AI Buyer Insights:

Cantor Fitzgerald, a Kyriba Treasury customer evaluated GTreasury

Moog, an UKG AutoTime customer evaluated Workday Time and Attendance

Citigroup, a VestmarkONE customer evaluated BlackRock Aladdin Wealth

Swedbank, a Temenos T24 customer evaluated Oracle Flexcube

Westpac NZ, an Infosys Finacle customer evaluated nCino Bank OS

Wayfair, a Korber HighJump WMS customer just evaluated Manhattan WMS

Michelin, an e2open customer evaluated Oracle Transportation Management

Cantor Fitzgerald, a Kyriba Treasury customer evaluated GTreasury

Moog, an UKG AutoTime customer evaluated Workday Time and Attendance

Citigroup, a VestmarkONE customer evaluated BlackRock Aladdin Wealth

Swedbank, a Temenos T24 customer evaluated Oracle Flexcube

Westpac NZ, an Infosys Finacle customer evaluated nCino Bank OS

Wayfair, a Korber HighJump WMS customer just evaluated Manhattan WMS

Michelin, an e2open customer evaluated Oracle Transportation Management

List of Rapid7 Incident Command Customers

Apply Filters For Customers

Logo Customer Industry Empl. Revenue Country Vendor Application Category When SI Insight
AMN Healthcare Healthcare 4230 $5.2B United States Rapid7 Rapid7 Incident Command Security Information and Event Management (SIEM) 2022 n/a
In 2022, AMN Healthcare implemented Rapid7 Incident Command as part of a broader Rapid7 Managed Detection & Response and Insight platform deployment. The implementation targeted Security Information and Event Management (SIEM) functionality to centralize alerting and incident handling across AMN Healthcare’s large, distributed staffing environment in the United States. This effort accompanied AMN’s adoption of Rapid7 Managed Detection & Response, InsightVM, InsightAppSec and InsightConnect to unify detection, automate response, and reduce false positives. Rapid7 Incident Command was configured to deliver core SIEM capabilities including centralized log aggregation, real time alerting, incident triage workflows and playbook driven response orchestration. The configuration emphasized automation using InsightConnect orchestration and standardized investigation playbooks to streamline analyst handoffs and reduce manual triage. Tuning and alert suppression were applied to lower false positive rates while preserving detection fidelity. Integrations centered on the Rapid7 suite, linking Rapid7 Incident Command with InsightVM, InsightAppSec and InsightConnect and ingesting telemetry and investigation data from Rapid7 Managed Detection & Response. Operational coverage focused on SOC operations and security teams supporting AMN Healthcare’s staffing functions across the United States, consolidating events and case management into a single Incident Command workflow. The platform served as the central investigation queue for security operations and orchestration of response activities. Governance changes formalized incident handling processes inside Rapid7 Incident Command, aligning SOC playbooks, escalation paths and audit trails with automated response sequences. Reported activity in 2022 included Rapid7 handling thousands of investigations, reflecting high utilization of the Incident Command and MDR combination. The deployment emphasized unifying SOC workflows, automated orchestration, and tuned alerting to reduce false positives while centralizing Security Information and Event Management (SIEM) operations.
Citywide Service Solutions Professional Services 1000 $233M Australia Rapid7 Rapid7 Incident Command Security Information and Event Management (SIEM) 2020 n/a
In 2020, Citywide Service Solutions implemented Rapid7 Incident Command as part of a Rapid7 Managed Detection and Response engagement to gain 24/7 SOC coverage, improve phishing detection, and stabilize security for a distributed Australian workforce following COVID-19 driven remote work changes. Rapid7 Incident Command was deployed to provide Security Information and Event Management (SIEM) capabilities central to the MDR service model. The implementation centralized telemetry collection and log management, with configuration of correlation rules, alerting pipelines, and incident case management to support SOC workflows. Rapid7 Incident Command was used to instrument detection use cases and incident playbooks consistent with Security Information and Event Management (SIEM) functional patterns, including automated alert enrichment and workflow-driven triage. Platform level integrations were used to ingest telemetry from endpoints, cloud workloads, identity systems, and email platforms to surface phishing indicators and lateral threat activity, aligning the SIEM telemetry layer with the managed detection service. Operational coverage extended across Citywide IT and security operations teams supporting a geographically distributed workforce in Australia, with SOC analysts operating under the MDR 24/7 model. Governance changes focused on standardized incident escalation paths, role based access controls in the SIEM, and documented runbooks for phishing response and remote user incidents. The stated outcomes were continuous 24/7 SOC coverage, improved phishing detection, and a more stable security posture for the distributed workforce using Rapid7 Incident Command as the SIEM backbone.
Modine Manufacturing Company Manufacturing 11000 $2.3B United States Rapid7 Rapid7 Incident Command Security Information and Event Management (SIEM) 2021 n/a
In 2021 Modine Manufacturing Company implemented Rapid7 Incident Command as a central Security Information and Event Management (SIEM) solution to consolidate SOC detection and incident response across its global manufacturing environment. Rapid7 Incident Command was deployed alongside Rapid7 managed services and the vendor’s cloud products, creating a cloud-centric command platform that aligns SIEM and MDR workflows with existing Rapid7 tooling. The implementation leverages typical SIEM and SOAR capabilities, including centralized alert ingestion, case management, automated playbook orchestration, and enrichment-driven triage to reduce analyst workload. Rapid7 Incident Command is described as operating on the same command platform conceptually used by InsightIDR and Rapid7’s SOAR capabilities, enabling coordinated detection and automated remediation across detection and response pipelines. Integrations explicitly reflect Modine’s use of Rapid7 InsightIDR, InsightVM, InsightAppSec, and InsightConnect, with Incident Command positioned to consolidate signals from those cloud-based products into a unified command console. Operational coverage spans Modine’s security operations center, incident response teams, and IT security functions supporting distributed manufacturing sites, providing a single pane for cross-product alerts and response actions. Governance and process changes focused on centralizing SOC detection and automating remediation workflows to standardize incident handling across sites. The implementation context identifies improved incident response and reduced alert volume as reported outcomes of using Rapid7 managed services and the integrated product set including Rapid7 Incident Command.
Showing 1 to 3 of 3 entries

Buyer Intent: Companies Evaluating Rapid7 Incident Command

ARTW Buyer Intent uncovers actionable customer signals, identifying software buyers actively evaluating Rapid7 Incident Command. Gain ongoing access to real-time prospects and uncover hidden opportunities.

Discover Software Buyers actively Evaluating Enterprise Applications

Logo Company Industry Employees Revenue Country Evaluated
No data found
FAQ - APPS RUN THE WORLD Rapid7 Incident Command Coverage

Rapid7 Incident Command is a Security Information and Event Management (SIEM) solution from Rapid7.

Companies worldwide use Rapid7 Incident Command, from small firms to large enterprises across 21+ industries.

Organizations such as AMN Healthcare, Modine Manufacturing Company and Citywide Service Solutions are recorded users of Rapid7 Incident Command for Security Information and Event Management (SIEM).

Companies using Rapid7 Incident Command are most concentrated in Healthcare, Manufacturing and Professional Services, with adoption spanning over 21 industries.

Companies using Rapid7 Incident Command are most concentrated in United States and Australia, with adoption tracked across 195 countries worldwide. This global distribution highlights the popularity of Rapid7 Incident Command across Americas, EMEA, and APAC.

Companies using Rapid7 Incident Command range from small businesses with 0-100 employees - 0%, to mid-sized firms with 101-1,000 employees - 33.33%, large organizations with 1,001-10,000 employees - 33.33%, and global enterprises with 10,000+ employees - 33.33%.

Customers of Rapid7 Incident Command include firms across all revenue levels — from $0-100M, to $101M-$1B, $1B-$10B, and $10B+ global corporations.

Contact APPS RUN THE WORLD to access the full verified Rapid7 Incident Command customer database with detailed Firmographics such as industry, geography, revenue, and employee breakdowns as well as key decision makers in charge of Security Information and Event Management (SIEM).