Combined Data Loss Prevention Incident Response release notes for upgrades from Xanadu to Zurich

  • Release version: Zurich
  • Updated July 20, 2026
  • 6 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Combined Data Loss Prevention Incident Response release notes for upgrades from Xanadu to Zurich

    This consolidated guide provides ServiceNow customers with key information about upgrading the Data Loss Prevention Incident Response (DLP IR) application from the Xanadu release family through to Zurich. It highlights new features, changes, activation instructions, and important upgrade considerations to help prepare for a smooth transition and maximize the value of DLP Incident Response capabilities.

    Show full answer Show less

    New Features

    • SLA Triggers and Definitions: From Yokohama and continuing in Zurich, customers can create SLA triggers and define SLA conditions and durations to ensure timely and efficient incident responses to data breaches.
    • Proofpoint Integration: Introduction of configuring applications in Proofpoint to obtain client credentials, enabling secure API access for automation and integration. Zurich adds installation and configuration guidance for Proofpoint integration for DLP incident investigations.
    • Evidence File Management Enhancements: Enhanced ability to store evidence files directly in ServiceNow with Proofpoint integration and Symantec DLP support. Customers can preview and download evidence files from Microsoft OneDrive, Exchange Online, SharePoint, and Netskope integrations, simplifying evidence review.
    • ICAP Integration: Yokohama introduced ICAP support to ingest alerts and fetch matched content and evidence files from Amazon S3 in ICAP-supported DLP deployments.
    • Playbooks and Incident Consolidation: Playbooks introduced in the DLP Workspace improve operational efficiency, and incident consolidation rules prioritize parent incidents among grouped cases.

    Changes

    • The DLP incident table’s “Custom Fields” column was renamed to “Additional Incident Data Fields” starting in Yokohama to better reflect its purpose.

    Activation and Installation

    DLP Incident Response must be requested and installed via the ServiceNow Store for Yokohama and Zurich releases. Customers should consult the ServiceNow Store version history release notes for cumulative information on all app versions.

    Upgrade Preparation and Important Notes

    • Review and complete pre- and post-upgrade tasks to ensure readiness for Zurich.
    • Note that from Xanadu to Zurich, there were no removals or deprecations of features.
    • Browser, accessibility, localization, and additional requirements remained unchanged across these releases.

    Key Outcomes for ServiceNow Customers

    • Enhanced operational efficiency and incident management through SLA triggers, definitions, and playbooks.
    • Improved integration with key DLP vendors like Proofpoint, Symantec, Microsoft, and Netskope, enabling better evidence handling and streamlined investigations.
    • More accurate incident prioritization with consolidated incident rules ensuring parent incidents maintain highest priority.
    • Consistent upgrade experience with clear activation instructions and minimal disruption due to lack of deprecated or removed features.

    Consolidated page of all release notes for Data Loss Prevention Incident Response from Xanadu to Zurich.

    How to use this page

    To help you prepare for your upgrade, we have combined the cross-family Data Loss Prevention Incident Response release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Xanadu to Zurich.

    Tip:
    If there were no updates for a release notes section in a certain family release, we included a short note for your reference. For example, if a product did not have any updates in Tokyo, the row says "No updates for this release."

    Important information for upgrading Data Loss Prevention Incident Response to Zurich

    Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    New features

    Between your current release family and Zurich, new features were introduced for Data Loss Prevention Incident Response.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    Create a Data Loss Prevention Incident Response SLA trigger
    Enable prompt and efficient responses to incidents by creating SLA triggers.
    Create a Data Loss Prevention Incident Response SLA definition
    Outline the conditions and duration for responding to data breaches by creating Data Loss Prevention Incident Response SLA definitions.
    Create an Application in Proofpoint and Obtain Client Credentials
    Create an application in Proofpoint and configure the required settings to obtain client credentials. These credentials enable secure access to the Proofpoint API for seamless integration and automation.
    Internet Content Adaption Protocol (ICAP) integration for DLP IR
    Integration supports the ingestion of Data Loss Prevention Incident Response alerts, allows the fetching of match content, and evidence files from Amazon S3 created on the ICAP supported Data Loss Prevention Incident Response deployment.
    Configure evidence file storage
    Store evidence files directly in your ServiceNow instance with Proofpoint integration, by enhancing the ability to manage and track evidence files within the platform.
    Configure evidence file storage
    Symantec DLP supports evidence file storage to securely store the evidence files for the DLP Incidents.
    Preview Evidence files for DLP incidents of type Exchange Online, OneDrive, and SharePoint.
    With the DLP Microsoft integration, preview evidence files in the DLP Workspace in the Microsoft OneDrive, Microsoft Exchange Online, and Microsoft SharePoint formats. You can preview and download evidence files directly from the preview interface, simplifying evidence review and retrieval.
    Netskope integration: Preview evidence files and Download evidence files
    With Netskope integration you can preview and download evidence files directly from the preview interface, simplifying evidence review and retrieval.
    Preview evidence files
    Preview evidence files and download them directly from the preview interface, simplifying evidence review and retrieval.
    Playbook for Data Loss Prevention Incident Response
    Introduced playbooks in the DLP Workspace to enhance operational efficiency.
    Create incident consolidation rules
    Parent incident is always assigned the highest priority among consolidated incidents, enhancing incident management accuracy.

    Zurich

    Create a Data Loss Prevention Incident Response SLA trigger
    Enable prompt and efficient responses to incidents by creating SLA triggers.
    Create a Data Loss Prevention Incident Response SLA definition
    Outline the conditions and duration for responding to data breaches by creating Data Loss Prevention Incident Response SLA definitions.
    Create an Application in Proofpoint and Obtain Client Credentials
    Create an application in Proofpoint and configure the required settings to obtain client credentials. These credentials enable secure access to the Proofpoint API for seamless integration and automation.
    Install and configure the Proofpoint integration for Data Loss Prevention
    Install and configure the Proofpoint integration to use the  Proofpoint DLP incident data to investigate DLP incidents.

    Changes

    Between your current release family and Zurich, some changes were made to existing Data Loss Prevention Incident Response features.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    Create Additional Incident Data Fields
    In the DLP incident table, the Custom Fields column has been renamed Additional Incident Data Fields.

    Zurich

    No updates for this release.

    Removed

    Between your current release family and Zurich, some Data Loss Prevention Incident Response features or functionality were removed.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Deprecations

    Between your current release family and Zurich, some Data Loss Prevention Incident Response features or functionality were deprecated.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Activation information

    Review information on how to activate Data Loss Prevention Incident Response.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    Install Data Loss Prevention Incident Response by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.

    Zurich

    Install Data Loss Prevention Incident Response by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.

    Additional requirements

    If any additional requirements were introduced or changed for Data Loss Prevention Incident Response we have noted them here.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Browser requirements

    If any specific browser requirements were introduced or changed for Data Loss Prevention Incident Response we have noted them here.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Accessibility information

    Review details on accessibility information for Data Loss Prevention Incident Response, such as specific requirements or compliance levels.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Localization information

    If there are specific localization considerations for Data Loss Prevention Incident Response we have noted them here.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Highlight information

    If there are specific highlight considerations for Data Loss Prevention Incident Response we have noted them here.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    • Enhanced the ability to securely store, manage, and track evidence files within the platform for all Data Loss Prevention Incident Response integrations.
    • Preview the evidence file of an incident from either the DLP IR analyst workspace or end user workspace.
    • Enhanced the DLP incident closure process by adding support for closure codes.
    • Introduced the Playbook feature in the DLP IR workspace to enhance operational efficiency.
    • Improved response to Data Loss Prevention (DLP) incidents through the initiation of SLA triggers.

    See Data Loss Prevention Incident Response for more information.

    Zurich

    • Improved response to Data Loss Prevention (DLP) incidents through the initiation of SLA triggers.
    • Introduced SLA Definition functionality that outlines the conditions and duration for responding to data breaches.
    • Configured DLP Proofpoint to generate Client ID and Client Secret to enable secure access to proofpoint.

    See Data Loss Prevention Incident Response for more information.