{"id":771044,"date":"2025-10-14T13:47:09","date_gmt":"2025-10-14T11:47:09","guid":{"rendered":"https:\/\/www.devoteam.com\/expert-view\/whats-new-in-the-servicenow-zurich-release-for-secops-sir-vr-and-spc\/"},"modified":"2025-10-14T13:47:09","modified_gmt":"2025-10-14T11:47:09","slug":"whats-new-in-the-servicenow-zurich-release-for-secops-sir-vr-and-spc","status":"publish","type":"expert-view","link":"https:\/\/devoteam.info\/en-nl\/expert-view\/whats-new-in-the-servicenow-zurich-release-for-secops-sir-vr-and-spc\/","title":{"rendered":"What\u2019s new in the ServiceNow Zurich release for Security Operations: SIR, VR, and SPC updates"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The pace of threat analysis and remediation is constantly accelerating. To keep security teams ahead of the curve, ServiceNow&#8217;s Zurich release delivers a powerful suite of updates across Security Incident Response (SIR), Security Posture Control (SPC), and Vulnerability Response (VR). This release is engineered to tackle two core problems facing security teams: manual overhead and prioritisation fatigue. So, let&#8217;s have a look in detail at the most interesting updates.<\/p>\n\n\n\n<h2 class=\"wp-block-heading has-large-font-size\" id=\"h-security-incident-response\">Security Incident Response<\/h2>\n\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\" id=\"h-closing-multiple-incidents-at-once\" style=\"font-style:normal;font-weight:500\">Closing multiple incidents at once<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.servicenow.com\/docs\/bundle\/zurich-release-notes\/page\/release-notes\/family-release-notes.html\" target=\"_blank\" rel=\"noreferrer noopener\">ServiceNow Zurich release<\/a> introduces a brand new feature that allows analysts to efficiently close multiple security incidents at once. In the Security Incident Response Workspace, using the new \u201c<strong>Close\u201d<\/strong> button on the Security Incident list view, analysts can review the incidents and apply Close codes and notes to several incidents in bulk. This significantly reduces manual effort, especially when managing incidents with a common root cause.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ultimately, this enhancement streamlines case management, ensures consistent documentation, and frees up security teams to focus on proactive threat mitigation.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"679\" src=\"https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image2-1024x679.png\" alt=\"\" class=\"wp-image-755294\" srcset=\"https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image2-1024x679.png 1024w, https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image2-300x199.png 300w, https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image2-768x509.png 768w, https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image2.png 1437w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">SIR Workspace &#8211; Bulk close security incidents feature, Source: ServiceNow<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\" id=\"h-core-enhancements\" style=\"font-style:normal;font-weight:500\">Core enhancements<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The release also brings key core enhancements to the Security Incident Response workspace, designed to improve efficiency, visibility, and collaboration across teams. One of the desired requests was to <strong>link multiple ITSM records<\/strong> to a single SIR record. That is now possible, enabling richer context and stronger correlation between incidents, changes, and service requests.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Additionally, the new user presence feature provides <strong>real-time visibility<\/strong> into who is actively viewing or working on SIR or SIT records within the workspace, helping teams avoid duplicate efforts and improve collaboration. These core updates enhance situational awareness, streamline workflows, and strengthen coordination across security and IT operations, empowering analysts to respond faster and more effectively to security incidents.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"495\" src=\"https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image4-1024x495.png\" alt=\"\" class=\"wp-image-755349\" srcset=\"https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image4-1024x495.png 1024w, https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image4-300x145.png 300w, https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image4-768x372.png 768w, https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image4-1536x743.png 1536w, https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image4.png 1999w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">SIR Workspace &#8211; Linking incidents feature, Source: ServiceNow<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"489\" src=\"https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image6-1024x489.png\" alt=\"\" class=\"wp-image-755213\" srcset=\"https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image6-1024x489.png 1024w, https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image6-300x143.png 300w, https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image6-768x367.png 768w, https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image6-1536x734.png 1536w, https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image6.png 1999w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">SIR Workspace, Source: ServiceNow<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\" id=\"h-integration-updates\" style=\"font-style:normal;font-weight:500\">Integration updates<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Another new addition to SIR is the new <strong>CrowdStrike Falcon Next-Gen SIEM Integration<\/strong>, creating security incidents in ServiceNow from high-value CrowdStrike detections. It supports bidirectional data synchronisation, ensuring security teams always have complete context for faster, smarter action across both platforms.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The new release also presents <strong>Splunk<\/strong> enhancements, like adding a new role to manage profiles in SIEM integrations (sn_si ingestion_profile_admin), Splunk Sighting Search integration enhancements and other Splunk ES integration enhancements.<\/p>\n\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\" id=\"h-ai-assisted-shift-handover-reports\" style=\"font-style:normal;font-weight:500\">AI-assisted Shift Handover Reports<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">One of the Now Assist features is the <strong>Manage Shift Handover Records<\/strong> feature to significantly improve continuity and efficiency across security shifts. Analysts can now create, edit, and manage structured handover records directly tied to specific shift names, replacing previous manual, unstructured notes.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This enhancement standardises the transfer of incident history, open actions, and priorities, making past handovers fully traceable and preventing information loss or duplicate work. Furthermore, <strong>Now Assist for SIR<\/strong> provides intelligent automation by adding relevant incident details to these reports, ensuring comprehensive context transfer and elevating overall shift-to-shift collaboration.<\/p>\n\n\n\n<h2 class=\"wp-block-heading has-large-font-size\" id=\"h-security-posture-control\">Security Posture Control<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Maintaining a strong security posture isn&#8217;t a one-time task; it&#8217;s a continuous journey. Organisations struggle with a constantly shifting attack surface, an influx of new vulnerabilities, and the pressure to comply with an array of regulatory standards. Traditional, fragmented security tools often lead to blind spots, manual overhead, and delayed remediation, ultimately increasing the risk of breaches.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ServiceNow&#8217;s <strong>Security Posture Control<\/strong> was designed to address these challenges by providing a unified platform for security teams. With Zurich, the capabilities have been expanded to offer even greater automation and actionable intelligence.<\/p>\n\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\" id=\"h-editable-policies-and-automated-closures\" style=\"font-style:normal;font-weight:500\">Editable policies and automated closures<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In previous versions, managing security policies could be a rigid process. Zurich changes this by making <strong>policies always editable<\/strong>. This new flexibility allows security teams to adapt quickly to changes in security standards, business needs, or regulatory requirements. More importantly, this feature comes with robust <strong>version tracking<\/strong>, giving you a complete audit trail of every change made to a policy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The true game-changer, however, is the <strong>automated closure of related test results<\/strong>. When a new policy version is published or a policy is deleted, the system can be configured to automatically close all associated security findings (test results).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This functionality streamlines policy management and ensures that your security findings are always aligned with the latest policies. It eliminates the manual, time-consuming task of cleaning up outdated findings, allowing your security team to focus on relevant, high-priority issues.<\/p>\n\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\" id=\"h-enhanced-asset-search-and-cmdb-filtering\" style=\"font-style:normal;font-weight:500\">Enhanced asset search and CMDB filtering<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">One of the most notable improvements that came with the ServiceNow Zurich release for security analysts is definitely an <strong>enhanced asset search and CMDB filtering<\/strong>. The CMDB connection condition builder now includes powerful new criteria, such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Host Name Regex:<\/strong> This allows for flexible and advanced searches using regular expressions to find assets based on naming patterns, such as &#8220;prod-web-[0-9]+&#8221; to locate all production web servers.<\/li>\n\n\n\n<li><strong>First Seen Timestamp:<\/strong> You can now filter assets by the date they were first discovered, helping you quickly identify newly added assets that may not yet be properly secured or configured.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">These new search capabilities are a massive productivity booster, enabling analysts to narrow down their focus to the most critical or recently discovered assets, accelerating investigations and vulnerability analysis.<\/p>\n\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\" id=\"h-software-asset-management-sam-integration\" style=\"font-style:normal;font-weight:500\">Software Asset Management (SAM) integration<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">One of the most common security blind spots is unmanaged software. Organisations often have a clear view of their hardware assets but lack insight into the software running on them, particularly unauthorised or &#8220;shadow IT&#8221; applications. Zurich release directly addresses this by integrating with your Software Asset Management (SAM) data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This new feature allows you to <strong>query the Security Posture Control module for discrepancies<\/strong> between software discovered by your vulnerability scanners and the software already managed and tracked in your SAM.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It brings a crucial layer of visibility, helping your team quickly identify and address unmanaged software that may pose a security risk. By correlating data from your security scans with your SAM inventory, you can uncover unauthorised applications, unpatched legacy software, and other unmanaged assets that could be a gateway for attackers.<\/p>\n\n\n\n<h2 class=\"wp-block-heading has-large-font-size\" id=\"h-vulnerability-response\">Vulnerability Response<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In the current era of relentless digital expansion, safeguarding critical assets has become more complex than ever. Threats evolve daily, demanding smarter, faster, and more integrated security approaches. The ServiceNow Zurich release delivers on this need with innovative features that empower teams to detect vulnerabilities earlier, manage risks more effectively, and respond with confidence.<\/p>\n\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\" id=\"h-granular-vits-for-microsoft-tvm\" style=\"font-style:normal;font-weight:500\">Granular VITs for Microsoft TVM<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">With the new Zurich release, you can now configure Microsoft Threat &amp; Vulnerability Management (TVM) recommendations as a Vulnerable Item (VIT) key. This creates <strong>individual VITs for each recommendation<\/strong>, which gives you better ownership and accountability for remediation activities. The granular approach also improves workload distribution across teams and enables faster, more effective vulnerability resolution by enhancing the tracking of specific recommendations.<\/p>\n\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\" id=\"h-ci-lookup-rules-enhancements\" style=\"font-style:normal;font-weight:500\">CI Lookup Rules Enhancements<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">CI Lookup Rules Enhancements bring a refined level of precision to the configuration management process, ensuring that only relevant and up-to-date data is taken into account. By intelligently <strong>excluding Discovered Items that have not been scanned for more than 90 days <\/strong>when lookup rules are reapplied, the platform streamlines the way CIs are evaluated and maintained. This targeted approach <strong>reduces noise and unnecessary licensing costs<\/strong>, while significantly improving processing efficiency.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For organisations that do not follow Common Service Data Model (CSDM) standards, a new system property (sn_sec_cmn.ci_lifecycle_status_source) ensures that DIs and associated VITs are properly marked as Decommissioned and excluded from the CI Lookup.&nbsp;Additionally, the previously scheduled job for reconciling Unmatched Discovered Items is now deprecated. Users can instead \u201c<strong>Reapply Lookup Rules<\/strong>\u201d for selected or filtered items directly in the discovered items table, simplifying workflows and giving teams a more streamlined platform to manage CI-vulnerability mapping efficiently.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"401\" src=\"https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image1-1024x401.png\" alt=\"\" class=\"wp-image-755267\" srcset=\"https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image1-1024x401.png 1024w, https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image1-300x117.png 300w, https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image1-768x301.png 768w, https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image1-1536x601.png 1536w, https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image1.png 1668w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Vulnerability Manager Workspace &#8211; Lookup rule, Source: ServiceNow<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\" id=\"h-vulnerability-response-integration-with-wiz\" style=\"font-style:normal;font-weight:500\">Vulnerability Response Integration with Wiz<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The new Vulnerability Response integration with Wiz expands ServiceNow\u2019s visibility into your cloud environment,<strong> importing host vulnerability findings for virtual machines and serverless assets<\/strong>. This powerful integration creates a unified platform for tracking and remediating vulnerabilities across your hybrid infrastructure, strengthening your cloud security posture and streamlining workflows by bringing critical cloud insights directly into ServiceNow.<\/p>\n\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\" id=\"h-modify-the-severity-for-a-cve-or-tpe\" style=\"font-style:normal;font-weight:500\">Modify the severity for a CVE or TPE<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A key improvement in the ServiceNow Zurich release is the introduction of a new feature within the VR module that allows security professionals to <strong>manually adjust the Severity level of Common Vulnerability Entries (CVEs) and Third-Party Entries (TPEs)<\/strong>. This capability is critical because traditional prioritisation based solely on the static Common Vulnerability Scoring System (CVSS) fails to incorporate organisational context or real-world threat intelligence, often leading teams to waste resources on low-impact, yet technically challenging issues.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"643\" src=\"https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image3-1024x643.png\" alt=\"\" class=\"wp-image-755322\" srcset=\"https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image3-1024x643.png 1024w, https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image3-300x188.png 300w, https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image3-768x483.png 768w, https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image3-1536x965.png 1536w, https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image3.png 1999w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Vulnerability Manager Workspace &#8211; Modifying severity, Source: ServiceNow<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The manual modification feature is a <strong>post-ingestion action<\/strong> that enables users to override the Normalised Severity of a record to reflect its <em>actual risk<\/em> to the business. This functionality is a core enabler of Risk-Based Vulnerability Management (RBVM). The change is managed by a sophisticated <strong>asynchronous workflow<\/strong>; when the Severity is modified, a business rule sets a flag, triggering a scheduled job &#8211; &#8220;Run severity calculator after vuln entry promotion&#8221; &#8211; to recalculate the risk score of all related Vulnerable Items (VIs). This batched process <strong>ensures system responsiveness<\/strong> while accurately applying updated Risk Scores across the environment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This offers significant business value by enabling precise risk prioritisation. By allowing users to manually adjust the normalised severity to reflect actual business risk, organisations can more effectively focus resources on the vulnerabilities that pose the greatest threat.<\/p>\n\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\" id=\"h-tenable-cs-integration-for-cloud-and-container-vulnerabilities\" style=\"font-style:normal;font-weight:500\">Tenable.cs integration for cloud and container vulnerabilities<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The Zurich release features a <strong>native integration of Tenable.cs<\/strong> (Tenable Cloud Security) for managing vulnerabilities across complex, fragmented cloud-native and containerised environments. This improvement is a strategic leap forward, as it unifies vulnerability data from cloud and container assets with findings from traditional IT infrastructure, providing a single, holistic view within the ServiceNow platform.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The integration <strong>leverages the Service Graph Connector for Tenable<\/strong> to bring Tenable&#8217;s rich cloud vulnerability data directly into ServiceNow&#8217;s Configuration Management Database (CMDB) and VR modules. This unified data model is essential for the platform&#8217;s advanced features, as <strong>new AI-powered capabilities<\/strong> like Now Assist for Vulnerability Response require a complete and consolidated dataset to function effectively.&nbsp;Furthermore, the integration enables a <strong>&#8220;closed-loop remediation process,&#8221;<\/strong> which automates the entire lifecycle from detection and prioritisation to the assignment of remediation tasks and subsequent validation via re-scan, significantly improving operational efficiency.<\/p>\n\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\" id=\"h-qualys-integration-for-secops-detection-splitting\" style=\"font-style:normal;font-weight:500\">Qualys integration for SecOps \u2013 detection splitting<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">To solve the challenge of ambiguous vulnerability ownership, ServiceNow introduced the vulnerability <strong>Detection Splitting<\/strong> capability for Qualys integration. Previously, if the same vulnerability (e.g., Log4j) appeared in multiple applications on a single server, all instances were consolidated into one Vulnerable Item (VI), hindering clean assignment to the correct application owners.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Detection Splitting feature resolves this by leveraging <strong>Proof data<\/strong> (such as the specific file path or directory) from the Qualys scanner payload and incorporating it into the Vulnerable Item Key. This results in the creation of a <strong>unique Vulnerable Item for each specific vulnerability instance<\/strong>. This enhanced granularity allows Vulnerability Assignment Rules to route work automatically and precisely to the correct remediation team. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This shift from a consolidated to a granular model is expected to <strong>decrease the Mean Time to Remediate (MTTR)<\/strong> by eliminating the manual triage and internal friction associated with unclear ownership.<\/p>\n\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\" id=\"h-activate-the-qualys-qvs-score-integration\" style=\"font-style:normal;font-weight:500\">Activate the Qualys QVS Score integration<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Last but not least, Zurich release significantly elevates prioritisation by allowing for the seamless import of <strong>Qualys&#8217;s proprietary risk scores<\/strong>, including the Qualys Vulnerability Score (QVS), Qualys Detection Score (QDS), and the holistic <strong>Qualys TruRisk Score<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <strong>TruRisk score<\/strong> is a critical improvement, providing an overall risk metric (typically 0-1000) for an asset. It dynamically combines granular technical vulnerability scores (QDS) with the <strong>Asset Criticality Score (ACS)<\/strong> from the CMDB. This multi-dimensional scoring moves beyond the static nature of CVSS, allowing security teams to filter out low-risk &#8220;vulnerability noise&#8221; and <strong>hyper-focus remediation efforts<\/strong> on the issues that pose the greatest danger to the organisation&#8217;s most valuable assets.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By incorporating this high-fidelity, threat-informed intelligence, ServiceNow&#8217;s workflow engine can facilitate automation that can lead to an estimated <strong>60% reduction in MTTR<\/strong> and an 85% reduction in the number of critical vulnerabilities teams must contend with.<\/p>\n\n\n\n<h2 class=\"wp-block-heading has-large-font-size\" id=\"h-conclusion\">Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The ServiceNow Zurich release delivers a unified, high-impact update across the entire security operations suite. It is engineered to boost efficiency and shift teams from reactive measures to proactive risk mitigation.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Core SIR features like bulk incident closure and AI-assisted Shift Handover reduce manual effort and eliminate context loss. Simultaneously, enhancements to Security Posture Control (SPC) and Vulnerability Response (VR) &#8211; especially the new ability to import the high-fidelity Qualys TruRisk Score &#8211; empower analysts to cut through the noise.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By providing clearer visibility and allowing for risk-based prioritisation, the Zurich release ensures security teams focus their limited time on the most critical threats to the business, achieving a tangible reduction in Mean Time to Remediate (MTTR).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The pace of threat analysis and remediation is constantly accelerating. To keep security teams ahead of the curve, ServiceNow&#8217;s Zurich release delivers a powerful suite of updates across Security Incident Response (SIR), Security Posture Control (SPC), and Vulnerability Response (VR). This release is engineered to tackle two core problems facing security teams: manual overhead and [&hellip;]<\/p>\n","protected":false},"featured_media":755447,"template":"","categories":[2271,1044],"tags":[],"industry":[],"class_list":["post-771044","expert-view","type-expert-view","status-publish","has-post-thumbnail","hentry","category-governance-risk-and-compliance-workflows-en-nl","category-servicenow-en-nl"],"acf":[],"cards":"\n\t<div class=\"single-post-card\">\n\n\t\t<figure class=\"wp-block-post-featured-image\"><a href=\"https:\/\/devoteam.info\/en-nl\/expert-view\/whats-new-in-the-servicenow-zurich-release-for-secops-sir-vr-and-spc\/\" target=\"_self\" ><img width=\"1920\" height=\"1080\" src=\"https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/secops-zurich-release.jpg\" class=\"attachment-post-thumbnail size-post-thumbnail wp-post-image\" alt=\"What\u2019s new in the ServiceNow Zurich release for Security Operations: SIR, VR, and SPC updates\" style=\"aspect-ratio:4\/3;width:100%;object-fit:cover;\" decoding=\"async\" loading=\"lazy\" srcset=\"https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/secops-zurich-release.jpg 1920w, https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/secops-zurich-release-300x169.jpg 300w, https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/secops-zurich-release-1024x576.jpg 1024w, https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/secops-zurich-release-768x432.jpg 768w, https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/secops-zurich-release-1536x864.jpg 1536w\" sizes=\"auto, (max-width: 1920px) 100vw, 1920px\" \/><\/a><\/figure>\n\n\t\t\n\t\t<div class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-43282307 wp-block-group-is-layout-flex\">\n\t<p style=\"font-style:normal;font-weight:700\" class=\"has-link-color wp-elements-1 wp-block-lp-post-type has-text-color has-primary-color has-small-font-size\">Expert View<\/p>\n\n\t\t\n\t\t<h3 style=\"font-style:normal;font-weight:400\" class=\"wp-block-post-title has-base-font-size\"><a href=\"https:\/\/devoteam.info\/en-nl\/expert-view\/whats-new-in-the-servicenow-zurich-release-for-secops-sir-vr-and-spc\/\" target=\"_self\" >What\u2019s new in the ServiceNow Zurich release for Security Operations: SIR, VR, and SPC updates<\/a><\/h3><\/div>\n\t\t\n\t<\/div>\n\n","yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.4 (Yoast SEO v28.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>What\u2019s new in the ServiceNow Zurich release for Security Operations: SIR, VR, and SPC updates | Devoteam<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/devoteam.info\/en-nl\/expert-view\/whats-new-in-the-servicenow-zurich-release-for-secops-sir-vr-and-spc\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What\u2019s new in the ServiceNow Zurich release for Security Operations: SIR, VR, and SPC updates\" \/>\n<meta property=\"og:description\" content=\"The pace of threat analysis and remediation is constantly accelerating. To keep security teams ahead of the curve, ServiceNow&#8217;s Zurich release delivers a powerful suite of updates across Security Incident Response (SIR), Security Posture Control (SPC), and Vulnerability Response (VR). This release is engineered to tackle two core problems facing security teams: manual overhead and [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/devoteam.info\/en-nl\/expert-view\/whats-new-in-the-servicenow-zurich-release-for-secops-sir-vr-and-spc\/\" \/>\n<meta property=\"og:site_name\" content=\"Devoteam\" \/>\n<meta property=\"og:image\" content=\"https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image2.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1437\" \/>\n\t<meta property=\"og:image:height\" content=\"953\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/devoteam.info\\\/en-nl\\\/expert-view\\\/whats-new-in-the-servicenow-zurich-release-for-secops-sir-vr-and-spc\\\/\",\"url\":\"https:\\\/\\\/devoteam.info\\\/en-nl\\\/expert-view\\\/whats-new-in-the-servicenow-zurich-release-for-secops-sir-vr-and-spc\\\/\",\"name\":\"What\u2019s new in the ServiceNow Zurich release for Security Operations: SIR, VR, and SPC updates | Devoteam\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/devoteam.info\\\/en-nl\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/devoteam.info\\\/en-nl\\\/expert-view\\\/whats-new-in-the-servicenow-zurich-release-for-secops-sir-vr-and-spc\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/devoteam.info\\\/en-nl\\\/expert-view\\\/whats-new-in-the-servicenow-zurich-release-for-secops-sir-vr-and-spc\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/devoteam.info\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/secops-zurich-release.jpg\",\"datePublished\":\"2025-10-14T11:47:09+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/devoteam.info\\\/en-nl\\\/expert-view\\\/whats-new-in-the-servicenow-zurich-release-for-secops-sir-vr-and-spc\\\/#breadcrumb\"},\"inLanguage\":\"en-NL\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/devoteam.info\\\/en-nl\\\/expert-view\\\/whats-new-in-the-servicenow-zurich-release-for-secops-sir-vr-and-spc\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-NL\",\"@id\":\"https:\\\/\\\/devoteam.info\\\/en-nl\\\/expert-view\\\/whats-new-in-the-servicenow-zurich-release-for-secops-sir-vr-and-spc\\\/#primaryimage\",\"url\":\"https:\\\/\\\/devoteam.info\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/secops-zurich-release.jpg\",\"contentUrl\":\"https:\\\/\\\/devoteam.info\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/secops-zurich-release.jpg\",\"width\":1920,\"height\":1080},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/devoteam.info\\\/en-nl\\\/expert-view\\\/whats-new-in-the-servicenow-zurich-release-for-secops-sir-vr-and-spc\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/devoteam.info\\\/en-nl\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Expert View\",\"item\":\"https:\\\/\\\/devoteam.info\\\/en-nl\\\/expert-view\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"What\u2019s new in the ServiceNow Zurich release for Security Operations: SIR, VR, and SPC updates\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/devoteam.info\\\/en-nl\\\/#website\",\"url\":\"https:\\\/\\\/devoteam.info\\\/en-nl\\\/\",\"name\":\"Devoteam\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/devoteam.info\\\/en-nl\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-NL\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"What\u2019s new in the ServiceNow Zurich release for Security Operations: SIR, VR, and SPC updates | Devoteam","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/devoteam.info\/en-nl\/expert-view\/whats-new-in-the-servicenow-zurich-release-for-secops-sir-vr-and-spc\/","og_locale":"en_US","og_type":"article","og_title":"What\u2019s new in the ServiceNow Zurich release for Security Operations: SIR, VR, and SPC updates","og_description":"The pace of threat analysis and remediation is constantly accelerating. To keep security teams ahead of the curve, ServiceNow&#8217;s Zurich release delivers a powerful suite of updates across Security Incident Response (SIR), Security Posture Control (SPC), and Vulnerability Response (VR). This release is engineered to tackle two core problems facing security teams: manual overhead and [&hellip;]","og_url":"https:\/\/devoteam.info\/en-nl\/expert-view\/whats-new-in-the-servicenow-zurich-release-for-secops-sir-vr-and-spc\/","og_site_name":"Devoteam","og_image":[{"width":1437,"height":953,"url":"https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/image2.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/devoteam.info\/en-nl\/expert-view\/whats-new-in-the-servicenow-zurich-release-for-secops-sir-vr-and-spc\/","url":"https:\/\/devoteam.info\/en-nl\/expert-view\/whats-new-in-the-servicenow-zurich-release-for-secops-sir-vr-and-spc\/","name":"What\u2019s new in the ServiceNow Zurich release for Security Operations: SIR, VR, and SPC updates | Devoteam","isPartOf":{"@id":"https:\/\/devoteam.info\/en-nl\/#website"},"primaryImageOfPage":{"@id":"https:\/\/devoteam.info\/en-nl\/expert-view\/whats-new-in-the-servicenow-zurich-release-for-secops-sir-vr-and-spc\/#primaryimage"},"image":{"@id":"https:\/\/devoteam.info\/en-nl\/expert-view\/whats-new-in-the-servicenow-zurich-release-for-secops-sir-vr-and-spc\/#primaryimage"},"thumbnailUrl":"https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/secops-zurich-release.jpg","datePublished":"2025-10-14T11:47:09+00:00","breadcrumb":{"@id":"https:\/\/devoteam.info\/en-nl\/expert-view\/whats-new-in-the-servicenow-zurich-release-for-secops-sir-vr-and-spc\/#breadcrumb"},"inLanguage":"en-NL","potentialAction":[{"@type":"ReadAction","target":["https:\/\/devoteam.info\/en-nl\/expert-view\/whats-new-in-the-servicenow-zurich-release-for-secops-sir-vr-and-spc\/"]}]},{"@type":"ImageObject","inLanguage":"en-NL","@id":"https:\/\/devoteam.info\/en-nl\/expert-view\/whats-new-in-the-servicenow-zurich-release-for-secops-sir-vr-and-spc\/#primaryimage","url":"https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/secops-zurich-release.jpg","contentUrl":"https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/secops-zurich-release.jpg","width":1920,"height":1080},{"@type":"BreadcrumbList","@id":"https:\/\/devoteam.info\/en-nl\/expert-view\/whats-new-in-the-servicenow-zurich-release-for-secops-sir-vr-and-spc\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/devoteam.info\/en-nl\/"},{"@type":"ListItem","position":2,"name":"Expert View","item":"https:\/\/devoteam.info\/en-nl\/expert-view\/"},{"@type":"ListItem","position":3,"name":"What\u2019s new in the ServiceNow Zurich release for Security Operations: SIR, VR, and SPC updates"}]},{"@type":"WebSite","@id":"https:\/\/devoteam.info\/en-nl\/#website","url":"https:\/\/devoteam.info\/en-nl\/","name":"Devoteam","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/devoteam.info\/en-nl\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-NL"}]}},"uagb_featured_image_src":{"full":["https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/secops-zurich-release.jpg",1920,1080,false],"thumbnail":["https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/secops-zurich-release-150x150.jpg",150,150,true],"medium":["https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/secops-zurich-release-300x169.jpg",300,169,true],"medium_large":["https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/secops-zurich-release-768x432.jpg",768,432,true],"large":["https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/secops-zurich-release-1024x576.jpg",1024,576,true],"1536x1536":["https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/secops-zurich-release-1536x864.jpg",1536,864,true],"2048x2048":["https:\/\/devoteam.info\/wp-content\/uploads\/2025\/10\/secops-zurich-release.jpg",1920,1080,false]},"uagb_author_info":{"display_name":"akielin","author_link":"https:\/\/devoteam.info\/en-nl\/author\/"},"uagb_comment_info":0,"uagb_excerpt":"The pace of threat analysis and remediation is constantly accelerating. To keep security teams ahead of the curve, ServiceNow&#8217;s Zurich release delivers a powerful suite of updates across Security Incident Response (SIR), Security Posture Control (SPC), and Vulnerability Response (VR). This release is engineered to tackle two core problems facing security teams: manual overhead and&hellip;","_links":{"self":[{"href":"https:\/\/devoteam.info\/en-nl\/wp-json\/wp\/v2\/expert-view\/771044","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devoteam.info\/en-nl\/wp-json\/wp\/v2\/expert-view"}],"about":[{"href":"https:\/\/devoteam.info\/en-nl\/wp-json\/wp\/v2\/types\/expert-view"}],"version-history":[{"count":0,"href":"https:\/\/devoteam.info\/en-nl\/wp-json\/wp\/v2\/expert-view\/771044\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devoteam.info\/en-nl\/wp-json\/wp\/v2\/media\/755447"}],"wp:attachment":[{"href":"https:\/\/devoteam.info\/en-nl\/wp-json\/wp\/v2\/media?parent=771044"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devoteam.info\/en-nl\/wp-json\/wp\/v2\/categories?post=771044"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devoteam.info\/en-nl\/wp-json\/wp\/v2\/tags?post=771044"},{"taxonomy":"industry","embeddable":true,"href":"https:\/\/devoteam.info\/en-nl\/wp-json\/wp\/v2\/industry?post=771044"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}