- Post History
- Subscribe to RSS Feed
- Mark as New
- Mark as Read
- Bookmark
- Subscribe
- Printer Friendly Page
- Report Inappropriate Content
yesterday
In 2026, AI accelerated both the ability for attackers to strike faster and stronger, and defenders to respond faster and more comprehensively. Recent incidents, including AI agents that autonomously coordinated to breach infrastructure at Hugging Face over several days, show this isn't theoretical.
“60 minutes to contain is no longer enough for our CISO” as one customer told us. The new goal, as the Head of Security of another big bank told us, is “From alert to containment in 10 minutes”.
Security teams are expected to respond faster, investigate deeper, and demonstrate measurable outcomes with limited resources.
While AI has become a non-negotiable part of modern Security Operations Centers (SOCs), two challenges remain: helping security analysts quickly find the intelligence they need to make decisions, and helping leaders measure the value AI is creating.
The new version 6.5 of ServiceNow Otto for SIR (formerly known as Now Assist for SIR) addresses both challenges with 2 new capabilities:
- Security Incident 360: An AI-powered experience that brings together relevant security intelligence to help analysts, managers, and executives investigate and respond faster.
- AI ROI Summary Dashboard: A centralized dashboard that measures AI adoption, time savings, value creation, and overall business impact.
Together, these capabilities help organizations operationalize AI insights and clearly demonstrate AI-driven outcomes.
Ask Anything, Get Answers: Security Incident 360
Security incidents affect different stakeholders in different ways.
- Security Analysts need to understand what's happening and what actions to take next.
- SOC Managers need visibility into recurring patterns and emerging trends across incidents.
- CISOs need a broader view of organizational exposure, risk concentration, and changing threat patterns.
Security Incident 360 is designed to provide the right insight for each persona.
Security Intelligence through Natural Language
Following the massive success of Security Exposure 360 – which has become our fastest adopted AI feature in USEM in the past 90 days – Security Incident 360 is an AI capability built into Security Incident Response leveraging the same architecture. Users can ask ANY questions in natural language and receive answers grounded in data across their ServiceNow instance. For example:
Security Analysts can ask:
- Has this combination of asset and technique occurred before, and how was it resolved?
- What root causes are commonly associated with this type of security incident?
- Show me a timeline of the key events that happened in this incident from the past 60 minutes
SOC Managers can ask:
- What patterns have existed across recurring incidents from the past 90 days?
- What’s our Mean Time to Contain (MTTC)? What’s our 6-month trend?
CISOs can ask:
- Where is incident activity concentrated today?
- What changes in organizational exposure from the past 90 days require attention?
- What are 3 important narratives about my security posture to share with my Board this quarter?
From Insights to Actions – In Minutes
When combined with the agentic capabilities built into Security Incident Response, Security Incident 360 shifts response time from 2–4 hours down to 10 minutes or less. Analysts get answers to their most pressing questions in seconds to minutes, then launch the Security Incident Resolver Agent to handle the incident end-to-end in 5 minutes or less, or the Wrap-up Agent to close a security incident in 2 minutes or less.
Analysts can also assign incidents to the T2 SOC AI Specialist, which takes over investigation, orchestration, and response entirely.
This is what separates leading Security Operations Centers today: they respond in minutes, not hours or days.
How It Delivers Accurate Answers
Unlike AI experiences limited to a single record or table, Security Incident 360 uses ServiceNow’s Enterprise Knowledge Graph to understand relationships across security data before generating a response.
This enables ServiceNow customers to gain the following unique advantages:
- Automatically identify relevant data sources without requiring users to know which tables or fields contain the answer.
- Traverse relationships across security incidents, assets, services, and attack techniques to answer complex questions in a single interaction.
- Incorporate external intelligence when needed, combining it with internal security context to provide more complete answers.
Built for Your Security Operations – Easily extendable
Security Incident 360 works with standard SIR data models and can be tailored to fit your organization's environment. All responses generated by our Agent abide by the rules of existing platform permissions and ACLs.
Organizations can very easily extend our knowledge graph to:
- Include custom tables as part of the investigation context (by simply selecting them. No coding is needed)
- Include custom fields as part of the investigation context.
- Teach our Agent organization-specific terminology and mappings so responses align with how teams work.
Proving AI’s Worth: The AI ROI Summary Dashboard
As organizations expand their use of AI-powered capabilities such as Security Incident 360, security leaders need visibility into adoption and value.
As one customer told us, “I need a way to show my CISO and CFO the ROI of my AI investment” - Enter the AI ROI Summary Dashboard. This dashboard provides a centralized view of AI usage and outcomes across Security Operations.
Organizations can measure specific metrics on:
- Total time saved
- Estimated business value generated
- AI adoption and engagement trends
- Skill and workflow utilization
- Overall AI consumption patterns
The dashboard helps leaders answer pressing questions such as:
- How much manual effort AI is eliminating?
- Which teams and users are adopting AI most effectively?
- Which AI skills and workflows deliver the greatest value?
- How do AI usage and outcomes evolve over time?
From incident summarization and post-incident analysis to resolution notes, recommended actions, shift handovers, and Security Incident 360 interactions, organizations can now quantify the impact of AI across their security operations.
By turning AI value into measurable outcomes, the dashboard helps leaders make informed decisions about adoption, investments, and operational improvements.
The Feedback Loop: Intelligence In, Accountability Out
The future of Security Operations is not simply adding more AI. It is making intelligence easier to access while measuring the value it creates.
Security Incident 360 helps users turn connected security data into actionable insights and faster decisions. The AI ROI Summary Dashboard helps organizations quantify the efficiency, adoption, and business impact of those AI experiences.
Together, they create a continuous feedback loop: AI improves security decision-making, while measurable outcomes help organizations optimize and expand AI adoption.
Both capabilities are live now on the ServiceNow Store as part of ServiceNow Otto for SIR (v6.5 and above). Download it today and see how fast – and how measurable – your security operations can be.
We want to hear from you: what's the one question you wish your security data could answer right now? Tell us in the comments – your feedback shapes what we build next.
Onwards and upwards!
The SecOps PM Team
