---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Explore

# Exploring ServiceNow Otto for Security Incident Response (SIR) {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Exploring ServiceNow Otto for Security Incident Response (SIR)

ServiceNow Otto for Security Incident Response (SIR) leverages generative AI skills and intelligent workflows to assist security analysts in efficiently triaging, investigating, and closing security incidents within their existing workflow.
This solution provides concise incident summaries, recommended next steps, post-incident analyses, and performance metrics, enabling faster and more informed decision-making.
Show full answer Show less  

## Key Features

* **Incident Summaries:** Quickly review security incident details, including issue specifics, observations, key actions, and closure information in an easy-to-read format.
* **Recommended Actions:** Generate suggested next steps to help analysts progress and close security incidents effectively.
* **Closure Notes:** Automatically draft closure notes based on remediation and containment activities, editable by analysts before finalizing.
* **Post-Incident Analysis:** Generate root cause analysis, impact assessments, and lessons learned to improve future responses.
* **Correlation Insights:** Connect current incidents to historical events involving the same users, configuration items, or observables to enhance investigation context.
* **Performance Metrics:** Analyze Security Operation Center (SOC) performance through AI-driven metrics and receive suggestions for improvement (requires activation of the Security operations metrics analysis skill).
* **Quality Assessment Reports:** Generate detailed quality assessments for security incidents to support continuous improvement.
* **Customization:** Administrators can tailor generative AI skills for summaries and closure notes by modifying related tables, availability, and display settings.

## Key Outcomes

* **Faster Incident Triage:** Security analysts save time reviewing lengthy incident activity streams by accessing concise summaries and contextual information.
* **Improved Incident Closure:** Automatically generated closure notes and recommended actions accelerate incident resolution while maintaining accuracy and relevance.
* **Enhanced Collaboration:** Findings, incident details, and closure notes can be easily shared among analysts, managers, and key stakeholders through the ServiceNow Otto panel.
* **Data-Driven Insights:** Post-incident analyses and correlation insights provide deeper understanding to prevent recurrence and optimize security operations.
* **Performance Optimization:** SOC managers gain actionable visibility into team performance with AI-generated metrics and improvement suggestions.

## Users

* **Security Analysts and Managers:** Benefit from incident summaries, recommended actions, closure note generation, and correlation insights to streamline investigations and incident management.
* **Administrators:** Can customize generative AI skills to better align with organizational workflows and reporting needs.  
Security analysts can use intelligent workflows and ServiceNow generative AI skills to help them triage, investigate, and close security incidents within the flow of their work with ServiceNow Otto for Security Incident Response (SIR).

## ServiceNow Otto for Security Incident Response (SIR) overview {#exploring-now-assist-security-incident__cf-exploring-parent-overview}

With generative AI skills and agentic workflows, your security analysts have the option to:

* Summarize security incident details and review the context quickly in a concise, easy-to-read format.
* Generate recommended next steps for a security incident.
* Generate post-incident analysis data.
* Generate performance metrics for your remediation teams with an agentic workflow.For this feature, the Security operations metrics analysis skill is activated for use with an AI agent. See [Analyze security operations metrics](https://servicenow-prod.fluidtopics.net/IOjk1qFmeHEg25PcW3Qbow "Chat with an AI agent from the ServiceNow Otto panel to help you gain insight into how efficiently your security analysts are working with security incidents resolution.") for more information.

* Generate a resolution plan.
* Generate closure notes.
* Generate correlation insights
* Generate shift handover reports
* Generate a quality assessment report for a security incident

{#exploring-now-assist-security-incident__ul_yls_52d_ycc}

Security analysts can share findings, incident details, and closure notes with other analysts, managers, and key stakeholders.

## Users {#exploring-now-assist-security-incident__cf-exploring-parent-users}

{#exploring-now-assist-security-incident__table_vxr_4cq_xbc__entry__2}

| User | Description |
|-|-|
| Security analysts and managers | Preview security incident details, see their potential impact, and view the key remediation actions already taken with security incident summaries using generative AI. Summaries and recommended next steps (actions) give analysts and managers a head start with their investigations and help with closing security incidents. Automatically generate a draft of closure notes using generative AI. Closure notes for security incidents are created quickly based on remediation and containment activities, in addition to other relevant details that are related to their closure. |
[Table 1. Users]

{#exploring-now-assist-security-incident__table_vxr_4cq_xbc}

## Benefits {#exploring-now-assist-security-incident__cf-exploring-parent-benefits}

{#exploring-now-assist-security-incident__table_yxr_4cq_xbc__entry__3}

| Benefit | Feature | Users |
|-|-|-|
| Expedite triaging of security incidents with long activity streams by reviewing work notes and contextual information quickly in a concise, easy-to-read format. | Generate summaries for security incidents that include the following information: * Issue * Details * Observations * Key actions taken * Closure details {#exploring-now-assist-security-incident__ul_jys_vlv_zbc} | * Security analysts * Security managers {#exploring-now-assist-security-incident__ul_ad1_mpq_1cc} |
| Automatically generate a draft of closure notes for a security incident when it's ready for closure. Analysts can modify any content that is generated by the AI skill by editing it, removing it, or adding their own notes before they close the security incident. | Generate security incident closure notes | * Security analysts * Security managers {#exploring-now-assist-security-incident__ul_qww_mpq_1cc} |
| Generate recommended next steps within the workflow upon request to help you close a security incident. | Generate security incident recommended actions | * Security analysts * Security managers {#exploring-now-assist-security-incident__ul_ygd_lgd_ycc} |
| Generate a post-incident analysis that includes a root cause analysis, impact assessment, and lessons learned within the workflow of closing a security incident. | Generate post-incident analysis | * Security analysts * Security managers {#exploring-now-assist-security-incident__ul_jmg_5hd_ycc} |
| Connect current incidents to past events that involve the same affected users, configuration items (CIs), or observables. | Generate correlation insights | * Security analysts * Security managers {#exploring-now-assist-security-incident__ul_kzs_dk5_pdc} |
| Gain insight into how efficiently your security analysts are working with security incidents with am AI agent. | GenerateSecurity Operation Center (SOC) Performance Analysis and get suggestions for improvement from an AI agent. Note: You must activate the Security operations metrics analysis skill if you want to use the Analyze security operations metrics agentic workflow. | Security managers |
| Learn about the details of a security incident quickly by accessing summaries and closure notes from the ServiceNow Otto panel. | Access the generative AI summary and closure notes from the ServiceNow Otto panel. Type in requests for more basic information about security incidents in the panel. | * Security analysts * Security managers {#exploring-now-assist-security-incident__ul_owp_3pq_1cc} |
| Generate a quality assessment report for a security incident. | Generate Quality Assessment report | Security managers |
| Customize the generative AI skills for summaries and closure notes to suit your needs. | Copy a skill and modify select related table fields, define the availability of the skill, and choose where the skill is displayed. | admin |
[Table 2. ServiceNow Otto for Security Incident Response (SIR) features]

{#exploring-now-assist-security-incident__table_yxr_4cq_xbc}

## What to explore next {#exploring-now-assist-security-incident__cf-exploring-parent-links}

To learn more about configuring and using ServiceNow Otto for Security Incident Response (SIR), see:

* [Configuring ServiceNow Otto for Security Incident Response (SIR)](https://servicenow-prod.fluidtopics.net/kQJX4pdfDgl0zHon2~2B8Q "The ServiceNow Otto for Security Incident Response (SIR) application is supported in the Security Incident Response Workspace and in the legacy Core UI (UI16). Use the guided setup in the AI Admin Hub console to configure ServiceNow Otto for Security Incident Response (SIR).")
* [Summarize a security incident](https://servicenow-prod.fluidtopics.net/WuiYXhGs_TTCmYr4nkbuCg "Understand the context of a security incident with the Security Incident summarization generative AI skill.")
* [Generate closure notes](https://servicenow-prod.fluidtopics.net/HWeP1dIXilE1F2K8DTzG7w "Automatically generate a draft of the closure notes for a security incident when you close it. The draft is editable and will be reviewed before closing the security incident, and it can be used or modified as needed. Closure notes provide information about the resolution of a security incident to other analysts, managers, and key stakeholders.")
* [Generate correlation insights](https://servicenow-prod.fluidtopics.net/UWB1_7QXFC2dkUcsXolv2Q "Generate correlation insights to avoid duplicating your investigation into affected users, configuration items, and observables and resolve the security incident that you're working on quickly. You select the criteria from a security incident that you want to base the correlation insights on.")
* [Generate recommended actions](https://servicenow-prod.fluidtopics.net/~o2W9XqVxDNrJDbRLYNZhg "Automatically generate the next steps your analysts can take to help them close a security incident in the Security Incident Response Workspace. The recommended steps are based on existing security incidents and knowledge articles.")
* [Generate a post-incident analysis](https://servicenow-prod.fluidtopics.net/x4G0umVhTvkHQVXZoOsoEQ "Automatically generate a post-incident analysis for a security incident that includes a root cause analysis, impact assessment, and learning and recommendations information.")
* [Analyze security operations metrics](https://servicenow-prod.fluidtopics.net/IOjk1qFmeHEg25PcW3Qbow "Chat with an AI agent from the ServiceNow Otto panel to help you gain insight into how efficiently your security analysts are working with security incidents resolution.")
* [Inputs and triggers](https://servicenow-prod.fluidtopics.net/sQ~bNfdkGhQFZCY9pyidmw "You can configure some of the inputs or triggers for a generative AI skill. Inputs or triggers permit you to determine how and when a skill is used.")
{#exploring-now-assist-security-incident__ul_zxr_4cq_xbc}

