ServiceNow Otto for Security Incident Response (SIR) (SIR) release notes

  • Release version: Zurich
  • Updated January 28, 2026
  • 6 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of ServiceNow Otto for Security Incident Response (SIR) Zurich Release Notes

    ServiceNow Otto for Security Incident Response (SIR) enhances security analysts' ability to autonomously resolve security incidents through intelligent workflows and generative AI capabilities. The Zurich release introduces multiple improvements and new AI-powered skills, agents, and workflows designed to streamline incident management, resolution, and reporting within the ServiceNow platform.

    Show full answer Show less

    Key Features

    • Incident Resolution Plan Enhancement: Integrate existing runbooks into the AI-powered Security Incident Resolution Plan skill to provide richer context and improve resolution accuracy.
    • Now Assist AI Agents and Skills: Multiple AI agents and skills are activated by default, enabling functions such as incident summarization, resolution note generation, post-incident analysis, and quality assessment reporting.
    • Agentic Workflows: AI-driven workflows assist in resolving incidents, generating shift handover reports, and analyzing security operations metrics like MTTA and MTTR to optimize team performance.
    • Shift Handover Reporting: AI agents help populate shift handover reports by extracting relevant incident details and refining content based on analyst feedback.
    • Correlation Insights Enhancements: Generate insights based on multiple configuration items (CIs) or affected users beyond just primary associations, improving investigation depth.
    • User Interface Improvements: Introduction of a “Show More” UI card for recommended actions, allowing analysts to access additional context and investigative steps easily.
    • Security and Role Configuration: Additional role configurations are required for agentic workflows and AI agents to ensure appropriate access and execution control.
    • Integration Requirements: The AI Search application must be enabled for recommended actions to function correctly.

    Practical Benefits for ServiceNow Customers

    • Automated and intelligent incident resolution reduces manual effort and accelerates response times.
    • Enhanced reporting capabilities improve communication during shift changes and support compliance requirements.
    • Insightful metrics and AI recommendations help manage and improve security operations team performance.
    • Flexible and enhanced correlation insights aid in thorough investigations by considering multiple related entities.
    • Default activation of key AI skills and workflows simplifies setup while maintaining control over individual skill activation.
    • Improved user experience through UI enhancements facilitates faster access to actionable recommendations.

    Upgrade and Activation Notes

    Upgrading to the Zurich release automatically activates default Now Assist skills unless previously deactivated or configured otherwise, allowing customers to maintain control over AI features. Dependency applications update automatically, and enabling AI Search is mandatory for full functionality. ServiceNow Otto for Security Incident Response (SIR) must be installed via the ServiceNow Store.

    The ServiceNow® ServiceNow Otto for Security Incident Response (SIR) application helps your security analysts resolve security incidents autonomously with intelligent workflows and generative AI skills. ServiceNow Otto for Security Incident Response (SIR) was enhanced and updated in the Zurich release.

    ServiceNow Otto for Security Incident Response (SIR) highlights for the Zurich release

    Zurich Patch 7
    • Help enhance incident resolution plan generation by adding your existing runbooks to the AI runbooks section within the Security incident resolution plan skill. The existing runbooks provide additional context to the skill.
    • Use the Sightings search and Isolate host capabilities in the Resolve security incident workflow to help resolve security incidents.
    Zurich Patch 5
    • Review changes to Now Assist usage measurement.
    Zurich Patch 4
    • Some Now Assist skills are now turned on by default.
    • Use generative AI to create a quality assessment report of a security incident.
    • Additional role configuration required for agentic workflows and AI agents included with your applications.
    Zurich Patch 1
    • Help analysts to add security incidents details to the Shift Handover report by chatting with AI agents in the Now Assist panel.
    Zurich Early Availability
    • Help your analysts to gain insight into security incident record metrics with an agentic workflow. Chat with AI agents in natural language from the Now Assist panel.
    • Help your analysts to resolve security incidents by chatting with AI agents in the Now Assist panel where the AI agent can assist in providing a resolution plan.
    Important:
    ServiceNow Otto for Security Incident Response (SIR) is available in ServiceNow Store. For details, see the "Activation information" section of these release notes.

    Important information for upgrading ServiceNow Otto for Security Incident Response (SIR) to Zurich

    Note:
    The following Now Assist skills, agents, and agentic workflows for ServiceNow Otto for Security Incident Response (SIR) are activated by default:
    Skills
    • Security incident summarization
    • Resolution notes generation
    • Post incident analysis
    • Security incident recommended actions
    • Correlation insights generation
    • Security incident quality assessment
    • Natural language condition evaluator
    • Generate content for shift handover
    • Quality assessment report NACM
    • Security incident resolution plan
    • Security operations metrics analysis
    Agentic workflows
    • Wrap up security incident
    • Resolve security incident
    • Generate SIR shift handover report
    • Analyze security operations metrics
    Agents
    • EDR AI agent
    • Exchange online integration handling AI agent
    • Observable analysis AI agent
    • Security incident activities handling AI agent
    • Security incident resolution AI agent
    • Security incident retrieval AI agent
    • Security incident shift handover AI agent
    • Security incident wrap up generator AI agent
    • Security metrics analysis AI agent
    For more information, see Now Assist skills, agents, and agentic workflows on by default
    Note:
    Upgrading the Now Assist plugins activates any designated skills that were previously untouched by the customer.
    • If you installed the plugins for a skill but never configured it, meaning you never activated it nor adjusted associated roles, any skill on by default is activated on a per skill basis when upgrade.
    • If you previously toggled a skill from active and then back to inactive, or updated any roles for that skill, that skill remains inactive when upgrading.
    • You maintain full control over deactivating individual skills at any time after activation.

    When you update the ServiceNow Otto for Security Incident Response (SIR) (SIR) application, the dependency applications are automatically updated.

    For more information about required applications for ServiceNow Otto for Security Incident Response (SIR), see Supporting information for Now Assist for Security Incident Response.

    The AI Search application must be enabled so that the recommended actions skill works for security incidents with ServiceNow Otto for Security Incident Response (SIR). To verify that AI Search is enabled on your instance, navigate to All > AI Search > AI Search Status. Contact support if the page indicates that AI Search isn’t enabled.

    New in the Zurich release

    Zurich Patch 7
    Resolve a security incident
    Help enhance incident resolution plan generation by adding your existing runbooks to the AI runbooks section within the Security incident resolution plan skill. The existing runbooks provide additional context to the skill.
    Zurich Patch 4
    Role configuration required for agentic workflows and AI agents
    Agentic workflows and AI agents included with your applications require additional security configuration. If you select Users with selected roles for your user access security controls for an agentic workflow or AI agent, you must add the installed roles, or they will not execute. See the documentation for the agentic workflow or AI agent for the specific roles you must add.
    Exploring Security incident quality assessment with Now Assist for Security Incident Response
    Use generative AI to create a quality assessment report of a security incident. The reports are generated using a predefined, natural language rule set. The report provides an overall assessment summary followed by the detailed assessment for all the rules.
    Zurich Patch 1
    Generate SIR Shift Handover Report
    The AI agent helps add security incident details to a shift handover report. The agent populates the different sections of the shift handover with appropriate content by identifying the relevant details from the security incident. The AI agent can fetch details of the security incident and identify if the analyst has access to the shift handover record. The AI agent can generate content for each section of the shift handover record and asks for analysts feedback on the content. The AI agent refines the content based on the feedback and saves the content to the records on approval.
    Zurich Early Availability
    Using agentic AI workflows in Now Assist for Security Incident Response
    The analyze security operations metrics agentic workflow helps security managers to analyze their teams' performance.
    • Generate metrics for Security Incident Response (SIR) records for case volume, mean time to assign (MTTA), and mean time to resolve (MTTR) for a date range of your choosing.
    • Request suggestions for how to improve MTTR, MTTA, and volume based on your metrics.
    Enhancements to correlation insights in ServiceNow Otto for Security Incident Response (SIR)
    You can generate and view results for correlation insights in the Security Incident Response Workspace.
    • Correlation insights aren’t limited to the primary configuration item (CI) or affected users associated with a security incident. You can base your correlation insights on any CI or affected user for a security incident.
    • You can generate correlation insights from the Investigation tab for a security incident in any state in the Security Incident Response Workspace.
    • You can generate insights for multiple items simultaneously for Associated Observables, Configuration items, and Affected Users.
    • Results are displayed in a modeless dialog that you can size and move.
    Using the security incident resolution agentic workflow
    Use the security incident resolution agentic workflow to close your security incidents. Analysts can chat with AI agents in natural language to resolve the security incidents. The AI agent analyzes the incident details, existing runbooks, Knowledge articles, and past similar security incidents as inputs, and provides a resolution plan. The AI agent also assists the analysts to resolve the security incident.

    UI changes

    Generate recommended actions for a security incident with Now Assist for Security Incident Response
    A new Show More UI card has been introduced to enhance the visibility of recommended actions. As a security analyst, you can now access additional context along with further recommended steps to assist in the analysis and investigation of security incidents.

    Changed in this release

    Zurich Patch 7
    Resolve a security incident
    Use the Sightings search and Isolate host capabilities in the Resolve security incident workflow to help resolve security incidents.

    Activation information

    Install ServiceNow Otto for Security Incident Response (SIR) by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.