What is our primary use case?
My main use case for Rapid7 MDR is to onboard all new applications, both built in-house and third-party acquired. As part of the onboarding process, I run them through a sandboxed environment and allow Rapid7 MDR to do an initial scan, looking for vulnerabilities that might not otherwise be publicly announced. Then, on an ongoing basis, while applications live and survive within the McKesson environment, I use Rapid7 MDR to aggregate data about new vulnerabilities or things that may have been discovered to determine if I have to do any kind of hardening or shelf the application.
A specific example of how I used Rapid7 MDR during the onboarding process involves a large number of applications within the healthcare environment, particularly information technology, that come from companies that may have a less than reputable stance as it pertains to their security. Change Healthcare would be a very good example. I had just purchased or acquired a new practice in the United States that was still using Change Healthcare software. I started an onboarding process of all the applications they have in their environment, and I used Rapid7 MDR in a sandbox to figure out if those were still vulnerable to the breach that occurred in 2024. It turned out that almost all of the applications that practice was using were in fact filled with the vulnerabilities that caused the 2024 breach.
What is most valuable?
Rapid7 MDR offers excellent features including a cloud-based platform that provides quite a bit of detailed ways to break information down into more digestible little bits. It is very user-friendly, very broad, and it has a lot of tools. It does require quite a bit of a learning curve, but it allows me to aggregate data and put it into presentations to send to the executives to let them know where their security stands as a whole across the entire enterprise.
My favorite aspect of the user-friendly interface is that the primary cloud-based dashboard is my most useful one that I tend to work with. I love the fact that even inside of a browser, the intuitive help options for figuring out what things are, whether it is hovering over a particular option and it giving me insight as to what I am looking at or even all the right-click features that offer tools and tips on how to interact or manage the vulnerabilities when I find them, are extremely helpful.
I would add that the interface is very clean; it is not overly convoluted or difficult to navigate, so I do enjoy interfaces that do not muddle things up.
Rapid7 MDR has positively impacted my organization because we migrated from several different platforms previously. When I started using Rapid7 MDR as my primary option, I still have other tools in the environment, but I think the impact has been that we are discovering all of the vulnerabilities that are out there, whether they are publicly or even zero-day, a lot faster and more efficiently than I ever did in the past, which is saving the company a lot of money in compliance issues and fines and possibly even lawsuits.
Regarding specific outcomes or metrics, I cannot speak to the financial aspect as that is an entirely different department. However, I can speak to the number of vulnerabilities that I am discovering. Discovery and remediation have improved by almost thirty-seven percent just in the last two years alone. Remediation especially has gone up significantly because I am finding these things and because Rapid7 MDR gives me tips on how to remediate or harden against them, whether that could be hardening options or upgrading to a better version if it is available. It does save the company money; I just do not know how much.
What needs improvement?
All software has its limitations, and Rapid7 MDR, although it is getting better every time a new update or version comes out, needs to improve on its zero-day detection for anomalous things without the use of other third-party software like Veracode or things that I would have to purchase. Having that in-house with Rapid7 MDR would be a much better feature. That is the only thing I can think of outside of maybe a couple of menu options that need to be cleaned up on the cloud platform.
Regarding additional improvements, it would be really beneficial if the integration with ServiceNow and OneTrust as a GRC platform would be significantly valuable to a lot of enterprises, especially McKesson.
For how long have I used the solution?
I have been working in the fields of cybersecurity on and off for about twelve years, sometimes as a project or program manager and sometimes as an information security officer.
What do I think about the stability of the solution?
Rapid7 MDR is a very stable platform, and thanks to its continuous updates and the transparency from the company, I have not had any real issues with it at all.
What do I think about the scalability of the solution?
Rapid7 MDR's scalability is very good; it works for small enterprise solutions and large enterprise solutions. McKesson is a very big global company, and I was able to put it out there almost within less than three months. I was able to scale it up between fourteen different countries and over fifty thousand endpoints and employees.
How are customer service and support?
Customer support from Rapid7 is superb. I am not an expert at everything, so when I get confused or have issues, an email or even a phone call takes no more than fifteen minutes to get the issue resolved, and I have never had a problem getting the right answers from somebody.
Which solution did I use previously and why did I switch?
I was only part of the team long enough to see the end of the previous solution; I did not get to use quite a bit of it, but it revolved around RSA's Archer platforms.
What was our ROI?
I can give a general amount of the return on investment, only speaking from an information security officer's point of view. It does not necessarily reduce the number of staff because I have always operated pretty lean as it is, but it does reduce the amount of issues that face the company, particularly when it comes to compliance or any laws or even lawsuits. I would imagine there has probably been a significant amount of money saved from a legal and compliance aspect and definitely as far as time, because I am able to fix things faster, identify things quicker, and remediate those things even faster than I could possibly imagine. That has to save a lot of time because it frees me up to do other things like forensic investigations or rebuilding of the enterprise.
What other advice do I have?
Regarding Rapid7 MDR's AI capabilities, I think the governance and security is very malleable, which can be valuable to a lot of my teams. Because of that, I can also lock it down and harden it, which I find very useful. The tool itself or the AI integration has been very useful for simulations and for other areas where I might be installing a piece of software and it going out and finding the dependencies that software is going to need to operate correctly and then identifying the vulnerabilities in those dependencies.
Concerning the accuracy and reliability of Rapid7 MDR's AI capabilities, I think the accuracy and reliability is decent for an AI platform, but it does require and will, I think, always require double-checking the sources of the information to make sure that I am not getting AI slop.
The transparency of Rapid7 MDR in terms of gaining visibility into detections and investigations is wonderful. The support that comes from Rapid7 as a company is also wonderful. When I have massive audits or things that are flagged that might cause problems in the future where I might need some assistance from the software itself or from the providers, the vendor, I have had nothing but astounding support and transparency when it comes to those things, especially concerning the findings that Rapid7 MDR is producing.
In terms of how the inclusion of digital forensics and incident response within the MDR service has impacted my incident recovery process, I have only been on the incident recovery team for a short while, less than six months. But in the short time that I have been working with incident response and incident recovery, the tools that Rapid7 MDR provides allow me to rapidly pull all the data necessary, whether it is the drives, the RAM, everything, and then coalesce it into a report that allows me to break that data down into smaller bytes and figure out exactly what had happened, when it happened, and who did it.
Regarding my impression of the risk-aware detection features in Rapid7 MDR, I find that report very valuable. The fact that Rapid7 MDR includes that on all platforms, whether it is the on-prem or the cloud or hybrid, gives me great insight on what to look for. I can narrow those things down specifically to software that revolves around the healthcare industry because that is my primary focus, but I can also widen it to a global set too.
Currently, I am not using the AI-assisted risk-aware investigation workflows as it has not been enabled. That is going through an AI review board to make sure that it is going to be useful and that it is secure. Once that is approved, I am sure I will start using it.
I am taking advantage of the expanded ecosystem telemetry support, and as far as the correlation and visibility, I would say that it has made it significantly more efficient. It also allows me to create or generate reports when necessary and on the spot to take to executives, vice presidents, even senior managers to say, "Hey, we need to make a change," or, "Hey, this is going to be a problem," which has sped up the process of my remediation techniques considerably.
I unfortunately did not sit in the seat for licensing or pricing or anything, so I do not really have enough authority to speak on that.
If you are looking for a solution that is going to help you identify and even give remediation tips or hardening tips to the vulnerabilities that exist within your infrastructure, Rapid7 MDR does a phenomenal job. I do not know much about the costs or the licensing or the seats behind it, but I have to imagine that the costs are a great deal less than a federal lawsuit. I would rate this product nine out of ten based on my overall experience.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?