ServiceNow Unveils Six Autonomous Security Products Built on $9B Armis and Veza Acquisitions

3 Sources

Share

ServiceNow launched six AI-native security products with autonomous AI specialists that handle vulnerability resolution and incident response at machine speed. Built on its $7.75 billion Armis and $1.3 billion Veza acquisitions, the solutions address fragmented security tools by unifying exposure management, cyber-physical security, and identity governance under its Shift Zero initiative.

ServiceNow Accelerates Autonomous Security Vision with Six Unified Solutions

ServiceNow has launched six security products alongside AI specialists designed to execute vulnerability and incident response workflows autonomously, marking its largest security push since completing two major acquisitions

1

. The company's $7.75 billion purchase of Armis, a connected device security firm, closed on April 20, while its acquisition of identity security company Veza for a reported $1.3 billion closed on March 2

1

. ServiceNow integrated both companies into a portfolio branded Autonomous Security & Risk in May, and today's releases extend that foundation

1

.

Source: CXOToday

Source: CXOToday

The new offerings deliver prevention-first cyber defense across unified exposure management, continuous vulnerability detection, cyber-physical security, identity and access security, agentic incident response, and cyber risk and compliance

2

. With AI specialists that complete security workflows autonomously, including the Vulnerability Resolution AI Specialist, these capabilities enable enterprises to prevent, contain, and remediate risk at machine speed before threats escalate into breaches

2

.

Shift Zero Initiative Targets Fragmented Security Tools

ServiceNow frames the underlying transformation as Shift Zero, a strategic move from fragmented, reactive security to prevention embedded at every layer

3

. The goal is zero exposure at all times, with enterprises able to answer what every system is doing, why, and who is accountable, while AI moves as fast as business demands

3

. The company points to fragmentation as the core problem: security teams at typical enterprises juggle more than 70 security tools, with endpoints, cloud environments, and identities monitored separately and findings rarely analyzed together

1

.

ServiceNow consolidates this complexity into one unified system where assets, identities, and agents are visible, contextualized, secured, governed, and auditable in a single motion

2

. "Machine identities double every 18 months. Fragmented security tools can't match the curve AI is creating," said Yevgeny Dibrov, senior vice president and general manager of cybersecurity and risk at ServiceNow, who co-founded Armis and served as its chief executive

1

. "Organizations need autonomous security and governance that matches the scale, velocity, and unpredictability of the threats coming."

Agentic Exposure Management and Vulnerability Resolution at Enterprise Scale

Agentic Exposure Management serves as the entry point, consolidating vulnerability findings from any source into a single stream

1

. ServiceNow layers on threat intelligence and vulnerability prioritization through its Fix Intelligence system, creating a remediation list ranked by risk and exploitability

2

. The Vulnerability Resolution AI Specialist handles triage at enterprise scale and can autonomously execute low-risk patches, turning exposure backlogs into closure pipelines

2

.

Three releases address continuous vulnerability detection across code, cloud, and infrastructure. Application Security now runs threat modeling on AI-generated code and model dependencies, surfacing supply chain vulnerabilities before deployment

1

. Dynamic Application Security Testing validates runtime vulnerabilities in live applications and APIs that only appear during execution

1

. External Attack Surface Management examines infrastructure from an attacker's perspective, revealing exposure points that threat actors could exploit

3

.

Agentic AI for Cyber-Physical Security Addresses OT and Medical Networks

Cyber-physical coverage draws heavily from the Armis acquisition. Agentic AI for Cyber-Physical Security discovers devices across operational technology and medical networks without installing agents on them

1

. The solution establishes behavioral baselines, validates compliance continuously in real time, and models attack paths so security teams understand how adversaries would move laterally

2

. Automated remediation workflows execute across brownfield environments without custom engineering, addressing a longstanding challenge in OT/medical device security where legacy tools often disrupt production

1

.

AI Agent Access Security and Non-Human Identity Remediation

Veza's technology powers the identity releases. AI Agent Access Security unifies access control for AI agents regardless of platform or model provider, closing the threat vector of ungoverned agents with escalated permissions

3

. Non-Human Identity Remediation moves beyond risk scoring into active remediation, automatically rotating keys, deprovisioning accounts, and revoking permissions across IT, operational technology, IoT, and medical networks

1

. The solution enables AI agents and service accounts to operate under identical identity governance as human users

3

.

Tier 2 SOC AI Specialist Automates Incident Response

The Tier 2 SOC AI Specialist targets second-tier security operations center work, autonomously building and executing multi-phase response plans for complex incidents

1

. Enrichment, correlation, and containment run without human intervention, with only high-risk decisions escalated to analysts

1

. This agentic incident response approach frees security teams to focus on sophisticated threats rather than routine triage tasks

3

.

Compliance Monitoring and Cryptographic Asset Management

Continuous control monitoring agents check segregation of duties, access rights, and configuration state in real time, both inside ServiceNow and in external systems

1

. Reports are available on demand for frameworks including SOC 2, ISO 27001, PCI DSS, and HIPAA

1

. Cryptographic Asset Compliance identifies legacy cryptographic algorithms across on-premises and cloud environments while guiding migration to quantum-resistant standards

1

.

Eight products are available immediately, including Agentic Exposure Management, Application Security, both identity releases, Dynamic Application Security Testing, External Attack Surface Management, and the cyber-physical package

1

. Four additional releases arrive in December: the Tier 2 SOC AI Specialist, Vulnerability Resolution AI Specialist, continuous control monitoring, and Cryptographic Asset Compliance

1

. All six solutions integrate into ServiceNow's AI Control Tower

2

.

Source: SiliconANGLE

Source: SiliconANGLE

ServiceNow's security and risk unit crossed $1 billion in annual contract value last year, and Chairman and CEO Bill McDermott called the company "the fastest-growing major enterprise software and cybersecurity company" in its second-quarter earnings release in July, when AI annual contract value also passed $1 billion for the first time

1

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved