ServiceNow’s $7.75bn bet on Armis signals a shift in cybersecurity, from detecting threats to resolving them. In a consolidating market, the companies that fix problems may prove more valuable than those that simply find them.

Spend enough time reading about enterprise cybersecurity and you start noticing a pattern: the industry is obsessed with detection. Find the threat faster, flag the vulnerability sooner, alert the analyst before the breach spreads. Detection is where venture capital flows, where marketing budgets go, and where conference keynotes point. CrowdStrike, for instance, built an $80 billion company almost entirely on finding threats faster than anyone else. It is also, increasingly, the wrong thing to optimize for.
ServiceNow’s $7.75 billion acquisition of Armis, announced December 23, 2025, the largest deal in ServiceNow’s history, is a $7.75 billion argument that the real value in enterprise security lies one step later: in what happens after something goes wrong. That argument is correct. And if ServiceNow executes, it will have pulled off one of the more elegant strategic pivots in recent enterprise software history.

The case for Armis starts with a problem that is surprisingly basic, given how much money the security industry spends each year. Roughly one-third of organizations have no formal centralized inventory—or no inventory at all—of active ICS/OT remote access points. Factory floors, hospital wards, energy substations—the physical infrastructure that actually keeps modern society running—are largely invisible to the security tools watching over corporate IT networks. You cannot patch a 20-year-old industrial controller. You cannot reboot a water treatment system mid-cycle. OT and industrial IoT environments prioritize safety and availability over confidentiality. Patching can halt production entirely, so updates are delayed for maintenance windows that may be months apart.
This is not a niche problem quietly contained to manufacturing. Ransomware attacks on the industrial sector spiked 87% year-over-year in 2024, making it the top ransomware target for four consecutive years. Nation-states are actively probing critical infrastructure. The Colonial Pipeline ransomware attack is the case study everyone cites; the incidents that did not make headlines are more numerous and accelerating. Armis addresses this through real-time, agentless discovery and classification of managed and unmanaged assets, including OT, IoT, medical, and industrial devices that traditional security tools routinely miss. Agentless is the only workable approach in environments where installing software means stopping a production line.
That capability made Armis worth acquiring. What makes it worth $7.75 billion is what ServiceNow intends to do with that visibility.
Critics will call the price an overpay. $7.75 billion for a company generating $340 million in annual recurring revenue is a multiple that demands flawless execution. The multiple is steep, but ServiceNow is buying position: the only credible solution to a problem that sits directly upstream of everything it already does. Consider what ServiceNow already owns: the workflow that tells the right person to fix the right problem at the right time, tracks whether they did, escalates when they have not, and documents the resolution for auditors afterward. Every large organization runs some version of this on ServiceNow. The company is not widely known outside enterprise IT circles, but it is embedded in the operational fabric of most Fortune 500 companies in a way that is genuinely difficult to displace.
What Armis adds is the upstream intelligence that makes that workflow actionable across the physical world. It connects asset discovery, threat intelligence, and risk prioritization with automated remediation in one unified stack. The walls between IT operations, security operations, and business process management have been collapsing for years; this deal finishes the job. Security is becoming the governing layer through which enterprises manage physical risk, operational continuity, and regulatory accountability simultaneously, and ServiceNow is positioning itself as that layer.
ServiceNow’s advantage here is specific: it owns the remediation workflow—the step that determines whether anyone actually fixes the threat that Microsoft, CrowdStrike, or Palo Alto Networks just identified. Nobody is contesting that lane, which is exactly why it is worth owning.
The harder question is integration. Dragos and Claroty built their entire companies around one commercially proven insight: OT engineers think in uptime and physical consequences, and they will walk away from any tool designed for an IT helpdesk. That cultural gap between OT and IT is a real obstacle that ServiceNow will need to navigate carefully if Armis is to retain the trust it has built in operational technology environments.
For ServiceNow, that history is an instruction manual. CrowdStrike has already acquired SGNL and Seraphic, and Palo Alto Networks has been evaluating its own asset visibility moves. The window is closing. Whether ServiceNow wins comes down to one question: does it have the organizational discipline to let Armis remain Armis, or does it absorb it into the existing platform and erase everything that made it worth $7.75 billion? That is a management challenge—and those are solvable.
The cyber exposure management market will not look the same in five years. Platform consolidation is already underway: ServiceNow, CrowdStrike, Palo Alto Networks, and Microsoft are all racing toward unified security architectures, steadily pushing independent specialists out of the market. Nozomi Networks, along with Dragos and Claroty, will either be acquired or gradually defunded by enterprises consolidating vendors. The OT security market is too strategically valuable—and too adjacent to the platform war—for specialists to hold independent ground at scale. The era of best-of-breed point solutions is declining.
ServiceNow will be one of two or three platforms left standing if it makes one decision correctly. Armis must become the foundation of a new architecture. The moment ServiceNow treats it as just another feature in a product catalog, the $7.75 billion is gone. ServiceNow’s leadership has bought something genuinely new. The only question is whether they have the discipline to act like it.
The company that fixes problems is worth more than the company that finds them. ServiceNow just spent $7.75 billion proving it believes that. How it integrates Armis will set a precedent for how the next generation of enterprise security platforms are built and who gets to build them. The next five years will show whether it was right.


