---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Add security incidents to an existing case

# Add security incidents to an existing case {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can add security incidents to one or more existing cases. After the security
incidents have been added to cases, you can use Security Case Management to analyze the
data.

## Before you begin

The Threat Intelligence plugin must be activated to use Security Case Management.

Role required: sn_ti.case_user_write

## About this task

You need to navigate to the security incidents you want to add to existing cases.

## Procedure

1. Navigate to AllSecurity IncidentIncidentsShow Open Incidents.  
   The Security Incidents list opens.
2. In the list, select one or more security incidents that you want to add to existing cases.  
   Note:  
   If you select multiple security incidents, the selected security incidents are added to each of the selected cases.
3. From the Actions on selected items drop-down list, select Add to Security Case.  
   The Add to Security Case dialog box opens and displays the cases assigned to you.
4. Select the cases into which you want to add the selected security incidents.
5. Click Add.  
   A message indicates that the selected records have been added to the cases, along with a link to the cases in Security Case Management.
{#add-sec-inc-to-cases__steps_mdc_lfb_cz}
**Related tasks**   

* [Create a case from security incidents](https://servicenow-prod.fluidtopics.net/fexBWCXKq2xBGHuaFNCqew "In Security Incident Response, you can create cases from security incidents. After the security incidents have been used to create a new case, you can use Security Case Management to analyze the data.")

*[\>]: and then


