---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Early Warning for Security Exposure Management

# Early Warning for Security Exposure Management {#ariaid-title1}

* Release version: Australia
* 
* Updated June 24, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 6 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Early Warning for Security Exposure Management

Early Warning for Security Exposure Management, powered by Armis and integrated with ServiceNow's Unified Security Exposure Management (USEM), enhances vulnerability management by providing real-time intelligence about vulnerabilities that threat actors are actively planning to exploit.
This capability allows security teams to prioritize patching efforts proactively, reducing noise from less urgent vulnerabilities and accelerating remediation within existing workflows.
Show full answer Show less  
By leveraging signals from honeypot activity, open-source intelligence, and operational research, Early Warning flags vulnerabilities posing immediate risk, enabling organizations to shift from reactive to proactive defense against cyber threats.

## Key Features

* **Vulnerability Intelligence Enrichment:** Adds flags and detailed attributes to CVE records, such as Admiralty confidence scores and detection dates, improving prioritization based on real-world threat activity rather than severity scores alone.
* **Integration with USEM:** Automatically ingests early warning signals into the vulnerability database, elevating CVE priorities and triggering existing Vulnerability Change Management workflows without additional configuration.
* **Risk Rule Configuration:** Supports adding Early Warning flags and Admiralty scores as criteria in risk calculators, allowing customized weighting and refined vulnerability prioritization.
* **Asset Risk Visibility:** Correlates vulnerability intelligence to assets tracked in USEM, highlighting at-risk systems without requiring extra CMDB mapping.
* **Monitoring and Health Checks:** Provides integration overview pages within the Security Exposure Management workspace to review ingestion status and run history.

## Practical Benefits for Customers

* **Prioritized Remediation:** Focuses patching efforts on vulnerabilities with evidence of active exploitation, reducing operational noise and resource strain.
* **Proactive Patch Planning:** Enables scheduling patches during planned maintenance windows, especially valuable for environments with costly downtime such as healthcare, manufacturing, financial services, and regulated industries.
* **Improved Risk Management:** Demonstrates a prevention-first approach that satisfies compliance requirements and enhances security posture against sophisticated threats.
* **Expanded Risk Coverage:** Detects emerging threats earlier than some public intelligence sources, giving organizations a strategic advantage.

## Implementation and Requirements

* Requires Unified Security Exposure Management (Vulnerability Response v30.x) and the Vulnerability Integration Framework plugin.
* Access to Armis vulnerability intelligence feed with valid credentials is necessary.
* Installation involves enabling the Early Warning integration plugin, configuring ingestion schedules, and adding Early Warning criteria to risk rules.
* Setup includes configuring the Armis Intelligence Center console prior to ServiceNow platform integration.

## Key Components

* **Integration Plugin:** Manages data ingestion and enrichment of vulnerability records.
* **CVD Attributes Table:** Stores detailed Early Warning threat signals.
* **Flag Rollup Business Rules:** Consolidate Early Warning flags from CVEs to third-party entries for holistic risk assessment.
* **Risk Calculator Field:** Boolean criteria for custom weighting in risk scoring.

## Using the Data

Once integrated, vulnerability records in USEM display two new fields: an Early Warning flag indicating active exploitation risk, and detailed CVD attributes including intelligence dates and confidence scores. These fields can be used to filter, sort, and prioritize vulnerabilities, enabling your security team to act decisively and efficiently.  
Early Warning for Security Exposure Management, powered by Armis, enriches the Central Vulnerability Database (CVDB) in Unified Security Exposure Management (USEM) with vulnerability intelligence of imminent exploit. This enables your security team to prioritize and patch vulnerabilities before threat actors weaponize them.

Early Warning assesses vulnerability intelligence through honeypot activity, open-source research, and operational threat analysis, flagging which vulnerabilities pose immediate risk to your environment. This enrichment helps your
team reduce noise and prioritize what truly matters, while accelerating remediation and coordinate patching efforts within your existing vulnerability management workflows.

## When Early Warning matters {#armis-early-warning-integration__section_ktg_nj2_vjc}

Early Warning shifts vulnerability management from reactive crisis to proactive defense, providing strategic advantage by detecting which vulnerabilities threat actors are actively trying to exploit.

Without early warning: When security teams rely primarily on severity, all critical and high-severity vulnerabilities may appear to require immediate attention. This can create noise, stretch remediation
teams, and make it difficult to determine which vulnerabilities pose the most urgent risk to the organization.

With early warning: Early Warning enriches Common Vulnerabilities and Exposures (CVE) records with vulnerability intelligence derived from signals such as honeypot activity, OSINT, and operational research.
When the Early Warning flag is set to true, teams can focus first on critical vulnerabilities with evidence of active exploitation or heightened attacker interest, rather than treating every critical or
high-severity vulnerability the same. This additional context helps teams reduce noise, prioritize what matters most, validate fixes, coordinate patching across teams and regions, and deploy updates through planned maintenance
windows instead of relying only on reactive emergency remediation.  
When Early Warning Is critical: Early Warning is most valuable for organizations where patching takes time or downtime is costly:

* Legacy systems and industrial controls (ICS/SCADA): Systems that can't be rebooted quickly or easily patched. Early warning provides time for safe, planned updates instead of emergency changes that risk production downtime.
* Healthcare systems: Patient care equipment and Electronic Health Record (EHR) systems require validation before patching. Early warning allows time to coordinate updates during low-patient-census windows without disrupting care.
* Manufacturing and operations: Downtime costs millions per hour. Early warning allows time to plan patches during scheduled maintenance windows instead of emergency shutdowns.
* Financial services and payment systems: Patch windows are scheduled in advance. Early warning ensures patches are tested and ready to deploy when the window arrives, instead of scrambling on the deployment day.
* Multi-region enterprises: Complex environments with factories, offices, or data centers across regions take time to coordinate. Early warning provides the runway to test and deploy across all sites safely.
* Regulated industries: Compliance auditors want to see proactive vulnerability management, not reactive patch-and-pray. Early warning demonstrates a prevention-first security posture.
* High-value targets: Organizations subject to nation-state or sophisticated cyber attacks. Early warning closes the window where you're undefended before threat actors act.
{#armis-early-warning-integration__ul_hmk_pj2_vjc}

Detecting exploitation signals from honeypots, OSINT, and operational research before broader industry recognition or CISA KEV inclusion enables proactive patching and reduces the need for high-risk emergency updates.

## How it works {#armis-early-warning-integration__section_how_it_works}

Early Warning for Security Exposure Management performs the following operations when integrated with USEM:

* Detection: Identifies a vulnerability that threat actors are planning to exploit.
* Integration: Ingests early warning signal automatically ingested into USEM and elevates the priority of that CVE in your vulnerability inventory.
* Prioritization: Enables your security team to prioritize patching these vulnerabilities ahead of others, even if Common Vulnerability Scoring System (CVSS) scores don't reflect the real-world threat.
* Response: Enables your team to coordinate proactive patch deployment during planned maintenance windows and focus on vulnerabilities threat actors are actively targeting - not just those with the highest CVSS scores.
The integration appears in the Security Exposure Management workspace alongside other enrichment integrations such as the CISA Known Exploited Vulnerabilities integration. You can monitor integration run history, ingestion health, and processing health from the integration overview page.

## Key benefits {#armis-early-warning-integration__section_key_benefits}

Early Warning for Security Exposure Management provides the following benefits:

* Earlier risk prioritization: Early warning flags surface alongside your vulnerability risk scores, so remediation teams focus on the threats that matter most. Instead of patching by CVSS score alone, you patch based on real-world threat actor behavior.
* Faster remediation without extra setup: Early warning CVEs trigger existing Vulnerability Change Management workflows automatically, with no custom integration required.
* Faster identification of at-risk assets: Filter findings by early warning status to surface which assets carry elevated risk.
* Built-in asset correlation: Early Warning signals roll up from CVE records to third-party entries (TPEs) automatically, extending risk visibility to the assets already tracked in USEM with no additional CMDB mapping required.
{#armis-early-warning-integration__ul_y1d_wgj_tjc}

## Data available in USEM {#armis-early-warning-integration__section_xwq_2lg_vjc}

When you integrate Early Warning for Security Exposure Management, two new columns appear in your vulnerability records:

* **Armis Early Warning:** A flag indicating that threat actors are planning to exploit this CVE.
* **Armis Early Warning CVD Attributes:** Detailed vulnerability intelligence including:
  * CVE ID and affected product
  * Intelligence date (when Armis detected the threat actor activity)
  * Admiralty score (confidence rating of the vulnerability intelligence)
  * Honeypot detection date
  * Research date
  {#armis-early-warning-integration__ul_abz_glg_vjc}

{#armis-early-warning-integration__ul_z1z_glg_vjc}

You can use these columns to filter, sort, and prioritize your vulnerability remediation workflow.

The integration appears in the Security Exposure Management workspace alongside other enrichment integrations, such as CISA Known Exploited Vulnerabilities. From the integration overview page, you can monitor run history, ingestion
health, and processing status. For more information, see [Security Exposure Management Workspace List view](https://servicenow-prod.fluidtopics.net/cU0SPlBFgUyK~YNIGlh4UQ "The List view in the Security Exposure Management Workspace enables vulnerability and security managers and analysts to view remediation progress on records, drill down into records, and view the status of their approval requests and exceptions.")

## Admiralty score {#armis-early-warning-integration__section_admiralty-score}

Each CVE in the Armis feed includes an Admiralty score - a confidence rating based on the NATO Admiralty grading system. Scores range from A1--A6, B1--B6, C1--C6, D1--D6, E1--E6, and F1--F6, where A1 represents information from a
completely reliable source that has been independently corroborated. A lower confidence rating does not prevent a CVE from being identified as an early warning signal. CVEs with lower Admiralty scores may still be surfaced when
other factors indicate potential relevance or risk.

You can use the Admiralty score as an additional condition in a risk rule to refine prioritization. For example, you can configure the rule to apply a weight only to CVEs whose admiralty score meets a defined reliability
threshold.

## Configuring risk rules {#armis-early-warning-integration__section_downstream-risk-scoring}

The early warning flag and Admiralty score are available as criteria in your risk rules, allowing you to configure how early warnings influence your vulnerability scores.

In the default risk calculator, you can:

* Adjust the weight applied to early warning CVEs
* Add Admiralty score as an additional condition for refinement
* Create custom rules that combine early warning signals with other risk criteria

{#armis-early-warning-integration__ul_rlw_ypg_vjc}

In the default risk calculator, you can adjust the weight or add the admiralty score as an additional condition to refine prioritization.

Early Warning extends risk coverage to CVEs which may not yet be identified by intelligence sources such as CISA KEV or EPSS.

## Key components {#armis-early-warning-integration__section_key_components}

Early Warning for Security Exposure Management consists of the following components:

Integration plugin
:   Early Warning for Security Exposure Management (`sn_vul_ew`): Handles data ingestion via the Vulnerability Integration Framework

CVD attributes table
:   `sn_vul_ew_cvd_attributes`: Stores early warning-specific threat signals (admiralty score, honeypot date, intelligence date, research date, CWE)

Flag rollup
:   Business rules propagate `ew_exists` flag from NVD entries to third-party entries for consolidated risk assessment

Risk calculator field
:   `vulnerability.ew_exists`: Boolean risk criteria available for custom risk rule weighting

## Dependencies and prerequisites {#armis-early-warning-integration__section_dependencies}

The Early Warning for Security Exposure Management integration requires the following:

* Unified Security Exposure Management (Vulnerability Response v30.x)
* Vulnerability Integration Framework plugin
* Access to Armis vulnerability intelligence feed and valid authentication credentials
{#armis-early-warning-integration__ul_abd_wgj_tjc}
* **[Install the required applications for Early Warning for Security Exposure Management](https://servicenow-prod.fluidtopics.net/9DdC8HXmeCavHugZZ67C2g)**   
  Install the required applications for Early Warning for Security Exposure Management.
* **[Set up requirements for Early Warning for Security Exposure Management](https://servicenow-prod.fluidtopics.net/POjzUogyzvBRyG4zO2~5ow)**   
  Complete the following setup steps in your Armis Intelligence Center console environment before you configure Early Warning for Security Exposure Management in your ServiceNow AI Platform® instance.
* **[Configure the Early Warning for Security Exposure Management integration](https://servicenow-prod.fluidtopics.net/Ujq48wTsyyrkoKEADPeBeA)**   
  Install and configure the Early Warning for Security Exposure Management integration plugin to ingest vulnerability intelligence and enrich your vulnerability database with threat signals.
* **[Add Early Warning criteria to a risk rule](https://servicenow-prod.fluidtopics.net/Pn4cQqmUjnyF98bqd9cT6A)**   
  Add the Early Warning flag or Admiralty score as a weighted criterion in a risk rule to prioritize vulnerable items based on vulnerability intelligence data.
* **[Schedule the Early Warning for Security Exposure Management integrations](https://servicenow-prod.fluidtopics.net/rH5mKRe5UaBQ2Up38GMu8w)**   
  You can schedule the integration import times on the records in the Vulnerability Integrations \[sn_vul_int_fw_integration\] table and launch them on-demand.
* **[View Early Warning for Security Exposure Management integration health](https://servicenow-prod.fluidtopics.net/l8hN9GwkCDJJ2dI96owoHA)**   
  Monitor the Early Warning for Security Exposure Management integration by reviewing run history, ingestion performance, and processing health from the Security Exposure Management Administration console.
* **[Early Warning CVD Attributes field reference](https://servicenow-prod.fluidtopics.net/Qo5~OJ_cnofPgtkw4PCeIQ)**   
  The Early Warning CVD Attributes table stores vulnerability intelligence signals for vulnerabilities. Each attribute represents a threat indicator ingested from the Early Warning feed.

**Related concepts**   

* [Integrations for Central Vulnerability Database](https://servicenow-prod.fluidtopics.net/HsxrTZsMaM3QSt1fwjih4g "The Central Vulnerability Database supports integration with trusted global vulnerability data sources, including the National Vulnerability Database, European Union Vulnerability Database (EUVD), and Japanese Vulnerability Notes (JVN), to enrich and normalize vulnerability records.")
* [Security Exposure Management Workspace List view](https://servicenow-prod.fluidtopics.net/cU0SPlBFgUyK~YNIGlh4UQ "The List view in the Security Exposure Management Workspace enables vulnerability and security managers and analysts to view remediation progress on records, drill down into records, and view the status of their approval requests and exceptions.")  
**Related tasks**   

* [Define fields and weights for the risk rule for Unified Security Exposure Management risk calculators](https://servicenow-prod.fluidtopics.net/_rGD5l29QxKdjvNVNzr75Q "Customize risk rule parameters and weights to generate risk scores that reflect your organization's specific finding and asset data. By selecting relevant fields for the risk rule, you can create an effective risk scoring framework that meets your organization's unique needs.")

