Rapid7, Inc. (RPD) Earnings Call Transcript & Summary

May 23, 2023

NASDAQ US Information Technology Software conference_presentation 36 min

Earnings Call Speaker Segments

Brian Essex

analyst
#1

All right. Good afternoon, everyone. My name is Brian Essex, JPMorgan's security software analyst. And thank you very much for joining us. With me this afternoon, I have Corey Thomas, the Chairman and CEO of Rapid7; and Sunil Shah from Investor Relations on the end there. Maybe to start, for those that are not very familiar with Rapid7 and what you do, could you give us a brief overview of the company? How it was started and when you stepped in to become involved?

Corey Thomas

executive
#2

Okay. Well, one, thank you, Brian, for having me here today.

Brian Essex

analyst
#3

Sure.

Corey Thomas

executive
#4

So Rapid7 started in the early 2000s, primarily focused -- the founders were enterprise software architects, and their big observation was that data collection and cybersecurity was a challenge. And so the company was founded on the premise that you would need lots of security telemetry to manage cybersecurity environments going forward. So they started with their premise and they actually built it out to vulnerability management. I joined the company in 2008, right as they were actually starting to get traction in the vulnerability management space. And that time, they were like 1 or like 8 vulnerability management vendors, so it was like the wild west then. But the thing that was unique and the thing that attracted me to the company was sort of like 2 sort of unique things, is one, their focus on making it easy to actually collect security telemetry. I thought that was going to be a long-term game changer. Before that, I also had a series of start-ups and I was at Microsoft before that, and so I knew the value of ease of use when it came to sort of like making technologies mainstream. And so Rapid7 was one of the few companies that actually had an ease of use and a productivity story when it came to security. So I joined the company then. I became CEO in 2012. And what we went after, it was really the core security operations market, which is about how do you actually collect security telemetry data? How do you actually analyze it? And then how do you actually automate security workflows based on that data? And our whole goal was how do we actually take the complexity and the cost out of security operations while driving up productivity and efficacy? And that's the journey we've been on, and that's what's pretty much catalyzed our success.

Brian Essex

analyst
#5

Great. Great. No, thank you for that. I guess maybe, after that, I think where we'll move is on the macro, everyone's got a pretty close eye on. It's kind of the default question of these sessions. Maybe -- and you guys certainly called it out on your earnings call. Could you share a bit of insight around where you saw pressure last quarter? And have there been over -- any changes in the environment over the past, say, 1.5 months as you've executed past that?

Corey Thomas

executive
#6

Yes. And so last quarter was a lot of what we expected to see. So I would just say that, while there was some mild incremental select questions right around the Silicon Valley Bank, I think, last quarter actually ended quite healthy, and it ended up fairly what we expected to see. We expected, this year coming in, to see incremental pressure in the environment. So let's just talk about that and then break it down. It's one, we see very healthy fundamental demand, but we see customers' budgets under pressure. And so they're trying to do 2 things, do more with less and try to navigate sort of like how they get their projects funded. And so what that means for us is that, one, we need to be part of helping them do more with less. That's our platform, consolidation offerings, our focus squarely on how do we actually help both existing customers and new customers to get more done with a more constrained, tighter budget. So that's one. The second thing that we saw and we expected to see was that customers are going to be working their ways into what their budgets are, and that means that we have to actually get better and better at managing deal cycles and timing and the approval processes that go along with that. And that was definitely par for the course. Now luckily, part of the reason that we were a bit more, I would say, conservative and thoughtful in the first half of the year. And while we expected to ramp, is that we knew coming in, that we would have to have higher coverage ratios because some deals were just going to push out. And so we set our guidance based on the pipeline that we had, and said we needed enough coverage ratios to actually hit these and hit these wells. And exactly what we expected to happen, happened. Now the good news is our teams got better and better at actually forecasting and understanding the deal cycles that they're currently in and asking the right questions about what are the approval processes? What are the time frames? And our customers, frankly, are getting better at navigating that and managing through that. So that was par for the course and was expected. And then the last thing that we specifically saw is we saw a good uptick in our consolidation offerings and packages. And so those are the things that we actually saw as we actually came out and started the year. Sunil, did I miss anything material?

Sunil Shah

executive
#7

No, I think that's right. I think the latter point really speaks to what we're seeing from a customer demand standpoint in this environment, which is customers are trying to do more and get more value for the budget that they're spending. And I think that plays into sort of the engagement that we're seeing with them and the opportunity that we're seeing to consolidate more of their sort of stack and their dollars into a unified offering.

Corey Thomas

executive
#8

I do think the one thing that may get misunderstood because it's somewhat confusing, is there a widening gap between the fundamental demand that security teams see what they need, and the budgets that they're able to get. Now you can actually sort of have 1 or 2 perspectives, is one, is that gap persists and that the security teams don't need it, aren't going to get it, and so it's going to be like that in perpetuity. Of which then, you would see the -- both the growth rates in the public companies and the crisis that you've seen some of the private companies continue. Or the alternate view is, in some ways, what I think that many experts, both across government and across the private sector, is you'll see that lack of investment actually end up causing issues, and that you will see people actually catching up because there are fundamental sort of like lags in sort of like security programs that actually have real material risk for both companies and the U.S. economy.

Brian Essex

analyst
#9

Got it. And from what -- from your perspective, anything you can call out in terms of, I guess, pressure that you can attribute to specific verticals, customer sizes, segments of technology, that is notable?

Corey Thomas

executive
#10

Yes. And so one question we'll get, so I'll just hit it in upfront. So is there a financial services pressure? Look, we think that the finance -- I would say that we did not see any specific pressure in financial services. That said, I think there was a crop of companies that, if you were sort of in a certain profile of regional banks, then you probably saw some pressure if you happened to have deals closed. But we have large insurers. We have a wide cross-section of financial services companies, everything from large insurers to credit unions. So we didn't see any material delta there. Where we continue to see pressure, although not as bad from a pipeline build as we expected, is in the, I would say, the mid-market and lower mid-market. We continue to see pressure there. I would say those organizations are slightly more reactionary to what's happening in the macro economy and uncertainty because they're running on tighter margins and tighter business models. And so they tend to cut spending fast and accelerate spending fast. And so we expected to see pressure there, and that's what we saw the pressure.

Brian Essex

analyst
#11

Yes. How would you differentiate it? It seems like, in the first quarter, a lot of that kind of mid-market, they were slower to get like budgets finalized. Enterprise is faster to kind of like finalize the budgets and get going. Was that different than what you saw kind of through the remainder of the quarter? Or was the, I guess, deal activity like pushed into like the back end of the quarter a bit more as well?

Corey Thomas

executive
#12

It gets a little bit tricky. This is why sales was better than expected. Because what happens in the mid-market is just -- this is, in some ways, where you're sales seems to -- you have so many organizations, so in some ways, your selection bias matters. And so are you good at selecting where you actually spend time? And so I would say that we're expecting less pressure as the year goes on. And that -- but that's just as much of, I think, that our sales teams have actually gotten better at actually figuring out how to qualify which companies are under pressure and which ones aren't under pressure. If you think about the tail end of last year, is that you actually have the pipeline that you actually have, so you're in the deals that you're actually in. This is -- I was joking around with Sunil that this is the first time that I think our sales reps were actually listening to earnings calls. And so might be -- which is actually -- which is great. But it just goes to show that like they're actually taking a much thoughtful approach.

Brian Essex

analyst
#13

So you're doing a better job picking your battles. [ And where you ] the most successful.

Corey Thomas

executive
#14

Picking our battles. Look, in the midsized market, picking your battles matters hugely because there's lots of companies that you can actually spend time on. And ultimately, we have a reasonable amount of salespeople, but it's not unlimited. So how you allocate your time matters hugely in this segment.

Brian Essex

analyst
#15

Great. Great. And then maybe to kind of move to a strategic -- from a strategic point of view, you've migrated from kind of a relatively vulnerability management-centric platform and have recently evolved in kind of adjacent markets, including threat intelligence and cloud security. How would you characterize the catalyst for that migration, the way the platform shifted to those? I guess a year ago, it was like 3 pillars, now it's mostly like 2 with an overlay of vulnerability management to it.

Corey Thomas

executive
#16

Yes. And so there's 2 questions there. One, why did we shift? And two, how are we shifting, right? So one, I would just say, we looked at the security operations market and said that, that market is ripe for consolidation. It's a bunch of point tools and solutions that are fairly expensive, that are fairly complex, and customers will want to rationalize it. That looks like a very good bet, just to be clear. Like the -- if you talk about any market that is primed for consolidation, is you have to have an enterprise-level risk view of your environment and you have to have an enterprise-wide way to actually detect and respond to attacks. That was the thesis. It's been the thesis for like the last 6 years. It's been sort of like a lot of work, but that thesis is actually paying massive dividends now because people do have to figure out how to manage risk across the environment and how detect and respond to attacks across the environment. So that's the why, is that there was a market opportunity that was too complex, that did not have enough reach across the broader ecosystem and had too many failed projects. And so we wanted to actually pursue that. And we actually had a reasonable right to win because we were actually good at collecting security telemetry. The approach, now you actually get to the approach question, is about why did we actually organize our platform offerings and our go-to-market around the risk in the enterprise risk management and around end-to-end threat management? And why is vulnerability management a feature of those things? Well, first and foremost, the cloud is the most -- it is the highest-growth area of strategic importance in the risk space, and it is currently a must-have when the vulnerability management is a something that you should do. And so when you think about prioritizing your sales efforts, one of the most important thing when it comes to prioritizing sales efforts is you want to prioritize those efforts on things that are much likely projects that are likely to close. And so cloud security projects have a higher likelihood of closing their vulnerability management projects. It's where the energy is, it's where the focus is, it's where companies and organizations are. So that's the first thing that we're focused on. The second thing, if you think about the threat space. Part of the reason we've had such consistent growth in the threat space, and I would say that continued even last year, is that the one thing that companies cannot skip over is actually monitor for attacks in their environment. It's a must-have. It is an area where we have competitive position. And so if you look at the SIEM market, you have a bunch of legacy players, IBM, ArcSight. You have Splunk, which is having mixed success. So they're still a very strong, healthy company. And then you have the managed detection response, is where companies need help to actually manage it. And we do high-margin MDR services there. And there, I would say that we're actually gaining rapid share and it's becoming an us and an Arctic Wolf world in that environment. And for the high-margin services for the larger clients, we're actually winning quite substantially there. And so that is an area where the market is actually playing to our favor. It's one of the most consistent areas of land. In the cloud space, it's 100% about how do we actually upgrade our installed base to our cloud security offerings, which is the lower risk way to actually participate in the cloud market.

Brian Essex

analyst
#17

Got it. Got it. And I guess, overall, it recently sounds like vulnerability -- and I think you alluded to it a little bit. Vulnerability management has had like less traction in the market, or maybe it was like slower growth...

Corey Thomas

executive
#18

Well -- yes, let me add [ a heart mark ]. So vulnerability management is actually critical. It's something that people won't stop doing. It's something that they actually need to do when they need to cover their environment. There's 2 trends, and this is part of why we got in cloud security. At the end of the day, vulnerability management is about visibility into the environment, and it's actually about risk management of the environment. What's my risk? What's my exposure? And how do I actually remediate it? Now it has dominated the on-prem world. And so we looked at it and we said, "Listen, we want to be the risk management platform of choice for how people get visibility into their environment and how they manage risk across their environment." In a world where more and more people are actually deploying on the cloud, it became a critical focus and priority for us to actually make sure that we had dominant, strong technology and win visibility and risk management in the cloud, while we actually give up something that we were -- actually had a strength in. So we look at cloud security as a continuation of the vulnerability management focus on visibility and risk management. Now in that light, I would say that more of the new deployments over the last few years have been in cloud, which is why you see urgency of people to catch up on risk and visibility in cloud security space. Lots of what's left in the on-prem world, or they get to add it in the on-prem, happens to actually just be less critical. That does not mean vulnerability management is not critical. It doesn't mean it's not going to be -- continue to grow. But in an environment which we're in right now, where people have to make choices about where they actually do their spend, customers start focusing on like, all right, what is most critical today? And what's the most critical today is the cloud environment and getting visibility and control of the cloud environment. Vulnerability management is still important. It's still something that's going to -- people are going to do. It's still something that's going to expand. But that will happen as budgets loosen back up over time. And we're still -- by the way, we're still closing new vulnerability management business. I'm talking about in aggregate.

Brian Essex

analyst
#19

And I guess maybe on the cloud security side of the business, who do you typically see for competition there? And is that -- it seems like it's a big focus for everybody.

Corey Thomas

executive
#20

It's a big focus for everyone. I would say that we're very disciplined. Like look, we are not going to spend unlimited amounts of money on cloud security and so on marketing. We'll spend an unlimited amount of money on the technology to make sure it's best-in-class technology. But there's people that have massive war chests out there to actually lose money on a go-to-market, and we're not going to lose money on cloud security. The advantage that we have that other people don't is that we have 10,000 customers around the world, of which we are their risk management platform. And so a home run is upgrading 30% of my installed base to our cloud security offerings. A double, this is baseball analogy, is sort of upgrading 20% of our installed base. But the point here is that we're not going out and chasing new. We're actually focused on the very efficient model of upgrading our vulnerability management and our detection and response customers to cloud security, and we have a preferred right to win there because we're already their risk management platform of choice. That's our strategy for cloud security. We're not taking one that says we're going to spend an inordinate amount of money to actually go try to compete for lots of new head-to-head land. It's just not a good use of our capital at this stage.

Brian Essex

analyst
#21

Got it. And as you push into cloud security, are there -- I mean, where are you drawing the boundaries where you think you can be most competitive? Whether it's from the developer side of the equation...

Corey Thomas

executive
#22

Yes. So we're focused on the cloud infrastructure management. So we focus on agentless cloud security, and that is sort of like people that are deploying in multi-cloud ideally, the people who want to assess the risk profile of the cloud. So you can think about this as cloud vulnerability management and cloud security posture management. And then people that want to automate the remediation. So we have a heavy focus on automation in that environment, but that is the heavy focus. Now we cover the full cloud security stack, but where we aim to be differentiated is in 3 areas: 2 today and 1 we have a massive investment in. It's we're differentiated in cloud vulnerability assessment and cloud security posture management and automation. Those are areas -- those are actually 3 areas. And the other one that we're actually adding in, because it's our core expertise, is cloud detection and response. The area's where we actually have strong capabilities, but it's sort of different, it's sort of cloud workload protection, is we have a Kubernetes-centric approach or some people are taking a more agent-centric approach, which is fine and that works for some people. But there's lots of Kubernetes in the world that's actually going fast. But that's our approach about how we're actually approaching, where we're differentiated in that environment.

Brian Essex

analyst
#23

Got it. And then I guess maybe to focus on attach rates. We used to have a little bit of visibility into attach rates. Any comment in terms of how attach rates -- now that you've kind of like re-shifted this platform to both cloud security and threat management or threat intelligence? I mean, how do you think about attach rates now that you've kind of like reorganized the platform?

Corey Thomas

executive
#24

And we are working on how do we actually communicate it to you all over time. Look, so here's what we're doing. We have products that we actually have consolidated into platform offerings, and so what used to be a stand-alone product is now a component of an offering that we still monetize because we actually are charging a higher amount for that consolidated offering. You can think about it a little bit like Microsoft has E3 and E5. We actually are taking an approach that actually says we want to make it simple for people to consume enterprise risk management. And so that includes, sort of like at the baseline level, cloud vulnerability assessment, traditional vulnerability assessment and external threat intelligence. At the next level, that adds security posture management and a whole bunch of other cloud services around that. That model is -- the question is, are you talking about the individual components, of which you have a menu of like 15, 20 different things? Or are you talking about sort of like the traditional product categories? We will actually talk more about that right now. I think the thing that we've actually reported on because our investors had such a big focus about like, are you getting traction with your platform consolidation? Are you getting consolidation in budgets? Well, we sort of like provided some indicators on were specifically the platform consolidation offerings and their traction uptake. And what we said is, in Q4, it was 10% of our new ARR; and in Q1, it was at 20% of our new ARR, and so those are just leading indicators. But Sunil and Elizabeth are continuing to work through how they actually describe the overall taxonomy going forward.

Brian Essex

analyst
#25

Got it. Got it. Super helpful. Maybe on the strategic side, I want to touch on M&A. Can you maybe frame out the rationale behind your recent acquisition of Minerva? What does that bring to your platform? And then I have some follow-ups there.

Corey Thomas

executive
#26

Yes. And so keep in mind, the backdrop is that we're likely going to enter a phase where the -- you can even argue see somewhat of a low and sort of like big security compromises and attacks. But that will escalate 100% sort of like as you actually go forward if you look at what's happening in the attacker landscape, what's happening from a nation-state perspective. And so there's 2 things that we're focused on, is one, we want to have a highly efficient business model. So we're doing lots of stuff to focus on the efficiency of our overall organization and company. That has benefits to investors, of course, from profitability, but it also has benefits of allowing us to actually invest back in. So that's one. The second thing is we want to make sure that our risk platform and the risk and the threat parts of our security operations platform are relevant for the world that we're going to find ourselves in as we actually go forward, and that is actually a very different world. Now we've talked a lot about the stuff that we're doing on the risk side, where we've made significant investments in cloud security, and we've tied that into an overall enterprise risk strategy. The next area is on the threat side of the equation, where you actually have to actually be able to manage threats from the endpoint to the traditional environment to the cloud. Now I talked about our cloud investments in cloud detection response, which is increasing the tech vector. We've done lots of stuff over the last few years to actually get -- not just get market share but get a leadership position in the traditional SIEM market. But one of the gaps was how do we actually think about the -- how do we actually reduce friction in the endpoint ecosystem. Now I want to be clear upfront. We integrate with partners like CrowdStrike and sitting in one and others. But what we're finding is that around the world, there was lots of customers who could not actually afford, I would say, more advanced things, and they were relying on technologies like BitDefender and Microsoft Defender. But they were hard to manage, and they were not integrated into their response. And so what Minerva allows us to do is -- and we have a partnership with Microsoft. It allows us to actually manage directly Microsoft Defender, add some advanced in-memory protection to Microsoft Defender, also a BitDefender and integrate that into our overall Incident Detection and Response platform. So we're able to go from the endpoint, leveraging Microsoft Defender and BitDefender plus Minerva, manage that seamlessly into our traditional SIEM and extend that into the cloud, providing end-to-end threat detection and response. So what you see is that in a world where attackers can actually attack any piece of the chain, we have end-to-end visibility and the thing that we actually liked about the Minerva strategy is it did not acquire customers to actually go do something net new. It allowed them to leverage their vesting investments. Look, Microsoft put a ton of money into the Microsoft Defender strategy, and so it allowed us to actually leverage that investment that was actually already out there to integrate that data directly into our platform and provide a holistic end-to-end solution while solving customers' problems about how to actually manage that environment.

Brian Essex

analyst
#27

Got it. Maybe side or adjacent question there is how closely do you work with Microsoft in that regard? And do you have a lot of visibility on what their road map is?

Corey Thomas

executive
#28

So Microsoft, like maybe the platform is coopetition. I spent a lot of years working at Microsoft, and so I would say that we spend time with and we do work with Microsoft. They compete in some areas. We work together in some areas. This is one of the areas, though, that I would just say is not fraught with tension because it's out there and they want to make their customers successful, and this is part of the integrated sort of like stack. And so this is one area that we actually just work together quite well. And so I just -- I can't comment on the road map.

Brian Essex

analyst
#29

Yes. Okay. Fair enough. In terms of your M&A aspirations and opportunities that you see in the market, particularly considering some of the headwinds that you've seen recently over the past few quarters, how would you frame your appetite from M&A -- for M&A, the pipeline that you see of potential deals? And what might be more attractive segments that you're looking at?

Corey Thomas

executive
#30

Yes. So a couple of different things is that the -- I think Minerva was a good interesting thing because we paid a reasonable price for it for the technology. The traction actually. What it got it was -- it was early stage, but [ probably the reason why ]. I have to say that I'm somewhat cheap, and I really can't tolerate sort of like a big disparity between the public market pricing and private markets. Private markets are starting to reconcile down. Right now, I would say that it's the lower quality companies that are affordable, and so I'm sitting on the sidelines right now. But I do think you'll have decent quality over the next 2 years of companies that sort of like just have big valuation gaps. And that could be interesting, but I have patience right now because I think the prices will actually get to a reasonable level over the next couple of years.

Brian Essex

analyst
#31

Okay. So excellent. Maybe on the execution side, from a sales cycle point of view, I think you touched on a little bit of pressure. We certainly seen it across our coverage and some of the elongation of cycles -- sales cycles. But anything specifically that you're doing to manage deal cycles and return, particularly with regard to that, what seems to be a pretty common approval to procurement type of stage?

Corey Thomas

executive
#32

I don't try to fight the river, and so this just goes down to fundamentals. So there's a couple of things that we actually do fundamentally. First is that you actually have to -- and we had this debate with our team, they've come around mostly. You actually have to have higher coverage ratios. Like if it took you a 3x coverage to actually close the deal before, you got to have a 4, 5x coverage right now because you should not expect things that are normal to actually not happen. And you're going to have delays, so that means you have to have enough pipe and enough deals that are going to close to actually have 1/4 of those deals not closed and you still hit your number. And that's part of why if you look at our original model, we said it was back-end loaded versus front-end loaded because I'm definitely not going to try to change the -- assume the things are going to close fast in this environment. That means that the pipe that I'm building in the first half of the year really is not going to close to the second half of the year. And so -- but we're building pipe that actually has a higher coverage ratio for the second half of the year, presuming that you're going to actually just need more pipe to close. And that's a little bit -- and by the way, that's what played out in Q1. Like our estimates ended up being quite good, is that you had a little bit of economic pressure with the Silicon Valley Bank, and we actually hit our targets, but primarily because we actually sort of presumed exactly what the ratios are going to be that you actually needed. So that's one. The second thing is a sales discipline and training that anyone can actually sell when things are easy. But in this environment, you actually have to be respectful. And you -- part of it, we actually had to -- this is why our sales force listens to earnings calls. We have to humanize it a little bit because what happens is that historically, security teams and [ CCLs ] could greenlight projects, they could say, "We want to fund it. Go." In this environment, [ CCLs ] get pushed back from their finance on their budget. And I don't know about you. No one really likes to actually have authority taking away from them. And so if our sales force goes out and it actually says that like, "Hey, who's the decision maker on this?" Of course, someone's going to say, "I'm the decision maker on it." And so they've had to get better, and this is where our sales leadership is coming in and actually doing, I would say, friendly investigations. And so they had to get better at sort of like doing things like, hey, who do you need to consult on this deal to get it close? Not do you need approval, but who do you have to consult? What's the time line of consultation? That's the stuff that is being adopted. It's not 100% of our sellers yet. But that's the tools and techniques that we're having to put in place to actually make sure that we have clear line of sight and we can better forecast. It has gotten better, and it will get better still as we actually get them more uniform. But that is probably 1 of the 2 or 3 biggest priority areas that our sales leadership is focused on is, yes, I know that this worked in the past, but just because it worked in the past does not mean it works right now.

Brian Essex

analyst
#33

Great. I want to sneak one more in, and then I'll open it up to the audience for questions. But I wanted to ask, net new ARR declined over 50% year-over-year as well as sequentially, guidance implies real acceleration of net new ARR through the rest of the year. Maybe help us understand what factors support confidence in better net new ARR.

Corey Thomas

executive
#34

It's a fair question. I think the important thing is to understand, I always start with why is the question valid and sort of how people think about it. So the thing to look at is we actually had poor sales productivity in Q4, and Q1 was okay. And so why is sort of like sales productivity, which is going to be the primary driver of that, going to be higher this Q4? So let me just be clear. We are not expecting record high productivity or even average productivity for our sales force in Q4. We're expecting sub-average productivity. Okay? And that is still materially higher and last year is higher than Q1, why we actually have confidence in that. There's 3 factors I'd point to that says we don't get to even average productivity, we have to sub-average productivity. The first is that in Q4, our sales team was coming to maturity. That means they were hitting the market where they should be productive right as the economy was turning south. That's just sort of like more unfortunate. But just like we just had that last discussion about how you manage the sales cycle, this Q4 will have the majority, almost all, not all, but like a super majority of our sales team that will actually sort of like be both mature and have over a full year selling in a pressured environment. That's a big difference in terms of experience and expectations. The second thing is that if you look sort of like in the past, our pipe constitute is like 2 classes of things, things that companies should buy but they could delay and things that were must-have. The must-have were the cloud security and Incident Detection and Response. And so if you look at the conversion rates on the things that are must-have, the cloud detection and incident response categories, those conversion rates have stayed fairly consistent. And we're projecting that those conversion rates do not improve at all over the course of the year. Now what we're projecting improves is the percentage of our pipe that makes up those deals in Q4. And we're managing through that, and we're actually tracking the management for that. So again, more mature sales force, consistent conversion rates. It's just the pipe mix, the shift to those must-have areas. The last thing that I'll actually highlight is the thing that we actually talked about earlier, is that do you actually have enough pipe coverage so that like delays, which are inevitable to happen in this environment, don't actually cause you to actually miss and you're fretting about specific things. And again, we've been building up -- and we are. It's not we have. We have to do it every week, building up the pipe over the course of the year to actually have the excess pipe that you actually need in this type of environment. Those are the factors that we're actually looking at.

Brian Essex

analyst
#35

Got it. Got it. With that, I wanted to give an opportunity if anyone out there who wants to ask a question. All right. I have more. We got one?

Corey Thomas

executive
#36

All right. No.

Brian Essex

analyst
#37

No. All right. I guess maybe on that point, a little bit kind of towards execution, progress with the sales transition, and I think you kind of moved from more of a land anywhere to more sell the platform transition that you're currently in the process with through the sales force. How is that going? And how are you tracking progress with your sales force kind of like selling in that motion?

Corey Thomas

executive
#38

Well, I mean first is to understand why. I mean the reason we had to move from a land anywhere is the land anywhere means that we're indiscriminate about whether we're selling the things I should do versus things that I have to do from a customer project perspective, and so we needed to actually force the shift to make sure our sales force was only selling the stuff that was likely to close and had a higher likelihood to close. So that's part of why the land anywhere strategy doesn't work. And by the way, it's not even that they're not actually valid deals. On Saturday, I actually saw like a fairly large customer, [ Bigbank ], and they have one of the very, very large project that's on the should-have list, and I said, "Hey, what's going on with that, can you give me a little bit of insight?" He said, so like a bunch of dollars, it's going to be one of the -- I'm going to green light it. And that's not a great place to be, and so that was the requirement there. Now how is it going? I would say it's going better than expected. And the reason for that is straightforward is the biggest concern whenever you make a change that impacts the sales force is do you actually have a sales force mutiny where they actually sort of like vote with their feet and they walk away. And by the way, in the last 2 years, that's a very real fear. There's 2 things that have actually worked in our favor. The first is that we close enough of those deals that it created envy, and so people wanted to actually do it because they thought it can actually help them hit their number. And so seeing success actually helps, and so that was a positive thing. The other one that we had to do with, the tech environment has gotten more favorable to companies, and so people are less likely to walk because they're not sure they're going to be able to keep the job. And so that's just an environmental change. But those 2 together actually set it up where we're making traction and we have the time to actually make that change with our sales force.

Brian Essex

analyst
#39

Got it. Maybe last one I'll hit you with is vendor consolidation is a theme. I think you've touched on it a little bit. Certainly one that we're seeing resonate across the past few -- several quarters across our space. Where do you see the most traction with share consolidation on your platform? Where is it coming from? And is it skewed toward the mid-market or maybe enterprise clients across the world?

Corey Thomas

executive
#40

Well, that's a great question. It is -- so we see it both on the threat and the risk side. I would just say there's urgency on the threat side, but that's mostly because we can really land sort of like well there. And so from a land perspective, it's happened on the threat side. We expect to see more of the upgrades to the cloud to complete over time. As far as segment of the market, I personally think that Russell 3000 and the private company is an ideal sweet spot right about now. And the reason for that is these are large enterprises, but they have lots of budget dollars and pressures, but they're too big to ignore security. And this is both the private companies and the public companies, and so it's not really the mid-market. It's in that sweet spot of companies that are probably like high hundreds of millions of dollars in revenue to billions of dollars in revenue. Those ones have to do security, but they actually have urgency to actually get some -- they have to do it efficiently. And so we see lots of demand for that right now on the consolidation piece.

Brian Essex

analyst
#41

Got it. Maybe we're almost just about out of time, but I want to hit you with one last one. Most misunderstood things, particularly with around investors with regard to Rapid7 and message that you're trying to get across.

Corey Thomas

executive
#42

Look, I think the most misunderstood is, I think, has most to do with understanding the competitive environment because it's just noisy and actually why it's actually most understood. Here's a simple way to think about it, is that if you look at the landscape of customers and if you think about mainstream enterprises, being that Russell 3000, large, mid enterprises and even the margin constraint, the manufacturers of the Fortune 500. Our goal is not to win 100% of them. Our goal is to be dominant and then win all of them that are actually margin constrained and have to do security but need to do it productively. We're uncontested in that market in that space. We are the most productive security platform for security operation on the planet. And our goal -- and we have a lot of growth by being the dominant provider of technology to those customers. And so it is not an apples-to-apples to look at the whole market. It's really when you think about companies that actually are large have to do security and they want to do it at high levels of productivity and efficiency and they want to have good security and not a $1 more, there's no platform that actually compares to what we actually offer there.

Brian Essex

analyst
#43

Great. Great. With that, I think we're definitely out of time. And so Corey and Sunil, thank you both very much. I really appreciate it, and thank you all for joining us.

Corey Thomas

executive
#44

Thank you all.

Sunil Shah

executive
#45

Thanks, Brian.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete Rapid7, Inc. transcript — plus 252,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.

Get the API View API docs →

This call discussed

For developers and AI pipelines

Programmatic access to Rapid7, Inc. earnings transcripts and 252,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.