decryptingtech

Technology. Business models. Market debates.

Browse this section

ServiceNow (Cybersecurity)

Technology / Cybersecurity / Company deep dive

This report focuses on ServiceNow’s cybersecurity business. For the wider business and AI strategy, read the ServiceNow company profile ↗.

ServiceNow does not discover most attacks and it does not enforce most security controls. Its value begins when another product has found something and the enterprise must decide whether it matters, identify the accountable owner, make a safe change and prove that the risk was removed. That sounds administrative until one recognises that remediation—not detection—is where many security programmes fail.

The company is using more than $11 billion of recent acquisitions to move upstream from workflow into proprietary security context. Armis adds continuous asset intelligence, including unmanaged and cyber-physical equipment. Veza adds effective-permission data across human, machine and AI identities. Moveworks provides a conversational front end and data.world adds a semantic layer. The strategy is coherent: know what exists, know who can reach it, understand its business importance and then execute the response. The open question is whether ServiceNow can integrate those products deeply enough to justify the acquisition cost without destroying the partner neutrality on which its security franchise was built.

What ServiceNow actually does in security

Security Operations is the workflow layer for incidents and findings. Security Incident Response receives alerts from SIEM, endpoint, network, cloud and threat-intelligence products; associates them with users, assets and business services; creates investigation and containment tasks; and records escalation, approvals and closure. Vulnerability Response and Unified Security Exposure Management perform the same function for vulnerabilities, misconfigurations, application findings and other exposures. Integrated Risk Management connects technical conditions to controls, policy exceptions, audit evidence and enterprise risk.

The operating chain: source-tool finding → affected configuration item → business service and owner → risk-based priority → remediation or approved exception → controlled change → validation and audit evidence.

This chain explains both the moat and the weakness. ServiceNow can see who owns the server, which revenue service depends on it, whether a related incident is open, when the maintenance window begins and which approval is required. A scanner rarely owns that organisational context. But ServiceNow is only as reliable as its configuration data and integrations. If the configuration database is stale, identities do not reconcile or the source tool sends poor telemetry, the platform automates bad assumptions at enterprise scale.

ServiceNow is often dismissed as a ticketing system. That description is incomplete but useful. The ticket is not the moat; the embedded operating process around it is. Security teams can replace an alert console more easily than a cross-functional process involving IT operations, application owners, legal, compliance and change management. ServiceNow’s opportunity is to turn that process from human coordination into software execution.

Why Armis and Veza change the strategy

Before the acquisitions, ServiceNow largely consumed asset and identity context from other systems. Armis and Veza give it ownership of two data sets that determine whether an exposure is dangerous. Armis discovers devices and behaviour across IT, cloud, OT, IoT, medical equipment and other environments where installing an agent may be impossible. Veza’s Access Graph maps effective permissions—what a person, service account, machine or AI agent can actually access—rather than relying only on directory membership.

Combining those data sets with ServiceNow’s configuration and service graph can produce materially better prioritisation. An internet-facing, unmanaged device with privileged access to a critical production service is not simply three separate findings. It is an attack path with an owner, business consequence and remediation workflow. The strategic move is therefore from “system that routes security work” to “system that supplies part of the security decision”.

AcquisitionCapability acquiredWhy it fits ServiceNowWhat must be proved
data.world
Closed 2025
Data catalogue, metadata and knowledge graphGives Workflow Data Fabric and the Context Engine governed meaning, lineage and ownership. This matters when AI must select authoritative enterprise data.Semantic context must improve decisions inside workflows; an invisible catalogue bundled into the platform is not enough.
Moveworks
$2.85bn; closed Dec 2025
Enterprise search and conversational assistantProvides the front door through which an employee can ask for access, report an incident or initiate a workflow. It becomes part of EmployeeWorks and Otto.Natural-language entry must convert into accurate, permission-aware action. A better chatbot does not by itself strengthen cybersecurity.
Veza
About $1.2bn; closed Mar 2026
Access Graph and identity-governance functionsAdds effective-permission context to incidents and exposures and gives ServiceNow a way to govern non-human and AI-agent identities.Customers must use Veza data to revoke or redesign access, not merely produce another entitlement report. Integration with existing identity stacks is essential.
Armis
$7.75bn; closed Apr 2026
Continuous asset intelligence and exposure visibilityRepairs a structural weakness in configuration data and extends discovery into unagented OT, IoT and medical environments.Armis Centrix must share asset identity, risk and workflow natively with ServiceNow. The acquisition cannot be justified by cross-selling two separate consoles.
Why Armis and Veza change the strategy

Armis is the decisive transaction. Veza is strategically clean because identity context naturally improves workflow. Armis is larger, enters more specialist security markets and creates a much higher return hurdle. The purchase price is several times the size of ServiceNow’s existing Security and Risk contract base, which had passed $1 billion of annual contract value before the deal. Annual contract value is not reported revenue, and ServiceNow does not disclose security revenue separately.

The accounting reinforces the point. Goodwill increased by more than $6 billion following the 2026 acquisitions, while their early contribution was not material to consolidated results. That is normal immediately after closing, but it shifts the burden of proof from strategic slides to product behaviour. Shared records, common policy, one investigation, one remediation path and simpler packaging are evidence of integration. Joint selling and a common logo are not.

The AI and autonomous-security proposition

ServiceNow has three distinct AI roles. First, assistants can summarise an incident, correlate previous cases, draft a response plan and prepare remediation tasks. Second, AI Control Tower can inventory models and agents, connect them to owners and business services, and apply governance. Third, AI specialists can execute defined steps across ServiceNow and third-party tools through Action Fabric.

Veza and Armis make the governance story more credible. An AI agent is both software and an identity: it runs somewhere, has an owner, calls tools and holds permissions. Armis can help identify the asset and its behaviour; Veza can show effective access; AI Control Tower can attach policy; ServiceNow can approve and record the action. This is a better architecture than treating AI security as another alert feed.

“Autonomous security” should nevertheless be interpreted narrowly. Automatically enriching an alert, opening a case, collecting evidence or disabling an obviously compromised token is different from changing a production firewall, revoking a senior executive’s access or isolating an industrial device. The attractive product is graduated autonomy: machines perform high-volume analysis and reversible fixes; consequential changes preserve approval, rollback and an audit trail. ServiceNow has a right to win here because change governance is already part of its installed workflow, not because its AI models are uniquely capable.

Competitive position: complement first, competitor second

Control pointIncumbentsServiceNow’s edgeWhere ServiceNow remains weaker
Detection and SOCMicrosoft, Palo Alto Networks, CrowdStrike, Google and CiscoCoordinates work across security, IT and business teams after an alert; strong case and change governance.Does not own the richest endpoint, network, email or cloud telemetry and lacks a comparable threat-research franchise.
Exposure managementQualys, Tenable, Rapid7, Wiz, Microsoft, CrowdStrike and Palo Alto NetworksMaps findings to business services and can drive them through patch, configuration, exception and validation workflows.Source-tool coverage and asset fidelity still depend on integrations; Armis is deep in asset intelligence but not every form of scanning.
Identity securitySailPoint, CyberArk, Okta and MicrosoftConnects access decisions to employee events, incidents, assets, risk and service workflows. Veza adds effective-permission analysis.Is not the primary identity provider or privileged-access enforcement layer in most customers.
Security automationTines, Torq, Swimlane and automation inside major security platformsBroad cross-enterprise approvals, ownership, service context and auditability.Security-native tools can offer faster analyst workflows and deeper actions inside their own telemetry platforms.
Cyber-physical securityClaroty, Nozomi Networks, Dragos, Fortinet and Palo Alto NetworksArmis adds passive discovery while ServiceNow links operational assets to owners, maintenance and risk processes.OT buyers require protocol depth, safety expertise and operational trust that cannot be created through IT distribution alone.
Risk and complianceArcher, AuditBoard, OneTrust and MetricStreamControls and evidence sit beside the incidents, assets and remediation tasks that create or reduce risk.Broad workflow can become administrative overhead when implementation is poorly designed.
Competitive position: complement first, competitor second

ServiceNow’s historical neutrality made it a safe destination for every vendor’s alerts. Armis and Veza improve proprietary context but change that relationship. Microsoft, Palo Alto Networks and CrowdStrike increasingly offer their own exposure management, automation and case workflows. They will continue to integrate because customers demand it, but they have less reason to help ServiceNow own the strategic security layer. The correct strategy is to compete for prioritisation and remediation while remaining open to heterogeneous detection. Trying to replace every security control would weaken the ecosystem that feeds the platform.

Business model and sales motion

The installed base is the commercial advantage. ServiceNow already has CIO relationships, enterprise data models and long-lived workflows. Security and Risk can be attached without asking the customer to adopt an entirely new operating platform. Once incident, vulnerability, change and risk processes share records, switching becomes difficult because the customer would need to rebuild integrations, approvals, reporting and organisational ownership—not merely export security data.

That distribution advantage has limits. Security, identity and OT are specialist buying centres with different proof requirements. A CIO-led platform sale does not guarantee that a CISO trusts the detection context or that a plant operator accepts an automated change. Armis and Veza also introduce direct sales motions that cannot simply be folded into an IT-service-management renewal. The operating test is whether ServiceNow increases wallet share while shortening deployment and time to value; revenue purchased through acquisitions or attached through discounting would be lower-quality evidence.

Implementation complexity is another constraint. The platform’s value rises with workflow depth, but deep workflows require clean data, integration and process redesign. Partners can help, yet heavy services increase cost and delay outcomes. ServiceNow must productise asset reconciliation, permission mapping and remediation so that customers receive value before a multi-quarter transformation programme is complete.

The investment debate

DebateInvestment caseFailure modeFalsification test
Can security become a major platform?The company owns remediation workflow and now adds asset and access intelligence, creating a differentiated decision layer.Security remains an attachment to IT workflows while detection platforms absorb orchestration.Growth outside the existing IT-service-management base and larger multi-product Security and Risk deployments.
Do the acquisitions compound?Armis, Veza, data.world and Moveworks supply complementary layers of asset, identity, semantic and user context.More than $11 billion buys separate growth engines, overlapping interfaces and organisational distraction.One asset and identity model, common policy, shared investigations and measurable closed-loop remediation.
Is the CMDB a moat?Business-service ownership and change history make technical findings economically actionable.Poor data quality makes prioritisation unreliable and encourages customers to use specialist exposure graphs.Automated reconciliation, lower orphan-asset rates and decisions that demonstrably change remediation priority.
Does AI improve the product?AI reduces manual triage and lets ServiceNow execute high-volume remediation with governance.Agentic features repackage workflow automation, add usage cost and increase outage risk.Shorter verified remediation time, less analyst effort and no deterioration in change-failure rates.
Can neutrality survive?An open action layer is more valuable because large enterprises will remain multi-vendor.Security platforms withhold strategic cooperation and keep automation inside their own products.Continued depth of third-party actions and joint customer wins with major detection vendors.
The investment debate

What to monitor

  • Product integration: whether Armis assets and Veza permissions appear as native ServiceNow entities with common policy and remediation.
  • Independent security demand: wins led by the CISO, identity team or operational-technology buyer rather than attached to a broad platform renewal.
  • Closed-loop outcomes: verified time to remediate, automation rates, exception ageing and change failures—not alerts ingested or AI agents created.
  • Partner behaviour: richness of integrations with endpoint, SIEM, cloud and network platforms as ServiceNow competes more directly.
  • Acquisition return: sustained security growth and cash contribution relative to the capital committed, especially for Armis.
  • Data quality: the speed and accuracy with which customers reconcile configuration, discovered assets and effective permissions.

Bottom line

ServiceNow’s defensible cybersecurity position is not detection. It is control over the organisational path from a finding to a verified fix. Armis and Veza can make that path materially smarter by supplying asset and access truth that the configuration database could not reliably produce alone. The combination is strategically stronger than workflow by itself and potentially more valuable than another security dashboard.

Our view: ServiceNow now has the components of a credible security decision-and-remediation platform, but not yet proof that it has built one. The bull case requires native integration, independent security demand and measurable closure of risk. The bear case is straightforward: the company paid more than $11 billion to fill data gaps while the vendors that own detection continue moving into workflow. Until integration evidence arrives, Armis should be treated as a high-cost strategic bet and payback—not product breadth—as the central investment question.