Rapid7 reveals availability of Rapid7 Cyber GRC

Rapid7-expands-platform-with-governance,-risk-and-compliance-capabilities

Rapid7, Inc. has announced the availability of Rapid7 Cyber GRC, expanding the Rapid7 Command Platform with native governance, risk and compliance (GRC) capabilities.

According to the company, the new offering helps organisations continuously understand cyber-risk, validate control effectiveness and simplify compliance by connecting GRC workflows with live security operations data.

This shared data foundation gives security and compliance teams a unified, continuously updated view of control performance, active threats and organisational risk. 

With Rapid7 Cyber GRC, Rapid7 becomes the first major security operations platform to unify SecOps and GRC, extending its Preemptive Security strategy across risk, controls and compliance.

Cyber GRC

The company explained that by introducing Rapid7 Cyber GRC organisations can:

  • Continuously validate security controlsusing live platform telemetry to identify control deficiencies and drift between formal assessments
  • Automate audit readinessby collecting evidence and mapping controls across multiple compliance frameworks
  • Streamline third-party risk managementwith an AI Assessment Assistant that accelerates vendor questionnaires and reviews
  • Connect security action to measurable risk reductionby bringing active threats, exposures and findings into year-round compliance workflows

The Cyber GRC also uses AI-powered assistants for compliance workflows and third-party assessments.

These capabilities support policy management, third-party risk management, risk registers, audit-ready reporting and optional PCI Approved Scanning Vendor scanning.

“An active part of security operations”

Corey Thomas, Executive Chairman of Rapid7 stated: “Preemptive security goes beyond detecting and responding to threats.

“Organisations need to continuously understand where risk exists, whether controls are working and where action is needed before gaps become incidents.

“By bringing GRC into our platform, Rapid7 Cyber GRC connects what teams detect, what they fix and what they can prove, turning compliance from a point-in-time exercise into an active part of security operations,” Thomas concluded.

Suitability

Since launching Cyber GRC in early access in May 2026, Rapid7 said that it has advanced the offering through customer validation, commercial adoption and an expanding assurance partner ecosystem.

Early customers included GetWell Networks and SelectQuote Insurance Services, demonstrating demand among organisations seeking to connect security operations with continuous compliance.

“More accurate, timely and defensible risk reporting”

Bill Theissen, Managing Partner and Vice President of Consulting Services at Cyber Watch commented: “What excites me most about Rapid7 Cyber GRC is the ability to use the wealth of security data, asset inventories and API connectivity already available to us to produce more accurate, timely and defensible risk reporting.

“Just as important, the platform helps bridge the divide between security engineering and GRC teams through a shared view of risk and a common language for communicating it,” he added.

Partners

Rapid7 is also building an ecosystem of audit, assurance and GRC partners that extends continuous assurance beyond the platform.

Partners including HITRUST, Insight Assurance and 360 Advanced help organisations support certification and compliance programs across frameworks such as SOC 2, ISO 27001, HITRUST, CMMC and FedRAMP.

Black Hat USA 2026

Rapid7 highlighted that Cyber GRC is one of four platform innovations Rapid7 is showcasing at Black Hat USA 2026 as part of its broader Preemptive Security strategy, alongside:

  • AI-Accelerated Exposure Discovery & Visibility,which applies natural language querying and AI-generated summaries to help teams surface exposures faster, identify software risk across the full technology stack and communicate risk posture clearly to the business
  • Preemptive MDR Alerts, which surface high-confidence threats before they escalate into incidents
  • Agentic SOC, which applies AI agents to accelerate investigations and guide response while preserving analyst control over high-impact decisions

Together, these innovations extend Rapid7’s vision for Preemptive Security; helping organisations anticipate risk, continuously validate defences and disrupt attacks before they become incidents.

Attendees can experience live demonstrations and expert-led sessions at Rapid7 Booth #2445 in the Black Hat USA Business Hall, as well as at the company’s private space at Border Grill in Mandalay Bay.

Share this content

Latest Issue

Connect with us

Free digital subscription

Receive the latest breaking news straight to your inbox