[DigitalToday reporter Chi-gyu Hwang] ServiceNow has unveiled six autonomous security products and an AI security agent lineup following its acquisitions of Armis and Vectra. SiliconANGLE reported on Monday, local time, that the products support processes such as vulnerability handling and incident response through to closure without analysts having to intervene directly at every step.
ServiceNow completed its acquisition of connected device security company Armis on April 20, and also completed the acquisition of identity security company Vectra on March 2.
ServiceNow integrated the two companies into its Autonomous Security and Risk portfolio in May and expanded it with the new products.
ServiceNow is emphasising a security strategy focused on moving away from post-incident response tools and embedding controls at each layer to eliminate point-in-time exposure.
ServiceNow has pointed out that typical corporate security teams use more than 70 tools in parallel, and that endpoints, cloud and identity data are managed separately, making it difficult to view results together.
According to the company, "Agentic Exposure Management" consolidates vulnerability information from multiple sources in one place and then presents threat intelligence and a prioritised list of actions. "Vulnerability Resolution AI Specialist" handles triage in large-scale environments and can apply low-risk patches on its own. In detection, products were added for application security, dynamic application security testing and external attack surface management.
Armis technology was reflected in cyber-physical security. "Agentic AI for Cyber Physical Security" discovers operational technology and medical network devices without installing agents and performs behaviour baseline setting, continuous compliance checks and attack path modelling. In identity security, which applies Vectra technology, "AI Agent Access Security" and "Non-human Identity Remediation" were added. The two products support integrated control of AI agent access as well as key rotation, account decommissioning and permission revocation.
Incident response and compliance automation were also included. "Tier 2 SOC AI Specialist" establishes and executes a multi-step response plan for complex security incidents. It handles enrichment, correlation analysis and isolation without human intervention and passes only high-risk cases to analysts. A continuous monitoring agent checks segregation of duties, access rights and configuration status in real time across ServiceNow internal and external systems. "Cryptographic Asset Compliance" identifies legacy cryptographic algorithms in on-premises and cloud environments and supports a shift to post-quantum standards.