The ServiceNow Yokohama release is here with exciting new features, and as you might expect, it places a strong emphasis on GenAI—bringing automation to streamline your security workflows and reduce unnecessary overhead. In addition, we’ll highlight some practical enhancements from a platform perspective. Let’s dive in!
Vulnerability Response
The Vulnerability Response application (v25.0.x) introduces a long-awaited feature that allows vulnerability managers and analysts to create Remediation Tasks directly from the list view in the Vulnerability Manager Workspace or the IT Remediation Workspace.
This manual task creation capability provides granular control over remediation management, enabling you to dynamically group vulnerable items into remediation tasks in real-time. This applies to infrastructure, application, and container vulnerabilities, as well as configuration test results. A much-appreciated addition—thank you, ServiceNow!

Additionally, the Vulnerability Response integration with the National Vulnerability Database (NVD) now supports entries for Common Vulnerability Scoring System (CVSS) v4.0 values. This latest scoring system reflects a modern approach to vulnerability management, helping you stay ahead of evolving adversary tactics. You can leverage these values within your own custom risk score calculator to prioritise the most critical vulnerabilities effectively.
Security Posture Control – Mitigation Control Detection
To help teams better prioritise security actions, ServiceNow enables the detection of assets with mitigation controls in place. This reduces the final risk score for such assets, effectively freeing up remediation owners to focus on more pressing threats.
ServiceNow has implemented two initial use cases:
- Web application firewalls (WAF) protecting certain configuration items (CIs)
- Endpoint Detection and Response (EDR) agents configured to block exploits
More mitigation control mechanisms will be introduced in future releases. The diagram below illustrates how mitigation controls connect to your ServiceNow instance via API. Security Posture Control then leverages IT Operations Management (ITOM) to map MITRE ATT&CK mitigation techniques to vulnerabilities within your environment.

Scalability: Handling 300M Vulnerable Items in Workspaces
ServiceNow Vulnerability Response now supports 300 million Vulnerable Items (VIT), ensuring a high-performance experience in Workspaces. This enhancement improves scalability, allowing security teams to manage large volumes of vulnerability data efficiently and with confidence.
Security Incident Response
Now Assist for SIR
There are several Out Of The Box functionalities for the Now Assist in SIR Workspace. Using AI, the investigation phase of Security Incidents can be quicker and easier as it reduces the manual labour done by the analysts. On the Security Incident form, analysts can use the new tab Recommended Actions which can help them with the next steps of the resolution by generating actions from existing Security Incidents and Knowledge articles.
Now Assist itself can be used for anything you predefine. Some of the already implemented functionalities are Correlation Insight and the generation of Post Incident Analysis or Resolution Notes.

Relationship Graph
Were you missing some graphical overview of the entities connected to the incident? Not anymore! It was just added with the ServiceNow Yokohama release. The brand new related list was added for the Security Incident Workspace. You can see all the items and records related to the current incident.
The graph can be improved by adding several category nodes, like:
- Observables
- Affected Users
- Related CIs
- Response Tasks etc.
You can use the canvas for zooming to the objects, dragging the nodes, adding subsidies and hiding any node/sub-node. As it is intended to be used mainly for reporting, it offers a quick and easy option to export what you see – basically it will be exported in the exact way you see it in the frame. Once you leave the related list, the graph is restarted to the default view.

Reporting
ServiceNow Yokohama has also added a new functionality for reporting. Now, a template for the reports can be created and designed the way you like and then saved for future use. You can have multiple templates, e.g. if you want to have separate ones for different entities or incident categories.
When the analysts want to generate the report for a specific Incident, they can do it directly from the form. They can create a new report, duplicate the existing one and when drafted, they can modify it as well so they are not limited by the template only. When published, it can be downloaded or sent directly to an email address.

Conclusion
Looking at all the updates that came with the ServiceNow Yokohama release, we can say with certainty that this release brings tangible improvements for security professionals. Features like direct remediation task creation, enhanced vulnerability scoring, and AI-powered incident response translate to increased efficiency, reduced overhead, and improved threat prioritisation. All of these, combined with scalability improvements, will equip your security teams to tackle the challenges with greater confidence and effectiveness.
These advancements in Security Operations showcase the power of applying GenAI to enterprise challenges. This platform-wide initiative also has a major impact on customer-facing roles, and you can learn more about enhancing customer service with AI in the ServiceNow Yokohama release.


