Skip to content

Rapid7 Launches Cyber GRC to Turn Security Data into Compliance Evidence

Rapid7 launched Cyber GRC, tying compliance evidence to security data it already collects, but withheld pricing, launch frameworks, and integration details.

Rapid7 Cyber GRC third-party dashboard with criticality, type and data-protection charts over a vendor list
Credit: Rapid7

Rapid7 launched Cyber GRC this week, a governance-risk-and-compliance product that pulls audit evidence from the same security telemetry its exposure-management and detection tools already collect, instead of compliance staff rebuilding that evidence by hand elsewhere. According to Rapid7, Cyber GRC brings control monitoring, evidence collection, policy management, risk and issue tracking, and third-party vendor-risk workflows into one workspace tied to live security data, so a control's status reflects current activity, not just the last audit.

Rapid7 folds vendor risk into the same workflow instead of running it separately, arguing outside dependencies carry too much weight to sit apart from internal controls. Rapid7 said that Verizon's 2026 Data Breach Investigations Report, the DBIR, found breaches involving third parties rose 60% year over year and accounted for 48% of total breaches, citing that figure as the reason to track vendor oversight, control status, and evidence in the same place as internal compliance work.

Bill Theissen, managing partner at Cyber Watch Systems, said Cyber GRC's ability to use existing security data, asset inventories, and API connectivity could produce "more accurate, timely, and defensible risk reporting." Phil Harris, IDC's research director for governance, risk, and compliance solutions, said organizations face severe audit fatigue because compliance workflows and security operations run on disconnected systems, particularly where teams still depend on point-in-time spreadsheets and manual evidence collection. Cyber GRC's underlying claim is narrower than the compliance language suggests: it surfaces evidence that controls are operating, not proof an organization has passed or will pass an audit.

Rapid7 did not publish pricing for Cyber GRC, did not name which compliance frameworks the product covers at launch, and did not detail which systems feed its control and evidence data. Cyber GRC also enters a compliance-automation market that already includes standalone platforms such as Vanta and Drata, plus compliance modules built into broader security suites, so Rapid7's differentiation rests on tying evidence collection back to security data customers already generate inside its own platform, not on a new category of tooling.

Share this story

Grace Sullivan

Grace Sullivan writes for the techshooked news desk, covering breaking technology stories across the site's beats. She works to the daily news standard: lead with what happened, name the source, and separate confirmed fact from claim.