Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

Looking for real-world SIR implementation lessons learned

Aebalo
Tera Contributor

Hi everyone,

 

I’m looking to connect with practitioners who have implemented or currently support Security Incident Response (SIR), especially in public-sector or large-enterprise environments.

 

I’m looking to better understand the real-world experience with SIR beyond product demos and documentation.

 

A few things I’d especially like to learn:

 

  • What use case did you start with, and would you start there again?
  • Where has SIR worked particularly well for your organization?
  • Where did you run into gaps or have to adjust your process?
  • How do you handle intake from teams outside of Security?
  • What integrations have been most important to your implementation?
  • If you were starting your SIR implementation again today, what would you do differently?

 

I’d also appreciate any recorded customer presentations, implementation examples, public-sector use cases, or other Community resources that demonstrate SIR operating in real-world environments.

 

Happy to trade lessons learned as well. I’m currently doing quite a bit of work around ITSM, CMDB, CSDM, and enterprise ServiceNow governance.

 

Practitioner/customer perspectives only, please. No vendor or partner outreach on this one.

 

Thanks in advance.  I’d appreciate any experiences, lessons learned, or resources the Community can share.

0 REPLIES 0