Hello, everyone, and thank you for joining us for our growth stock conference and today's session with Rapid7. My name is Jonathan Ho, and I'm the analyst covering Rapid7 for William Blair. Rapid7 has certainly gone through some significant leadership changes in the past 24 hours, so we're pleased to have with us the newly appointed CEO, Wael Mohamed, Executive Chairman, Corey Thomas, and CFO, Rafe Brown, who will provide an overview presentation for the company, followed by a fireside chat. Before we begin, I'm required to inform you that a complete list of research disclosures or conflicts of interest is available at our website at www.williamblair.com. As a quick reminder, the breakout session will be in the Burnham A room following the presentation. With that, I'll hand it over to Wael, Corey, and Rafe. Thank you. Great. Thank you so much. Thank you, Jonathan. Thank you all for joining us here today. Before we got started on the Q&A with both Jonathan and with you all, we thought we'd just give you a little bit of overview of the business that we're in, how we approach it, and what we do. We're in the security operations space. Security operations's primary focus of how do you actually make sure the organization does not have unnecessary exposures, vulnerabilities, and weakness that make them easily susceptible to attackers. If attackers do get in, how do you find them, shut them down, and stop them as quickly as possible? This market has actually undergone a lot of changes over the last five years in of itself. It used to be a market that was categorized by people using tools and managing, quite frankly, a small part of the environment. As cybersecurity got more serious, people started really advancing the tools and the technologies they were using, expanding their resources and investment. Frankly, as they were trying to tackle the problems, they actually started partnering with managed services providers, MDR providers, to manage their entire swath of their security operations and exposures. Rapid7 was a major player, first in the tools market. We led the transformation in the MDR shift, where people actually partner with us to actively manage their environment and to take some of the risk management operations off their plate. Even today, by and large, the pace of change is insurmountable. I'm sure we'll talk about AI and a bunch of stuff a little bit later on, but if you look at the biggest factors that has happened is that, one, people are adopting technology at an even faster rate. The rate of vulnerabilities and exposures from AI, accelerated exploits and vulnerabilities is increasing at an incredibly fast rate. The time that attackers are in environments, called the dwell time in the industry, it's just like how fast are people getting in and doing damage, is compressing, and so the need to respond faster is a bigger deal than ever before. When you think about what that means for the overall cybersecurity industry, people have to cover more of their environment faster, cheaper, and more effectively. What we've actually are moving towards and what we're pioneering is the autonomous SOC. The core idea around an autonomous SOC is that you use technology to provide scale and cost efficacy. It's not just technology, it's also the people and the tools that tailor the technology, the tools, the AI resources to a customer's environment, so ensuring it matches their risk profile, the skill and maturity of their cybersecurity operations, and is tuned in a way that allows them to respond as quickly as possible. This combination of AI technology and the people that tailor it to customers' environments will be the model that people use to actually manage and scale their security operations cost effectively over time, and we're pioneering that space. If you look at the core of our business today, our leading segment and our highest growth segment, which is we're still unlocking the TAM around that, is around the MDR and its shift to a agentic MDR. The way to think about that is that we're applying agentic technologies. We recently made an acquisition called Kenzo that allows us to actually process more data, more scale for our customers, and then allow them to actually monitor more of their environment at scale. We're going to do the same thing with risk and exposures. We're going to do the same thing with compliance. We're going to do the same thing with third-party risk over time. Then there's some interesting areas about how we enable people to respond that will be a long-term and do a differentiator. That's the opening sort of view and lens overall. Excellent. Thank you for that. I think we definitely have to kind of start with the elephant in the room, so thank you for joining us, Wael, and also Corey, to come by and sort of give us an overview of what's been happening and changes within Rapid7. Maybe first, can you help us understand the strategic rationale and the timing to make the change in leadership at Rapid7 right now? Yeah. You want. Sure. Absolutely. No, go ahead. No problem. I did start yesterday, but actually the journey started a long time ago. I joined the board a year ago, where Corey and I sat down and tried to talk about how can we reimagine our company in this new era of AI. Our industry has been using machine learning and machines for many, many years, and we actually have done a very, very good job across many functions. We're in a place where we're going to have to reimagine how machines and humans are going to be working together in a space where we're designed to protect against bad people. Now we need to be able to figure out bad people, bad states, as well as bad machines at a scale that we have never experienced before. In this journey, when Corey and I sat down and tried to basically say, "Okay, what do we need to do? What core competency we need to be able to bring to the company, and what type of skill set we need to be able to bring in, and what's going to break?" I believe the number one thing in our industry, some of the definitions will actually be broken. It will be redefined. We came in a world known and unknown, zero-day. How can you actually say zero-day when we know that it's probably 6 months in the known world that has not really surfaced yet? Maybe the bad guys already know about it. How you deal with a world where now you got the speed, the accuracy, the scale, not only on your offensive side, but actually on the defensive side. How can you simulate that? Taking all the tools that Corey's talking about it and know that now the bad guys already have the same tools, and maybe even at a higher scale. They have access to resources more than you do. I have not met a customer in the last couple of years who did not tell me, "We want to use AI very fast." Our problem is what is going to break in the process, and what can you do to make sure that we take a full advantage of it, but we do not lose what we have built over the years? There is a lot of institutional memory that we have built, processes, requirements, reporting, compliance, many, many intertwined things inside the organization. One of the things that Corey talked about, the autonomous SOC, is designed from the ground up to be the operating layer that sits between both. It will allow you to have your cake and eat it too, it allow you to be able to use all these new models that it can actually work on a light speed, but without breaking all the processes that you have built over time. Although I started yesterday, I actually started a year ago working with Corey and the team, and we've been doing a lot of stuff in the background, preparing our organization to be ready for what's going to happen tomorrow, which is, I believe, is exciting and a little bit scary because there is a lot of unknown things we're going to have to be prepared for. I think we're ready. Absolutely. As far as the timing goes is that Wael had been one of my counselors on the board who was thinking about not just what we wanted to build, but how do we operationalize it. It's clear that we're in a cusp moment of we know the technology's possible. We have a bunch of key releases that are coming out over the next nine months. We really shifted the focus to think about, okay, how do we make sure that the organization operates efficiently to execute against that? As that got closer and closer, I found myself going to Wael more and more for advice about how to operationally make sure that we were ready to go at the speed and pace, and efficiency that we needed to go at. Then it became natural at a point in time where it's like, "Hey, you have a clear line of sight on how to think about that. How about you come on board and do that full time. Yeah. As an ex technology guy myself, it's a lot more fun to be able to play with the product a lot less to deal with the management side, especially with Corey. We've known each other since you started at the company. Exactly. I've really enjoyed working with you as well, and continue to look forward to those conversations. Yeah, likewise. Wael we're not going to put you on the spot, just given you've been here for 24 hours in terms of the strategic vision, we'll give you a few days to figure that out. We'll go on to the bigger picture and hopefully, we'll be able to make some great memories as well as Rapid7 evolves in its story. Thank you, Jonathan. One thing I wanted to maybe understand a little bit more about is, the other elephant in the room is Mythos, right? Yeah. There's been broad discussion about how this is impacting both your customers as well as Rapid7. Can you talk about what customers are coming to you to solve when it comes to Mythos and for Rapid7? We can do one, two here. Go ahead. Yeah, go ahead. You want to. Yeah. I can start. For me, Mythos is a great prototype to show us what's possible, and I think they've done a fantastic job. I think it's just scratching the surface. I think there is way more we can be able to do with those type of models and that type of approach. I think what's really proven to the customer side that there is a lot can be accomplished at an incredible speed. There's some part what the industry used to do is going to become a commodity. It's going to be faster, at a scale, at a high level of accuracy. We always suffered in an industry where how are we going to strike the balance between false positive and false negative? How are we not going to overwhelm our operations, and how we can be able to set the right priorities. Mythos basically showed that, you know what? We already know that in every 1,000 line of code, there is a bug. We know that. We know that for 30 years. You know what I mean? We're hopeful that they are not going to be exposed, and when they are actually discovered, that it's not exploitable. Mythos basically proven that you can accelerate and short-circuit that cycle extremely fast. There is all kind of other things we can be able to add to the table, is the remediation side, or we call it internally the reasoning side. That's where now the expert and the machine can do some really, really cool things. That's what we're excited about. We're excited that that same technology that's going to put tremendous pressure on our industry in the short term, it will become an enabler to allow us to do things we could not do in the past. The thing I would add to that is that, one, it has reinvigorated customers' interest in understanding how to manage their exposure and threat environment. That's very clear. As part of that, one, they want to know what it is. For reference, I think Anthropic has expanded their coverage. We have access to it, both that, the OpenAI. They want to understand it first. The second thing is that for those that understand it, they have a couple of takeaways. One, they're finding a significant higher level of vulnerabilities in the environment. It's how do you actually help me deal and manage this increased risk exposure surface. Luckily, our big focus on exposure management on, one, understanding exploitability, two, orchestrating for remediation, has been warmly received. We view this as a net positive for our exposure management business, which needs to re-accelerate. The last thing is, Wael hit it. People know that the operational window to respond is shrinking. They're looking for a partner to actually help them navigate that, and that's something that we're heavily invested in. That makes a ton of sense. I think there's a lot of consternation out there from customers as these model gains and capabilities start to materialize. One thing I wanted to understand is how quickly can those conversations maybe turn into revenue opportunities, and has it changed the narrative around prioritization of some of the traditional exposure management out there? One, it went from a back burner conversation to a conversation where every CISO is actively engaged in it. Frankly, boards are being invigorated. It was dwindling in focus, to be clear, where you had AI security. The core agentic SOC has always been on the list. It is now back on the agenda. The question is, how fast does that turn to ARR and purchases? Look, we're a couple of months in, and so it's too early to actually comment on that. If you look at the customer interest in starting to plan for organize and look at how they're going to actually manage this larger backlog and volume of issues, right now my expectation is that that will translate into real market opportunity. The timing and whether these are shorter sales cycles or everything else, it's just too early to actually call the ball on that. Makes sense. It takes a while for these budgets to formulate and for people to understand what the actions they want to take. Certainly, we're seeing that pressure start to build as Mythic shortens the timeframe for people to have to react, I think. Keep in mind, just very few people have access to it today, too. It'll be interesting because right now, again, it's been tightly distributed. By the way, it's not the only one. We're talking about Mythic, but it's actually, I think you're at three or four now that are approaching the capabilities. It might not be at the same capabilities, but they're approaching it. Yeah. With MoE, they all sort of converge. Exactly with the large model trained models. Exactly. We have Vera Rubin following that. Exactly. We're not done here, and it will be a brave new world once those models become available to the threat actors. You've talked about some declines in the business stabilizing, and one thing I wanted to understand a little bit better is maybe what gives you the confidence, Rafe, in terms of seeing that stabilize and maybe that the worst is over now when it comes to these challenges? Sure. One of the things we did this last quarter is provide a little bit more clarity into the business, right? For what we really tried to take everyone through is to help people see how the performance of our core platform offerings versus some non-core, which are non-platform, standalone offerings that are Because there's very different stories. Frankly, what you're hearing from Wael and Corey is all about where we're investing, and that's in our core offerings. Our core offerings, our D&R solution, our exposure management solutions, and that constitutes over 80% of our business. D&R, we've seen it continue to grow. We called out on the last quarter, it was growing at 7% overall. The exposure management business is offsetting some of that growth. When you netted them down, we were at about a 2% growth. We've seen a rather steady performance there. You hear what we're doing up here. We've got between increased customer interest, a lot of investment going on the product side, and driving that business, really helps people see where we want to take the business, where we want to focus that business. It also reflects our focus internally. When people come and ask for funds or dollars or what have you, if it's on core, we have a conversation, right? It just really helps drive that. I think it's that clarity that has helped us share with the broader investment community about how to think about our business. Also, we reiterated our guidance yesterday as well, right? We're just demonstrating, we are really digging in to make sure we have the clarity, the run rate, if you will, to make sure we can see where we are in the quarter, where we are in the year, and to be able to share that with people. I think that's really what stands behind it. If anything, with the changes that are going on at the CEO level, we're looking at how we accelerate ourselves on this journey. That's the big focus here. The one other thing I would add is, I just had my six-month anniversary with the company, which means between the three of us, I'm the longest one in position. Wow. That's a great point, right? There's been other changes within the C-level positions as well. Yes, absolutely. I think Rapid7 is definitely entering a new era in terms of that opportunity set, and certainly something to get excited about. One thing that just maybe continuing on this theme of re-acceleration is that we've been observing that with this heightened concern around Mythic, one of the traditional narratives around vulnerability management is that you can use substitute products. You can use things from the hyperscalers, or you can use things as part of a platform. Do you see a switch back to Tier 1 scanning or a switch back to vendors that have remained focused on exposure and risk management, as opposed to those that maybe are just bolting it onto their platforms? Sure. You know what? In our industry, as you know, we always moved from best-of-breed to suites and basically back and forth. It depend on the priorities, how the industries basically look at the market need, the customer demand, and so forth. One of the major transformation that we're going through, we were basically built to be a platform company that we provided multiple products in a way that it was very scalable, and it basically custom catered to our customer size. We've done an incredible job. We're above $800 million a year Doing that incredible stuff. A couple of years ago, it was very clear that the market is shifting, and now there is a real need for best-of-breed again. Every few years, if you've been in the industry as long as I have been, every five years, we flip-flop based on the demand and the new threats and some of the new changes. We are entering an era where customers are now going to be very demanding for certain solutions that has to be able to do certain things at the best possible way. AI is actually stressing that, and as I said, it's allowing everybody to reimagine it. One of the things we're doing internally, we're moving from basically a suite solution that we did a lot of things good, to do a couple of things great and the best possible way, and making sure that the two things that we're going to be doing exactly what the market needs and where we can actually become category leaders in them. That's really the changes that we've been doing, not in the last 24 hours, we've been doing the last two years. As you can imagine, there is a lot of things underneath in the processes, the thinking, the DNA of the company, needed to change to allow that to happen. We also believe that with all the new models, we'll accelerate that. Before, all customers at the board level knew there was an issue. For them, they get to the point it was about risk mitigation. Now how can I deal with every single day I wake up and I know going to be bad news. Right now, they asking actually their security team to say, "How many vulnerabilities do we have?" It's almost there is a license where we before, basically the CSO comes in to say, "Why is your security?" He's coming back and saying, "Can you tell me how big is the problem?" Right? Because he can hear in the news 10,000 vulnerability, X number of this, and so forth. That's almost a license to be able to say, "Okay, since we know now, what are we doing about it?" I believe there is huge room for best-of-breed that can be able to partner with some of the customers on some of those jobs. We believe we're in an incredible position to actually provide those jobs very well. Excellent. Maybe speaking of some of the areas where you can create this differentiated solution, I think, Corey, in the summary, you referenced your MDR solutions. It seems like this is an exciting space, particularly with agentic SOC becoming more and more of a discussion point. Help us understand, how is Rapid7 well-positioned for this? What is sort of the role of AI versus the role of Rapid7 within the agentic SOC? Yeah. If you just break down what the agentic SOC is and the evolution of it's the idea that technology can actually process most of customers' security-related data and alerts, to figure out where bad things are happening. It's at the most basic, simple level overall. On one hand, you could actually think about that, okay, that's an AI winner. It could be commoditized. Anyone can actually do that. You have to zoom into actually what's happening in a customer's environment for that to be true. There's a couple different things. There's one, you actually have to not just process the alerts, you have to understand the context that the data is actually happening in. Most of these things are just geared towards, and most competitors are just geared towards processing alerts. One of the things that we recognized early is that environmental context matters. You have to understand what's the technology. By the way, every single customer has a bunch of new and advanced technology and a bunch of old and legacy technology and a bunch of stuff somewhere in between. Some of it's very well-maintained. Some of it's very poorly maintained. If you don't understand the state of the environment, you actually cannot really process or understand threats, risk, and understand what behavior is bad and good. One of the biggest investments we've made over the last two years is collecting deep data about our customers' technology environment that we can then use to actually process and understand two things. Now, part of understanding, people are like, "Why do you have to understand the environment to actually make the decision?" Well, the environment matters overall. Think about if you're trying to price insurance. How do you want to price hurricanes if you're in Florida versus California? Same with earthquakes. If you don't know the environment that you're actually in, you cannot make the right decisions. We've been invested in understanding the environment our customers that are in overall. That provides two advantages. One, the efficacy of our ability, now that we've acquired one of these models to do it, is we have much richer context. Their team's already looking at they were a standalone market-leading AI SOC company with great core technology leveraging AI models to actually do detection. What they found is leveraging our full contextual data is that their accuracy and efficacy rates have skyrocketed. Context matters as a differentiator. The most important thing is the entire industry was built on a premise that it's all about detection. In the AI world, where you have attacks happen fast, it's all about the speed and accuracy of the response. In order to understand response, again, you have to understand what is available in the environment to respond. We understand both the environment, the controls that are available, and so our whole goal is how do we actually enable people to actually have a 15-minute time to adoption, time to response, time to containment? We're not there yet. We have the data and the context to enable that. Those two things are massive differentiators. Both the context and the ability to respond with that context are different than most of the standards in the market today. Wael, you look at this stuff all the time. No, absolutely. Look, when we talk to customers, the old model was not sustainable. I was talking to some CSOs who are basically saying, every single day is like really. They don't know what they're going to be dealing with. Now, with all the AGI models allow you to be able to do things way faster and can be able to know what's going on on the detection side. As Corey said, now, since you managed to save a lot of time and reclaim a lot of basically resources on that side, what can you do about it? You know what I mean? Basically, how you can maximize all the control that you have or all the mechanism. That's the area we're focusing on, the R side, the reasoning side. I think that's the exciting part, where the real experts and the machines working together to do things we could not do before, then we can finally feel that we're ahead. I believe in our industry, we're very lucky that the use case of cybersecurity is very prime to those models, and it's proven that we can do these jobs extremely well. I think now we can reclaim some of those resources and that time to be able to actually get ahead in this arms race. Because we were not winning, although we're doing a lot, but we're still not winning because one attack bypass is just one attack enough to completely make a big damage. We were stopping millions, but it's not good enough. Now we're finally feel we can win this, and we're excited about what's possible. Excellent. It makes a ton of sense that you'll be able to bring AI to your customers and you're using the right tool for the right job, ultimately. I wanted to maybe understand a little bit better now that we've covered the product and product strategy side. How do you think about the sales execution piece? It seems like Rapid7's moving in the right direction here. Help us understand what's the opportunity set, what's left to be done. How do you think the sales side is going to do? I can jump in since I am now responsible for the numbers since yesterday. Corey and I, and the board, we've been actually working extremely hard making sure that we have the right leadership at all the right critical positions for what we need to be able to do ahead. One of the jobs were the head of go-to-market. We're very lucky that we attracted some really, really serious leadership, who've been working extremely hard in the last four months or so. Exactly. You know what I mean? Right now, we were fully loaded with basically what we need to be able to execute forward the coverage, the skill set, the enablement, the training, the internal processes. That we had great processes before, we just needed to modernize it for the speed and the scale that we needed to build. I think we're in a position way better than we've ever been. I'm very confident in our leadership as well as basically the team that Allan have put in place, and I'm excited to work with him and his team in the next period to do great things. Excellent. Just from a financial perspective, how do we think about the margin opportunity longer term? What maybe has to happen for that operating leverage to show through in the model? Is this just a function of seeing more productivity, the funnel that you're seeing convert? Just help us understand how do we get to that leverage. Yeah, absolutely. We've touched on a lot of it. Building the AI-driven SOC is going to be a big part of that story. Building automation into what we do every day is very much part of the strategy over time. We're very focused on our core platforms products growing, but we're also talking routinely about balanced growth, meaning not only are we growing the top line, but we're committed to growing the bottom line. Throughout the organization, with changes like new leadership coming in in sales, the ultimate measure is productivity, and we called out in Q1 that we're happy to see a nice uptick year-over-year in productivity per rep. That's just, if you will, a down payment on the promises we have to deliver over time. Again, it's drive growth and drive productivity throughout the organization. Throughout 2025, we saw a number of areas where we were making investments, largely in the product and the customer experience. As we've seen some of that come to bear, it's producing those productivity gains that we have baked into our guidance. Our guidance implies our margins improve throughout the year. What we're really very focused on is making sure we're working on the organization this year to drive next year's margins. We're constantly rolling that out to give us room to invest in our products and our customers, but also to make sure we're building margins over time. Excellent. Unfortunately, this brings us to the end of our time, please join us with the continuation of the conversation upstairs. Thank you. Thank you.
Loading workspace