Rapid7
- Market cap
- 859.70M
- P/E (TTM)i
- 41.15
- P/Bi
- 4.37
- EPSi
- 0.36
- Div yieldi
- 0.00%
- 52W posi
- 52%
Anonymous reader poll. Unscientific, not investment advice.
Valuation each multiple against its own 5-year range
Vs. peers Software - Infrastructure
| Company | Market cap | P/E (TTM)i | P/Bi | Div yieldi |
|---|---|---|---|---|
| Rapid7 (RPD) | 859.70M | 41.15 | 4.37 | 0.00% |
| Microsoft (MSFT) | 3.95T | 29.64 | 8.93 | 0.67% |
| Palantir (PLTR) | 483.71B | 172.04 | 49.49 | 0.00% |
| Oracle (ORCL) | 427.25B | 22.15 | 6.91 | 1.42% |
| Palo Alto Networks (PANW) | 336.47B | 1,028.33 | 12.24 | 0.00% |
| CrowdStrike (CRWD) | 278.21B | 7,150.26 | 54.54 | 0.00% |
Other StockVane-tracked companies in the same industry.
Morningstar
Trading 21.6% above Morningstar's fair value estimate.
Analyst note
Rapid7 reported second-quarter results that included sales of $211 million, down 1.5%, and adjusted operating margin of 14%, down 300 basis points. The firm also announced a 12% workforce reduction, which it expects to boost adjusted margins in 2026 and beyond.
Why it matters: Rapid7 is undergoing a transition. It is working to stabilize its core business, with a focus on investing in growing solutions such as its detection and response solutions, which constitute more than half of its top line and grew 5% year over year. At the same time, however, overall top-line growth is being dragged lower by underperforming products, including exposure management tools as well as products in areas such as threat intelligence, vulnerability management, and application security. The challenges faced by Rapid7 are symptomatic of the broader vendor consolidation trend in security. Customers increasingly prefer to bundle solutions onto larger platforms, putting providers without comprehensive platforms at a competitive disadvantage.
The bottom line: We maintain our $10 fair value estimate for no-moat Rapid7. While shares traded up sharply after the earnings report, we view this runup as overdone. We'd need to see evidence that the turnaround that management is attempting, with a clear focus on driving growth through detection and response solutions, is bearing fruit before raising our fair value estimate. We'd also note that the competitive landscape for firms like Rapid7 is getting tougher as artificial intelligence spending drives further consolidation onto larger platforms.
Key stats: The 12% workforce reduction is a step in the right direction, allowing Rapid7 to not only increase operating leverage but also conserve cash for the $600 million in convertible notes coming due in March 2027.
Fair value
Our fair value estimate is $10 per share, implying a fiscal 2026 enterprise value/sales multiple of 1 times.
We forecast Rapid7’s revenue declining at a 2% compound annual growth rate over the next five years. We expect the firm's near- to medium-term growth to be affected by the weakness in its core VM business even as its MDR business continues to grow by single digits.
Rapid7’s gross margins have hovered around 70% over the last three years, due to a modest impact from the growing cloud mix. We expect the firm's gross margins to remain around 70% over our explicit forecast.
Rapid7 spent heavily on research and sales in prior years in order to expand its toolkit beyond vulnerability management. Looking ahead, we expect these line items to decline as a percentage of revenue as the company scales. As well, the firm is entering a cost management phase in order to improve its long-term operating leverage. After achieving GAAP profitability in fiscal 2024, we expect Rapid7 to continue to improve its margin profile, with operating margins around 6% in five years.
Economic moat
We assign Rapid7 a no-moat rating as we believe the company may face challenges that will likely prevent it from meaningfully achieving excess returns on invested capital over the next decade. While we believe Rapid7 is well exposed to secular tailwinds within the cybersecurity industry, we currently do not see the typical moat sources taking hold at the company to the same degree as we would expect for narrow-moat or wide-moat cybersecurity vendors.
Looking at the broader cybersecurity segment, we believe the complexity and intensity of threats are ever-increasing. As enterprises undergo digital transformations and cloud migrations that expand their digital footprints, the number of attack vectors is rapidly increasing. In response to this escalating threat level, IT teams are adopting more cybersecurity tools. However, in many instances, the adoption of more tools creates data silos in which disparate solutions are not interoperable. This lack of interoperability presents the opportunity for cybersecurity vendors to provide multiple solutions within one basket, displacing vendors providing only point solutions. Vendors like Rapid7 can entrench solutions across client workflows, and further grow wallet share among customers as their needs evolve in an increasingly digitized world. For example, an IT team may adopt Rapid7’s vulnerability management solution to gain greater visibility into the risks present in their internal IT environment. As the customer grows, as do the number of attack vectors, the IT security team may onboard additional modules from Rapid7 like its threat intelligence module, allowing the firm to expand usage within a customer while also entrenching itself further into the customer’s security apparatus.
As security vendors entrench numerous safety solutions into clients' IT infrastructure, we see switching costs increase, as it becomes more costly and difficult to rip out and replace security solutions. The transition to a new vendor and re-training of staff on a new platform creates a period of increased expense and vulnerability. Enterprises have high loss aversion in regard to security which makes switching from a functioning platform unlikely. As well, this loss aversion leads to enterprises opting for the most reputable and reliable solution, rather than selecting solely on price.
Rapid7's Insights platform is well-armed with tools to defend businesses against modern-day cyber-attacks across on-premises, cloud, and hybrid environments. We are impressed with Rapid7's portfolio expansion over the last decade through addition of new security modules. However, the competitive landscape for security vendors is tough, with Rapid7 going up against strong platform vendors across its portfolio. For instance, take Rapid7’s InsightsIDR solution. Here, next-gen security information and event management, is offered, as well as extended detection and response. SIEM takes high volumes of data and produces a real-time analysis of a company’s security infrastructure. XDR, a nascent subsector, collects and automatically correlates data across multiple endpoints for detection of threats as well as response. In today’s world with ever-increasing threats and endpoints, there is heightened demand for solutions like InsightsIDR. However, Rapid7 faces stiff competition from the likes of narrow-moat CrowdStrike and Splunk (being acquired by Cisco), both leaders in XDR and SIEM, respectively. As well as these vendors, larger security players like Palo Alto Networks and Fortinet have been expanding into these security end-markets, creating further competition for smaller vendors like Rapid7.
While Rapid7’s platform suggests a sticky offering, we do not see evidence of switching costs. The company does not report its gross or net retention, making it difficult to ascertain its customer lifetime and stickiness of its solutions. Further, as a vendor with substantial exposure to the small and medium sized business market, we’d expect Rapid7’s churn to be higher than its security peers focusing on the enterprise market.
Further, Rapid7 has heavily invested in research and sales and made several acquisitions to expand its security portfolio. As a result, the firm has incurred hefty operating losses and taken on substantial debt. We expect it will be a few years before the firm maintains an economic profit and meaningfully outearns its cost of capital. As well, we fear the firm’s large debt balance will prohibit further investment in its platform to stay competitive with its peers; many of whom have much stronger cash flow generation profiles as well as greater cash in hand. Due to the uncertainty around the firm’s profitability in the near- to medium term, we do not foresee Rapid7 generating excess returns on capital, which precludes us from assigning an economic moat rating to the firm.
Bull case
Rapid7 has strong secular tailwinds in endpoint security and security operations where both markets are projected to grow rapidly.
Rapid7 has the ability to upsell modules to customers and therefore increase its stickiness overtime.
Rapid7 has ample opportunity to capture business within the SMB space, where the firm is less likely to run into competition against larger players.
Bear case
The firm will likely have poor operating leverage and cash flow for the next few years, making it difficult to invest in order to stay competitive.
Rapid7 faces competition from vendors like CrowdStrike and Splunk, which are much larger and more well-capitalized than Rapid7.
As Rapid7 primarily serves small and midsize businesses the firm might be more susceptible to macroeconomic swings and higher levels of churn.
By Malik Ahmed Khan, CFA
Quote time 2026-10-08 10:00:25 · For reference only, not investment advice and not tailored to your situation.