In conjunction with

Enterprise Cybersecurity Incident Response Management Across Security, Legal and Compliance

BreachRx builds enterprise software for managing cyber incidents across the whole business rather than inside the security team alone, a category the company brands Cybersecurity Incident Response Management. Co-founders Andy Lunsford, who spent more than fifteen years in privacy law and commercial litigation, and Matt Hartley, previously with FireEye, iSIGHT Partners and Lockheed Martin's Advanced Technology Labs, built it around the premise that breaches are legal, regulatory and communications events as much as technical ones. Buyers are enterprises coordinating security, legal, privacy, IT, communications and executive leadership.

The Rex Platform operates as a shared system of record: role-based workflows activate when an incident is declared, assign owners and deadlines to each function, and log actions, decisions, approvals and escalations with timestamps so the timeline never has to be reconstructed afterward. Cyber RegScout matches incident details and data types against more than 200 cybersecurity and privacy regulations, surfacing notification obligations as facts change. Segmented access controls and protected channels keep sensitive discussion inside legal privilege, while Rex AI adapts tasks as conditions shift.

Positioning rests on breadth rather than detection depth: the tooling assumes a SOC already exists and instead governs what happens once an incident escalates past it. Integrations with Slack, Microsoft Teams, ServiceNow, Jira, PagerDuty, CrowdStrike, Cortex XSOAR, Okta and Google SecOps let incidents be launched and tracked from systems teams already use, with mobile command for responders away from a desk. Recognition includes the Fortune Cyber 60 in 2025, a 2024 SINET16 Innovator Award and TAG's 2025 top-five distinguished vendor list.

Market Segment:

Cybersecurity Incident Response Management (CIRM)

Categories:

GRC - Incident Management