ServiceNow unveils six autonomous security products
Thu, 6th Aug 2026 (Today)
ServiceNow has expanded its cybersecurity portfolio with six unified security products as part of its Autonomous Security offering.
The rollout brings together exposure management, vulnerability detection, cyber-physical security, identity and access security, incident response, and cyber risk and compliance on one platform, as companies face rising security demands from AI agents, machine identities, and connected devices.
The new line-up is intended to give security teams broader visibility across assets and identities while adding more automation to remediation and investigation work often spread across multiple tools.
Many enterprises still rely on fragmented security estates. ServiceNow said the average enterprise uses more than 70 security tools across endpoints, networks, cloud environments, and identity systems, making it harder to maintain a single view of risk.

Unified approach
The six product areas cover unified exposure management, continuous vulnerability detection, cyber-physical security, identity and access security, agentic incident response, and cyber risk and compliance.
In exposure management, ServiceNow is consolidating vulnerability findings from different sources into a single stream and adding threat intelligence and remediation prioritisation. It also introduced a Vulnerability Resolution AI Specialist designed to handle triage and remediation tasks, including low-risk patching.
For vulnerability detection, it is extending application security to AI-generated code and model dependencies. It is also adding dynamic application security testing for live applications and APIs, along with external attack surface management for internet-facing infrastructure.
In cyber-physical security, ServiceNow is targeting operational technology, medical devices, and internet-connected systems that often sit outside standard IT controls. Its approach uses agentless discovery, behavioural baselining, compliance monitoring, and attack-path modelling, alongside automated remediation workflows.
Identity and access security is another core part of the expansion. ServiceNow said the growth of non-human identities, including service accounts, cloud identities, and AI agents, has created a governance gap many companies have yet to address. New products include AI Agent Access Security and Non-Human Identity Remediation, which support tasks such as key rotation, deprovisioning, and permission revocation.
ServiceNow is also adding more automation to security operations centres. Its Agentic Incident Response product is designed to build and execute response plans for complex incidents by combining enrichment, correlation, containment, and blocking actions, while escalating higher-risk decisions to human analysts.
On the compliance side, ServiceNow wants to shift organisations away from periodic audit preparation and towards continuous monitoring. Tools in this area include continuous control monitoring and cryptographic asset compliance, aimed in part at helping organisations move from older cryptographic standards to quantum-resistant approaches.
AI pressure
The launch reflects a broader shift in cybersecurity strategy as companies try to manage risks introduced by AI systems that can create new identities, software components, and operating connections at a pace manual teams struggle to match.
ServiceNow framed the strategy around what it calls "Shift Zero", describing it as a move away from reactive, tool-based security and towards prevention embedded across systems, identities, and agents.
"As AI exposures compound exponentially, security teams operate on a human clock," said Yevgeny Dibrov, SVP and GM, cybersecurity and risk, ServiceNow.
"Machine identities double every 18 months. Fragmented security tools can't match the curve AI is creating. Organisations need autonomous security and governance that matches the scale, velocity, and unpredictability of the threats coming: where all assets, identities, AI agents, critical infrastructure, cloud environments and code are protected, and can adapt as fast as the ecosystem moves to detect and remediate threats in real-time. Security becomes an accelerant, not the brake."
The product expansion also draws on technology from Armis and Veza, now integrated into ServiceNow. Armis contributes visibility across connected assets, while Veza maps effective permissions across human, machine, and AI identities.
The integration is intended to support a single operational view across security and risk functions, with an audit trail showing what actions were taken and by whom. ServiceNow said this model is designed to help organisations manage accountability as more security tasks move into automated workflows.
Customer feedback included support from industrial users, a segment where cyber-physical visibility is often a priority because operational disruption can have direct safety and production consequences.
"For organizations operating complex industrial environments, effective cybersecurity starts with understanding risk and maintaining visibility across the enterprise," said Brandon Glaze, Senior Director, Cybersecurity (OT/ICS) at Baker Hughes.
"We've appreciated the collaboration and innovation from the ServiceNow (Armis) team as we continue working together to improve cyber resilience and support secure, reliable operations."