ServiceNow Autonomous Security & Risk: A UK CISO Playbook for Armis, Veza and Agent Identities
Knowledge 2026 put Armis asset intelligence and Veza identity graphs on ServiceNow security plane. Here is a 30-day UK path to govern AI agents, NHIs and connected assets without a rip-and-replace.

Knowledge 2026 put Armis asset intelligence and Veza identity graphs on ServiceNow security plane. Here is a 30-day UK path to govern AI agents, NHIs and connected assets without a rip-and-replace.
- Autonomous Security & Risk combines Armis asset intelligence and Veza Access Graph on the ServiceNow AI Platform.
- Every AI agent is a non-human identity; UK estates must inventory entitlements before scaling agents.
- CMDB enrichment and least-privilege enforcement must close into existing VR/SIR workflows.
- 30-day path: baseline NHI/OT blind spots then one graph slice then one supervised autonomous response use case.
CISOs now run at two speeds — agents force both
UK boards are asking for AI ROI and for proof that non-human identities are not a silent breach class. ServiceNow's answer at Knowledge 2026 was Autonomous Security & Risk: put Armis asset intelligence and Veza identity/permission graphs on the same platform that already runs vulnerability, exposure and incident workflows.
That matters because every agent is an identity. Most of those identities still inherit human-shaped entitlements, then act at machine speed. Fragmented tools cannot answer who approved access, why it exists, or whether it is still valid.
Security operations and connected infrastructure
This playbook is for UK CISOs, CROs and ServiceNow security architects who need a governed path from Knowledge announcements to a live attack-surface and identity graph — without a multi-year rip-and-replace.
What shipped: asset graph + identity graph + autonomous response
Armis: see the attack surface that CMDB never held
Once integrated, Armis is positioned to deliver continuous, agentless visibility across IT, OT, IoT, code and connected devices, enriching asset records with classification, firmware, behaviour and risk posture. That intelligence is meant to flow into the ServiceNow CMDB, turning a static inventory into a live picture of the attack surface ServiceNow can already remediate.
For UK estates that still reconcile OT and IoT outside ITSM, this is the practical pitch: stop maintaining a parallel "shadow CMDB" for devices your scanners never owned.
Veza: govern human and non-human identities together
Veza's Access Graph maps who/what has access, what they can do, and how that changes as agents multiply. Integrated into the ServiceNow AI Platform, it is meant to surface risk, enforce least privilege at the point of action, trigger remediation, and keep the audit trail regulators expect — including for non-human identities that already outnumber people in many estates.
A major US financial services example cited by ServiceNow: 96% of dormant non-human identities eliminated once least privilege became enforceable rather than aspirational.
AI specialists on the same plane
Two security/risk AI specialists were announced to handle vulnerability resolution and security operations end to end — clearing vulnerability backlogs and investigating phishing alongside humans — under AI Control Tower inventory, risk scoring and least-privilege enforcement, with A2A/MCP interoperability for agents on other platforms.
ServiceNow's own SecOps team is described as handling incidents seven times faster with every action documented. Customer stories include a global energy company saving 1.2 million hours and cutting contain time by 97%, and a Fortune 100 aerospace manufacturer cutting control-attestation time by 75% and compliance-gap close time by 85%.
Treat those figures as directional case studies, not your business case. Build your UK numbers from your own MTTC, dormant NHI count and attestation cycle time.
Why UK regulated firms should care now
- Non-human identity is now a board risk. Agents with over-broad tokens are the new service accounts — except they decide and mutate.
- CMDB without live asset context fails AI SecOps. If OT/IoT/code assets are invisible, autonomous response will chase the wrong perimeter.
- Audit wants a single graph. FCA/PRA-style evidence packs want who/what/why/when on access and remediation — not screenshots from five consoles.
- AI Control Tower alone is not enough. You already covered Control Tower and AI Gateway in prior Insights posts; Autonomous Security & Risk is the security data plane those controls sit on.
A 30-day UK adoption path
Days 1–7 — Baseline the blind spots
- Count non-human identities (integrations, Mid Servers, spokes, OAuth clients, agent service accounts, MCP connectors).
- Map OT/IoT/medical/edge assets that never land in CMDB cleanly.
- Name owners: CISO for risk appetite, ITAM for CMDB classes, IAM for NHI lifecycle.
- Decide the first kill-switch path for a misbehaving agent (Control Tower + IAM revoke).
Days 8–16 — One graph slice, not a platform rewrite
- Pilot Armis enrichment into a bounded CMDB class (e.g. network devices + one OT plant).
- Pilot Veza Access Graph on one high-blast domain (prod cloud IAM + ServiceNow integrations).
- Wire findings into existing Vulnerability Response / Security Incident workflows — do not invent a parallel queue.
- Require every new AI agent registration to carry an identity owner, permission set and review cadence.
Days 17–30 — Prove autonomous response with humans in the loop
- Enable one AI specialist use case (phishing triage or vulnerability backlog) with mandatory human approval on high-impact actions.
- Measure: time-to-enrich asset, % NHIs with owner, dormant NHI reduction, MTTC for a tabletop incident.
- Document the audit trail: identity → permission → asset → action → ticket.
- Only then discuss broad Autonomous Security & Risk packaging with procurement.
Implementation pitfalls we see on UK estates
- Buying the story without CMDB hygiene. Armis will not forgive duplicate CIs and empty ownership fields.
- Treating Veza as "another IGA tool." The value is closing the loop into ServiceNow remediation, not another dashboard.
- Letting agents inherit human roles. Build agent-specific least privilege; never copy a human ACL wholesale.
- Skipping Control Tower registration. Ungoverned MCP/A2A agents recreate the NHI problem at higher speed.
- Ignoring OT change windows. Agentless monitoring still needs operational buy-in from plant and clinical engineering teams.
Expert view
Autonomous Security & Risk is ServiceNow saying the quiet part out loud: AI security fails when identity and asset graphs are split. UK firms that already run SecOps and ITAM on ServiceNow should treat Armis + Veza as force multipliers for the platform they own — not as a reason to pause AI programmes. Firms with weak CMDB and no NHI programme should fix that first; otherwise autonomous response will automate confusion.
Bottom line
If you are a UK CISO evaluating Knowledge 2026 security claims, ask three questions this month:
- Can we list every AI agent identity and its entitlements today?
- Does CMDB reflect OT/IoT/code assets that actually talk on our networks?
- Can we revoke and remediate from one workflow with an auditor-grade trail?
If any answer is no, start the 30-day path above before you buy more agent capacity.
UK CISOs should treat Armis + Veza as the security data plane under AI Control Tower — not another dashboard purchase. Fix CMDB ownership and NHI lifecycle first, or autonomous response will automate confusion.
