Sep 01, 2026

Operational Technology Demands Autonomy and Certainty. We Deliver Both.

3d render of a modern data center

At Black Hat USA 2026, ServiceNow announced its Autonomous Security vision with six foundational pillars, one being Cyber-Physical Systems Security (CPS). For Armis from ServiceNow, this is more than a portfolio announcement. It puts cyber-physical security at the center of our broader strategy to secure the future: bringing asset intelligence, exposure management, AI-powered analysis, governed response, and cyber risk together through the AI Control Tower.

That matters because OT security cannot be treated like enterprise IT security. In a factory, power plant, hospital, port, or other critical environment, knowing what is exposed is only the beginning. Security teams need the context to understand what an asset controls, what a disruption could mean, and which actions can safely be automated. The goal is autonomy without surrendering operational control.

That is the principle behind our approach to CPS security and the foundation of Shift Zero: move from fragmented, reactive security toward continuous prevention, with intelligence and governance built into every step. AI is here to accelerate discovery, analysis, prioritization, and recommendations with certainty.

Built for what comes next

ServiceNow’s decision to establish CPS Security as a dedicated pillar reflects something we have believed from the beginning: securing operational environments requires deep cyber-physical expertise, not an IT security product adapted for OT.

Armis has spent years building that expertise into its platform. Now, as part of ServiceNow, that capability can connect directly with the systems organizations already use to manage assets, risk, change, compliance, and operations.

The result is a different model for OT security

Instead of discovering an exposed controller in one system, assessing its risk in another, opening a ticket somewhere else, and reconstructing the evidence later, organizations can connect the entire workflow. One asset record. One view of exposure. One governed path from intelligence to action.

That is the opportunity behind the Autonomous Security vision: not simply to make security faster, but to make it more connected, contextual, and increasingly autonomous, without removing the controls that OT demands.

How the market evaluates and recognizes us

To us, being named a Leader in the Gartner® Magic Quadrant™ for CPS Protection Platforms for a second consecutive year continues to carry particular significance. Since the report was published in March, Armis has continuously strengthened the capabilities that established it as a trusted OT security provider, advancing its Cyber Exposure Management platform and sharpening its focus on proactive security through the launch of ‘Shift Zero’. In our view, this evolution demonstrates industry leadership by moving beyond fragmented visibility tools to a unified platform that manages cyber risk across the entire attack surface.

At the time, we felt that the report highlighted AI and automation as a defining development across the CPS protection market. The Gartner Critical Capabilities for CPS Protection Platforms report recommends that organizations evaluate vendors that offer ways to reduce complexity with advanced capabilities:

“Evaluate a vendor’s ability to reduce the complexity of ongoing CPS security operations. Vendors offer varying ways to reduce complexity, such as workflow augmentation powered by automation and AI techniques, as well as solutions that are part of a larger security ecosystem provided by the same vendor.”

Source: 2026 Gartner Critical Capabilities Report for CPS Protection Platforms.

The point here, is not simply that AI is appearing in analyst reports, market conversations and our roadmap. It is that AI is being applied to our platform where it can create operational value—while the architecture around it preserves the context and governance OT requires.

Magic Quadrant for CPS Protection Platforms - 2026

Since the publication of this report, Armis from ServiceNow has released Armis Centrix™ for Application Security, extending that strategy into code analysis.

One platform across the factory floor

OT environments are rarely clean/ simple.

A single facility can contain decades of controllers, different generations of equipment, proprietary protocols, undocumented dependencies, building-management systems, connected devices, and systems that were never designed to be connected to modern security tooling.

The security challenge is therefore not just finding more assets or vulnerabilities. It is understanding which exposures matter, why they matter, and what can safely be done about them.

That is where cyber exposure management for CPS becomes critical.

Deep asset intelligence provides the foundation. ServiceNow provides the operational system of record around it. Together, they can turn a security finding into prioritized, accountable work—with the relevant context, approvals, change processes, and compliance evidence connected from the start.

The results are already measurable across our customer base:

  • Approximately 90% faster incident resolution
  • 60% fewer critical-infrastructure vulnerabilities
  • 75% less time spent preparing for audits

Source: https://www.armis.com/analyzing-the-economic-benefits-of-armis-centrix/

At the Port of Antwerp-Bruges, this approach helps provide unified security coverage across one of Europe’s most complex operational environments.

 

Autonomy where it helps. Control where it matters.

The most valuable automation in OT is not necessarily automation that takes action. It is automation that makes people better at making the right decision.

Consider the scale of the problem: correlating firmware with advisories, mapping an exposed device to the process it controls, identifying dependencies, and separating a vulnerability on a production historian from the same vulnerability on a spare engineering workstation.

Our approach is therefore to automate the intelligence around the decision. For example, segmentation recommendations can be accompanied by the traffic evidence behind them and a view of what would have been blocked over the preceding 90 days. Isolation recommendations can be routed to the person responsible for the relevant line or asset, with the process context needed to approve, reject, or defer the action.

That is autonomous security designed for OT: the machine does more of the work, while the human retains the final say.

Where we are going

The next phase of our CPS roadmap starts with OT engineering realities, not with security industry hype.

That means continuing to advance:

  • Process-aware risk, so exposure is assessed in the context of what an asset actually controls, rather than relying solely on generic severity scores.
  • AI-powered analysis and recommendations, helping teams prioritize complex environments and act on the exposures that matter most.
  • Continuous compliance evidence, reducing the manual effort required to demonstrate alignment with frameworks such as IEC 62443, NERC CIP, NIS2, and sector-specific requirements.
  • Deeper CPS intelligence, connecting devices, vulnerabilities, processes, dependencies, and operational context.
  • Governed automation, increasing the amount of security work machines can perform while keeping consequential OT decisions accountable.

This is the direction of Autonomous Security: more intelligence, more automation, and more certainty, without compromising operational control.

For OT teams, that is the promise of bringing CPS Security into the ServiceNow Autonomous Security portfolio.

Not autonomy for its own sake. Autonomy that understands what is at stake.

 

Gartner, Critical Capabilities for CPS Protection Platforms, By Wam Voster et. al, 9 March 2026

Gartner, Magic Quadrant for CPS Protection Platforms, By Katell Thielemann et. al, 3 March 2026

Gartner and Magic Quadrant are trademarks of Gartner, Inc. and/or its affiliates.

Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.

This graphic was published by Gartner, Inc. as part of a larger research document and should be evaluated in the context of the entire document. The Gartner document is available upon request from Armis.

 

Get Updates

Sign up to receive the latest from Armis.