Rapid7 Continues to Excel with 17th Consecutive Quarter of Record Revenue

Company thrives with sustained technology innovation, international development, and focus on customer satisfaction

Boston, MA — July 30, 2013

Rapid7, a leading provider of IT security risk management software and cloud solutions, today announced its seventeenth consecutive quarter of record revenue. In Q2, Rapid7 stayed on top with product innovations across the portfolio, international expansion and community recognition on the heels of increased investments in its comprehensive security solutions and dedication to outstanding customer satisfaction.

Product and IT Security Risk Management Innovation

In the second quarter of 2013, Rapid7 released new innovations for its solution portfolio, which included improvements to Metasploit, Nexpose and Mobilisafe. Metasploit 4.6, the enhanced version of Rapid7's penetration testing software, offers three new wizards to make penetration testing quick and easy. Metasploit 4.6 is also the first penetration testing solution to provide testing capabilities for the Open Web Application Security Project (OWASP) Top 10 2013.

Also included in the portfolio advancements was Nexpose 5.6, the next evolution of its vulnerability management solution. New "Top Remediation" reports offer users a faster path to action and increased security and this version also introduces Center for Internet Security (CIS) Benchmarks for Red Hat Enterprise Linux.

Additionally, Mobilisafe, Rapid7's solution for mobile risk management, now integrates with Microsoft Office 365 to protect companies who use the cloud-based application to access sensitive information on mobile devices.

Industry Recognition

In Q2, Mobilisafe was included in Gartner's report on Cool Vendors in Security: Security Intelligence 20131. The Cool Vendors report discusses Mobilisafe's TrustScore metric, which enables organizations to focus on users and devices that pose the highest risk. Mobilisafe's inclusion in the Cool Vendors report points to the importance of mobile security as a component of a comprehensive security program.

At the HackMiami 2013 Hacker Conference in Q2, Nexpose and Metasploit won in a head-to-head test against other web application scanning tools. The competition involved simulations of realistic, challenging situations, testing web applications like PHP, JSP, and .NET. Nexpose web application scanner received a nearly perfect score of 19.8 out of 20, and earned the highest score in the field of competitors in each category: Ease of Interface, Vulnerability Detection, Reporting, and Overall Value.

International Development

With an increasing focus on international expansion, Rapid7 signed a partner agreement with Terach Benelux, a next generation distributor for the region which includes Belgium, the Netherlands, and Luxembourg. Terach now distributes Rapid7's products in Benelux as part of their strong security portfolio.

Additionally, the Dubai World Trade Centre (DWTC) began using Nexpose for vulnerability management. The solution, implemented by Rapid7's regional partner Spire Solutions, was deployed to enable DWTC to identify and remediate threats, misconfigurations, and malware in their environment. DWTC's adoption of Nexpose indicates that businesses in the region are not only concentrating more on building security awareness, but also taking action to protect their organizations from information security risks.

Research & Security Community Support

Rapid7 continued its commitment to promoting security awareness by providing the community with vital research. Rapid7 Labs discovered an attack campaign, dubbed KeyBoy, targeting victims in Vietnam and India using a custom backdoor. Rapid7 advised that these types of targeted attacks, although common, should not necessarily take priority over any other threat in the environment.

Research from Rapid7 Labs also found 114,000 insecure serial servers connected to the internet, many of which provide little or no access control to their connected serial ports. This research sheds light on a serious and prevalent issue, highlighting potential risk for thousands of organizations. Rapid7 recommends disconnecting affected systems from the internet to minimize this risk.

Customer Portfolio Expansion

In Q2, Rapid7 added nearly 200 customers across education, government, technology, retail, travel and hospitality, healthcare, banking, and other industries. New customers include Northeastern University, a private research university in Boston well known for their signature cooperative education program, Netsuite, a global cloud-based business management software provider, and Swift Transportation, a full service truckload motor carrier in America, Mexico, and Canada.

Exemplifying Rapid7's dedication to continued customer satisfaction, many existing Rapid7 customers increased their investment in the Company's products and services, including TASER International, Duke University, PCCW Global, Athenahealth, and Wells Fargo & Company.

Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

1 Cool Vendors in Security: Security Intelligence, 2013 by Joseph Feiman, Neil MacDonald, Dionisio Zumerle, Avivah Litan, Andrew Walls, Ray Wagner. Published by Gartner on 29 April 2013.

About Rapid7

Rapid7 security analytics software and services reduce threat exposure and detect compromise for 3,000 organizations across 78 countries, including over 250 of the Fortune 1000. We understand the attacker better than anyone and build that insight into our solutions to improve risk management and stop threats faster. We offer advanced capabilities for vulnerability management, penetration testing, controls assessment, incident detection and investigation across your assets and users for virtual, mobile, private and public cloud networks. To learn more about Rapid7 or get involved in our threat research, visit www.rapid7.com.

Media Contact