Rapid7, Inc. (RPD) Earnings Call Transcript
May 21, 2024
Earnings Call Speaker Segments
All right. Good afternoon, everyone. Thank you for joining us. My name is Brian Essex. I'm a JPMorgan security software analyst. And with us today, we have Andrew Burton, Chief Operating Officer of Rapid7, and Elizabeth Chwalk from IR. You don't have to say anything, do you? No prepared remarks?
No, no. Go ahead.
All right. Great. Great. Well, thank you for joining us.
Thanks for having us.
We really appreciate it. Maybe we could start off with a brief overview of -- for those that maybe aren't intimately familiar with Rapid7, the evolution of the company, you see like pure-play VM and then you expand it into other markets. So maybe little bit of a background to lead into some of these other questions that I have for you.
Yes, no problem. So we started out largely with this key insight around the underserved or mainstream enterprise opportunity for cybersecurity people that were looking for visibility into their environment about where vulnerabilities might exist was largely been characterized as the vulnerability management segment. And in that -- those early years and largely up through the IPO back in 2015, we were largely a VM provider to this kind of mainstream enterprise buyer. And what we heard from these buyers is it was great to give them visibility where they were really easy to use, affordable kind of quickly consumable product. But that -- as we give them visibility into where they had exposures, they needed to also understand where those exposures being exploited, where they being actively breached or whether instance that could occur. And so our second chapter of the company was really expanding out what we think of as our security operations offering which was largely around the extended SOC and this idea of the SIEM being inverted to be more detection-based and we've built out a pretty substantial piece of our business that is now growing over $300 million, over 20%. And that was in this proposition of helping security teams, again, mainstream enterprise to understand what's going on in their environment and be able to monitor and detect if malicious activity is occurring or could occur, how to take proactive steps, right? And now what we're doing is largely bringing this consolidated and integrated view to security teams, again, mainstream enterprise, where we can give people visibility across their attack surface and better visibility leads to better monitoring and detection, which also then allows their security teams to achieve better outcomes. So the history of the company is from originally this VM company around understanding exposures to an integrated SecOps company around understanding exposures plus active monitoring and prevention to now a consolidator for the mainstream enterprise around really delivering better security outcomes around these problems.
Right. And what about on the cloud side of the business and how that maybe evolved as well?
Yes, it was interesting. The cloud is, I think, as folks -- hindsight is 2020, but at the time, what we saw and everyone has seen now is clearly the emergence of public cloud and cloud environments. And not one, but multiple clouds. And so these mainstream enterprise companies have -- nowadays, it's obvious. They have a multi-cloud environment, right? And so as the cloud emerged, a lot of our customers say, well, it's important for us to have the policies, controls and assessments in place for the cloud. Now at the time, there's a lot of active debate is who would own cloud security and would that be separate teams or would that be 1 of the teams we're already working with. And so the early years, we were building out dedicated cloud security capabilities and it's in a dedicated offering, right? What we have seen is really a more integrated approach that security teams, mainstream enterprise, not high end or cloud-native organizations. But when we think about mainstream enterprise I think about it as the Russell 3 or in 3/4 of the rest -- of the Fortune 5. So it's folks that have a security team but they're not the super rich or the super well funded. There are people that are often outside of financial services or maybe outside of 1 of the core tech-enabled spaces, right? And so what we saw was the security team that was being asked to cover the fuller environment, not just traditional workloads, but cloud workloads. And what we've seen is those -- as the cloud has matured, and has become really a core part now. It seems obvious now, but as we see now as the cloud is a core part of an organization's infrastructure, security now is responsible for securing the entire environment. They still have to work with IT and DevOps and cloud ops teams but they're ultimately responsible to both the Board and the CEOs and the CFOs to have a good security program. And so we have gone on this journey. We had a dedicated cloud offering, but now we have brought that into our broader SecOps and integrated SecOps software.
Got it. And you've done few acquisitions to kind of get to that point, too. I mean what have you kind of acquired versus built organically? And how has this all been assembled on the platform?
Yes, it's -- so back when -- so we had an organic effort around our traditional VM base of helping people assess their workloads. And what we saw at the time is we had an opportunity to accelerate our development efforts. So we acquired a company called Divi Cloud, which was the cloud security posture management, right? And that was -- at the time, that was the core thesis of having the policies and controls around your cloud workloads and not just 1 cloud but multiple clouds. And what became apparent and again, in hindsight 2020, is that people also wanted to assess vulnerabilities in the cloud environments. And so we augmented some organic work we were doing with also buying a company called Alcide which is an Israeli company. And our belief was that these separate cloud capabilities would combine and consolidate into a singular set of cloud security offer, right? Now it seems pretty obvious, but emergent technology often comes out in point solutions and then it evolves into being a more consolidated integrated offer. So we've seen workload assessment and workload protection, consolidate with policy management, entitlement and event management coming together. And I think now we're seeing it really expand or integrated into the broader security program. And so one of the things that we're focused on is making better security in the cloud, but also across the attack surface is more accessible to mainstream enterprise.
Got it. And I guess if we think about some of the peers in your space, a few of them originated from some of the same kind of vulnerability management focus and they branched into certain different directions compared to where Rapid7 has gone, how do we think about the way peers have evolved versus the way that you evolved? And how would you characterize your business in terms of a point of differentiation with regard to maybe some of the 2 VM peers that people will naturally compare you to?
It's a great question. I'd say one of the most kind of most significant distinctions was our belief that you would need to be actively monitoring and detecting things in the environment. That's in addition to telling you is there risky -- are you exposed? Or do you have risky exposures, right? So when we -- largely the SIEM market, when we created a -- I think, we've got the first, one of the first to build a cloud-based SIEM. But we built it to do detections at its core, right? And so the original VM players all took different paths, but our probably, we were unique in that we said, "Hey, you know what, it's really going to be important is that these environments are going to continue to expand they're going to become more dynamic and they're going to become more diverse, and you will need a detection first or detection-based security program at the core, right?" And so we built that out. And I think we've had quite a bit of success doing that. But that was probably one of the first and probably one of the biggest distinctions. Now we still believe visibility is important, assessing your environment, understanding what your security posture is, where ones are. We still believe that's very important, but it's part of a broader proposition. And so I think there's been debates between the different VM companies about is visibility and assessment in and of itself, the market or is it part of a bigger proposition. And we have argued that it's important, but it's part of a bigger proposition.
How do you think about some of the larger vendors getting into VM? I mean you have some of these larger platform vendors and they'll say, "Well, we look at some vulnerabilities management and cloud or whatever?"
Yes, Elizabeth and I were discussing this earlier. So you see like 2 notable names, right? Microsoft and CrowdStrike are talking about vulnerabilities -- vulnerability management, it's been part of their security offerings. And I think this largely validates 2 things. One, it's hard to do, right? This is not something anybody can do. I mean CrowdStrike and Microsoft are quite significant security players. They have a massive amount of resources, and it requires expertise. But two is, it isn't something in and of itself that is a stand-alone business, right? I think when you look at what the vendors, including us ourselves are saying is, if you look at Microsoft and it's visibility across your attack surface is important, right? And understanding potential vulnerabilities or misconfigurations is the first step. And I think it actually validates our strategy to say, this is important, but it's part of a broader proposition. So if I would worry as if no one -- if people were saying it wasn't important, right? So the fact that you have multiple vendors saying it's important, I think, recognize. Now the question is, how does it fit into a broader strategy, right? And I think our point of view is that visibility leads to better monitoring and better detection. And so it's the entree or the first step into a better security program. But we are very clear. It's a step. It's an entree. It's not the main event.
Got it. And then maybe taking a step back and looking at recent events with company performance. You recently changed your posture around investing in growth, shifting focus towards margins and the cash flow, announcing a reduction in force last year? And maybe if you could frame out the thought process behind that shift and how it's evolved since?
Yes. Yes, I'll frame it as a couple of steps, right? So last summer, we looked at our business, and we felt like we had really done a nice job around our MDR or Managed Detection Response business of consolidating multiple capabilities. We had log analytics. We had endpoint protection, we had network detection, we had UBA. We consolidate a lot of capabilities into a singular integrated offering. And that is, as I say, is a very healthy piece of our business, right? And when we looked at that, we said, look, this is a really a strategic bet for us. And we looked at how the company was set up, how it was -- where the investments were occurring. And we found that we needed to make some structural changes to the business to help us better align to where we were building things how we were going to market and we really decided to introduce a couple of things. One, integrated consolidation offerings, right? So similar to our MDR, we said, look, we're going to offer and capture more ARR per customer. So we wanted to build out our offerings in a way that they were integrated but could offer customers more value for their dollar, right? And the macro had changed at this point and people began to really think about how to maximize their security investments because security is still #1 in the spend of IT spend, but it's not immune to these macro environments, right? So we looked at it and said, "Look, we've got to take advantage of more offshore development. We're going to take advantage of aligning our investments and our people to the strategy." And so we did do a reduction and a restructure, right? Now that set us up for an efficient growth model. The balance between free cash flow and growth. And so we said we would double free cash flow from $80 million to $160 million and we now have a $160 million number that's out there for this year, right, and we feel very good about. But it began to really set up efficient growth. So the first step was, are you organized for success and do you have the strategy to execute. That's why I think about last summer. Then we had been piloting these consolidation offerings. And our MDR offering, again, growing quite well, having quite a bit of success. We continue to really focus our go-to-market efforts and our sales and product efforts around that. As we entered this year, the visibility side of the equation, the ability to consolidate integrated visibility across the attack surface, what we call CRC was our traditional VM business in our cloud security business. And we said, look, we're going to integrate this as well. And when we set guidance last quarter, one of the things that we had assumed was that the rate so we saw an uplift of security and some cloud security and BM spend in Q4. And we assume that, that would continue this year. And what we saw was actually the depth of integration needed -- was going to be planned for this summer and that we needed to introduce, there was some price dislocation in the market. And so we felt like this to drive CRC, we needed to make these changes, but the rate of purchasing and the rate of spend around vulnerability management and our cloud offerings, went down as we were working on this new offering. And there's a couple of reasons why, but that's what led us to take a step back and basically say, "Hey, we want to reset our outlooks." Still have free cash flow, right? So our profit and free cash flow is unchanged. But we said, "Look, we want to adjust our guide, so we can do this investment in building this new consolidated offering." And we have shared or provided an outlook that has basically has very minimal contribution of our CRC offering, and we continue to really expect no change in the macro, but our MDR/MTC offering will continue to maintain its current healthy pace.
How do we think about that kind of like dip in CRC adoption?
Yes. I think it was a couple fold. I think 1 in the mainstream enterprise, if you were born in the cloud, or a cloud-dominant organization, cloud security has been very important, right? Our buyer is this mainstream enterprise where it's a hybrid environment. They have a mix environments. And so what we're seeing is they're largely being locked out of participating because it's a premium purchase. And so what we've heard from a lot of CISOs is, look, I need to protect my environment, but I can't narrow that coverage. So if you charge me more in one part of the environment and my budgets are fixed, which they largely are constrained, I have to narrow my coverage. And we feel like that's a false choice. And so what we've seen is the need to lower the price points on cloud security and have more of an integrated offering requires us to both lower the price point on the cloud security capabilities, but then also expand coverage, so you can do 100% coverage. The thing I would share is we did this once before with D&R, where people used to charge for data. They're like, "Oh, you just want -- and security teams are like, "Well, I can't pay for all the data, so I'm going to constrain what I collect," and that was a false choice. And so we see that once again in the attack surface side of the equation where people are saying, well, if I pay these market rates on cloud or I pay a lower rate in year 1 and someone tries to charge me more in year 2, that's forcing me to narrow my coverage. And what we want to do is lower the price points to participate in cloud security, but then also expand coverage to provide integrated visibility across the attack surface. And so the CRC repackage or relaunch is going to include both integrated capability with a lower effective price point that's offset with broader coverage, if that makes sense. And that's really what I think that will unlock, I think 1 of 2 things, the existing VM customer who wants to expand that coverage, that's a win and the ability for more people to participate in covering their full attack surface, if that makes sense.
Yes. Yes, it does. And so when do you anticipate you'll be able to have there, like fully integrated CRC in the market? And what do you do in the interim?
So we still have some nominal participation of the customers. It's the consolidated offering that we're really focusing on. So there are 2 things. We've told -- we've communicated that it will be this summer. We'll have the new integrated offering, what we call V2. And to be clear, it's an acceleration strategy versus something new because we have this first version that was well received people just say, "I need 2 things. I need them be more accessible to me at my budgets, and I need some -- an integrated approach I call an integrated attack -- we call an integrated attack path mapping, which is a fancy way of saying, I need the map laterally across the environment just within a given silo.
Okay. Got it. And as you mentioned, you gave I guess, cash flow guidance, I think $160 million this year, it's doubling over last year. How do you manage throttling investment in growth versus profitability? And as you prioritize one versus the other, what are the levers that you'll pull to invest more in growth?
Yes. So one, I think we've got this question today, actually quite a bit around how do you feel about your sales and marketing investments for growth. And I'd say we feel very good and we have -- we feel like we have capacity available to continue. Part of the reason we took down our guide was to create space for us to deliver the integrated offering and to do the repackaging and repricing, right? And so I think we feel like we have a lot of -- we have a ton of confidence in the $160 million of free cash flow. We have capacity in our go-to-market engine, right? And our investments are being actually directed at driving the core foundational work of pricing, packaging and some of the integrated work, right? So I don't think of it as a throttling perspective. I think it is have we invested the right level to basically drive efficient growth and do we have that balance between growth and profitability. And the macro, our assumption, by the way, we've gotten this question as well today is the macro. We do not believe it changes. We believe it continues to be a constrained environment, and that's something that's been going on for several quarters and we've talked about that as such. So deal inspection is high level of CEO, CFO board-level involvement is quite high. Large deal cycles are taking some time, but that's just something that we've been managing in the last couple of quarters.
So you don't feel as though your focus on margins and cash flows constraining your growth all it's more of a demand issue?
Yes. I think it's -- we have to execute a little bit better in some of our packaging and pricing. And I would be -- a lot of the foundational technology work, the hard work isn't done. One of our -- and we were meeting with one of our investors earlier, and we were talking about the ability to have integrated data contacts enrichment across the attack surface. We've built out what I would call the hard engineering capabilities, right, and delivering that at a very attractive cost basis is largely there, right? What we have shared is what we need to do is better execution on the packaging and the pricing and then how we actually deliver the integrated capabilities to the market, right? And so that's what we've talked about in this summer.
Okay. And I look at Elizabeth when I ask this question, but net new ARR was relatively low this quarter, right? So you need an acceleration through the rest of the year to kind of targets. I guess, how do you characterize the level of confidence you have in the ability to hit those targets? And what has to be done? Obviously, you just said execute but what has to happen in order for you to get there?
Yes. We -- so what we've said for the remainder of the year, we expect single digit -- high single-digit millions of net new ARR in the second quarter and then that ramping throughout the back half. We said that, that was really dependent on our detection and response business continuing to be healthy this year. And that is really the bulk of what is driving the net new ARR growth this year. Our expectations for cloud risk complete and AM are fairly modest. We expect that revamped offering midway through the summer to get some additional traction towards the end of the year, but there's a very modest amount of that built into our guidance for this year.
Yes. And how we're thing so far? I mean, we're halfway through the quarter. I realize the quarter may be somewhat back-end loaded, but how do things feel so far this quarter in terms of executing to those goals?
I mean there's no update from what we said on our earnings call, just I think things are tracking as we expect.
Yes. I mean what we tried to do, and I think this is a learning for us. Obviously, a hard learning out of Q1 is to provide more specifics on what the levers are that we expect and what those kind of -- so as Elizabeth shared, like D&R is a healthy part of our business. It's over $300 million. It's growing north of 20%. We just expect that, and there's no reason to see otherwise why that won't continue, right? We see nominal contribution of the second package, the CRC package. And what contribution we see is very late in Q4. So okay, that seems reasonable, right? We also assume there's no change in the macro and the spending environment, which is already constrained, right? And so we've tried to do a better job of exactly what the assumptions are. One that we did talk about at earnings was also we see -- we're investing more in the channel versus our -- we had this shift out of direct some higher expense direct efforts. And so we are seeing that channel focus having a really nice impact. But it's kind of like rebalancing water levels, right, where that -- we've got to see that mix shift occur. But again, I think our outlook takes these into consideration. And again, I think we've shown really nice command with cost in the profit side of the equation. So I think we feel pretty good about what we shared during earnings.
Got it. And I guess as we think about the level of investment that you're making into the business, what will drive the incremental -- particularly sales and marketing, what will drive the incremental investment in sales and marketing?
Yes. I think one, it always starts for me with this idea of where -- how do the customer -- the broader customer value proposition, how does that sit? And I've been thinking about it as like a value hierarchy, right? With great visibility you get better monitoring. Our core business today and the value we provide, the share of wallet we get is in the -- helping you detect and monitor and respond to potential malicious or risky behavior in your environment, right? That starts with visibility. So I think now that we're aligning those better, I think that will be key. And then how do we deliver value-added or even more premium services and products on top. So as we work through this, I think we have a lot of capacity in our sales and marketing engine. But as we look to reaccelerate growth in the second half, we don't need to invest or increase our investment in sales and marketing at this point. But as we start to unlock that reacceleration, I think you'll see a natural opportunity as we look at '25 is to be able to drive and continue to drive efficient growth. We have talked about free cash flow expansion or increases of free cash flow through ARR growth, right? So I think we can -- we're set up well to do that. But we also recognize the next couple of quarters. We've got to focus on just driving the execution around our pricing and our packaging and some of these integrated offerings.
Okay. And I think Corey has talked about before selling the platform. Now you have that complete, cloud risk complete. What is the profile of your installed base look like? How much overlap is there? And are I guess, platform sales going to be net new? Or is it going to be more cross-sell of one into the other?
Yes, it's a great question. So we have talked historically about platform versus non-platform customers. And the nonplatform customers were kind of legacy software, people that were off the platform or not running in our cloud. So I think we'll increasingly -- we'll talk less about those. But that has led to some of the kind of I'd say, the long tail, a lot of international customers and whatnot. So what I think you're really hitting on is people that have one of your cloud products, what is their rate of them participating in these consolidated offerings. And we've said this is -- it's quite low. So there's plenty of white space there. One of the opportunities that you'd probably naturally wonder is take our VM base and give them the broader proposition of participating in cloud risk complete. That's absolutely part of our plans, right? We value that part of our customer base, and we think that they have a broader challenge that we can help them with. And we also see the opportunity to take our MDR customers and have them continue not just to do our threat complete offering, but be able to give them also the cloud risk complete offering. So I kind of think of it as a little bit of expansion on both sides of the equation, which will naturally drive us to have more expansion versus net land, but we'll still see some modest land, I think.
Okay. I wanted to pause for a minute and see if there are any questions from anyone in the audience because I think we have got a few minutes left in the session. No takers. Okay. That's okay. I got more.
We got one.
Oh, we got one?
Maybe.
[indiscernible] any areas of efficiency within your cloud platform. It's such a fragmented space with such a priority -- high priority areas of spend that maybe the value prop of your platform resonates less than people are quantifying as best of breed?
Yes, it's a great question about the best-of-breed versus integrated platform. And so our thesis you're definitely not going to compromise. People will not put their security programs at risk by taking subpar quality, right? I think the question we get is what is my security outcome I'm trying to get to. I'll use an example. The example I was giving earlier attack path mapping, right? So in a cloud world, you say, I want to be able to look across a threat graph and be able to see exactly how an attacker might be exploiting my environment. What I've heard several CISOs say is, Andrew, that's great. We need that. But my environment doesn't end at the wall or the barrier of my cloud, right? People can come in across multiple different attack factors, and I need to look at that holistically. And so what I think we're really trying to provide is fuller coverage with still excellent capability. And I think part of the -- as you mentioned, the data, security data, and I think we've seen this, whether it's with IBM and Palo, whether we see it with CrowdStrike, whether you see it with Microsoft, security companies are talking more and more about the value of data or the flip side of the challenges of unlocking this data. And so when I look at it, I don't think it is just providing a bunch of UI. I think it is how do you unlock the power of all the security data to tell you what's going on in your environment. And I think this fragmentation that you referenced, is the problem, meaning if you fragment the attack surface by having point tools and you leave it up to the CISO to be the system integrator, a lot of those CISOs mainstream enterprise, right, for our buyer those mainstream enterprise security teams don't have the resources to integrate those products on their own. And so what we're trying to do is do the integration for them so they can focus on security, and so it's not fragmented, right? Not compromising capability, but in providing them with the ability to focus on their security program. So that's our core thesis. And I think it is a balance, right? But I think increasingly, we're seeing people say, mainstream enterprise, right, is these folks is the majority, right, if you think about the curve. For the majority of these teams, they're already overburdened under resource and they have too many vendors in there, and they've been left to stitch it together, right? And so we are seeing people say they want to see a more holistic view of their tax service.
Any others from the audience? Another one I had is it's been a really difficult environment for logo growth. Your logo growth was a little weak in the quarter. Like how focused are you on increasing the logo count? And how are you incentivizing sales force versus channel to drive that kind of the business?
Yes. So our net logo growth, I mentioned the long tail of the software because we've talked about the non-platform customers. So those as definitely a headwind on it, right? So that will, over time, even get less of a headwind. So that's one element. I think the other part is we are very much focused and we have a great set of customers, right, over, I think it's 11,000 now. Over 11,000 customers that we believe we can help to the previous -- to the gentleman's previous question, about providing a more integrated holistic solutions to help them get to a better place, right? We did it with MDR, we're going to do it with cloud risk complete, right? And so we do believe that's a natural expansion motion as I think most vendors talk about expanding into your current base is going to be less costly more profitable and you're going to be able to get more share of wallet. But I do think there'll be some attraction with people that are also locked out. We will have some modest customer growth over time. But our focus is on expanding and really having -- providing our customers with a more comprehensive integrated solution. And then we'll see some modest growth, but I don't think it will be some dramatic change.
Yes. As you sell into your installed base, you try to expand within your installed base what are you competing with? I mean is it some of these larger platform vendors? Or are there more point solutions? Or how do we think about that?
Yes. I'll just use it in my head on a couple of customers I've talked with, right? So the first thing I'd say is, I've only got so much spend right? And so one of the things we're competing with is just the availability for incremental spend or how they have looked at allocating existing spend. So that's why I think a lot of security vendors are talking about consolidation, consolidation because the spending budget environments are not like they were 2, 3 years ago, right, where people are just, oh, hey, I need more money, I need more money. CISOs like the broader IT spend is constrained. So we're competing against either, a, not doing anything. B, I've already got something that maybe isn't delivering what it needs, but there's money being locked in there. or C, there is some level of inspection or review that we've got to make our customers have to make a case for. Let's take that off the table for a moment. So we still see like our MDR projects getting funded because the detection-based security program is really important. And I think we see more and more people in our industry talking about those projects. So we see that going through. So that way you're competing with this to the previous question is, okay, well, am I going to go a point solution? Or do I look for something that's a more integrated approach to help me so I don't have to necessarily do all this work myself, right? And I think you are seeing a couple of handful of vendors some we've talked about that are taking a more platform-based approach. So the question is, well, you're competing at stand-alone versus platform? Well, why is that? The platform vendors have an argument that by consolidating down, you will get to a better proposition because you can deliver more integrated services, right? So that seems reasonable to me, right? I think we're -- there's roughly 20 to 30 vendors in the average mainstream enterprise security teams environment. That's a lot, right? I mean you get to 5 or 6, you're doing a nice job, right? So then you say, okay, well, then why does our platform have an advantage of these others, right? And this goes back to what I frame is better visibility equals better monitoring and detection response. We have built and we are a leader in this detection and response category, and we are continuing to innovate and invest in that offering, right? And so I think most security people, if you said, is your environment changing? Is it getting more dynamic? Is it getting more diverse? Is it -- generally, that requires a detection-based approach across the environment. It's not just the endpoint and it's not just the cloud. It's from the endpoint to the cloud and everything in between. So our platform presumes you don't have a bias on where the data comes from, and you don't have a bias on only having certain tools in your environment.
Got it. Great. With that, I think we're out of time. So thank you much.
Yes, I appreciate it. Thank you.
Thank you, everyone.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete Rapid7, Inc. transcript - plus 252,000+ transcripts from 12,000+ companies, speaker segments and full-text search - through the EarningsAPI REST API or hosted MCP server.
Get an API key View API docs →For developers and AI pipelines
Programmatic access to Rapid7, Inc. earnings transcripts and 252,000+ others is available through the
EarningsAPI REST API and the hosted MCP server.
Quarterly plans from $105 - full transcripts, speaker segments, full-text search,
and the /api/v1/transcripts/recent polling endpoint for ETL pipelines.