Rapid7, Inc., known for its AI-driven managed cybersecurity operations, has unveiled new cloud security features within Exposure Command, its notable exposure management solution.
The latest enhancements include runtime validation and Data Security Posture Management (DSPM), aimed at helping organizations identify, validate, and prioritize potential risks based on genuine attack pathways and their impact on business operations.
Enhancing Security in Hybrid and Multi-Cloud Environments
As businesses continue to expand across hybrid and multi-cloud infrastructures, traditional security approaches that focus solely on assessments are no longer sufficient.
By incorporating runtime validation and DSPM, Rapid7 is advancing Exposure Command from merely assessing to continuously validating security postures, enabling organizations to proactively reduce exposure across diverse environments. Runtime validation pinpoints vulnerabilities and misconfigurations that are susceptible to exploitation, whereas DSPM contextualizes these risks by linking sensitive data and access identities to genuine attack vectors.
Adapting to Dynamic Cloud Risks
Craig Adams, Rapid7’s Chief Product Officer, emphasized the importance of addressing cloud risks that stem from a combination of vulnerabilities, identities, and critical data.
He remarked, “By embedding runtime validation and data context into Exposure Command, we enable security teams to identify the exposures that pose the greatest risk and prioritize remediation earlier, strengthening resilience before those risks translate into breach impact.”
Key Capabilities of Rapid7’s Cloud Security Tools
- Continuous Runtime Visibility: Analyze and validate active vulnerabilities within live cloud workloads using eBPF-based sensors and AI for baseline behavior assessment. This technique correlates runtime signals with posture findings and relevant business context.
- Monitoring AI-Driven Workloads: Continuously monitor and mitigate risks in AI workloads, moving beyond static vulnerability scores by confirming active exposures.
- Automated Incident Response in the Cloud: Activate automated remediation processes to contain and minimize threats post-detection, including pausing, quarantining, or halting processes.
- Data-Aware Risk Prioritization: Utilize sensitive data intelligence alongside attacker pathways to consistently classify data and map identity access across various environments, allowing for impact-based remediation prioritization.
Proactive Risk Management
The combined power of runtime validation and DSPM significantly boosts Exposure Command’s effectiveness in identifying and addressing exploitable risks. This empowers organizations to identify and remediate active threats before they manifest into real security breaches.
Rapid7 is set to showcase these new capabilities at the RSAC 2026 Conference in San Francisco, taking place from March 23-26 at booth #S-3201. In addition to demonstrations, Rapid7 will hold sessions detailing the exploitation of Cellular IoT and operations within telecom backbones, with experts Deral Heiland and Christiaan Beek leading these discussions.
Rapid7, Inc., a pioneer in AI-powered managed cybersecurity operations, announced new cloud security capabilities within Exposure Command, its industry-pioneer exposure management solution. The introduction of runtime validation and Data Security Posture Management (DSPM) enables organizations to identify, validate, and prioritize exploitable risk based on real-world attack paths and business impact.
As organizations scale hybrid and multi-cloud environments, security programs must move beyond reactive models built on assessment alone. With runtime validation and DSPM, Rapid7 advances Exposure Command from continuous assessment to continuous validation, enabling proactive exposure reduction across hybrid environments. Runtime validation determines which vulnerabilities and misconfigurations are actively exploitable, while DSPM provides critical context by mapping sensitive data and identity access to real-world attack paths that increase risk.
Unpredictable cloud environments
“True cloud risk happens at the intersection of vulnerabilities, identities, and sensitive data in production,” said Craig Adams, chief product officer at Rapid7. “By embedding runtime validation and data context into Exposure Command, we enable security teams to identify the exposures that pose the greatest risk and prioritise remediation earlier, strengthening resilience before those risks translate into breach impact.”
Rapid7’s new cloud security capabilities in Exposure Command include:
- Continuous visibility at runtime: Analyze live cloud workloads and validate which vulnerabilities and misconfigurations are actively exploitable. Leveraging eBPF-based sensors and AI-to-baseline application behavior, the solution correlates runtime signals with posture findings and business context.
- Continuous monitoring of AI-driven workloads: Detect and neutralise deviations in highly complex, unpredictable cloud environments by continuously monitoring AI agents. Going beyond static vulnerability scoring, this validates which exposures are active across AI workloads.
- Automated cloud incident response: Initiate automated remediation actions once a threat is detected and validated. Steps include pausing, quarantining, or killing processes to neutralise and reduce the blast radius of any attack.
- Data aware risk prioritisation: Align sensitive data intelligence with attacker reachability to continuously discover and classify sensitive data and map identity access across cloud, SaaS, and hybrid environments. This shows whether high-value data is realistically reachable through real-world attack paths, enabling remediation decisions based on breach impact rather than vulnerability severity alone.
Remediate active exposures
Together, runtime validation and DSPM enhance Exposure Command’s ability to identify and prioritise exploitable risk, enabling organizations to continuously detect and remediate active exposures before they become legitimate threats.
Rapid7 will be demonstrating the new cloud security capabilities, recent innovations in our Managed Detection and Response (MDR) service, and the full capabilities of Exposure Command live at the RSAC 2026 Conference in San Francisco, March 23-26, booth #S-3201.
Rapid7 will also present the following sessions at the conference:
- Exploiting Cellular IoT Pathways to Compromise Trusted Access -Deral Heiland, Principal Security Researcher, IoT - March 24, 1:15 PM - 2:05 PM PDT, Moscone West 2020
- Sleeper Cells in the Telecom Backbone: Covert Ops - Christiaan Beek, VP of Cyber Intelligence - March 26, 12:20 PM - 1:10 PM PDT, Moscone West 2018