---
sourceDocument: Brazil Release Notes
sourceDocumentLink: https://www.servicenow.com/docs/r/release-notes

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Release Notes

ft:clusterId :

    - rn

bundleId :

    - rn


---

# Security Incident Response release notes

# Security Incident Response release notes {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read  
The ServiceNow®
Security Incident Response (SIR) application helps your organization connect security and IT teams, respond faster and more efficiently to threats, and gain insight into your organization's security posture. See the following sections for release notes by release.

## About Security Incident Response {#secops-sir-rn__secops-sir-rn-about}

* Connect security and IT teams to respond faster and more efficiently to security threats.
* Gain insight into your organization's security posture.
* Automatically create and enrich security incidents by integrating with third-party detection and SIEM sources such as CrowdStrike Next-Gen SIEM and Microsoft Defender.
* Rapidly build new integrations using Now Assist LLM-powered auto-code generation.
* Visualize attack-defense relationships using MITRE-ATT\&CK and MITRE D3FEND data directly within a security incident.
{#secops-sir-rn__ul_secops-sir-rn-about}

See [Security Incident Response](https://www.servicenow.com/docs/access?context=sir-landing-page&version=brazil&pubname=brazil-security-management&ft:locale=en-US) for more information.{#secops-sir-rn__secops-sir-rn-about-2}

## Activation and other requirements {#secops-sir-rn__secops-sir-rn-requirements-activation}

Activation information{#secops-sir-rn__secops-sir-rn-activation-info}
:   Install Security Incident Response by requesting it from the ServiceNow Store. Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) to view all the available apps, and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).

    Install ServiceNow Otto for Security Incident Response (SIR) to use the AI features.
    {#secops-sir-rn__secops-sir-rn-requirements-info-1}
{#secops-sir-rn__secops-sir-rn-requirements-info-1}

Additional requirements{#secops-sir-rn__secops-sir-rn-add-reqs}
:   The Security Support Common plugin is activated automatically when any of the plugins for the main Security Operations applications are activated. These applications include Security Incident Response, Vulnerability Response, Threat Intelligence, and Configuration Compliance.{#secops-sir-rn__secops-sir-rn-requirements-additional-1}
{#secops-sir-rn__secops-sir-rn-requirements-additional-1}{#secops-sir-rn__secops-sir-rn-activation-details}

## Brazil Early Availability {#ariaid-title2}

This release adds MITRE ATLAS threat detection to help you investigate and respond to security incidents faster. ServiceNow Otto for Security Incident Response (SIR) introduces conversational data analysis, value realization dashboard, and quality assessment reporting enhancements.

### What's new {#secops-sir-rn-2026-09__secops-sir-rn-2026-09-new}

[MITRE ATLAS framework](https://www.servicenow.com/docs/access?context=about-mitre-atlas&version=brazil&pubname=brazil-security-management&ft:locale=en-US){#secops-sir-rn-2026-09__secops-sir-rn-2026-09-new-feature-1}
:   Detect, classify, and respond to AI- and ML-specific threats --- such as prompt injection, model poisoning, data extraction, and adversarial attacks --- using the MITRE ATLAS framework alongside MITRE-ATT\&CK. ATLAS techniques associated with a security incident appear in the MITRE node map, incident timeline, and MITRE info card with a distinct icon. This lets you tell MITRE-ATT\&CK and ATLAS techniques apart at a glance. Administrators can configure ATLAS-related properties on the Threat Intelligence Properties page.

[Analyze security incident data](https://www.servicenow.com/docs/access?context=analyze-data-sir&version=brazil&pubname=brazil-security-management&ft:locale=en-US){#secops-sir-rn-2026-09__secops-sir-rn-2026-09-new-feature-3}

:   Ask questions about your security incident data in a conversational language, without writing queries or knowing how reports are structured. Ask follow-up questions in the same
    session or move to a different question. AI-generated responses include insights and recommendations rather than only direct answers.{#secops-sir-rn-2026-09__secops-sir-rn-2026-09-new-feature-3-intro}

[Review Security Incident AI ROI Summary dashboard](https://www.servicenow.com/docs/access?context=ai-roi-summary-dashboard&version=brazil&pubname=brazil-security-management&ft:locale=en-US){#secops-sir-rn-2026-09__secops-sir-rn-2026-09-new-feature-4}

:   Track the value your team realizes from the AI features under Security Incident Response Management. The metrics include time saved per capability, total assists consumed, assists per resolved incident, and daily unique users, so you can see which capabilities are adopted.{#secops-sir-rn-2026-09__secops-sir-rn-2026-09-new-feature-4-intro}

[Map incident fields](https://www.servicenow.com/docs/access?context=pan-cortex-xsiam-mapping&version=brazil&pubname=brazil-security-management&ft:locale=en-US)

:   Build Cortex XSIAM field mappings from a known incident. Select the Incident ID ingestion method and enter an ID in the XSIAM Incident ID field to retrieve its actual field values.

    {#secops-sir-rn-2026-09__secops-sir-rn-2026-09-new-feature-7-intro}
{#secops-sir-rn-2026-09__secops-sir-rn-2026-09-new-feature-7-intro}

[Automate incident updates and closures](https://www.servicenow.com/docs/access?context=pan-xsiam-automate-inc-updates&version=brazil&pubname=brazil-security-management&ft:locale=en-US)

:   Map Security Incident fields to Cortex XSIAM on the new SIR to XSIAM Mapping panel using drag-and-drop, override, and transformation scripts. When the check box is selected, any new or updated data from
    SIR Incident will automatically sync with the corresponding fields in the XSIAM portal.

    {#secops-sir-rn-2026-09__secops-sir-rn-2026-09-new-feature-8-intro}
{#secops-sir-rn-2026-09__secops-sir-rn-2026-09-new-feature-8-intro}{#secops-sir-rn-2026-09__secops-sir-rn-2026-09-new-list}

### What's changed {#secops-sir-rn-2026-09__secops-sir-rn-2026-09-changed}

[Exploring Security incident quality assessment](https://www.servicenow.com/docs/access?context=na-sir-quality-assessment&version=brazil&pubname=brazil-security-management&ft:locale=en-US){#secops-sir-rn-2026-09__secops-sir-rn-2026-09-changed-feature-1}
:   Customize or regenerate entire draft reports or specific sections within it, before you share it with stakeholders.
{#secops-sir-rn-2026-09__secops-sir-rn-2026-09-changed-list}

### What's deprecated or removed {#secops-sir-rn-2026-09__rn-deprecated-removed_zgk_ggr_kkc}

Now LLM service deprecation
:   Starting with the September 2026 release, Gemma 4 joins our growing portfolio of open-weight models available through Now LLM Service. The latest industry advancements are available alongside sovereignty-focused options. All models are hosted and governed by ServiceNow with the same infrastructure and data protections. Older models will remain available for existing published AI skills, agents, and agentic workflows, but will no longer be available for new development or configuration. For details, see the [KB3066214: ServiceNow Otto Model Upgrades](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3066214) article in the Now Support Knowledge Base.
{#secops-sir-rn-2026-09__secops-sir-rn-2026-09-dep-list}

### Plugin information {#secops-sir-rn-2026-09__secops-sir-rn-2026-09-plugin-info}

Deprecated plugins{#secops-sir-rn-2026-09__secops-sir-rn-2026-09-deprecated-plugins}

:   Security Incident Response Process Mining Content Pack (com.sn_sir_process_mining_cp): This plugin is deprecated and replaced by the core Process Mining Content Pack application,
    which is automatically installed for Security Incident Response. No action is required.{#secops-sir-rn-2026-09__secops-sir-rn-2026-09-deprecated-plugin-1}

{#secops-sir-rn-2026-09__secops-sir-rn-2026-09-plugin-details}

