List of ServiceNow Security Operations Customers
Santa Clara, CA, 95054,
United States
Since 2010, our global team of researchers has been studying ServiceNow Security Operations customers around the world, aggregating massive amounts of data points that form the basis of our forecast assumptions and perhaps the rise and fall of certain vendors and their products on a quarterly basis.
Each quarter our research team identifies companies that have purchased ServiceNow Security Operations for Incident Management from public (Press Releases, Customer References, Testimonials, Case Studies and Success Stories) and proprietary sources, including the customer size, industry, location, implementation status, partner involvement, LOB Key Stakeholders and related IT decision-makers contact details.
Companies using ServiceNow Security Operations for Incident Management include: Cencora (formerly AmerisourceBergen), a United States based Distribution organisation with 47000 employees and revenues of $321.33 billion, Optum, a United States based Insurance organisation with 300000 employees and revenues of $257.00 billion, Cardinal Health, a United States based Healthcare organisation with 53084 employees and revenues of $222.58 billion, Evernorth Health Services, a division of The Cigna Group, a United States based Healthcare organisation with 50000 employees and revenues of $140.00 billion, Bank of America, a United States based Banking and Financial Services organisation with 213000 employees and revenues of $101.89 billion and many others.
Contact us if you need a completed and verified list of companies using ServiceNow Security Operations, including the breakdown by industry (21 Verticals), Geography (Region, Country, State, City), Company Size (Revenue, Employees, Asset) and related IT Decision Makers, Key Stakeholders, business and technology executives responsible for the software purchases.
The ServiceNow Security Operations customer wins are being incorporated in our Enterprise Applications Buyer Insight and Technographics Customer Database which has over 100 data fields that detail company usage of software systems and their digital transformation initiatives. Apps Run The World wants to become your No. 1 technographic data source!
Apply Filters For Customers
| Logo | Customer | Industry | Empl. | Revenue | Country | Vendor | Application | Category | When | SI | Insight |
|---|---|---|---|---|---|---|---|---|---|---|---|
|
|
3M | Manufacturing | 61500 | $24.6B | United States | ServiceNow | ServiceNow Security Operations | Incident Management | 2016 | n/a |
In 2016 3M implemented ServiceNow Security Operations to centralize security alert handling and formalize Incident Management within its IT and SecOps functions. ServiceNow Security Operations served as the primary Incident Management application supporting ITSM, HRSD, CSM, and SecOps workflows across the organization.
The implementation included configuration and deployment of Event Management with event rules and thresholds to monitor infrastructure health, Service Catalog for user access, Incident Management, Asset Management, IT Operations Management, Change and Release Management, and PPM Service Portal workstreams. The team leveraged ServiceNow CMS and Service Portal customization to create a user-facing PPM Service Portal and Employee Self-Service experiences, and used orchestration capabilities to automate repetitive tasks in SecOps workflows.
Integrations were implemented to ingest and correlate monitoring data and to link issue tracking with DevOps pipelines, explicitly integrating Nagios and SolarWinds for event ingestion and Azure DevOps, GitHub, and Jenkins for automated issue tracking and change request workflows. The architecture centralized event and alert ingestion into the ServiceNow platform to enable automated orchestration and to feed SecOps and ITOM dashboards and analytics.
Governance and rollout included designing approval chains for CSM contract review and renewal, implementing role based access control for HRSD, authoring BRDs and training materials, and conducting workshops for end users and developers. Training emphasized DevOps methodologies applied to ServiceNow development and governed change and release processes to improve cross team collaboration and adoption.
Documented outcomes in the implementation included improved collaboration between development and operations teams, automation of SecOps tasks that improved operational efficiency and reduced response times, and dashboards that provided stakeholders visibility into SecOps metrics and vulnerabilities. ServiceNow Security Operations was positioned as the centralized Incident Management platform supporting ongoing ITOM and security operations reporting.
|
|
|
AAA Auto Club Group | Insurance | 11000 | $3.9B | United States | ServiceNow | ServiceNow Security Operations | Incident Management | 2019 | n/a |
In 2019, AAA Auto Club Group implemented ServiceNow Security Operations to strengthen enterprise Incident Management and centralize security event triage. The deployment was positioned within the company security operations practice and aligned to Incident Management workflows used across insurance operations and IT support teams.
The implementation of ServiceNow Security Operations included core SecOps modules such as Security Incident Response, Vulnerability Response, and Vendor Risk Management, with configuration focused on automated case creation, structured triage workflows, and role-based task assignments. ServiceNow Security Operations was configured to leverage ITSM constructs for incident enrichment and lifecycle control, extending standard ServiceNow incident, problem, change, asset management, service catalog, knowledge, and CMDB relationships into security workflows.
Integration architecture used platform-native web services and API patterns, with REST and SOAP endpoints supporting inbound alerts and orchestration, and scripted integrations to enrich CMDB records and assets. Development and operational practices reflected the client team skill set, including microservices and RESTful interfaces, and aligned with existing CI/CD toolchains such as Jenkins, Docker, and Pivotal Cloud Foundry for packaging and automated delivery of integration components.
Governance and operational rollout relied on ITSM-driven workflows and Agile delivery practices, with security operations, IT operations, and vendor risk teams engaged in sprint-based configuration, testing, and on-call handover. The implementation emphasized CMDB-backed enrichment and workflow instrumentation to formalize security incident handling within AAA Auto Club Group’s broader Incident Management framework.
|
|
|
Ally Bank | Banking and Financial Services | 10000 | $3.7B | United States | ServiceNow | ServiceNow Security Operations | Incident Management | 2024 | n/a |
In 2024, Ally Bank began implementing ServiceNow Security Operations at its Sandy, Utah site with an explicit focus on Incident Management as part of a broader ServiceNow platform program that spans ITSM, ITOM, SecOps, GRC, HRSD, FSM and employee self service channels. The ServiceNow Security Operations deployment is framed as a centralized security incident response capability, with Security Incident Response, Vulnerability Response and Threat Intelligence implemented alongside existing ITSM modules to align security workflows with operational ticketing and service delivery.
Configuration work included extensive use of Client Scripts, Business Rules, UI Policies and UI Actions to tailor forms and automation, and the team transitioned workflow automations from Workflow Editor to Flow Designer to modernize approval, SLA and remediation flows. Service Catalog items were created with custom catalog client scripts and notifications to automate financial service requests, while Performance Analytics and native reporting were used to surface real time KPIs for IT and security leadership. The ServiceNow Security Operations application was validated through Automated Test Framework scripts and platform upgrades were managed across releases from Helsinki through Washington DC using UAT and regression testing.
Integrations were implemented using SOAP and REST APIs, LDAP and Azure AD for identity, MuleSoft for enterprise integration, and Oracle and MySQL for CMDB and analytics imports, with Integration Hub and MID Server components supporting secure, real time data exchange. ITOM capabilities including Discovery, Service Mapping, Event Management and Orchestration were used to populate the CMDB and drive dependency mapping, and RBAC and ACL controls were configured to protect sensitive financial and customer information. Field Service Management was extended with Mobile Agent and Now Mobile, enabling technicians to receive and close work orders from mobile devices while preserving security and audit trails.
Governance centered on CSDM aligned CMDB lifecycle controls, role based access governance and GRC driven workflows to support SOX and FINRA compliance and automated audit readiness. The implementation was delivered in agile sprints with cross functional participation from IT, security, HR and field operations, and included knowledge base development, end user training, Virtual Agent automation and Employee Service Center consolidation to improve workforce experience.
Explicit outcomes recorded during the engagement included streamlined banking and IT operations workflows and improved process efficiency, better SLA adherence through automated catalog and approval processes, improved on site service efficiency and technician collaboration via mobile workflows, reduced resolution times for incidents and an enhanced enterprise security posture through integrated SecOps capabilities.
|
|
|
American Electric Power | Utilities | 16330 | $19.7B | United States | ServiceNow | ServiceNow Security Operations | Incident Management | 2023 | n/a |
In 2023, American Electric Power implemented ServiceNow Security Operations to extend enterprise Incident Management capabilities into vulnerability and security response workflows. The deployment emphasized vulnerability response management within ServiceNow Security Operations to automate identification, prioritization, and remediation of vulnerabilities while aligning security incident handling with existing IT incident processes.
Configuration work focused on vulnerability response modules, automated triage and prioritization workflows, and orchestration of remediation tasks. Automation leveraged ServiceNow workflow capabilities including Flow Designer and business rules to route security findings into Incident Management queues, create remediation tasks, and escalate based on predefined criteria.
Integrations were anchored on the CMDB and ITOM stack, with ITOM Discovery and Service Mapping providing asset and dependency context that feeds ServiceNow Security Operations and improves root cause analysis. MID Servers and discovery schedules were configured to populate CI data, and Event Management connector definitions were activated to funnel security-relevant events into security incident workflows, enabling coordination between ITSM, ITOM, and Security Operations.
Governance and operational controls were aligned with IRM and CMDB best practices, using IRM tooling to automate risk identification, assessment, mitigation, and monitoring for security-related risks. CMDB Health Dashboards and CSDM 4.0-aligned CI modeling supported accurate context for vulnerability prioritization, and CAM and automated monitoring controls were implemented to enforce least privilege and continuous review of user activity where relevant to security operations. ServiceNow Security Operations sits as a coordinated layer within American Electric Powers Incident Management ecosystem, linking security, IT, and risk workflows across the enterprise.
|
|
|
Arizona State University | Education | 12229 | $5.4B | United States | ServiceNow | ServiceNow Security Operations | Incident Management | 2024 | n/a |
In 2024 Arizona State University implemented ServiceNow Security Operations to automate incident response and vulnerability management within its Incident Management workflows, executing work across February 2024 to July 2024. The implementation was scoped to security operations, IT asset management, and finance process automation, with explicit involvement from security and finance teams for requirements and operational acceptance.
ServiceNow Security Operations was configured to deliver automated incident response, vulnerability management, and real-time incident tracking capabilities, while parallel work optimized CMDB, SAM, and HAM modules. Financial Management and Budgeting Automation modules were customized to automate procurement, budgeting, and expense tracking workflows, and dashboards and reports were developed to support accurate financial tracking and decision making.
Integrations were implemented with threat intelligence feeds and an enterprise SIEM and other security tools to enhance threat detection, and Discovery together with IntegrationHub was used to automate CMDB population of servers, network devices, applications, and services. Service Mapping was implemented to map critical IT services to underlying configuration items and integrated with incident and problem management to enable automatic impact analysis during service disruptions. Procurement and finance systems were integrated with CMDB and ITAM to ensure seamless asset tracking and expense management.
Governance constructs were established to maintain CMDB data quality, including CI data entry guidelines, validation rules, regular audits, and integration with ServiceNow GRC for automated compliance checks. CMDB relationship management was enhanced to visualize parent child and service dependencies and to tie those relationships into change, incident, and problem workflows. Training was delivered to finance teams on ServiceNow financial tools and operating procedures were defined with security teams to codify response protocols.
The implementation produced explicit outcomes stated by the project team, including enhanced threat detection through integrated intelligence feeds, real time incident tracking and mitigation, improved efficiency of finance teams through automation, and more accurate asset lifecycle tracking via integrated CMDB and ITAM data. ServiceNow Security Operations is positioned at ASU as the central Incident Management platform for security operations, ITAM, and related financial processes.
|
|
|
|
Banking and Financial Services | 6089 | $931M | United States | ServiceNow | ServiceNow Security Operations | Incident Management | 2023 | n/a |
|
|
|
|
Life Sciences | 18000 | $25.5B | United States | ServiceNow | ServiceNow Security Operations | Incident Management | 2018 | n/a |
|
|
|
|
Professional Services | 5300 | $1.3B | United States | ServiceNow | ServiceNow Security Operations | Incident Management | 2023 | n/a |
|
|
|
|
Professional Services | 56000 | $2.0B | United States | ServiceNow | ServiceNow Security Operations | Incident Management | 2020 | n/a |
|
|
|
|
Banking and Financial Services | 213000 | $101.9B | United States | ServiceNow | ServiceNow Security Operations | Incident Management | 2017 | n/a |
|
Buyer Intent: Companies Evaluating ServiceNow Security Operations
- Talan, a France based Professional Services organization with 7100 Employees
Discover Software Buyers actively Evaluating Enterprise Applications
| Logo | Company | Industry | Employees | Revenue | Country | Evaluated |
|---|---|---|---|---|---|---|
| Talan | Professional Services | 7100 | $971M | France | 2025-05-20 |