ServiceNow Launches Six AI‑Driven Security Solutions Powered by Armis and Veza

0
1

Key Takeaways

  • ServiceNow unveiled six new security products and a suite of AI agents under the Autonomous Security & Risk portfolio, following its acquisitions of Armis and Veza.
  • The “Shift Zero” strategy aims to embed controls at every layer to achieve zero exposure at any moment, countering the fragmentation of over 70 disparate security tools used by typical enterprises.
  • Agentic Exposure Management centralizes vulnerability findings from any source, enriches them with threat intelligence, and delivers a prioritized remediation list.
  • The Vulnerability Resolution AI Specialist performs enterprise‑scale triage and can automatically apply low‑risk patches, routing higher‑risk items to analysts.
  • Application Security now runs threat modeling on AI‑generated code and its dependencies, while Dynamic Application Security Testing and External Attack Surface Management catch runtime and external‑facing flaws.
  • Cyber‑physical coverage from Armis uses agentless discovery, behavioral baselines, and attack‑path modeling; Veza‑based identity releases govern AI agents and remediate non‑human identities.
  • The Tier 2 SOC AI Specialist builds and executes multi‑phase incident response plans, escalating only high‑risk events to human analysts.
  • Continuous monitoring agents enforce compliance with SOC 2, ISO 27001, PCI‑DSS, and HIPAA, and a dedicated Cryptographic Asset Compliance tool hunts legacy algorithms and guides migration to quantum‑resistant standards.
  • Eight capabilities are available now; the remaining four (Tier 2 SOC AI Specialist, Vulnerability Resolution AI Specialist, continuous control monitoring, and Cryptographic Asset Compliance) ship in December.
  • ServiceNow’s security and risk unit surpassed $1 billion in annual contract value, and leadership stresses that autonomous security is essential as machine identities double every 18 months and threats outpace fragmented toolsets.

Overview of ServiceNow’s Autonomous Security & Risk Initiative
ServiceNow today unveiled six new security products and a suite of artificial‑intelligence agents that together form the core of its Autonomous Security & Risk portfolio. The launch follows the company’s $7.75 billion acquisition of Armis Inc. (closed April 20) and the $1.3 billion purchase of identity security firm Veza Inc. (closed March 2). Branded under the Autonomous Security & Risk banner, the offerings embody ServiceNow’s “Shift Zero” strategy—moving from reactive tooling to controls embedded at every layer with the goal of zero exposure at any moment.

Fragmentation Challenge in Enterprise Security
ServiceNow points to fragmentation as the core problem facing modern security teams. A typical enterprise juggles more than seventy distinct tools, each monitoring endpoints, cloud workloads, or identity systems in isolation. Findings from these siloed solutions rarely get correlated, leaving gaps that attackers can exploit. By consolidating data into a single stream, ServiceNow aims to eliminate the blind spots that arise when teams must manually stitch together disparate alerts and reports.

Agentic Exposure Management: Centralizing Vulnerability Intelligence
Agentic Exposure Management serves as the entry point for the new security stack. Vulnerability findings from any source—scanners, code repositories, cloud posture tools—are ingested into a unified stream. ServiceNow enriches this data with external threat intelligence and then produces a prioritized remediation list. By presenting a single, ranked view of risk, the product enables teams to focus remediation effort where it matters most, reducing the time between detection and action.

Vulnerability Resolution AI Specialist: Automated Triage and Patching
The Vulnerability Resolution AI Specialist operates at enterprise scale, performing triage on the influx of findings. It evaluates each vulnerability’s severity, exploitability, and business impact, then decides whether a patch can be applied automatically. Low‑risk issues are remediated without human involvement, while higher‑risk items are routed to analysts with contextual guidance. This automation reduces manual triage workload and accelerates the closure of routine security tickets.

Application Security: Threat Modeling for AI‑Generated Code
Application Security now runs threat modeling on AI‑generated code and its model dependencies, catching supply‑chain problems before deployment. By analyzing the provenance of libraries and the behavior of machine‑learned components, the product identifies hidden risks that traditional scanners miss. This proactive stance helps organizations ship AI‑powered applications with confidence, knowing that potential backdoors or vulnerable dependencies have been surfaced early in the development lifecycle.

Dynamic Application Security Testing: Runtime Flaw Detection
A dynamic application security testing (DAST) product examines live applications and their APIs for flaws that only appear at runtime. It simulates attacker‑like interactions, probing for injection flaws, broken authentication, and insecure direct object references. Because DAST works against the running system, it detects issues such as misconfigured headers or insufficient input validation that static analysis might overlook, providing a complementary view of application security.

External Attack Surface Management: An Outside‑In View
External attack surface management looks at an organization’s infrastructure from the perspective of an external adversary. It continuously discovers internet‑facing assets, maps their relationships, and evaluates exposure to known vulnerabilities and misconfigurations. By mimicking attacker reconnaissance, the product highlights blind spots such as forgotten subdomains, exposed storage buckets, or outdated services, enabling teams to shrink the attack surface before a threat actor can exploit it.

Cyber‑Physical Security Powered by Armis: Agentless Discovery and Attack‑Path Modeling
Cyber‑physical coverage comes largely from Armis. Agentic AI for Cyber Physical Security discovers devices across operational technology and medical networks without installing agents on them. It establishes behavioral baselines, continuously checks compliance, and models attack paths so teams can visualize how an adversary would move through OT or IoT environments. Remediation workflows run in brownfield settings without requiring custom engineering, allowing rapid response to device‑level risks.

Identity Security from Veza: Governing AI Agents and Non‑Human Identities
Veza shows up in the identity domain with two releases. AI Agent Access Security unifies access control for AI agents regardless of platform or model provider, ensuring that autonomous systems receive least‑privilege permissions. The second release, Non‑Human Identity Remediation, goes beyond risk scoring into action: it rotates keys, deprovisions accounts, and revokes permissions across IT, OT, IoT, and medical networks. Together they provide end‑to‑end governance for both human and machine identities.

Incident Response: Tier 2 SOC AI Specialist Orchestrates Multi‑Phase Actions
ServiceNow’s Tier 2 SOC AI Specialist targets second‑tier security operations center work. Upon receiving an alert, it builds a multi‑phase response plan—enrichment, correlation, containment, eradication, and recovery—and then executes the steps automatically. High‑risk or ambiguous events are escalated to a human analyst with full context, ensuring that expert judgment is applied only where needed. This approach reduces mean time to respond while preserving analyst focus on complex investigations.

Continuous Compliance Monitoring: Real‑Time Controls Across Frameworks
Compliance is handled by a set of continuous monitoring agents that check segregation of duties, access rights, and configuration state in real time, both inside ServiceNow and in external systems. Reports are generated on demand and can be tailored to frameworks such as SOC 2, ISO 27001, PCI‑DSS, and HIPAA. By providing ongoing evidence of control effectiveness, the product helps organizations maintain audit readiness and avoid surprise findings during assessments.

Cryptographic Asset Compliance: Hunting Legacy Algorithms and Preparing for Quantum‑Resistant Standards
The sixth product, Cryptographic Asset Compliance, scans on‑premises and cloud environments for legacy cryptographic algorithms such as RSA‑1024, SHA‑1, or deprecated elliptic‑curve curves. It identifies where these weak primitives are used and guides teams through migration to quantum‑resistant standards like CRYSTALS‑Kyber or Dilithium. By automating discovery and remediation planning, the tool helps reduce the risk of future decryption attacks as quantum computing matures.

Product Availability: What’s Shipping Now and What Arrives in December
Eight of the products are available immediately, including Agentic Exposure Management, Application Security, and both identity releases (AI Agent Access Security and Non‑Human Identity Remediation). Dynamic application security testing, external attack surface management, and the cyber‑physical package are also shipping now. Four more capabilities arrive in December: the Tier 2 SOC AI Specialist, the Vulnerability Resolution AI Specialist, continuous control monitoring, and Cryptographic Asset Compliance. This staggered rollout lets customers adopt core functions early while adding advanced automation later.

Business Impact: Security Unit Growth, Financial Milestones, and Leadership Vision
Security has been one of the faster‑moving parts of ServiceNow’s business. The security and risk unit crossed $1 billion in annual contract value last year, and Chairman and CEO Bill McDermott called the company “the fastest‑growing major enterprise software and cybersecurity firm” in its Q2 earnings release, noting that AI‑related ACV also surpassed $1 billion for the first time. Yevgeny Dibrov, SVP and GM of cybersecurity and risk (co‑founder of Armis), emphasized that machine identities double every 18 months and that fragmented tools cannot keep pace with AI‑driven threats, underscoring the need for autonomous security at scale.

Conclusion: Toward Autonomous, Zero‑Exposure Security
ServiceNow’s latest launch illustrates a clear shift toward autonomous, zero‑exposure security. By consolidating vulnerability data, applying AI‑driven triage, securing AI‑generated code, extending coverage to cyber‑physical and identity domains, automating response, and ensuring continuous compliance, the company addresses the fragmentation that hampers most enterprises. As machine‑generated identities and threats proliferate, the integrated portfolio aims to let security teams focus on strategy rather than stitching together alerts, moving the industry closer to the goal of zero exposure at any moment.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here