Rapid7 has expanded its Command Platform with the general availability of Rapid7 Cyber GRC, a governance, risk and compliance solution designed to unify security operations and compliance management under a single platform.
Rapid7 Cyber GRC connects governance workflows directly to live security telemetry, enabling organisations to continuously assess cyber risk, validate security controls and automate compliance activities.
The platform is designed to address a long-standing challenge for organisations, where security operations and compliance teams often rely on separate tools.
Executive chairman Corey Thomas said organisations need continuous visibility into risk rather than relying on periodic compliance exercises.
“Pre-emptive security goes beyond detecting and responding to threats. Organisations need to continuously understand where risk exists, whether controls are working and where action is needed before gaps become incidents,” Thomas said in a 29 July statement.
“By bringing GRC into our platform, Rapid7 Cyber GRC connects what teams detect, what they fix and what they can prove, turning compliance from a point-in-time exercise into an active part of security operations.”
The platform includes AI-powered assistants for compliance workflows and third-party risk assessments, along with capabilities for policy management, risk registers, audit reporting and automated evidence collection across multiple compliance frameworks. It also features an AI Assessment Assistant to streamline vendor security questionnaires and reviews.
Rapid7 said the product has been refined since entering early access in May, with customers including GetWell Network and SelectQuote Insurance Services helping validate the platform.
Bill Theissen, managing partner and vice-president of consulting services at Cyber Watch, said integrating security telemetry with governance data would improve both reporting and collaboration.
“What excites me most about Rapid7 Cyber GRC is the ability to use the wealth of security data, asset inventories and API connectivity already available to us to produce more accurate, timely and defensible risk reporting,” Theissen said.
Rapid7 is also building a partner ecosystem supporting compliance programs such as SOC 2, ISO 27001, HITRUST, CMMC, and FedRAMP.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.
David Hollingworth
David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.