ServiceNow bets on security consolidation as AI compresses response times
ServiceNow on Wednesday announced six unified security solutions under its Autonomous Security offering, covering unified exposure management, continuous vulnerability detection, cyber-physical security, identity and access security, agentic incident response, and cyber risk and compliance.
New AI Specialists complete security workflows without analyst execution, including a Vulnerability Resolution AI Specialist that turns exposure backlogs into closure pipelines.
The portfolio is now among the broadest sold by any single vendor, and the more consequential question is where enterprise security spend goes next. ServiceNow is arguing that the industry’s decade-long preference for specialist tooling has become a liability once threats and remediation both move faster than the humans coordinating between products.
ServiceNow cites an average enterprise running more than 70 security tools across endpoints, networks, cloud environments, identities and autonomous agents. The number is usually read as evidence of overspend, though the operational damage runs deeper than cost.
Each product carries its own asset inventory, severity model and confidence scoring, so an enterprise with 70 tools holds 70 partial and frequently contradictory accounts of its own estate, with no mechanism for deciding which one is authoritative when they disagree.
Analysts spend their time arbitrating between those accounts, and arbitration is exactly the work that does not scale as the volume of findings rises. Yevgeny Dibrov, SVP and GM, Cybersecurity and Risk at ServiceNow, put the mismatch in terms of tempo. “As AI exposures compound exponentially, security teams operate on a human clock,” he said. He pointed to identity growth as the sharpest measure, stating that “machine identities double every 18 months”, a rate that no quarterly access certification or manual review cycle can absorb. Doubling every 18 months means an estate governed adequately today is governed at half sufficiency within two years without a single new deployment decision.
The product set is designed to remove human handoffs rather than to outperform incumbents feature by feature
Most of the six solutions face credible specialist competitors on their own terms. Unified Exposure Management pulls vulnerability findings from any source into a single stream enriched by Early Warning threat intelligence and Fix Intelligence prioritised remediation, with the Vulnerability Resolution AI Specialist orchestrating triage at scale and executing low-risk patches unaided.
Continuous Vulnerability Detection covers code, cloud and infrastructure through Application Security, which now models threats in AI-generated code and model dependencies, alongside Dynamic Application Security Testing for runtime validation and External Attack Surface Management, which shows infrastructure exposure the way an attacker sees it. Each of those categories has entrenched leaders with deeper detection engineering behind them.
The differentiation sits in what happens after detection. Cyber-Physical Security reaches the operational technology, medical device and IoT estate that legacy scanners cannot safely touch, using agentless discovery, behavioural baselines and attack path modelling, with remediation workflows that run across brownfield environments without custom engineering.
Identity and Access Security unifies access control for AI agents across any platform or model provider and takes non-human identity management into automated key rotation, deprovisioning and permission revocation across IT, OT, IoT and medical networks, so service accounts and agents fall under the governance already applied to human employees.
Agentic Incident Response allows the Tier 2 SOC AI Specialist to build and execute multi-phase response plans autonomously, handling enrichment, correlation, containment and blocking while escalating only high-risk decisions, and Cyber Risk and Compliance evaluates segregation of duties, access rights and configuration state continuously across ServiceNow and external systems, producing reporting on demand against SOC 2, ISO 27001, PCI-DSS and HIPAA. Cryptographic Asset Compliance addresses quantum-resistant migration through discovery, AI-powered risk profiling and guided workflows, a category most enterprises have yet to budget for.
Armis and Veza are the acquisitions that make the autonomy claim testable
Autonomous remediation fails on bad inventory data long before it fails on bad reasoning, which gives the acquisitions more weight in this announcement than the AI Specialists carry. Armis contributes continuous, non-invasive visibility across connected assets, tracking billions of devices in real time, including the operational and medical technology that cannot host a conventional agent and therefore sits outside most vulnerability management programmes altogether.
Veza contributes its Access Graph, which maps effective permissions across human, machine and AI identities, resolving what an account can actually do once inherited and nested entitlements are collapsed, a far more useful quantity than the entitlements recorded in a directory.
Together they supply the two inputs an autonomous action needs before it can be trusted, an accurate picture of what exists and an accurate picture of who can reach it, both feeding the ServiceNow AI Control Tower, Context Engine and orchestration layer. Dibrov set the requirement in terms of adaptation as much as detection, saying organisations “need autonomous security and governance that matches the scale, velocity, and unpredictability of the threats coming: where all assets, identities, AI agents, critical infrastructure, cloud environments and code are protected, and can adapt as fast as the ecosystem moves to detect and remediate threats in real-time.”
Proof of action, and not autonomy itself, is what regulated buyers will evaluate
ServiceNow calls the underlying shift Shift Zero, a move from fragmented, reactive security to prevention embedded at every layer, where the operating goal is zero exposure at all times and the enterprise can answer with evidence what every system is doing and who is accountable for it.
The accountability half of that sentence carries the commercial weight. An autonomous agent that revokes credentials or patches production without an audit trail relocates risk into the security tooling itself, and a CISO who cannot reconstruct why an action occurred has traded a visible backlog for an invisible one.
That is the standard against which the December 2026 releases will be judged, and it is a standard ServiceNow is better placed to meet than most security vendors, given the platform already exists to record approvals, ownership and change history for the rest of the enterprise.
For the sector, the announcement hardens a consolidation contest running across the largest vendors, each arguing that breadth outperforms specialist depth once response windows compress. Dibrov closed on the commercial case that security stops slowing delivery once it runs at the speed of the business, saying that “security becomes an accelerant, not the brake.” Whether buyers accept that trade will show up in renewal decisions across the 70-tool estate long before it shows up in breach statistics.