Technology / Cybersecurity / Company deep dive
This report focuses on ServiceNow’s cybersecurity business. For the wider business and AI strategy, read the ServiceNow company profile ↗.
ServiceNow does not discover most attacks and it does not enforce most security controls. Its value begins when another product has found something and the enterprise must decide whether it matters, identify the accountable owner, make a safe change and prove that the risk was removed. That sounds administrative until one recognises that remediation—not detection—is where many security programmes fail.
The company is using more than $11 billion of recent acquisitions to move upstream from workflow into proprietary security context. Armis adds continuous asset intelligence, including unmanaged and cyber-physical equipment. Veza adds effective-permission data across human, machine and AI identities. Moveworks provides a conversational front end and data.world adds a semantic layer. The strategy is coherent: know what exists, know who can reach it, understand its business importance and then execute the response. The open question is whether ServiceNow can integrate those products deeply enough to justify the acquisition cost without destroying the partner neutrality on which its security franchise was built.
What ServiceNow actually does in security
Security Operations is the workflow layer for incidents and findings. Security Incident Response receives alerts from SIEM, endpoint, network, cloud and threat-intelligence products; associates them with users, assets and business services; creates investigation and containment tasks; and records escalation, approvals and closure. Vulnerability Response and Unified Security Exposure Management perform the same function for vulnerabilities, misconfigurations, application findings and other exposures. Integrated Risk Management connects technical conditions to controls, policy exceptions, audit evidence and enterprise risk.
This chain explains both the moat and the weakness. ServiceNow can see who owns the server, which revenue service depends on it, whether a related incident is open, when the maintenance window begins and which approval is required. A scanner rarely owns that organisational context. But ServiceNow is only as reliable as its configuration data and integrations. If the configuration database is stale, identities do not reconcile or the source tool sends poor telemetry, the platform automates bad assumptions at enterprise scale.
ServiceNow is often dismissed as a ticketing system. That description is incomplete but useful. The ticket is not the moat; the embedded operating process around it is. Security teams can replace an alert console more easily than a cross-functional process involving IT operations, application owners, legal, compliance and change management. ServiceNow’s opportunity is to turn that process from human coordination into software execution.
Why Armis and Veza change the strategy
Before the acquisitions, ServiceNow largely consumed asset and identity context from other systems. Armis and Veza give it ownership of two data sets that determine whether an exposure is dangerous. Armis discovers devices and behaviour across IT, cloud, OT, IoT, medical equipment and other environments where installing an agent may be impossible. Veza’s Access Graph maps effective permissions—what a person, service account, machine or AI agent can actually access—rather than relying only on directory membership.
Combining those data sets with ServiceNow’s configuration and service graph can produce materially better prioritisation. An internet-facing, unmanaged device with privileged access to a critical production service is not simply three separate findings. It is an attack path with an owner, business consequence and remediation workflow. The strategic move is therefore from “system that routes security work” to “system that supplies part of the security decision”.
| Acquisition | Capability acquired | Why it fits ServiceNow | What must be proved |
|---|---|---|---|
| data.world Closed 2025 | Data catalogue, metadata and knowledge graph | Gives Workflow Data Fabric and the Context Engine governed meaning, lineage and ownership. This matters when AI must select authoritative enterprise data. | Semantic context must improve decisions inside workflows; an invisible catalogue bundled into the platform is not enough. |
| Moveworks $2.85bn; closed Dec 2025 | Enterprise search and conversational assistant | Provides the front door through which an employee can ask for access, report an incident or initiate a workflow. It becomes part of EmployeeWorks and Otto. | Natural-language entry must convert into accurate, permission-aware action. A better chatbot does not by itself strengthen cybersecurity. |
| Veza About $1.2bn; closed Mar 2026 | Access Graph and identity-governance functions | Adds effective-permission context to incidents and exposures and gives ServiceNow a way to govern non-human and AI-agent identities. | Customers must use Veza data to revoke or redesign access, not merely produce another entitlement report. Integration with existing identity stacks is essential. |
| Armis $7.75bn; closed Apr 2026 | Continuous asset intelligence and exposure visibility | Repairs a structural weakness in configuration data and extends discovery into unagented OT, IoT and medical environments. | Armis Centrix must share asset identity, risk and workflow natively with ServiceNow. The acquisition cannot be justified by cross-selling two separate consoles. |
Armis is the decisive transaction. Veza is strategically clean because identity context naturally improves workflow. Armis is larger, enters more specialist security markets and creates a much higher return hurdle. The purchase price is several times the size of ServiceNow’s existing Security and Risk contract base, which had passed $1 billion of annual contract value before the deal. Annual contract value is not reported revenue, and ServiceNow does not disclose security revenue separately.
The accounting reinforces the point. Goodwill increased by more than $6 billion following the 2026 acquisitions, while their early contribution was not material to consolidated results. That is normal immediately after closing, but it shifts the burden of proof from strategic slides to product behaviour. Shared records, common policy, one investigation, one remediation path and simpler packaging are evidence of integration. Joint selling and a common logo are not.
The AI and autonomous-security proposition
ServiceNow has three distinct AI roles. First, assistants can summarise an incident, correlate previous cases, draft a response plan and prepare remediation tasks. Second, AI Control Tower can inventory models and agents, connect them to owners and business services, and apply governance. Third, AI specialists can execute defined steps across ServiceNow and third-party tools through Action Fabric.
Veza and Armis make the governance story more credible. An AI agent is both software and an identity: it runs somewhere, has an owner, calls tools and holds permissions. Armis can help identify the asset and its behaviour; Veza can show effective access; AI Control Tower can attach policy; ServiceNow can approve and record the action. This is a better architecture than treating AI security as another alert feed.
“Autonomous security” should nevertheless be interpreted narrowly. Automatically enriching an alert, opening a case, collecting evidence or disabling an obviously compromised token is different from changing a production firewall, revoking a senior executive’s access or isolating an industrial device. The attractive product is graduated autonomy: machines perform high-volume analysis and reversible fixes; consequential changes preserve approval, rollback and an audit trail. ServiceNow has a right to win here because change governance is already part of its installed workflow, not because its AI models are uniquely capable.
Competitive position: complement first, competitor second
| Control point | Incumbents | ServiceNow’s edge | Where ServiceNow remains weaker |
|---|---|---|---|
| Detection and SOC | Microsoft, Palo Alto Networks, CrowdStrike, Google and Cisco | Coordinates work across security, IT and business teams after an alert; strong case and change governance. | Does not own the richest endpoint, network, email or cloud telemetry and lacks a comparable threat-research franchise. |
| Exposure management | Qualys, Tenable, Rapid7, Wiz, Microsoft, CrowdStrike and Palo Alto Networks | Maps findings to business services and can drive them through patch, configuration, exception and validation workflows. | Source-tool coverage and asset fidelity still depend on integrations; Armis is deep in asset intelligence but not every form of scanning. |
| Identity security | SailPoint, CyberArk, Okta and Microsoft | Connects access decisions to employee events, incidents, assets, risk and service workflows. Veza adds effective-permission analysis. | Is not the primary identity provider or privileged-access enforcement layer in most customers. |
| Security automation | Tines, Torq, Swimlane and automation inside major security platforms | Broad cross-enterprise approvals, ownership, service context and auditability. | Security-native tools can offer faster analyst workflows and deeper actions inside their own telemetry platforms. |
| Cyber-physical security | Claroty, Nozomi Networks, Dragos, Fortinet and Palo Alto Networks | Armis adds passive discovery while ServiceNow links operational assets to owners, maintenance and risk processes. | OT buyers require protocol depth, safety expertise and operational trust that cannot be created through IT distribution alone. |
| Risk and compliance | Archer, AuditBoard, OneTrust and MetricStream | Controls and evidence sit beside the incidents, assets and remediation tasks that create or reduce risk. | Broad workflow can become administrative overhead when implementation is poorly designed. |
ServiceNow’s historical neutrality made it a safe destination for every vendor’s alerts. Armis and Veza improve proprietary context but change that relationship. Microsoft, Palo Alto Networks and CrowdStrike increasingly offer their own exposure management, automation and case workflows. They will continue to integrate because customers demand it, but they have less reason to help ServiceNow own the strategic security layer. The correct strategy is to compete for prioritisation and remediation while remaining open to heterogeneous detection. Trying to replace every security control would weaken the ecosystem that feeds the platform.
Business model and sales motion
The installed base is the commercial advantage. ServiceNow already has CIO relationships, enterprise data models and long-lived workflows. Security and Risk can be attached without asking the customer to adopt an entirely new operating platform. Once incident, vulnerability, change and risk processes share records, switching becomes difficult because the customer would need to rebuild integrations, approvals, reporting and organisational ownership—not merely export security data.
That distribution advantage has limits. Security, identity and OT are specialist buying centres with different proof requirements. A CIO-led platform sale does not guarantee that a CISO trusts the detection context or that a plant operator accepts an automated change. Armis and Veza also introduce direct sales motions that cannot simply be folded into an IT-service-management renewal. The operating test is whether ServiceNow increases wallet share while shortening deployment and time to value; revenue purchased through acquisitions or attached through discounting would be lower-quality evidence.
Implementation complexity is another constraint. The platform’s value rises with workflow depth, but deep workflows require clean data, integration and process redesign. Partners can help, yet heavy services increase cost and delay outcomes. ServiceNow must productise asset reconciliation, permission mapping and remediation so that customers receive value before a multi-quarter transformation programme is complete.
The investment debate
| Debate | Investment case | Failure mode | Falsification test |
|---|---|---|---|
| Can security become a major platform? | The company owns remediation workflow and now adds asset and access intelligence, creating a differentiated decision layer. | Security remains an attachment to IT workflows while detection platforms absorb orchestration. | Growth outside the existing IT-service-management base and larger multi-product Security and Risk deployments. |
| Do the acquisitions compound? | Armis, Veza, data.world and Moveworks supply complementary layers of asset, identity, semantic and user context. | More than $11 billion buys separate growth engines, overlapping interfaces and organisational distraction. | One asset and identity model, common policy, shared investigations and measurable closed-loop remediation. |
| Is the CMDB a moat? | Business-service ownership and change history make technical findings economically actionable. | Poor data quality makes prioritisation unreliable and encourages customers to use specialist exposure graphs. | Automated reconciliation, lower orphan-asset rates and decisions that demonstrably change remediation priority. |
| Does AI improve the product? | AI reduces manual triage and lets ServiceNow execute high-volume remediation with governance. | Agentic features repackage workflow automation, add usage cost and increase outage risk. | Shorter verified remediation time, less analyst effort and no deterioration in change-failure rates. |
| Can neutrality survive? | An open action layer is more valuable because large enterprises will remain multi-vendor. | Security platforms withhold strategic cooperation and keep automation inside their own products. | Continued depth of third-party actions and joint customer wins with major detection vendors. |
What to monitor
- Product integration: whether Armis assets and Veza permissions appear as native ServiceNow entities with common policy and remediation.
- Independent security demand: wins led by the CISO, identity team or operational-technology buyer rather than attached to a broad platform renewal.
- Closed-loop outcomes: verified time to remediate, automation rates, exception ageing and change failures—not alerts ingested or AI agents created.
- Partner behaviour: richness of integrations with endpoint, SIEM, cloud and network platforms as ServiceNow competes more directly.
- Acquisition return: sustained security growth and cash contribution relative to the capital committed, especially for Armis.
- Data quality: the speed and accuracy with which customers reconcile configuration, discovered assets and effective permissions.
Bottom line
ServiceNow’s defensible cybersecurity position is not detection. It is control over the organisational path from a finding to a verified fix. Armis and Veza can make that path materially smarter by supplying asset and access truth that the configuration database could not reliably produce alone. The combination is strategically stronger than workflow by itself and potentially more valuable than another security dashboard.