Enterprise security teams are drowning in blind spots. The average large organization now manages 100,000s of connected assets, ranging from cloud workloads to industrial sensors. However, most security tools can only see a fraction of them. Unmanaged IoT devices, for example, remain largely invisible to traditional security platforms, creating exposure gaps that threat actors increasingly exploit. On acquiring Armis, ServiceNow is betting $7.75 billion that the answer lies in unifying cyber exposure management with automated workflow remediation.
The acquisition arrives as worldwide information security spending accelerates toward $240 billion in 2026, driven primarily by AI-related threats and the expanding attack surface. For tech buyers evaluating security architecture decisions, the ServiceNow-Armis combination raises several critical questions.
How ServiceNow and Armis Intend to Address the Asset Visibility Gap
Yevgeny Dibrov, co-founder and CEO of Armis, commented:
"AI is transforming the threat landscape faster than most organizations can adapt. Every connected asset has become a potential point of vulnerability."
Dibrov's company built its reputation on the agentless discovery of devices that traditional security tools often miss, including industrial controllers that can't support endpoint agents, medical devices running outdated operating systems, and the shadow IoT that bypasses IT procurement.
This visibility gap creates measurable business risk. A compromised industrial controller can halt production lines, resulting in significant financial losses for manufacturers, estimated at millions of dollars per hour. Healthcare breaches are increasingly targeting connected medical devices, posing a threat to both data security and patient safety. As enterprises deploy AI agents with access to sensitive systems, the inability to maintain comprehensive asset inventories undermines governance frameworks before they even begin.
ServiceNow's existing Configuration Management Database (CMDB) maps IT assets to business services, but lacks the real-time, agentless discovery capabilities that Armis provides for cyber-physical environments. The combination promises contextual understanding, not just of what assets exist, but also of which vulnerabilities pose the most significant business risk and which remediation actions should be prioritized.
From Detection to Security Automated Response
Visibility alone doesn't prevent breaches. The strategic value proposition centers on connecting Armis' exposure insights to ServiceNow's workflow automation. Rather than generating alerts that security teams manually triage, the integrated platform would automatically route findings to appropriate teams and trigger remediation workflows at scale.
Amit Zavery, president and chief product officer at ServiceNow, framed the vision:




