Rapid7, Inc. (RPD) Earnings Call Transcript & Summary

February 11, 2021

NASDAQ US Information Technology Software conference_presentation 41 min

Earnings Call Speaker Segments

Brian Essex

analyst
#1

Good afternoon, everyone. My name is Brian Essex. I'm Goldman Sachs security software analyst. So thank you to everyone for joining us today for the Last Day of our Technology and Internet Conference. [Operator Instructions] And with that today, I'm excited to have just Jeff Kalowski, the CFO of Rapid7; and Lee Weiner, the company's Chief Innovation Officer. Gentlemen, thank you so much for joining me today.

Lee Weiner

executive
#2

Great to be here, Brian.

Jeffrey Kalowski

executive
#3

It's good to be here. Thanks, Brian.

Brian Essex

analyst
#4

Maybe Lee, maybe we can start by framing out Rapid7's evolution. It would be great to kind of get a framework of the background of the company, where it came from. I think it's a little bit different in your space. Where you got initial traction in the market? And what's your focus been to develop into adjacent markets?

Lee Weiner

executive
#5

Yes. So Brian, we've been -- we're founded almost pretty close to 20 years ago now, really on the premise of finding vulnerabilities on your network, right? How do we find vulnerabilities that are created by software? And then how do we help you fix those? And so we had -- we built that product out for quite some time. And right around 2012, what we found was our customers were really looking for more analytical power from those solutions, right? Because 2010, 2011, 2012, technology started to proliferate a little bit more than it had in the previous decade. And organizations were getting overwhelmed with all the vulnerability data. And so we started to kind of really build around a model of how can we create some analytics that help you prioritize, what vulnerabilities you have and then help security operations teams remediate those. And that's kind of really where we started to have other discussions with customers about other challenges they were having around security operations, and we started to hear about concerns around kind of the modern era of computing with -- at the time, it was mobility. It was Software-as-a-Service applications. Cloud was kind of coming around a little bit, but it was still pretty early, but security teams were very concerned about how they could get visibility into that infrastructure and how they could analyze that for vulnerabilities but also for active threats. And then how could they operationalize the output. And so what we did in 2012 and 2013 is we began the development of our cloud-based platform. And that platform really was to help organizations get that visibility, perform those analytics and then automate the output of that. And the reason we built it in the cloud is that we wanted to address this problem for a lot of customers. And one of the failings we saw in the previous era of technology was that you would have to deploy a lot of storage and a lot of compute resources to deal with all that data because it's a lot of data that companies have to collect to understand this. And we wanted to take that burden off of them by building in the cloud. And so that's what we did. And then once we started building that platform, it enabled us to solve different problems. So we started solving a problem around detecting through active threats in your environment, not just finding vulnerabilities, but when do you have an active attack in your environment. It helps you detect that, right, and respond to that. We also started to address things not just about host-based vulnerabilities, but application vulnerabilities. So vulnerabilities that you find in web applications. And then from there, it was kind of a natural progression to say, well, we need to really help security teams more -- be more efficient and more effective. And so we brought automation into the platform. So we've got an automation component that automates a lot of the output of what we provide, so that you can do more with less, right? Your security teams can be more efficient and more effective. And then as we evolved most recently, what we found was again, kind of this next era of technology evolution, which has been the rise of public cloud infrastructure over the last few years. And so with that, we have brought a new offering into our platform called our Cloud Security offering. We acquired a company called Divi Cloud that really allows us to help our customers understand the risk that their cloud infrastructure may bring and how we can help them reduce that. So again, it really comes down to how do we help you deliver visibility and then how do we analyze that for risks and threats and then how do we automate the output of that for you so really improve your security effectiveness and your security posture. We've done some of that -- a lot of that organically, but we've also used M&A as a lever to accelerate some of that inorganically.

Brian Essex

analyst
#6

Right. That's pretty interesting. And then how much of that -- you guys, I think, relative to some of your other peers had more of mid-market exposure than larger enterprise exposure. But I think with mid-market comes more kind of cloud-native architecture. How are you thinking about the shift that we're seeing to cloud and we saw -- we heard from Microsoft yesterday, for example, talking about what they're seeing in Azure is actually from new cloud applications and not old applications, but they do think when those old applications remigrate, we're going to see this wave of new innovation. So how does your exposure to cloud versus on-prem reflect maybe others are seeing in their markets?

Lee Weiner

executive
#7

Yes. So I think you're right. We're definitely -- if you go back to right around the time that pandemic began in March last year, and then you looked at April, May, June, you saw cloud -- public cloud adoption rise, which makes complete sense, right? Because companies were realizing, well, connecting to the data center from home is hard, right? So maybe we should move this stuff to the cloud. I think what you saw and what we've seen over the last few years has been what people will refer to as lift and shift, right? Let's take our traditional infrastructure and lift it and shift it to the cloud. And with that comes a lot of security considerations for sure. I think that's still going on, don't get me wrong, but I think we are seeing now more kind of cloud-native development happen, right? So instead of just how do we take the legacy and try to modernize it, well, how do we build to a better future or a different future on the cloud natively. And I think for us, the great news for us is that we can help our customers with traditional on-prem technology, we can -- we have visibility into that. But we've built over the last few years, and like we said we made an acquisition, 2 acquisitions now in the cloud security space. We also can help you get visibility in your cloud infrastructure, whether it's lift and shift or cloud-native. And so for us, it's a big focus, and we're definitely seeing our customers respond well to that.

Brian Essex

analyst
#8

Excellent. Thank you. It's super helpful. Maybe I want to shoot a question to you, Jeff. I mean, I think characterized commentary by you and Corey at the onset of the pandemic is relatively conservative, certainly in retrospect, which we absolutely appreciate. But maybe if you could help us understand what your conversations have been with, like, been like with customers throughout 2020. And what changed relative to your initial expectations as you continue to weather the environment in 2020?

Jeffrey Kalowski

executive
#9

Yes. I wouldn't necessarily call it conservatism as well -- as much as we were genuinely concerned. And at the time, we did a lot of analysis of our customer base and which verticals were going to be stressed like hospitality, travel. And I think if I recall, I don't know. Sunil can correct me. We widened our range. We went to like $20 million range on ARR, which we had not done. And at the time, we did -- our midpoint was a U-shaped recession and then L-shaped at the downside and a V-shape recession. so we were -- it wasn't really so much as conservative. And we really didn't know at the time. If you remember back in March, April, everybody thought the sky was falling down. But having said that, it turned out to be more of a V-shaped recession for us. And I think as companies realized that they could work from home and they could function and do business, then they still -- they needed security and the work-from-home dynamic made that even more paramount. You had to protect all the workers from home. And that really was a tailwind to our IDR product line with detection and response. So we saw that evolve over the course of 2020. And I'm pleased to say we did a lot better than what we guided to back in that May forecast after Q1. I guess that's how I would summarize it. And what we're seeing is a strong demand for our security transformation solutions that we talked about in the call, and that's growing over 40% right now, and that's the most significant growth driver for us.

Brian Essex

analyst
#10

Excellent. Okay. And then I guess, following the onset of the pandemic, maybe would love your insight around what you saw -- I mean, at least from my seat, I saw an increased priority for tactical spend, right? It was time to keep the patient alive. How have -- but it seems like things are becoming a little bit more strategic. Particularly with the breach in focus at the end of last year and the increased need for network visibility, how do you think about -- I think we talked a little bit about this after your earnings call, but how do you think about the demand environment in 2021 for VM as a strategic tool and for Rapid7 specifically?

Jeffrey Kalowski

executive
#11

Well, I'll talk about the financial side, maybe we can tag team it on the product side. But I think that for VM, we -- it's still a critical component of any company's security hygiene. And it's still a growth driver. We said that it will decelerate. And our position for next year is we're saying the ARR will grow about 10%, and revenue will be a bit higher in the teens. But it is a growth driver, and it is a healthy market. But obviously, security transformation solutions are going to be growing faster in this environment. We've been fairly consistent in our messaging that we said that we would grow faster than the market. But over the course of the year, VM would decelerate. I think in 2020, what we said earlier on, I think, around Q1 or Q2, we said, look, we think the ARR for VM will grow over 10% of the revenue in the mid-teens. We did better than that last year. So we were pleased with our VM performance given the pandemic and really the shift as customers prioritize more about detection response over VM. and I'll let Lee piggyback on some of this.

Lee Weiner

executive
#12

Sure. Yes. I think, look, the vulnerability management problem is core to security teams, right? The hygiene of vulnerabilities and vulnerability risk is going to be important for a long time, for sure. And I think I think what we saw, and I think Corey highlighted this a little bit on the call and said, look, vulnerability management is a long-term problem. It's a very durable long-term problem. It takes time to change your operations and operationalize your patching process. I think what happened in 2020 was the detection response just became more urgent, right? It became more urgent because of some of the work-from-home dynamics. And I think what we'll see is with the threat landscape that could continue, how do you detect these threats? And how do you respond to them when you have an attacker in the environment, right, versus, hey, we're trying to minimize our exposure. Both are important. I think we tended to see last year a little bit more urgency around the [ incident ] response problem.

Brian Essex

analyst
#13

And how has your go-to-market shifted as the company has evolved? I mean are you still -- are you leading with VM right now? Or have you kind of shifted given where demand is to leading with incident response and other kind of security transformation solutions?

Jeffrey Kalowski

executive
#14

Well, I think the way we structured our Salesforce, we have a group that is focused on VM. We also have a group that sells everything and sells Divi and one of the things that we did this year is we have more reps selling more products. We've invested in training. So I wouldn't say that the go-to-market is changing as much as we're becoming more productive and focused on those areas. We want to make sure that we cover all the strategic points.

Brian Essex

analyst
#15

Got it. And then I want to touch on, maybe for Lee. Divi Cloud comes at a really interesting point. Particularly where other major cloud-native vendors like Zscaler or CrowdStrike are going to market with their workload protection platforms and still others like Palo Alto, targeting container security and workflow protection. How do you think about the evolution of the market and the attractiveness of the segment, and how you're positioned in the market relative to other vendors that are maybe coming at it from a different angle?

Lee Weiner

executive
#16

Yes. Yes. So I think, again, kind of from a macro standpoint, we've seen this shift go on for a little while, where organizations are migrating to the cloud. And I think there's kind of 2 dynamics that occur from a security standpoint. You have, on one side, for organizations that maybe are investing heavily in the cloud, have a strategic initiative around migrating to the cloud. They may be building the cloud center of excellence, right? And within that, cloud center of excellence, security becomes a big part of it. How are we going to transform securely? How we're going to build our security program around this? And in that, they look for tooling. And there's some core things that those teams need. Especially today where multi-cloud is almost -- is becoming much more common for a bunch of different reasons, they need a way to understand the hygiene or the risk that the cloud infrastructure may bring based on how we configure it, how we configure storage and applications and compute and users, how do we configure all of that, right? And so that becomes a really big issue for them. And they look to solve that problem with things like Cloud Security Posture Management and cloud identity and entitlement management, which Rapid7 has both of those capabilities, right? The other thing is, as the developers start rolling out applications, they look at rolling out things like containers, and applications through a variety of mechanisms. One of those mechanisms is increasingly Kubernetes. So Kubernetes is an orchestration layer to deploy containers at scale. And there's quite a bit of security needs in that. And so we made a recent acquisition of Alcide, a company we acquired a couple of weeks ago that gives us that container security and Kubernetes security pieces. So really, we're trying to build -- we're trying to bring all these things together, and we want to create an integrated experience and a more comprehensive offering. Now there's other types of companies that are dealing with the cloud probably more reactively. Like there's -- most companies have people spinning up cloud infrastructure. And so for those security teams, basically something lands on their desk, right? And they find out, one way or the other, that there's cloud infrastructure being rolled out. And so they need to get a handle on it. And for that, we can use that same solution we have with Divi Cloud though we have a really good relationship with a lot of those people already, right? Because those people tend to be in the vulnerability management program or the threat detection program or the threat and vulnerability management team, and they're kind of handed this. And so what we're doing is we're bringing these things closer together so that if you're using our vulnerability management solution and you want to access cloud risk, you can easily use Divi Cloud. So we're really trying to meet the customer where they are. And we feel like we're in a very strong position to do that. And again, we'll continue to build out this solution so that it's integrated and comprehensive. To your point, there's fragmentation in this market today, and we're trying to bring that together for people.

Brian Essex

analyst
#17

How would you frame the market opportunity? Is it still extremely nascent and we'll see how things play out? Or do you kind of have clear vision and line of sight into the market that you're trying to penetrate?

Lee Weiner

executive
#18

Yes. I would say it's early, for sure and evolving. But I think to your point, as we look at the way that organizations are rolling out cloud infrastructure, we see strong opportunities in these areas of Cloud Security Posture Management, Cloud Workload Protection and cloud identity and entitlement management. And we think that there's good visibility into continued success and opportunity there. But it is early. I mean, it's definitely an early market, for sure.

Brian Essex

analyst
#19

And how are you handling the selling motion on Divi Cloud? Is this for cloud application and security, I don't know, do all of your -- does your entire sales force? Are they up to speed on it? Is -- are you still kind of in the point where the selling motion is progressing and you need to get to a certain level of penetration with sales force education? And then just trying to understand how that's -- existing customers versus new customers, kind of understand how you're approaching it.

Lee Weiner

executive
#20

Yes. So we're -- I'll just hit, Jeff, real quick. So we're definitely enabling the sales team on cloud concepts. That's been ongoing for the last year. But we're going to continue to do that, right? That's a big part of what we're trying to do to your point. We are seeing success with net new customers, for sure, but also existing Rapid7 customers. So it's a mix of both. Jeff, do you want to talk a little bit about the kind of sales approach?

Jeffrey Kalowski

executive
#21

Yes. We've broadened -- at the time of the acquisition, we just obviously had the Divi sales force, which was relatively small. But we've really broadened that significantly. We've got even our VM -- our larger enterprise group sells that. We -- our SLED group sells it. Internationally, it sells it. So we've enabled more reps. And one of the other things that we did was we have a strong referral structure within the sales organization. You're talking to the customer, and they are talking to each other, and we're incenting the reps accordingly. So we are seeing a lot of pipeline generation just through internal referrals, even those reps that are not selling Divi Cloud are fueling the engine, so to speak. I mean, it's still early, but we are landing new customers as well as selling into the base. And right now, what we're seeing is very encouraging for the rest of 2021 and after that. So we've got more strength this year clearly than last year, and we've made a concerted effort at least to train these reps. That's very part of their structure this year, and they're being rewarded to get trained and up to speed to do that.

Brian Essex

analyst
#22

Got it. And maybe could you shed some light on your cloud identity access management governance module for Divi Cloud? And how has adoption trended? And what does the competitive environment look like in that segment given other access managed vendors might be?

Lee Weiner

executive
#23

Yes. So to clarify your point, Brian. So what Gartner calls this cloud identity entitlement management. Really, what it's about is that when you roll out cloud infrastructure, you create -- you roll out compute at the click of a button. You can create different services on those systems. And they all need permissions, right? They all need permissions on how do they communicate with one another, who has access to it, what machines have access to other machines. So it's not traditional user management at all, right? Traditionally user management of us working in our companies improved provisioning, deprovisioning. That is a very separate market that is well defined. I actually spent a lot of time in that market in my earlier career, very, very different. And so this really is focused on those kind of permissions and entitlements within the cloud infrastructure. And so what we -- what happens with that situation is you wind up with a lot of different permutations, right? And it can get quite complicated, and it can be a risk. And so what we do there is we take all the -- in Amazon, as an example, we can take all the AWS entitlements and roles and analyze them to help you understand what's actually happening and if you want to take a more least privileged access approach, right? How can I reduce the access to reduce the exposure, but still get the functionality I need. And so it's more of a governance approach, as you said, and then a way to automate the response around that. We're -- it's -- we just rolled this out at the beginning -- end of Q3 of 2020, beginning of Q4. So we've got some folks using it for sure. It's definitely early days, but it's going well. We're getting some adoption, but it's definitely early. So from a competitive standpoint, it's mostly small niche players. Like it's not the identity management players. We all know, it's very small niche players.

Brian Essex

analyst
#24

Got it. And then, Jeff, I think we touched on this a little bit on the earnings call, but just to kind of bring it full circle. In terms of the impact of the SolarWinds breach and how it's driven awareness and propensity to invest in better security infrastructure, how do you envision that impacting spend on your platform through over the course of 2021?

Jeffrey Kalowski

executive
#25

Yes. I think it's a more favorable backdrop. It's hard to determine the specific benefit. It definitely helped, but I think it draws more attention to the fact that you've got to have your hygiene. You've got us to be able to have detection response and detect the breach for things like this. So I think what we hope to see is that security budgets loosen up and focus on this area. I mean it brings the discussion also back to the Board level. It's really a high-profile item within corporations and Boards. They've got to pay attention to that. So what we see with the pandemic, we'll see if budgets released in the second half of the year, we'll see how it plays out over the course of the year. But clearly, our products, we believe we have a best-in-class platform. We cover the breadth of -- we're unique in that we have our SaaS platform. We cover vulnerability, application security, detection, response, automation. We don't think there's any company that has the ease of use and the breadth of solution that we have. So we believe that we're well positioned right now to take advantage of the market opportunity ahead of us.

Brian Essex

analyst
#26

And how many of your customers, I guess both new as well as competitive displacement, I mean, are attracted to the end-to-end platform or the breadth of the platform as opposed to the efficacy of a point solution?

Lee Weiner

executive
#27

Yes. I mean, I guess just -- I'll touch on that briefly. Jeff, maybe you can follow-up, too. I think the thing that we've really focused on, to your point is that we've built best-in-class products on top of a platform that interweaves them or interconnects them. So we're not asking our customers to compromise. I think that's the big difference maybe. And so a lot of our customers start with us in one area, whether it's something like vulnerability management or detection response or application security or cloud security, and then they evolve with us, right? And we try to make that easier throughout our evolution. We've got things like common components. So if you use our vulnerability management solution and you deploy some of our data collection technology like our agent to assess vulnerabilities, you can quickly then deploy our Detection and Response Solution because it leverages a lot of that same Detection and Response capability. And we definitely see customers -- I was talking to a company a couple of weeks ago that made that exact journey with us. And what it does, right, is not only do they get that seamless experience, but from our perspective, it changes the competitive dynamics, right? It's less about point to point. It's more about solution. And so that's -- I think our customers have really appreciated that. And we're going to continue to build out more capabilities that are more seamless so that it's -- they can adopt other services easily.

Brian Essex

analyst
#28

Got it.

Jeffrey Kalowski

executive
#29

Brian, just to piggyback on that a little bit. We talked about our ARR per customer at $45,000 with -- and we're adding -- we have customer growth. We have landing with new customers as well as expansion within the base. So last quarter, we said that the customer growth was 8%, and the ARR growth was 18%, which translates to 28% ARR growth. I guess the point I'm trying to make is that it's $45,000. And today, without Divi, we're going to sort of hold something back for Analyst Day in March 10. but our -- what we -- the analysis that we did a while ago, and we're going to refresh it is that an average-sized customer that bought all our products would have opportunity to spend $200,000 of ARR. We're only at $45,000, that is without Divi. So you can imagine in terms of expanding across the platform, once that number goes up, and I'll save that number to Analyst Day, but you can imagine that it's significant with the Divi acquisition and their ASPs. There's a lot of room to grow that number across the base.

Brian Essex

analyst
#30

Got it. Super helpful. And then I want to touch real quick on your strategy behind partnerships. How do you see that ecosystem evolving? And what kind of synergies are you seeing from partner relations, particularly as you are kind of working up market?

Jeffrey Kalowski

executive
#31

Are you asking with respect to the channel or technological partnerships? Or...

Brian Essex

analyst
#32

Both, really. Like as you migrate from more of a mid-market vendor to a large-enterprise vendor, how is that -- how are those relationships maturing?

Jeffrey Kalowski

executive
#33

I'll talk about the channel. We started 1 year or 2 years ago, investing in the channel. We were not as penetrated in the channel as we'd like to be, and we still have wood to chop. We still have improvement to go there. But a couple of years ago, I think we were about 60% direct, 40% channel. I'd say now we're closer to 50-50. I mean, we've seen improvement over the last couple of years. We've taken a key approach that we want to identify strategic partners in regions that are going to focus their resources on adding value to the customers and providing value-added services to make them successful, get them to deploy the products. So that's worked out well so far. We've hired channel managers to cultivate these channel partners. And we are seeing progress to date, but we -- there's ways to go. We can do better, but we like what we see right now.

Lee Weiner

executive
#34

Yes. And then just from the technology side, we've got an approach to an open ecosystem, right? Our customers use a lot of different technology. And so we need to build relationships with a lot of that ecosystem to collect data from those systems and also to process workflow and automation through them. And so it's a big part of the effort of developing those relationships but then also building into that ecosystem in how we do that. So that's a big part of the effort as well.

Brian Essex

analyst
#35

Got it. Great. And then Jeff, I want to touch on M&A strategy a little bit. And just my observation coming out of the global financial crisis, we saw this massive wave of consolidation. Maybe your thoughts on the market in terms of what the pipeline looks like, the -- what impact do you think consolidation might have on your industry? And how you think about, I guess, organic versus inorganic contribution to your platform?

Jeffrey Kalowski

executive
#36

Yes. Well, first of all, we're always primarily organic but always open to M&A. The Divi acquisition was great for us, and we just did Alcide. So we're very excited about that as well. To frame it, I would say that we're not looking for new pillars on the platform, but we are always looking for technology and teams and -- that can enhance the current insight platform, the products across that platform. These would be SaaS companies that would -- "1 plus 1 is 3" kind of things, could accelerate our time to market in development. But one point I will make is that if we do that, it has to be accretive. We have to monetize that acquisition in a relatively short period of time to make it accretive. And I would say that, that's really our focus with respect to acquisitions. We do have a pipeline. We have a corp dev function. We're always looking, but we're going to make acquisitions if they fit that criteria of fitting -- of supplementing our insight platform and then we can monetize it and be accretive in a reasonable time frame.

Brian Essex

analyst
#37

Great. Great. And maybe kind of move to some financial topics. I guess, last year was one where we saw a number of companies benefited from operating in a remote environment because of pandemic-related restrictions. And some of those are going to see headwinds this year as they just let it flow to the bottom line. You guys reinvested some savings back into the business during the year. And how should we think about the investment strategy in 2021? And what pace of operating leverage we can expect kind of going off of last year?

Jeffrey Kalowski

executive
#38

Yes. Well, we're keeping the same philosophy and the same strategy with respect to growing as well as providing more leverage. So let me reiterate the framework. So last year, we did about 0.5 point of profit. And what we said is if we're going to grow 20% to 25%, we're going to add 2 to 3 points of margin. If we grow 25% to 30%, 1 to 2, and over 30% will be less. We do see a growth opportunity, and we want to -- we're a growth company, and we want to make sure that if we have overperformance that we're going to spend it. I like to joke in when we made the commitment to profitability in '19, we said we're not going to leave any money on the table. If we do better, we're going to spend it because it just benefits down the road. So I think this year, we're putting, I don't know, 2.3% more leverage on the bottom line based on our guide at the midpoint. And I just want to say that, that pattern has been in effect over the last 2 years. We've consistently done that in '19. Notwithstanding even with the pandemic, we still invested when we did better than we had forecast. And looking back, glad we did. I mean, going back 3 years, we remember when we did our Analyst Day and the vision of the platform was still early, but we couldn't show as much as we wanted to today, and it's all playing out. Have we not made those incremental investments, we would not be where we are today as our platform being more mature. So I think as the second half progresses and as the pandemic, what we see plays out for the second half of the year, then maybe we'll invest more. We'll have to see how business plays out. But that's been our strategy is that we're going to provide more leverage every year, but we're also going to grow. And it will get better every year. The faster we grow, the less margin expansion and slower, obviously, the more. But that's our plan right now.

Brian Essex

analyst
#39

Got it. And then I want to touch real quick on the cadence of sales cycles. I mean, how did you see sales cycles materialize last year? And how they change into the end of 2020 and into 2021?

Jeffrey Kalowski

executive
#40

It's funny. I was having this conversation with one of the sales VPs, but overall, I don't think the sales cycle has changed dramatically. There hasn't been much of a change. We get asked, well, what was the -- how about SolarWinds, the breach? What did that do? It probably sped up some decisions that were on the fence. We can't quantify the specific ARR that benefited. But overall, like the smaller deal sizes are in the shorter range of maybe 3 to 6 months; and large ones, 6 to 12 months, and not much has changed. But there's one very important thing that did happen in my discussions that when the Divi sales pipeline, where we went to sell to those customers, the sales cycle was accelerated dramatically because they were Rapid7 customers as well. And that was notable. And I wanted to mention it because I thought that was more proof that we'll be able to get more sales productivity and leverage. That synergy is working. But I thought that, that was very notable to talk about, and we're pleased to see that. We had a few deals last quarter that actually accelerated in the sales forecast because they were existing Rapid7 customers.

Brian Essex

analyst
#41

And you're just cross-selling a Divi Cloud into those customers.

Jeffrey Kalowski

executive
#42

That's right. That's right. Well, it was probably the Divi sales organization. And then after the merger, then it accelerated the whole time frame.

Brian Essex

analyst
#43

Got it. And on the sales reps, from a go-to-market perspective, considering now that you have a broader set of solutions and modules to address the market with. How well trained is the sales force, particularly with regard to sales reps have -- as they've evolved, any indications of how to think about the productivity, given that you guys have had a lot of innovation over the past few years to digest?

Jeffrey Kalowski

executive
#44

Yes. It's a good question. We -- I like to say that we invest a lot in training our sales force from early days of onboarding, and we -- one of the things that's unique about what we do is we develop our sellers to train them how to sell to security professionals with a customer focus. So we want our customers to achieve outcome and drive value. And we start them. They come in at the entry levels, and we onboard them, and we train them. And as they move up to higher levels and become a full quota-carrying sales rep, they're trained throughout the sales process. So we put a high priority on that. We invest in education and ongoing training. And I would venture to say that I believe our sales force is well tendered and with respect to retention, I think we do better than most. I think we have a good group, and it's been working well for us. That formula has done very, very well.

Brian Essex

analyst
#45

And any change in the time frame it takes sales reps to contribute to pipeline build relative to historical rates?

Jeffrey Kalowski

executive
#46

I don't think there's any -- typically, you bring on a new sales rep, and they're not productive, they weren't, obviously, but it takes -- if they're graduating through the system, they've been a BDR and they move up and by the course -- their first year, by the end of the year, they're fully productive. And after 9 days, they have certain amount of productivity, whether it's 25%, 50% through the year. But they get up to speed in 3 months pretty quick -- and start really generating. So we see that as a good formula that we're going to continue.

Brian Essex

analyst
#47

Got it. And then maybe last one I had. With regard to gross margins. How should we think about that? I know it's kind of a housekeeping question asked on the call, but just want to get an understanding because I think it was material the decline that we saw over the course of the year, I wanted to understand what the trajectory would be going forward. And how might that impact profitability for the next kind of 1 year or 2?

Jeffrey Kalowski

executive
#48

Yes. I want to separate our aggregate gross margin was about 73%. But remember, the services drags that down. Look at the profit margin, it's not dissimilar from other SaaS companies. We were about 77-odd percent so what's driving in that -- there was some degradation over the course of the year. But what's driving that is more cloud-centric products versus the Nexpose on-prem dwindling. So it's really -- it's a good thing that those cloud products are accelerating. So overall, we think we're going to be in line with other SaaS companies, and we're going to be in that on product margins in that mid- to upper-70% range, overall, mid-70% range. So we don't see that as a negative for long term. There are things that we can do as we scale even more to provide efficiencies. But what you're seeing really right now is really the mix shift to our cloud product.

Brian Essex

analyst
#49

Got it. Got it. Great. With that, I think we're out of time. So Lee, Sunil, Jeff, thank you so much for joining me today. I really appreciate it.

Jeffrey Kalowski

executive
#50

Great, Brian. Thanks a lot.

Lee Weiner

executive
#51

Thanks, Brian.

Brian Essex

analyst
#52

All right. We'll talk to you in about a month.

Jeffrey Kalowski

executive
#53

Yes. Will do. Take care.

Brian Essex

analyst
#54

All right. Take care. Bye now.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete Rapid7, Inc. transcript — plus 252,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.

Get the API View API docs →

This call discussed

For developers and AI pipelines

Programmatic access to Rapid7, Inc. earnings transcripts and 252,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.