ServiceNow Vulnerability Response consulting for platform owners.
We help ServiceNow platform owners get VR working the way it was designed: findings on the right CI, work routed to the right team, SLAs that satisfy auditors, and a clean upgrade every release.
Vulnerability Response is the only thing we do.
- Thousands of findings sit on unmatched or duplicate CIs
- Remediation tasks get reassigned by hand every week
- Exceptions are approved in email and never expire
- Your last upgrade left a pile of skipped VR records
- Audit asks for SLA adherence and you build a spreadsheet
- Nobody remembers why that business rule exists
Five levels, from importing scans to reducing risk on purpose.
Most deployments we assess stall at Level 2. Pick a level to see what it looks like and what it takes to get past it.
Where does your deployment sit?
Four ways we work, all inside Vulnerability Response.
VR Health Check
A read-only review of your instance that tells you exactly where you stand and what to fix first.
- Maturity score against the five-level model
- CI match rate and CMDB identification review
- Customization and upgrade skip audit
- Prioritized 90-day roadmap with effort estimates
Implementation and Integration
New VR rollouts and rebuilds done out of the box first, so every future upgrade stays easy.
- Scanner integrations and scheduling
- IRE identification and reconciliation rules
- Remediation task, assignment and target rules
- Risk calculators tuned to your environment
Compliance Alignment
Turn your policy's remediation timelines into rules ServiceNow enforces and reports on.
- Remediation targets mapped to PCI, NIST, FedRAMP and more
- Exception workflow with approvals and expiry
- Audit-ready SLA and exception dashboards
Back to Baseline
We unwind the customizations that break upgrades and slow your team down, then document what stays.
- Revert modified out-of-box records safely
- Replace scripts with configuration
- Clear skipped records from past upgrades
Show auditors the rule, the record, and the result.
Every framework asks some version of the same question: do you find, fix, and track vulnerabilities on time? VR can answer it directly when it is configured for it.
| Framework | What it asks for | How we configure VR to prove it |
|---|---|---|
| PCI DSS v4.0 | Critical patches within one month (6.3.3); internal scans at least quarterly (11.3.1) | Remediation target rules for in-scope CIs, scan recency tracking, CDE-tagged dashboards |
| NIST SP 800-53 | Vulnerability monitoring (RA-5) and flaw remediation (SI-2) | Scanner coverage reporting, targets by risk rating, closure evidence on each item |
| FedRAMP | High findings in 30 days, moderate in 90, low in 180 | Target rules matched to those windows, POA&M-ready exception records |
| CISA BOD 22-01 | Known Exploited Vulnerabilities fixed by the catalog due date | KEV-aware risk scoring and target dates, KEV aging dashboard |
| ISO/IEC 27001:2022 | Management of technical vulnerabilities (A.8.8) | Documented process in VR workflow, exception approvals with owner and expiry |
| SOC 2 | Detect and monitor for new vulnerabilities (CC7.1) | Continuous ingestion, trend reporting, evidence exports for the audit window |
| HIPAA Security Rule | Ongoing risk analysis and risk management | ePHI system grouping, risk-ranked remediation, exception rationale on record |
Control references are summaries for orientation. Your auditor and policy define the exact requirement.
What we find in real instances, and what we do about it.
Modified out-of-box business rules on sn_vul_vulnerable_item
Revert to baseline and move custom logic into new, documented rules
Scanner imports creating duplicate CIs outside the IRE
Identification and reconciliation rules so every finding lands on one CI
Assignment hard-coded in scripts and reassigned by hand
Assignment rules driven by CI support group and ownership data
Custom exception tables and email approvals
Out-of-box exception workflow with approvers, reasons and expiry dates
Grouping rules that open thousands of tiny remediation tasks
Task grouping tuned to how your teams patch: by solution, CI class or owner
Years of skipped records in sys_upgrade_history_log
Review, merge or revert each one, then leave you a clean baseline
Assess first. Fix what matters. Hand it back clean.
Assess
Weeks 1 to 2Read-only instance review, stakeholder interviews, maturity score.
Plan
Week 3Roadmap ranked by risk reduction and upgrade impact, agreed with you.
Fix
Weeks 4 to 10Configuration over code, tested in sub-prod, promoted with update sets you own.
Hand off
Final weekRunbooks, admin training, and a before and after maturity score.
Start with a two week VR Health Check.
Fixed scope, fixed fee, read-only access. You get a maturity score, a customization audit and a 90-day plan, whether or not we do the work after.
Prefer email? Write to hello@nowprojects.ai