enterprise licence bundlingIndependent multi-vendor coverage and a genuine human service layerDefender arrives inside a licence the customer has already paid for
Arctic Wolf and MDR specialistsFocused service delivery aimed squarely at the mid-marketOwns its own platform rather than operating someone else productsService-only rivals compete on price without carrying platform research costs
Palo Alto NetworksBreadth across network, cloud, security operations and identitySimpler to buy and operate for a team without a large security functionConsolidation pressure squeezes smaller vendors out of budget cycles entirely
Competitive landscape

CrowdStrike and Microsoft represent the structural threat rather than the immediate one. Neither needs to build a better exposure management product; each needs only to make an adequate one available where the customer is already spending. This is the dynamic that has compressed the value of the scanning layer across the whole category, and it is why Rapid7’s stated intention to compete on remediation and outcomes rather than enumeration is the correct strategy even though it has not yet worked.

Against managed detection specialists the position is more comfortable. Rapid7 owns the platform it operates, which service-led competitors do not, and that supports both margin and product control. Management has noted endpoint vendors moving sideways into managed detection because budget and activity sit there, and has argued they lack the neutrality to win. The argument is sound; whether it survives aggressive bundling is a different question.

The investment debate

The starting point is the valuation. At roughly $11 a share, a market capitalisation near $772m and an enterprise value around $970m, the market values $824m of recurring revenue at about 1.2 times. The equity is worth less than the gross debt sitting above it. That is a multiple applied to businesses in run-off, and it is not obviously wrong: ARR growth ran 19% in 2022, 13% in 2023, 4% in 2024, approximately flat in 2025, then minus 0.6% in March and minus 2.0% in June, with September guided to roughly minus 3%.

Against that, the June quarter was operationally strong. Revenue was $210.9m, non-GAAP operating income $28.9m at a 13.7% margin, earnings of $0.44 a share against a consensus near $0.35, and free cash flow $31.9m. Full-year operating income guidance was raised to $129m to $133m, implying a fourth-quarter exit margin of approximately 20%. The shares rose 27%.

Leadership changed first. Wael Mohamed, previously chief executive of Forescout, joined the board through the settlement with JANA Partners and became chief executive on 1 June 2026, with Corey Thomas moving to executive chairman. A new chief financial officer, chief commercial officer and chief product and technology officer were appointed over the preceding year. On 7 August the company cut 12% of its workforce, at a cash cost of $10m to $11m, having cut 18% in 2023.

The balance sheet is the constraint that gives the debate its deadline. $598.2m of convertible notes mature on 15 March 2027 and now sit in current liabilities, against $702.6m of cash and short-term investments and an undrawn $200m revolver. Repayment is not in question and the conversion price is far above the share price. What repayment does is remove the largest asset on the balance sheet, eliminate the interest income earned on it, and leave a company generating around $130m of annual cash with no cushion, no acquisition currency and no growth.

The constructive case does not require ARR to grow. It requires the decline to stop mattering. Over 80% of ARR sits in two categories that are themselves expanding, the larger and faster-growing half holds a differentiator competitors cannot copy without self-harm, and the declining tail cannot fall below zero. At a 20% operating margin on an $830m revenue base the company earns roughly $165m of operating income and comfortably more than $150m of free cash flow against a $772m market capitalisation. No re-rating is required for that to be a good outcome; the cash simply has to keep arriving. JANA holds 10.3% at an average cost near $30 a share, and an activist carrying a four-fifths loss is not a patient holder. Reports of private equity interest from Advent, Bain and EQT date from October 2024 and no live process is known, but the shape of the asset has only become more attractive since.

The bearish case is that the core is not stable, merely more slowly unstable. Core Platform Solutions grew about 1% only because detection and response offset an exposure management business that is shrinking, and exposure management is half the reason to own the company. The cost lever is finite: a second large reduction follows an 18% cut three years ago, while savings are simultaneously promised to product investment. A services business that under-invests in its security operations centre degrades the product customers are actually buying, and churn in detection and response would be far more damaging than the non-core run-off because it represents 55% of ARR rather than under 20%.

The question that decides the outcome is therefore narrow. Does exposure management stabilise before the balance sheet flexibility is spent? After March 2027 there is no second restructuring lever of comparable size, no net cash and no currency for acquisitions. If exposure management returns to growth during 2027, the result is a cheap, cash-generative platform with a credible operator and a motivated shareholder. If it does not, the company will have converted its balance sheet into a debt repayment and its growth into margin, and what remains is a shrinking services business at a fair price.

What to watch

Sequential core ARR is the disclosure that matters most. Management guided the combined detection and response and exposure management businesses to be approximately flat quarter on quarter in September. If that turns negative, the argument that only the non-core portfolio is declining fails, and it fails in public.

Beyond that: whether the fourth-quarter 20% operating margin is delivered without a revenue shortfall; whether 2027 free cash flow is guided above the $130m expected for 2026, as management has implied it will be; whether gross margin stabilises or resumes its decline, since it is the most direct evidence of whether automation is genuinely reducing the analyst cost of serving a customer; whether Kenzo produces a shipped capability that wins competitive evaluations rather than a roadmap slide; and whether win rates in exposure management improve, which management has identified as its own measure of progress.

Ownership is worth tracking alongside the operations. The board settled with JANA in March 2026 without any commitment to a sale, and appointing an operator rather than a banker indicates an intention to fix the business rather than sell it. Whether JANA adds, holds or exits will say more about the likely endpoint than any management commentary, and if that position changes it will change quickly.

Bottom line

Rapid7 is not a broken company. It is a company that stopped growing and is being repriced accordingly. The diagnosis offered by its own chief executive, that the business reached a ceiling rather than failed, is unusually honest for a first earnings call, and the actions since match it: narrow the portfolio, remove the cost, fund the two categories where a defensible position exists, and ask to be measured on cash while the product work runs. Seventy days is enough to set direction and not enough to prove it.

The valuation already assumes the attempt fails. That is simultaneously the argument for owning the shares and the reason for caution, because at 1.2 times ARR the market is not pricing modest disappointment but continued decline. The evidence that settles the question is not the margin guidance, which management largely controls, but four consecutive quarters of core ARR, which it does not.