3 Sources
[1]
ServiceNow debuts six autonomous security products built on Armis and Veza
ServiceNow Inc. today unveiled six security products and a group of artificial intelligence agents it says can carry vulnerability and incident work through to closure without an analyst driving each step. The launch is ServiceNow's biggest security push since it closed two large acquisitions. Its $7.75 billion purchase of connected device security company Armis Inc. closed on April 20. Identity security firm Veza Inc. closed on March 2. ServiceNow did not disclose that price, though it reportedly came in at $1.3 billion. ServiceNow pulled both into a portfolio it branded Autonomous Security & Risk in May, and today's products extend it. ServiceNow calls the underlying shift "Shift Zero," a move away from reactive tooling toward controls embedded at every layer, with a stated goal of zero exposure at any given moment. Fragmentation is the problem the company points to. Security teams at a typical enterprise juggle more than 70 tools, ServiceNow said. Endpoints, cloud environments and identities each get watched separately, and the findings rarely get looked at together. Agentic Exposure Management is the entry point. Vulnerability findings from any source land in a single stream. ServiceNow then layers on threat intelligence and a prioritized remediation list. A second release, the Vulnerability Resolution AI Specialist, does triage at enterprise scale. The specialist can also push low-risk patches on its own. Three releases cover detection. Application Security now runs threat modeling on AI-generated code and model dependencies, which ServiceNow says catches supply chain problems ahead of deployment. A dynamic application security testing product checks live applications and application programming interfaces for flaws that only show up at runtime. External attack surface management looks at infrastructure from the outside, the way an attacker would. Cyber-physical coverage comes largely from Armis. Agentic AI for Cyber Physical Security finds devices across operational technology and medical networks without installing agents on them. It sets behavioral baselines, checks compliance continuously and models attack paths so teams can see how an adversary would move. Remediation workflows run in brownfield environments without custom engineering, the company said. Veza shows up in identity. AI Agent Access Security unifies access control for AI agents regardless of platform or model provider. The other identity release, Non-Human Identity Remediation, goes past risk scoring into action. It rotates keys, deprovisions accounts and revokes permissions across IT, operational technology, internet of things and medical networks. Response and compliance make up the last two. ServiceNow's Tier 2 SOC AI Specialist, aimed at second-tier security operations center work, can build a multi-phase response plan for a complex incident and then execute it. Enrichment, correlation and containment run without a human. Anything high-risk goes to an analyst. Compliance is handled by a set of continuous monitoring agents. They check segregation of duties, access rights and configuration state in real time, both inside ServiceNow and in outside systems. Reports are available on demand. Covered frameworks include System and Organization Controls 2, the International Organization for Standardization's ISO 27001 standard, the Payment Card Industry Data Security Standard and the Health Insurance Portability and Accountability Act. The sixth product, Cryptographic Asset Compliance, hunts down legacy cryptographic algorithms across on-premises and cloud environments. It also guides the migration to quantum-resistant standards. "Machine identities double every 18 months. Fragmented security tools can't match the curve AI is creating," said Yevgeny Dibrov, senior vice president and general manager of cybersecurity and risk at ServiceNow, who co-founded Armis and was its chief executive. "Organizations need autonomous security and governance that matches the scale, velocity, and unpredictability of the threats coming." Eight of the products are available now, including Agentic Exposure Management, Application Security and both identity releases. Dynamic application security testing, external attack surface management and the cyber-physical package are also shipping. Four more arrive in December. Those are the Tier 2 SOC AI Specialist, the Vulnerability Resolution AI Specialist, continuous control monitoring and Cryptographic Asset Compliance. Security has been one of the faster-moving parts of the business. ServiceNow's security and risk unit crossed $1 billion in annual contract value last year, and Chairman and Chief Executive Bill McDermott called the company "the fastest-growing major enterprise software and cybersecurity company" in its second-quarter earnings release in July, when AI annual contract value also passed $1 billion for the first time.
[2]
ServiceNow delivers Autonomous Security, the industry's most complete security offering
ServiceNow unveils six unified security solutions with AI Specialists to enable prevention-first, AI-native cyber defense that operates at machine speed ServiceNow today announced an acceleration of its Autonomous Security vision with six unified solutions that help deliver prevention-first, AI-native cyber defense across unified exposure management, continuous vulnerability detection, cyber-physical security, identity and access security, and agentic incident response, and cyber risk and compliance. With new AI Specialists that complete security workflows autonomously, including the Vulnerability Resolution AI Specialist, these capabilities enable enterprises to prevent, contain, and remediate risk at machine speed, before threats become breaches. As enterprises adopt agentic AI, security teams face an emerging challenge: every new agent, identity, and line of code multiplies exposure faster than any human team, or any patchwork of disconnected tools, can respond to. Closing that gap requires governed autonomy at the same machine speed. The average enterprise runs more than 70 security tools, fragmenting insights across the extended attack surface, including endpoints, networks, cloud environments, and identities. Today, ServiceNow becomes one of the most complete and fastest-growing security companies built for the AI era by consolidating this complexity into one unified system where assets, identities, and agents are visible, contextualized, secured, governed and auditable in a single motion. This is achievable through Shift Zero: the move from fragmented, reactive security to prevention embedded at every layer, where every system, identity, and agent is governed and secured in real-time as threats move at AI speed. In Shift Zero, the goal is zero exposure at all times with an enterprise able to answer, with proof, what every system is doing, why, and who is accountable, while AI moves as fast as the business needs it to. "As AI exposures compound exponentially, security teams operate on a human clock," said Yevgeny Dibrov, SVP and GM, cybersecurity and risk, ServiceNow. "Machine identities double every 18 months. Fragmented security tools can't match the curve AI is creating. Organizations need autonomous security and governance that matches the scale, velocity, and unpredictability of the threats coming: where all assets, identities, AI agents, critical infrastructure, cloud environments and code are protected, and can adapt as fast as the ecosystem moves to detect and remediate threats in real-time. Security becomes an accelerant, not the brake." Shift Zero: Prevention embedded at every layer Autonomous Security moves companies from reactive, fragmented security to prevention-first, autonomously governed security that operates faster than AI creates risk. The Autonomous Security offerings stand on six solutions that integrate into ServiceNow's AI Control Tower. Unified Exposure Management: Exposures pile up in silos, with security teams seeing vulnerabilities but not the assets that matter or which ones could be easily exploited. ServiceNow consolidates findings from any source and enriches data with business context and exploitation intelligence, enabling autonomous remediation at scale. * Agentic Exposure Management consolidates vulnerability findings from every source into a single stream enriched by Early Warning threat intelligence and Fix Intelligence prioritized remediation. * Vulnerability Resolution AI Specialist orchestrates triage and remediation at enterprise scale, executes low-risk patches, and turns exposure backlogs into closure pipelines. Continuous Vulnerability Detection: The attack surface spans code, cloud, and infrastructure, but traditional tools only see one layer at a time. ServiceNow closes these gaps, enabling security teams to govern code, cloud, and infrastructure risks from a unified platform. * Application Security extends threat modeling to AI-generated code and model dependencies with a new version that surfaces supply chain vulnerabilities before deployment. * Dynamic Application Security Testing (DAST) validates runtime vulnerabilities in live applications and APIs. * External Attack Surface Management (EASM) surfaces infrastructure exposure that attackers can exploit, showing a footprint the way threat actors see it. Cyber-Physical Security: OT, medical devices, and IoT systems can be blind spots because legacy tools disrupt production and lack the behavioral understanding needed to catch risky activity. ServiceNow brings continuous visibility and compliance monitoring to operational environments without disruption. * Agentic AI for Cyber Physical Security delivers agentless discovery across OT and medical networks, establishes behavioral baselines, validates compliance continuously in real time, and models attack paths, so security teams understand adversary movement. Automated remediation workflows execute across brownfield environments without custom engineering. Identity & Access Security: Non-human identities, service accounts, cloud identities, and AI agents are everywhere and almost entirely ungoverned. ServiceNow enables security teams to see, control, and govern every identity across the enterprise under consistent least-privilege principles. * AI Agent Access Security unifies access control for AI agents across any platform or model provider, closing the threat vector of ungoverned agents with escalated permissions. * Non-Human Identity Remediation moves beyond risk scoring into active action: automated key rotation, deprovisioning, and permission revocation at scale across IT, OT, IoT, and medical networks; enables AI agents and service accounts to operate under identical identity governance as human users. Agentic Incident Response: Incident response teams can lose hours stitching together threat intelligence, asset ownership, and identity data when they should be stopping threats. ServiceNow automates triage and investigation, freeing analysts to focus on sophisticated threats. * Agentic Incident Response enables ServiceNow's Tier 2 SOC AI Specialist to autonomously build and execute multi-phase response plans for complex incidents, performing actions like enrichment, correlation, containment and blocking while escalating only high-risk decisions to human analysts. Cyber Risk and Compliance: Compliance remains a pre-audit scramble. Evidence collection is manual, controls are monitored quarterly, and organizations are stuck playing catch-up. ServiceNow transforms compliance from a seasonal event into a continuous operational signal. * Agentic AI for Continuous Control Monitoring transforms control evidence into a continuous operational signal. Automated agents evaluate segregation of duties, access rights, and configuration state across ServiceNow and external systems in real time, surfacing violations the moment they occur. Compliance-ready reports exist on demand across regulatory frameworks including SOC 2, ISO 27001, PCI-DSS, and HIPAA. * Cryptographic Asset Compliance enables rapid migration from legacy cryptographic algorithms to quantum-resistant standards before the quantum threat window closes. ServiceNow delivers comprehensive discovery, AI-powered risk profiling, and guided migration workflows across on-premises and cloud environments, with full integration to ServiceNow Integrated Risk Management and Governance, Risk, and Compliance (IRM/GRC) products for regulatory compliance evidence at enterprise scale. What customers are saying about ServiceNow's security leadership "For organizations operating complex industrial environments, effective cybersecurity starts with understanding risk and maintaining visibility across the enterprise," said Brandon Glaze, Sr. Director, Cybersecurity (OT/ICS) at Baker Hughes. "We've appreciated the collaboration and innovation from the ServiceNow (Armis) team as we continue working together to improve cyber resilience and support secure, reliable operations." ServiceNow is building the world's most complete end-to-end security offering. Today's announcements are powered by ServiceNow's proven track record in security and risk and the depth of Armis and Veza now inside ServiceNow. Armis provides continuous, non-invasive visibility across every connected asset, tracking billions of devices in real time. Veza's Access Graph maps effective permissions across human, machine, and AI identities. Together, they feed ServiceNow's AI Control Tower, Context Engine, and orchestration layer with the unified business and operational intelligence that enables autonomous remediation with full governance and auditability.
[3]
Servicenow Unveils Six Unified Security Solutions with Ai Specialists to Enable Prevention-First Ai-Native Cyber Defense
ServiceNow announced an acceleration of its Autonomous Security vision with six unified solutions that help deliver prevention-first, AI-native cyber defense across unified exposure management, continuous vulnerability detection, cyber-physical security, identity and access security, agentic incident response, and cyber risk and compliance. With new AI Specialists that complete security workflows autonomously, including the Vulnerability Resolution AI Specialist, these capabilities enable enterprises to prevent, contain, and remediate risk at machine speed, before threats become breaches. ServiceNow becomes one of the most complete and fastest-growing security companies built for the AI era by consolidating this complexity into one unified system where assets, identities, and agents are visible, contextualized, secured, governed and auditable in a single motion. This is achievable through Shift Zero: the move from fragmented, reactive security to prevention embedded at every layer, where every system, identity, and agent is governed and secured in real-time as threats move at AI speed. In Shift Zero, the goal is zero exposure at all times with an enterprise able to answer, with proof, what every system is doing, why, and who is accountable, while AI moves as fast as the business needs it to. Autonomous Security moves companies from reactive, fragmented security to prevention-first, autonomously governed security that operates faster than AI creates risk. The Autonomous Security offerings stand on six solutions that integrate into ServiceNow?s AI Control Tower. Unified Exposure Management: Exposures pile up in silos, with security teams seeing vulnerabilities but not the assets that matter or which ones could be easily exploited. ServiceNow consolidates findings from any source and enriches data with business context and exploitation intelligence, enabling autonomous remediation at scale. Agentic Exposure Management consolidates vulnerability findings from every source into a single stream enriched by Early Warning threat intelligence and Fix Intelligence prioritized remediation. Vulnerability Resolution AI Specialist orchestrates triage and remediation at enterprise scale, executes low-risk patches, and turns exposure backlogs into closure pipelines. Continuous Vulnerability Detection: The attack surface spans code, cloud, and infrastructure, but traditional tools only see one layer at a time. ServiceNow closes these gaps, enabling security teams to govern code, cloud, and infrastructure risks from a unified platform. Application Security extends threat modeling to AI-generated code and model dependencies with a new version that surfaces supply chain vulnerabilities before deployment. Dynamic Application Security Testing (DAST) validates runtime vulnerabilities in live applications and APIs. External Attack Surface Management (EASM) surfaces infrastructure exposure that attackers can exploit, showing a footprint the way threat actors see it. Cyber-Physical Security: OT, medical devices, and IoT systems can be blind spots because legacy tools disrupt production and lack the behavioral understanding needed to catch risky activity. ServiceNow brings continuous visibility and compliance monitoring to operational environments without disruption. Agentic AI for Cyber Physical Security delivers agentless discovery across OT and medical networks, establishes behavioral baselines, validates compliance continuously in real time, and models attack paths, so security teams understand adversary movement. Automated remediation workflows execute across brownfield environments without custom engineering. Identity & Access Security: Non-human identities, service accounts, cloud identities, and AI agents are everywhere and almost entirely ungoverned. ServiceNow enables security teams to see, control, and govern every identity across the enterprise under consistent least-privilege principles. AI Agent Access Security unifies access control for AI agents across any platform or model provider, closing the threat vector of ungoverned agents with escalated permissions. Non-Human Identity Remediation moves beyond risk scoring into active action: automated key rotation, deprovisioning, and permission revocation at scale across IT, OT, IoT, and medical networks; enables AI agents and service accounts to operate under identical identity governance as human users. Agentic Incident Response: Incident response teams can lose hours stitching together threat intelligence, asset ownership, and identity data when they should be stopping threats. ServiceNow automates triage and investigation, freeing analysts to focus on sophisticated threats. Agentic Incident Response enables ServiceNow's Tier 2 SOC AI Specialist to autonomously build and execute multi-phase response plans for complex incidents, performing actions like enrichment, correlation, containment and blocking while escalating only high-risk decisions to human analysts. Cyber Risk and Compliance: Compliance remains a pre-audit scramble. Evidence collection is manual, controls are monitored quarterly, and organizations are stuck playing catch-up. ServiceNow transforms compliance from a seasonal event into a continuous operational signal. Agentic AI for Continuous Control Monitoring transforms control evidence into a continuous operational signal. Automated agents evaluate segregation of duties, access rights, and configuration state across ServiceNow and external systems in real time, surfacing violations the moment they occur. Compliance-ready reports exist on demand across regulatory frameworks including SOC 2, ISO 27001, PCI-DSS, and HIPAA. Cryptographic Asset Compliance enables rapid migration from legacy cryptographic algorithms to quantum-resistant standards before the quantum threat window closes. ServiceNow delivers comprehensive discovery, AI-powered risk profiling, and guided migration workflows across on-premises and cloud environments, with full integration to ServiceNow Integrated Risk Management and Governance, Risk, and Compliance (IRM/GRC) products for regulatory compliance evidence at enterprise scale.
Share
Copy Link
ServiceNow launched six AI-native security products with autonomous AI specialists that handle vulnerability resolution and incident response at machine speed. Built on its $7.75 billion Armis and $1.3 billion Veza acquisitions, the solutions address fragmented security tools by unifying exposure management, cyber-physical security, and identity governance under its Shift Zero initiative.
ServiceNow has launched six security products alongside AI specialists designed to execute vulnerability and incident response workflows autonomously, marking its largest security push since completing two major acquisitions
1
. The company's $7.75 billion purchase of Armis, a connected device security firm, closed on April 20, while its acquisition of identity security company Veza for a reported $1.3 billion closed on March 21
. ServiceNow integrated both companies into a portfolio branded Autonomous Security & Risk in May, and today's releases extend that foundation1
.
Source: CXOToday
The new offerings deliver prevention-first cyber defense across unified exposure management, continuous vulnerability detection, cyber-physical security, identity and access security, agentic incident response, and cyber risk and compliance
2
. With AI specialists that complete security workflows autonomously, including the Vulnerability Resolution AI Specialist, these capabilities enable enterprises to prevent, contain, and remediate risk at machine speed before threats escalate into breaches2
.ServiceNow frames the underlying transformation as Shift Zero, a strategic move from fragmented, reactive security to prevention embedded at every layer
3
. The goal is zero exposure at all times, with enterprises able to answer what every system is doing, why, and who is accountable, while AI moves as fast as business demands3
. The company points to fragmentation as the core problem: security teams at typical enterprises juggle more than 70 security tools, with endpoints, cloud environments, and identities monitored separately and findings rarely analyzed together1
.ServiceNow consolidates this complexity into one unified system where assets, identities, and agents are visible, contextualized, secured, governed, and auditable in a single motion
2
. "Machine identities double every 18 months. Fragmented security tools can't match the curve AI is creating," said Yevgeny Dibrov, senior vice president and general manager of cybersecurity and risk at ServiceNow, who co-founded Armis and served as its chief executive1
. "Organizations need autonomous security and governance that matches the scale, velocity, and unpredictability of the threats coming."Agentic Exposure Management serves as the entry point, consolidating vulnerability findings from any source into a single stream
1
. ServiceNow layers on threat intelligence and vulnerability prioritization through its Fix Intelligence system, creating a remediation list ranked by risk and exploitability2
. The Vulnerability Resolution AI Specialist handles triage at enterprise scale and can autonomously execute low-risk patches, turning exposure backlogs into closure pipelines2
.Three releases address continuous vulnerability detection across code, cloud, and infrastructure. Application Security now runs threat modeling on AI-generated code and model dependencies, surfacing supply chain vulnerabilities before deployment
1
. Dynamic Application Security Testing validates runtime vulnerabilities in live applications and APIs that only appear during execution1
. External Attack Surface Management examines infrastructure from an attacker's perspective, revealing exposure points that threat actors could exploit3
.Cyber-physical coverage draws heavily from the Armis acquisition. Agentic AI for Cyber-Physical Security discovers devices across operational technology and medical networks without installing agents on them
1
. The solution establishes behavioral baselines, validates compliance continuously in real time, and models attack paths so security teams understand how adversaries would move laterally2
. Automated remediation workflows execute across brownfield environments without custom engineering, addressing a longstanding challenge in OT/medical device security where legacy tools often disrupt production1
.Veza's technology powers the identity releases. AI Agent Access Security unifies access control for AI agents regardless of platform or model provider, closing the threat vector of ungoverned agents with escalated permissions
3
. Non-Human Identity Remediation moves beyond risk scoring into active remediation, automatically rotating keys, deprovisioning accounts, and revoking permissions across IT, operational technology, IoT, and medical networks1
. The solution enables AI agents and service accounts to operate under identical identity governance as human users3
.Related Stories
The Tier 2 SOC AI Specialist targets second-tier security operations center work, autonomously building and executing multi-phase response plans for complex incidents
1
. Enrichment, correlation, and containment run without human intervention, with only high-risk decisions escalated to analysts1
. This agentic incident response approach frees security teams to focus on sophisticated threats rather than routine triage tasks3
.Continuous control monitoring agents check segregation of duties, access rights, and configuration state in real time, both inside ServiceNow and in external systems
1
. Reports are available on demand for frameworks including SOC 2, ISO 27001, PCI DSS, and HIPAA1
. Cryptographic Asset Compliance identifies legacy cryptographic algorithms across on-premises and cloud environments while guiding migration to quantum-resistant standards1
.Eight products are available immediately, including Agentic Exposure Management, Application Security, both identity releases, Dynamic Application Security Testing, External Attack Surface Management, and the cyber-physical package
1
. Four additional releases arrive in December: the Tier 2 SOC AI Specialist, Vulnerability Resolution AI Specialist, continuous control monitoring, and Cryptographic Asset Compliance1
. All six solutions integrate into ServiceNow's AI Control Tower2
.
Source: SiliconANGLE
ServiceNow's security and risk unit crossed $1 billion in annual contract value last year, and Chairman and CEO Bill McDermott called the company "the fastest-growing major enterprise software and cybersecurity company" in its second-quarter earnings release in July, when AI annual contract value also passed $1 billion for the first time
1
.Summarized by
Navi
08 May 2025•Technology

23 Dec 2025•Business and Economy

27 Feb 2026•Technology

1
Technology

2
Technology

3
Science and Research
