Company Intelligence

Rapid7

Vulnerability management and managed detection vendor rebuilding around AI after activist pressure and a June 2026 CEO change

In this profile

Quick Facts

  • Founded 2000
  • Country United States
  • Industry AI in Cybersecurity
  • Founders Alan Matthews, Tas Giakouminakis, Chad Loder
  • Website Official site
  • Last Reviewed Jul 2026

Executive Summary

Rapid7 builds vulnerability management and threat-detection software rooted in an unusual founding decision: in 2009, the company acquired Metasploit, the open-source penetration-testing framework attackers and researchers use to actually exploit vulnerabilities, on the premise that understanding real attack techniques from the inside would produce better defensive products than working only from the defender's side. Alan Matthews, Tas Giakouminakis, and Chad Loder founded Rapid7 in Boston, Massachusetts, in 2000, nearly a decade before that acquisition defined much of the company's public identity.Rapid7 has spent the past two years navigating both a challenging growth environment and pressure from an activist investor, culminating in a June 2026 CEO change. For readers of Brel's AI in cybersecurity coverage, Rapid7 is a useful case study in how a mid-sized, publicly traded security vendor under investor pressure leans on AI-driven product announcements and a new chief executive to try to reset its growth story.

Why It Matters

Rapid7's 2009 acquisition of the Metasploit penetration-testing framework — buying the tool attackers use to break into systems in order to build better defenses — remains one of the more unusual founding decisions in the industry, and its 2025-2026 activist-investor pressure and leadership change make it a live case study in how underperforming public cybersecurity vendors are being pushed to prove their AI strategy translates into growth.

Products

Founders

Recent Developments

  1. 2026 Leadership

    June 1, 2026: Rapid7 appoints board member Wael Mohamed, former CEO of Forescout, as chief executive officer; Corey Thomas becomes executive chairman after nearly fourteen years as CEO.

    Source
  2. 2026 Acquisition

    March 2026: Rapid7 acquires Kenzo Security, adding proprietary AI models and a data mesh for machine-speed threat investigation across endpoint, identity, cloud, and SaaS.

    Source
  3. 2024 Partnership

    October 2024: Activist investor Jana Partners discloses a roughly 13% economic interest in Rapid7, citing operational execution and governance concerns.

    Source
  4. 2015 Development

    2015: Rapid7 completes its initial public offering on Nasdaq under ticker RPD, pricing at $16 per share.

    Source
  5. 2012 Leadership

    2012: Corey Thomas, who joined Rapid7 in 2008, is named CEO.

    Source
  6. 2009 Acquisition

    2009: Rapid7 acquires the Metasploit penetration-testing framework, adopting an attacker's-perspective approach to product development.

    Source
  7. 2000 Development

    2000: Alan Matthews, Tas Giakouminakis, and Chad Loder found Rapid7 in Boston, Massachusetts.

    Source
  8. 2000 Company founded

    Rapid7 was founded in 2000 per the company profile source on file.

    Source

Connected Reports

Connected Insights

Industries

Technologies

Introduction

Rapid7 builds vulnerability management and threat-detection software rooted in an unusual founding decision: in 2009, the company acquired Metasploit, the open-source penetration-testing framework attackers and researchers use to actually exploit vulnerabilities, on the premise that understanding real attack techniques from the inside would produce better defensive products than working only from the defender’s side. Alan Matthews, Tas Giakouminakis, and Chad Loder founded Rapid7 in Boston, Massachusetts, in 2000, nearly a decade before that acquisition defined much of the company’s public identity.

Rapid7 has spent the past two years navigating both a challenging growth environment and pressure from an activist investor, culminating in a June 2026 CEO change. For readers of Brel’s AI in cybersecurity coverage, Rapid7 is a useful case study in how a mid-sized, publicly traded security vendor under investor pressure leans on AI-driven product announcements and a new chief executive to try to reset its growth story.

What the company does

The Rapid7 Command Platform integrates exposure management and vulnerability data with managed detection and response, enriching security data with AI and threat intelligence to help security teams reduce risk and disrupt attackers. According to the company’s own materials, the platform has more than 500 integrations and is used to transform the cybersecurity operations of more than 11,500 global customers, with Managed Detection and Response cited by outside analysts as one of Rapid7’s market-leading offerings.

Who it serves

Rapid7 serves enterprises and organizations that rely on managed or co-managed security operations, spanning vulnerability exposure across endpoint, identity, cloud, and SaaS environments. Independent reporting on the company’s 2025 financial results puts total revenue at $860 million and annual recurring revenue at $840 million for the year, with a customer base of more than 11,000 organizations globally.

Company background

Rapid7 was founded in Boston in 2000 by Alan Matthews, Tas Giakouminakis, and Chad Loder. Corey Thomas joined the company in 2008 as an executive vice president of sales, marketing, and products, became chief operating officer, and was named CEO in October 2012, a role he held for nearly fourteen years. Rapid7 completed its initial public offering on Nasdaq under ticker RPD in 2015, pricing at $16 per share. In October 2024, activist investor Jana Partners disclosed a roughly 13% economic interest in the company, citing concerns over operational execution, forecasting, investor communication, corporate governance, and board composition; the resulting truce added new directors to Rapid7’s board, including Wael Mohamed, a cybersecurity industry veteran and former CEO of Forescout Technologies. On June 1, 2026, Rapid7’s board appointed Mohamed as chief executive officer, with Corey Thomas transitioning to executive chairman.

Product and AI capabilities

Rapid7 has framed its AI strategy around a specific technical claim: that its detection and investigation models are trained on roughly twenty-five years of real-world data about what happened after vulnerabilities and exploitation techniques were first identified, drawing in part on the legacy of its 2009 Metasploit acquisition. In March 2026, Rapid7 acquired Kenzo Security, adding proprietary AI models and a data mesh intended to enable machine-speed threat investigation across endpoint, identity, cloud, and SaaS environments — a capability the company has positioned as extending its existing Managed Detection and Response service with faster, AI-assisted correlation of security events across those different domains rather than requiring an analyst to pivot manually between separate tools.

Key developments

Rapid7 built its early reputation on vulnerability scanning and its unusual 2009 acquisition of Metasploit, then broadened into managed detection and response as security operations consolidated around fewer vendors. The company’s stock has struggled considerably relative to peers such as Qualys and Tenable in recent years, and Jana Partners’ October 2024 activist stake disclosure and subsequent board changes set the stage for a leadership transition. That transition arrived on June 1, 2026, when Wael Mohamed — who had joined Rapid7’s board in April 2025 as part of the Jana settlement and brought prior CEO experience at Forescout — succeeded Corey Thomas as chief executive, with Thomas moving to executive chairman. The March 2026 Kenzo Security acquisition, made in the months just before that leadership change, added AI-driven investigation capabilities the new CEO inherits as part of Rapid7’s current growth pitch.

Why it matters

Rapid7 is a useful, less-flattering counterpoint to the AI-security success stories in this batch: it is a vendor that has invested in AI-driven detection and acquired AI talent through Kenzo Security while simultaneously facing sustained activist-investor pressure and a steep stock decline, illustrating that AI product announcements alone do not automatically resolve a public security vendor’s growth or governance challenges. Its leadership transition, with a veteran cybersecurity operator brought in specifically through an activist settlement, gives Brel readers a concrete situation to track for whether new leadership and AI-driven product investment translate into a turnaround.

Sector context

Within Brel’s AI in cybersecurity coverage, Rapid7 competes most directly with Tenable and Qualys in vulnerability and exposure management, and with CrowdStrike and SentinelOne in managed detection and response, though Rapid7’s current market valuation trails both of those comparison sets significantly — a gap that is itself part of the context for its 2026 leadership change.

Sources and references

This profile draws on Rapid7’s official press release and SEC filing on its CEO transition, alongside independent press coverage.

  • Rapid7 Press Release — “Rapid7 Appoints Wael Mohamed Chief Executive Officer…” (2026)
  • U.S. SEC — Rapid7, Inc. Form 8-K (2026)
  • BankInfoSecurity — “Rapid7 Names Wael Mohamed CEO Amid Ongoing Growth Struggles” (2026)
  • Seek Argus — “Rapid7 Bought the Tool Hackers Use to Break Into Systems…” (2026)

Official resources

Sources and references

This article draws on publicly available company information, official websites, filings, interviews, announcements, and other cited sources. Information may change over time.

Company information is based on publicly available sources and is reviewed periodically. If you represent this company and would like to request a correction, contact Brel.

Explore Related Intelligence

The AI Brief

Weekly company intelligence in your inbox.

Subscribe