---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Update security incident with lookup results workflow

# Update security incident with lookup results workflow {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Update security incident with lookup results workflow updates existing security incidents with lookup results.

## Before you begin

Role required: sn_si.basic

## About this task

This workflow is triggered by a business rule on the lookup table which monitors when the Result field changes to Failed.  
Workflow process activities include:

* [Roll up lookup info to security incident activity](https://servicenow-prod.fluidtopics.net/gGTHQBlrU53r6UXCLPk~fQ "The Roll up lookup info to security incident activity can be used with any workflow to gather information from a threat lookup and output a summary of the contents as well as the ID of the originating security incident in task work notes.")
* [Update Task Worknotes activity](https://servicenow-prod.fluidtopics.net/G61~6J8FnOYPs1WI~XryxQ "The Security Common Orchestration - Update Task Worknotes workflow activity updates the Activity section (work notes) of a task record. This is useful for logging information.")


