---
sourceDocument: Zurich Release Notes
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/zurich/release-notes

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Release Notes

ft:clusterId :

    - rn

bundleId :

    - rn


---

# Security Incident Response release notes

# Security Incident Response release notes {#ariaid-title1}

Release version: Zurich  
Updated July 31, 2025  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 8 minutes to read  
The ServiceNow®
Security Incident Response (SIR) application helps your organization connect security and IT teams, respond faster and efficiently to threats, and gain insight into your organization's security posture. Security Incident Response was enhanced and updated in the Zurich release.

## About Security Incident Response {#secops-sir-rn__secops-sir-rn-highlights}

* Integrate Cortex XSIAM by Palo Alto Networks with ServiceNow Security Incident Response platform to turn SIEM insights into actionable incidents, thus accelerating response from detection to closure.
* Use Advanced Work Assignment (AWA) to automatically assign incidents to your security analysts, based on their availability, capacity, and skills.
* Ingest third-party risk scores in Security Incident Response to factor these scores when calculating risk scores.
* Starting in version 13.9.33, you can do the following:
  * Fetch closed offenses from IBM QRadar into Security Incident Response.
  * Set the batch size for correlation rules during IBM QRadar offense polling to optimize performance.
  * Use the Now Assist LLM-powered integration builder to rapidly build integrations for Security Incident Response using auto-code generation.
  * Ingest MITRE D3FEND data and visualize attack--defense relationships through an interactive graph directly within a security incident.
  {#secops-sir-rn__ul_qhz_vmg_xhc}
* Starting in version 13.9.21, you can do the following:
  * Integrate CrowdStrike Next-Gen SIEM integration with ServiceNow Security Incident Response platform to retrieve detections and convert them into security incidents, thus enabling automated response actions.
  * Improve incident classification and enable efficient retrieval of historical data and alerts through enhanced Splunk ES integrations.
  * Configure and use on-call scheduling to prevent gaps in coverage and ensure analysts are available to address security incidents by configuring shifts for analysts.
  {#secops-sir-rn__ul_m5v_l4p_fhc}
{#secops-sir-rn__ul_l2t_1hk_w2c}

See [Security Incident Response](https://www.servicenow.com/docs/access?context=sir-landing-page&version=zurich&pubname=zurich-security-management&ft:locale=en-US) for more information.{#secops-sir-rn__secops-sir-rn-highlights-2}

## Activation and other requirements

Important:  
Security Incident Response is available in the ServiceNow Store. For details, see the "Activation information" section of these release notes.

Activation information

:   Install Security Incident Response by requesting it from the ServiceNow Store. Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#secops-sir-rn__secops-sir-rn-activation-1}

    [Security Operations common
    functionality](https://www.servicenow.com/docs/access?context=sec-ops-common-functionality&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
    :   The Security Support Common plugin is activated when any of the plugins for the main Security Operations applications (Security Incident Response, Vulnerability Response, Threat Intelligence, or Configuration Compliance) are activated.

## Accessibility and localization

Accessibility information
:

    Dark theme
    :   The new Coral theme includes a dark theme option for web and mobile experiences. This option is commonly used to alleviate eye strain and improve readability.

## January 2026 {#ariaid-title2}

The ServiceNow®
Security Incident Response (SIR) application helps your organization connect security and IT teams, respond faster and efficiently to threats, and gain insight into your organization's security posture. Security Incident Response was enhanced and updated in the Zurich release.

### What's new {#secops-sir-rn-2026-01__secops-sir-rn-new-features}

[MITRE D3FEND framework](https://www.servicenow.com/docs/access?context=mitre-d3fend-framework&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:   Security administrators can now ingest MITRE D3FEND data. Security analysts can explore MITRE ATT\&CK and D3FEND techniques through an interactive, node-based visualization that maps attack techniques, defense techniques,
    and related artifacts within a Security Incident Response (SIR) record.
{#secops-sir-rn-2026-01__secops-sir-rn-new-features-1}

## Zurich Early Availability {#ariaid-title3}

The ServiceNow®
Security Incident Response (SIR) application helps your organization connect security and IT teams, respond faster and efficiently to threats, and gain insight into your organization's security posture. Security Incident Response was enhanced and updated in the Zurich release.

### What's new {#secops-sir-rn-2025-08__secops-sir-rn-new-features}

[Close multiple security incidents](https://www.servicenow.com/docs/access?context=close-multiple-incidents-sir&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:   Close security incidents in bulk with predefined closure comments or codes to reduce the time that would be spent on manually closing individual incidents. Closure candidates might include multiple incidents with common root
    causes such as alert misconfiguration, duplicates, or changes in system behavior.

[Process Mining for security incidents](https://www.servicenow.com/docs/access?context=sir-process-mining&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:   Identify factors contributing to delays in processing SIR incidents that take a long time to close or resolve by scanning historical SIR records through Process Mining. Time-consuming factors can include multiple reassignments, prolonged hold times, and periods of inactivity. Use analysis methods to identify these factors such
    as multi-hop analysis or bottleneck analysis.

[Send Observables to TISC](https://www.servicenow.com/docs/access?context=tisc-context-in-sir-workspace&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:   Add metadata to the observables such as confidence score, Traffic Light Protocol value, notes and TISC tags before sending them to TISC.
{#secops-sir-rn-2025-08__secops-sir-rn-new-features-1}

### What's changed {#secops-sir-rn-2025-08__secops-sir-rn-ui-changes}

[Shift Handover Records](https://www.servicenow.com/docs/access?context=manage-shift-handover-records&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:   The Start date and End date fields have been removed. You can now select the shift name instead when configuring the Shift Handover record.
{#secops-sir-rn-2025-08__secops-sir-rn-ui-changes-1}

## Zurich {#ariaid-title4}

The ServiceNow®
Security Incident Response (SIR) application helps your organization connect security and IT teams, respond faster and efficiently to threats, and gain insight into your organization's security posture. Security Incident Response was enhanced and updated in the Zurich release.

### What's new {#secops-sir-rn-release__secops-sir-rn-new-features}

[Security Incident Response Integration with Cortex XSIAM by Palo Alto Networks](https://www.servicenow.com/docs/access?context=cortex-xsiam-siem&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:   As a profile admin:

    * Create profiles for incident ingestion.
    * Filter Cortex XSIAM incidents.
    * Map Cortex XSIAM Incident, Alert, and Event fields to SIR security incident fields.
    * Aggregate incidents to existing open security incidents to avoid having to create duplicate security incidents.
    * Synchronize ServiceNow instance Work notes with Palo Alto Networks XSIAM comments.
    {#secops-sir-rn-release__ul_f2v_lz4_fhc}

[Setup ServiceNow Security Operations Event Ingestion Addon for Splunk ES](https://www.servicenow.com/docs/access?context=splunk-es-addon&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:   The ServiceNow Security Operations Event Ingestion Add-on for Splunk ES enables seamless integration between Splunk and ServiceNow Security Operations, allowing you to send security-related events from Splunk ES to a ServiceNow security incident.


[LLM-powered SIR integration builder](https://www.servicenow.com/docs/access?context=sir-integration-builder-now-assist&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:   With the ServiceNow platform's latest LLM powered integrations, you can create product-ready integration quickly. The LLM-powered integration builder has the following capabilities:

    * Automatically generates integration code from a public API documentation.
    * Provides guided setup built on existing capabilities.
    * Provides easy edit and maintenance of the generated auto code.
    {#secops-sir-rn-release__ul_iyz_y2q_fhc}

[Deny rule for phishing emails](https://www.servicenow.com/docs/access?context=urp-about&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:   The security admin can add rules to prevent the conversion of phishing emails such as false positives or low-risk messages into security incidents. Any new phishing email is verified first with the deny rules to avoid
    unwanted security incidents.

[Update information in security incident related records](https://www.servicenow.com/docs/access?context=edit-related-records-in-list&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:   The security analysts can now edit related records such as associated observables, for a security incident directly from the Related Records list view. Security analysts can quickly update the records without leaving their
    current context.

[Advanced Work Assignment for Security Incident Response](https://www.servicenow.com/docs/access?context=awa-for-sir&version=zurich&pubname=zurich-security-management&ft:locale=en-US)

:   Use Advanced Work Assignment (AWA) to streamline the security incident assignment process which ensure that critical incidents are handled by the most appropriate and available analysts. This improves overall response times and efficiency in security operations.As an admin, configure the following:

    * Service channels
    * Queues
    * Assignment rules
    * Presence states
    * Rejection reasons

    {#secops-sir-rn-release__ul_pj5_smq_khc}

    As an analyst, do the following:

    * Set your availability
    * Accept or reject incoming security incidents
    {#secops-sir-rn-release__ul_qj5_smq_khc}

[Prevent duplicate security incidents for IT incidents](https://www.servicenow.com/docs/access?context=si-creation&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:   Prevent the creation of duplicate security incidents when ITIL users escalate an IT incident to a security incident, the system by enabling the `sn_si.disable_duplicate_security_incident` system property.

[Ingest third-party risk scores](https://www.servicenow.com/docs/access?context=define-risk-score-calculator-rules-sir&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:   Factor third-party risk scores into security incident risk calculation by ingesting and mapping those scores for better prioritization of high-risk threats.

[Simplified adding categories and sub-categories for security incidents](https://www.servicenow.com/docs/access?context=category-management-sir&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:   Admin can create categories and subcategories in Security Incident Response Workspace based on threat types, compliance requirements, or reporting needs.

    Security analysts can assign these categories and subcategories to security incidents.

[Security incident Details tab](https://www.servicenow.com/docs/access?context=security-incident-details-form&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:   Include the Functional Impact, Recoverability and Information Impact fields on the Details tab of a security incident to improve triage accuracy, incident
    handling efficiency, and executive reporting for calculating the risk score.
{#secops-sir-rn-release__secops-sir-rn-new-features-1}

[Add indirectly linked VITs to CVEs](https://www.servicenow.com/docs/access?context=configure-mitre-att-ck-properties&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:   In MITRE-ATT\&CK framework, identify all third-party entities (TPEs) associated with common vulnerabilities and exposures (CVEs) and then calculate and display the total number of vulnerable items (VITs) indirectly
    linked to those CVEs through the TPEs by setting the sn_ti.include_cve_vit_indirect_relation system property.

[Configure on-call schedules](https://www.servicenow.com/docs/access?context=on-call-schedule-sir&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:   As an admin, manage on-call schedules through the following activities:

    * Create a shift and assign or remove members to or from the shift.
    * Create and edit on-call schedules for groups.
    * View any group's on-call schedule.

    {#secops-sir-rn-release__ul_gn2_qsj_y2c}

    As an analyst, track your on-call responsibilities through the following activities:

    * Specify your availability and preferred contact methods.
    * View your on-call schedule.
    * See other members of your shift.
    {#secops-sir-rn-release__ul_j5b_vsj_y2c}

[Users accessing the same incident](https://www.servicenow.com/docs/access?context=security-incident-overview&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:   When you open an incident, the initials of all the users currently accessing the same incident are displayed to avoid conflicts.

[Universal search field for linking observables](https://www.servicenow.com/docs/access?context=sir-records&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:   Search across all the field values of the associated observables for an incident.

[CrowdStrike Next-Gen SIEM integration](https://www.servicenow.com/docs/access?context=crowdstrike-next-gen-integration-secops&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:
    As a Profile Admin:

    * Discover CrowdStrike Next-Gen SIEM detections that are candidates for security incidents and automate the creation of these security incidents.
    * Create detection profiles.
    * Map CrowdStrike Next-Gen SIEM Detection and Events Fields to SIR security incident fields.
    * Filter CrowdStrike Next-Gen SIEM defects.
    * Aggregate detections to existing open security incidents so that you don't have to create duplicate security incidents.
    * Automate CrowdStrike Next-Gen SIEM detection status updates for Security Incident Response.
    * Synchronize CrowdStrike Next-Gen SIEM detection comments with SIR Work notes.
    {#secops-sir-rn-release__ul_fjz_pm1_yfc}

[Create and name an event profile for the Splunk Enterprise Security event ingestion
integration](https://www.servicenow.com/docs/access?context=splunk-event-ingest-create-profile-security&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:
    * Enables bidirectional updates and closure synchronization between Splunk ES and Splunk integrations.
    * Enables retrieval of historical, and ongoing data including closed events, with an option to pull the closed events into the ServiceNow Splunk ES instance.
    * Receive updates for the mapped fields in SIR.
    {#secops-sir-rn-release__ul_zcm_tsh_tfc}

[Components installed with Security Incident Response](https://www.servicenow.com/docs/access?context=installed-with-sir&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:   A new Profile Admin role (sn_si.ingestion_profile_admin) provides access to configure plugins, and to create, edit, delete, and manage profiles for the Splunk, Splunk ES, and Azure Sentinel Integration for Security Operations application.

[Enhancements to relationship graphs](https://www.servicenow.com/docs/access?context=sir-relationship-graph&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:
    As an admin:

    * Define default child nodes to populate in the relationship graph.
    * Configure relationship labels.
    {#secops-sir-rn-release__ul_cjb_hb4_y2c}

    As an analyst:

    * Add or remove child nodes at the parent node level.
    * Save the state of the relationship graph.
    * Retrieve updated data.
    {#secops-sir-rn-release__ul_cgn_kb4_y2c}

### What's changed {#secops-sir-rn-release__secops-sir-rn-ui-changes}

Coral theme
:   Coral is now the default theme for new portal, web, and mobile experiences with Next Experience or Core UI enabled. This theme provides a fresh look and feel, featuring brand-neutral illustrations to enhance your user experience. A dark theme option is available for web and mobile experiences.
{#secops-sir-rn-release__secops-sir-rn-ui-changes-1}

[Security Incident Response Other Records](https://www.servicenow.com/docs/access?context=security-incident-response-other-records&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:   Add  multiple ITSM incidents, problems, or change requests to a security incident for which multiple IT actions are needed. For more information, see the
    "Link multiple ITSM incidents"
    section.

[Modify attachments of a closed security incident](https://www.servicenow.com/docs/access?context=t_ClosingSecIncidents&version=zurich&pubname=zurich-security-management&ft:locale=en-US)
:   You cannot modify the attachments of a security incident once the security incident is closed.
{#secops-sir-rn-release__secops-sir-rn-changed-features-1}

