SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
United States
Rapid7 launches Cyber GRC to unite security & compliance

Rapid7 launches Cyber GRC to unite security & compliance

Tue, 28th Jul 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Rapid7 has launched Cyber GRC within its Command Platform, saying it is the first major security operations platform to combine security operations with governance, risk and compliance.

The new offering adds native governance, risk and compliance functions to Rapid7's platform and links those workflows with live security operations data. The goal is to give security and compliance teams a single view of control performance, threats and broader organisational risk.

The move addresses a long-standing divide between security operations teams and governance functions, which often work in separate systems. That separation can leave companies piecing together security findings, compliance evidence and business risk from different tools at different points in time.

Cyber GRC is designed to let organisations validate security controls continuously using platform telemetry, rather than relying only on periodic assessments. It also includes tools for audit preparation, control mapping across compliance frameworks, third-party risk management and reporting.

Artificial intelligence features are part of the product, including an assessment assistant for vendor questionnaires and reviews. The service also supports policy management, risk registers and an optional PCI Approved Scanning Vendor scanning function.

Platform shift

The launch expands Rapid7's broader push to bring more of cyber risk management into one platform. By connecting governance workflows to live security telemetry, it aims to make compliance part of day-to-day security operations rather than a separate exercise.

Corey Thomas outlined that position in comments accompanying the launch. "Preemptive security goes beyond detecting and responding to threats. Organisations need to continuously understand where risk exists, whether controls are working, and where action is needed before gaps become incidents," said Corey Thomas, Executive Chairman, Rapid7.

He added: "By bringing GRC into our platform, Rapid7 Cyber GRC connects what teams detect, what they fix, and what they can prove, turning compliance from a point-in-time exercise into an active part of security operations."

Rapid7 said the product was available to a limited group of users before its general release and was further developed through customer feedback and early commercial use. Early customers named by Rapid7 include GetWell Networks and SelectQuote Insurance Services.

Partner network

Rapid7 is also building a network of audit, assurance and GRC partners around the product. Those partners include HITRUST, Insight Assurance and 360 Advanced, which can support certification and compliance work across frameworks including SOC 2, ISO 27001, HITRUST, CMMC and FedRAMP.

That partner model reflects a wider market trend in cyber compliance, as software vendors seek to tie technology platforms more closely to assurance and audit processes. For customers, the appeal is often the prospect of using operational security data as evidence for compliance work instead of collecting it manually from separate systems.

One adviser involved with the product said access to existing security data was a key part of the appeal. "What excites me most about Rapid7 Cyber GRC is the ability to use the wealth of security data, asset inventories, and API connectivity already available to us to produce more accurate, timely, and defensible risk reporting," said Bill Theissen, Managing Partner and Vice President of Consulting Services, Cyber Watch.

He added: "Just as important, the platform helps bridge the divide between security engineering and GRC teams through a shared view of risk and a common language for communicating it."

Cyber GRC arrives as companies face growing pressure to show not only that controls are defined on paper, but that they are working in practice across changing technology estates. The challenge has become more acute as compliance requirements multiply and security teams are asked to report risk in ways senior executives and boards can understand.

Rapid7's latest release is intended to meet that demand by making control evidence, risk reporting and security findings part of the same workflow. The result, according to Rapid7, is a continuously updated view of control effectiveness, active threats and organisational risk.