This conference call transcript was computer generated and almost certianly contains errors. This transcript is provided for information purposes only.EarningsCall, LLC makes no representation about the accuracy of the aforementioned transcript, and you are cautioned not to place undue reliance on the information provided by the transcript.

Rapid7, Inc.
2/10/2026
Good day, everyone. My name is Kehei Alani, and I will be your conference operator today. At this time, I would like to welcome you to the Q4 2025 Rapid7 earnings call. All lines have been placed on mute to prevent any background noise. After the speaker's remarks, there will be a question and answer session. If you would like to ask a question during this time, and if you have joined via the webinar, please use the raise hand icon, which can be found at the bottom of your webinar application. At this time, I would like to turn the call over to Matt Wells, Vice President of Investor Relations.
Thank you, Operator, and good afternoon, everyone. We appreciate you joining us. Today, we will be discussing Rapid7's fourth quarter and full year fiscal 2025 financial results. We've distributed our earnings press release over the wire, and it can be accessed on our Investor Relations website. With me on the call today are Corey Thomas, our CEO, and Rafe Brown, our CFO. As a reminder, all participants are in a listen-only mode, and a question-and-answer session will follow our opening remarks. Before I hand the call over to Corey, I want to note that certain statements made during this conference call may be considered forward-looking under federal securities laws. Such statements are made pursuant to the safe harbor provisions of the Private Securities Litigation Reform Act of 1995 and include our outlook for the first quarter and fiscal year 2026, any assumptions for fiscal periods beyond that period, and our positioning, strategy, business plan, operational improvements, and growth drivers. These forward-looking statements are based on our current expectations and beliefs and information currently available to us. While we believe any forward-looking statements we make are reasonable, actual results could differ materially due to a number of risks and uncertainties, including those contained in our filings with the SEC. Reported results should not be considered indicative of future performance. We do not undertake and expressly disclaim any obligation to update or alter our forward-looking statements, whether as a result of new information, future events, or otherwise, except to the extent required by applicable law. Further information on these forward-looking statements and risk factors are included in the filings we make with the SEC, including the section titled Cautionary Language Concerning Forward-Looking Statements in our earnings press release. Additionally, over the course of this call, we'll reference non-GAAP measures to describe our performance. Please review our earnings press release and filings we make with the SEC for a rationale behind the use of non-GAAP measures and for a full reconciliation of these GAAP to non-GAAP metrics. These documents, in addition to a replay of this call, will be available on Rapid7's Investor Relations website. And with that, I'd like to turn the call over to Corey.
Thank you, Matt, and welcome to everyone joining us on the call today. I'm excited to be joined by Rafe Brown, our new CFO who joined Rapid7 in early December. Rafe will offer some initial impressions on Rapid7 and the opportunities he sees in his prepared remarks. Rapid7 exited fiscal 2025 delivering outperformance against our Q4 ARR revenue and profitability guidance. We ended 2025 with ARR of $840 million and total revenue of $860 million, both ahead of guidance. In the Q4, we saw sustained New Deal activity for our industry-leading NBR offering and encouraging growth within our Exposure Command platform. Throughout 2025, and more specifically during the second half of the year, we made strategic investments across key product growth initiatives to strengthen our position as a leader in AI-enabled security operations. We did all of this while continuing to generate significant cash flow, exiting 2025 with $136 million of operating income and $130 million of free cash flow. These investments enhance our security offerings with AI and machine learning capabilities, consolidate customer environments on a unified platform with our managed AI SOC, and enable our team to scale operations globally. Additionally, we just concluded our sales kickoff with the broader go-to-market team. It was our most impactful SKL years and a great opportunity for Chief Commercial Officer Alan Peters and his team to outline their priorities to re-energize the rapid segment growth engine. We expect to see tangible benefits of this organizational change throughout 2026 as we develop muscle memory with these new processes. Before I turn to business updates, I want to take a moment to address the broader landscape because I think context matters for how investors evaluate our business. We are operating in a period of significant disruption across the software sector, driven by a fundamental reevaluation of what AI means for software businesses. I understand why investors are asking hard questions. The rapid advancement of agentic AI capabilities has created real uncertainty about the durability of many software business models, particularly those built around perceived pricing. Then workflow layers are point solutions that can be replicated or disintermediated. I want to be direct. Not all software businesses are positioned equally in this environment, and cybersecurity is fundamentally different. Let me explain why we believe Rapid7 is on the right side of this divide. The security operations market is defined by three characteristics that make it structurally resilient, and in many ways, a direct beneficiary of the AI transformation happening across the enterprise. First, the threat environment is accelerating, not simplifying. AI is enabling attackers to move faster, at greater scale, and with more sophistication than ever before. This is not a theoretical risk. It's happening right now, and it's driving an urgent reevaluation of security postures across the enterprise. The regulatory environment is simultaneously becoming more complex and more fragmented around the world. This combination means that the need for comprehensive, expert-led security operations is growing, not shrinking. Second, security operations cannot be reduced to software alone. Unlike categories where an AI agent can trigger an API call or bypass the user interface, effective security operations requires the integration of broad telemetry, proprietary intelligence, real-world expertise, and yes, human judgment, particularly during incidents where the stakes are the highest. This is a market where outcomes depend on the combination of technology and deep domain expertise, not one or the other. And third, our business model is anchored on outcomes and value delivered, not seats. Our pricing is tied to the scope of environments that we protect and the outcomes that we deliver, which positions us well as the industry evolves towards outcome-based and usage-based models. This is the lens through which I ask you to evaluate Rapid7. We're not a wrapper over a generic model. We're not a point solution. We're a platform built on the broadest proprietary security data foundation in our market, continuously enhanced AI-driven productivity and innovation, and delivered through deep services and technical expertise that customers depend on to navigate an increasingly complex world. Now, turning to the evolution of our business. The cybersecurity market is changing and that presents us with phenomenal opportunity. AI driven attacks are escalating in both pace and sophistication, stretching security teams thinner than ever. At the same time, regulatory requirements continue to expand and fragment globally. From the EU's evolving framework to new compliance mandates across Asia Pacific and the growing patchwork of US state level requirements. This is driving a reevaluation wave across the enterprise security. And the winners in this market will be the vendors that can deliver on three things simultaneously. First, a broad proprietary data foundation that provides complete situational awareness across the attack surface. Not just what you connect lately, but the ability to integrate, normalize, and contextualize data from across a customer's entire environment. With over 500 integrations, our command platform provides the broadest data foundation in our market. And this data advantage compounds over time as we train our AI capabilities on real-world security operations data that no competitor can replicate. Second. AI-powered productivity and innovation that continuously improves the speed and accuracy of detection, prioritization, and response. Our expert-trained agentic AI workflows are built on years of SOC expertise, trained on live playbooks, and redefined through real-world analyst feedback. These are not generic models. They are purpose-built engines that improve outcomes in real time. And critically, we view AI innovation as a continuous engine, not a one-time product release. We're accelerating our pace of AI development and expect this to be a sustained differentiator. And last, deep services and human expertise that help customers navigate complexity that software alone cannot address. With a decade of experience managing our own 24 by 7 global stock and that of our customers, we have built an expertise layer that is essential, not optional, for effective security operations. As attacks grow more sophisticated and regulations grow more complex, this expertise becomes even more valuable, not less. Our managed services don't just monitor, they investigate, respond, and remediate with the context and judgment that only experienced security professionals can provide. The convergence of these three elements, data, AI, and expertise, is what defines the durable security operations platform of the future. And this is precisely what we're building. The framework guiding our investment and innovation is underpinned by a shift from reactive to proactive security postures, combined with outcome-driven service offerings. We are working to introduce more AI capabilities into our MDR and exposure offerings and evolving our platform to help customers get ahead of threats rather than simply respond. And throughout 2025, and particularly during the second half of the year, we made strategic investments across key product growth initiatives to accelerate our transformation into a leader in AI enabled security operations. One that enables customers and organizations to take a preemptive posture towards security operations. These investments augment our existing security offerings with AI and machine learning enhancements, consolidate customer security environments under a common UI, and our leading managed AI SOC, and position our team to drive scale across our global footprint. In detection and response, we have a significant opportunity to continue leading with our MDR offering. We made strategic investments to evolve, enhance, and scale our solutions while building on our expertise as one of the only providers in the market with a decade of experience managing our own stock. In 2025, we expanded our MDR coverage to enable management of third-party alerts in a vendor-agnostic fashion. We streamlined analyst workflows with our AI SOC for MDR and incident command, and we started to expand our adjustable market to larger enterprises by leveraging our AI-powered services. We're also continuing to build on our partnership with Microsoft. Just last month, we launched closer integrations, such as MDR for Microsoft that provides 24 by seven expert monitoring and native response across the entire Microsoft Defender Suite. This collaboration also extends to exposure management by unifying Microsoft delimitry with rapid sevens command platform to proactively identify and close security gaps before they can be exploited. In exposure management, our evolution is anchored around up-leveling our exposure command platform with AI tools, native telemetry, and open data integration, curated intelligence, and automation to deliver a unified system for risk remediation. Differentiating features such as AI-generated vulnerability scoring and active risk scoring combine technical severity with real-world threat intelligence, enabling security teams to begin patching zero-day threats before competitors who typically wait for official industry scores. Attack path analysis visualizes primary attack vectors and allows security teams to focus on patching critical vectors rather than low-risk issues. And our remediation hub provides a single destination for remediation across both exposure management and detection response, reducing mean time to detect, respond, and remediate. When we combine our leading detection response and exposure management solutions with outcome-driven AI-enhanced service offerings, we address the core issues customers are facing in the market today. And when we do this, we're playing offense. In this quarter alone, a leading offshore drilling company, we selected Rapid7 as their SIEM provider of choice. After being unable to achieve business outcomes promised by a competitor, this return customer saw real benefits from the investments that we've made in our product over the last two years. Our ability to effectively deploy, coupled with the service level capabilities, such as MTC and Vector Command, made this six-figure competitive win back stand out. One of the largest sovereign tribal governments in the country became a Rapid7 customer after a competitive deal cycle and displacement in which we showcased the benefits of consolidation and the integration into our MTC offering. This high six-figure deal underscores the unique value proposition we can offer, delivering service outcomes on top of leading technologies. A strategic MSSP provider selected Rapid7 as they continue to expand within the state, local, and education vertical. Our detection response solution provided the features and confidence they needed to deliver outcomes for their clients. We are consolidating a mix of competitive solutions and in-house monitoring onto the Rapid7 platform. These wins share a common thread. Customers are choosing Rapid7, not just for the technology, but for the combination of technology, data breadth, and expert-led services that delivers measurable security outcomes. This is our differentiation, and it's durable. Turning to our go-to-market priorities, we're focused on operationalizing our strengths to accelerate growth. We just concluded our sales kickoff with the broader go-to-market leadership team, and it was our most impactful in years. Alan, having completed his leadership team build-out, has crystallized his vision of a unified market approach across global sales, marketing, partners, customer success, and sales operations. With new leaders and plans in place, the team is executing a more focused sales motion with tighter alignment between marketing and sales to improve demand quality and conversion, and a refined customer success strategy designed to improve retention. Refreshed incentive structures are better aligned to drive net new growth, renewals, and cross-sell. These initiatives are still early stage, and our growth flywheel will take time to build momentum. However, the groundwork is in place to improve execution and drive sustained performance across product, marketing, and go-to-market, and become a share-taker over the medium term. In detection response, AR growth of 7% was driven by MDR ARR growth in the high single digits. As we drive product transformation to deliver increased value through our AI enhanced stock, we are positioning to take share as the MDR market evolves. We believe this market has significant runway and the combination of AI driven efficiency with deep human expertise creates a compelling and defensible offering that is difficult to replicate. In exposure management, we're focused on simplifying the migration of our core vulnerability management base to our exposure command platform. By removing friction from the upgrade engine, we're helping our core VM customers migrate to a unified AI-powered view of the attack surface, a move that replaces fragmented tools with integrated contextualized risk visibility. I want to spend a moment on how we're thinking about growth because this is where the AI transformation of our industry creates real opportunity for Rapid7. And I want to be transparent about the work underway. We're actively pursuing three parallel initiatives that we believe will drive both near-term efficiency and medium-term growth acceleration. First, we're shifting significant portions of our operational services work to our AI layer, and redeploying our expert talents towards higher-value customer engagement. Today, many of the repetitive, pattern-based tasks within our SOC operations, alert triage, initial investigations, and enrichment, are being systematically transitioned to our agentic AI workflows. This is not about reducing our commitment to service. It's about freeing our experienced security professionals to focus on what they do best, helping customers navigate an increasingly complex threat and regulatory environment, providing strategic guidance during incidents, and delivering the kind of expert judgment that no AI model can replace. The result is better outcomes for customers, improved unit economics for Rapid7, and a services model that scales more efficiently as we grow. Second, we're strategically redefining our portfolio of solutions. By proactively integrating advanced AI models into our core offerings, we're ensuring our solutions remain at the cutting edge of efficiency and performance. Rather than maintaining the status quo, we're choosing to prioritize innovation over legacy, making the deliberate decision to shift resources towards high growth, future-ready product areas. We believe this is the right trade-off, accepting near-term headwinds in parts of the portfolio that face structural pressure while concentrating our investment and energy on the areas where we have a clear differentiation and durable growth potential. Third and most importantly, our core growth engine is the extension of our AI enhanced services layer. This is where we see the most durable opportunity. Customers need a partner who can bridge the gap between the rapid pace of technology change and the operational reality of securing complex distributed environments under growing regulatory pressure. Our ability to deliver AI-driven efficiency alongside expert-led services integrated on a single platform with the broadest proprietary data foundation on the market is what sets us apart and what we believe will drive share gains over the medium term. At the core, our growth will come from extending this AI services layer, delivering AI to help our customers keep pace with technology change, paired with the expertise to navigate a complex and rapidly evolving security landscape. Our anticipation is that the investments we made last year will begin to yield dividends in our AI orientation this year. But just as importantly, we're fundamentally transforming and upgrading our engagement models this year to ensure that both our business and our customers are resilient in the face of regulatory and the threat environment we face today. In closing, I want to leave you with this perspective. The increasing pace and sophistication of attacks is driving a meaningful shift in how security budgets are allocated. Customers are looking for vendors who can deliver measurable business outcome, not just technology, but a combination of data, AI innovation, and expert services that actually make their organizations more secure. We believe this plays directly into Rapid7's strengths. Our business is built on proprietary data that becomes more valuable as we scale, capabilities that continuously improve through real-world operations, and a services layer that builds lasting trust and partnerships with security teams. This combination, data, AI, and expertise, is the foundation of a durable cybersecurity business and is what differentiates us in a market that is increasingly skeptical of software-only approaches. Rapid7 is invested across our platform to deliver security operations to give customers the ability to stay ahead of attackers. Our long-term strategy of integrating and exposure management with detection response is proven to be where the market is heading. Our command platform data mesh integrates more complete security data, including third-party sources into our AI engine for true scale and efficacy. And our services layer allows us to build lasting trust and partnerships with security teams, supporting them where they need us most. We're confident in this strategy. We're moving with urgency, evidenced by our recent leadership additions and organizational changes to improve our execution and capitalize on the significant opportunity in front of us. I look forward to sharing incremental progress throughout the year. I now like to pass the call to Rafe to discuss our financial results and guidance in more detail.
You're reading a preview of the RPD Q4 2025 earnings call.
Free account.