Services
Partners
Use cases
Clients
Company
Contact
FRENDE
Technology partner

Rapid7 integrator in Switzerland

We deploy and operate the Rapid7 exposure management solutions — surface inventory, vulnerability analysis and prioritisation. Scanning is the easy part; the programme is the subject.

Why this vendor

A scanner produces thousands of lines. No organisation fixes thousands of lines. The problem of vulnerability management was never detection — it is the decision: what to fix, in what order, within what deadline, and how to prove it was done.

Rapid7's approach rests on a shift of centre of gravity: from the vulnerability to the exposure. A critical flaw on an isolated server with no external exposure is not worth a medium flaw on an asset that is exposed and not inventoried. But you still need the inventory — and that is where most programmes fail, for not knowing what they own.

We integrate the tool, but our value lies elsewhere: in designing the programme. Which prioritisation criteria, accepted by whom, with what deadlines per severity level, and how the teams who fix receive the work. That is as much organisation as technology, and it is what determines whether the investment produces an effect.

Our offensive team brings a direct advantage here: we know what genuinely gets exploited, and what stays theoretical. A high score does not mean a flaw is reachable in your context.

Rapid7
What we bring
  • Designing the programme, not just the tool
  • Prioritisation by real exploitability
  • An offensive view of what is reachable
  • Articulation with the remediation teams
  • Deadline tracking and measured debt
Vendor website
Diagram

From surface to decision

Rapid7 architecture: unified exposure management Exposed surfaceSurface CommandVulnerabilitiesInsightVMExposure Commanda unified view of exposureExposure Command
The inventory governs everything else: you cannot prioritise what you do not know you own.

The products we integrate

Three complementary blocks: what you own, what is vulnerable in it, and what to address first.

Surface inventory

Surface Command builds and maintains the asset inventory, internal as well as Internet-facing. It is the most underestimated block of any programme: almost every organisation we audit discovers, at this stage, assets it did not know it owned — a test environment left online, a forgotten domain, a machine rebuilt without being declared.

Surface Command

Vulnerability analysis

InsightVM provides continuous detection and tracking over time. The value is not in the number of flaws found but in the trend: is the debt shrinking, are deadlines being met, do the same assets come back on every cycle. Those are the three questions the executive team asks, and a one-off scan answers none of them.

InsightVM

Prioritisation and decision

Exposure Command brings inventory and vulnerabilities together to produce a decision rather than a list. Prioritisation crosses technical severity, the asset's real exposure and its business importance — all three, not just the first.

Exposure Command
What makes the difference

A vulnerability management tool deploys in a few days. A programme that lasts requires prioritisation criteria everyone accepts, deadlines negotiated with those who fix, and a shared measurement. That is what we build with you, and it is what determines whether the investment produces an effect.

Exposure Command
Our approach

How we proceed

The cycle matters more than the tool. A programme that does not close its loop produces reports nobody reads.

Exposure management cycle 01Assetinventory02Continuousdetection03Prioritisation04Remediation05VerificationContinuous cycle
The cycle repeats: each turn verifies what was fixed and re-measures the remaining debt.
Frequently asked questions

Frequently asked questions

The design of the programme and the reading of its results. Our offensive certifications — OSCP, OSEP — let us judge whether a vulnerability is genuinely exploitable in your architecture, which no generic score tells you. Between a theoretical flaw and a reachable one, the gap changes the order of work completely.

It is enough to produce a list. It does not say what to fix first, does not know the business importance of your assets, and does not measure whether deadlines are met. The difference between a scanner and a programme is the decision — and a decision requires criteria that are written down and accepted.

They answer different questions. Vulnerability management covers broadly and continuously, but without judging the chain of exploitation. A penetration test covers narrowly and at a point in time, but proves what an attacker would actually obtain. The two complement each other — we do both.

Yes, through our support and managed service offering: running the cycles, qualifying results, tracking deadlines and producing the indicators. Or through a handover, if your teams take the programme on.

Thousands of lines, or decisions?

Describe your situation — we start by looking at what you know of your own surface.