For security architects, GRC analysts, and ServiceNow platform owners

See where your ServiceNow instance is exposed.

An independent, attacker's-eye audit of your ServiceNow configuration. Every finding ships with the detection script that proves it — instance-specific technical evidence, not a generic policy PDF.

Empty ACLs, scoped-app cross-scope grants, AI agent role-mask gaps, audit forensic blind spots — mapped to NIS2, DORA, and ISO 27001 at the article level.

No signup · no instance access · pick your release and get an instant CVE verdict.

Detection engine is open source — github.com/nowisor/instance-scan-pack · Apache-2.0

100+ Attack Scenarios
14 Security Domains
Open Source Detection Engine
NIS2 · DORA · ISO 27001
EU-Hosted Data
The Risk

Gaps That Standard Reviews Miss

!

Configuration Blind Spots

Misconfigured ACLs, exposed endpoints, and sys_properties that create exploitation paths invisible to standard reviews.

§

Missing Compliance Evidence

NIS2, DORA, and ISO 27001 require instance-specific technical evidence — not generic policy documents.

>_

Unreviewed Integrations

Every integration, MID Server, and OAuth token is a potential lateral movement path.

Why This Exists

Built by a ServiceNow Security Practitioner

After ten years as Principal Security Advisor in ServiceNow's Office of the CISO, I saw every enterprise hit the same blind spots. Nowisor — a virtual subject-matter expert (SME) for ServiceNow security — makes that expertise accessible on demand.

Rachid Harrando — FounderFormer Principal Security Advisor, ServiceNow Office of the CISO (10 years) · Co-founder of Black Hat Arsenal (2011) and Review Board member · 100+ enterprise instances advised
Author of Securing ServiceNow: A CISO's Field Guide (Leanpub, 2026) →
Real Attack ScenariosGrounded in real table structures, GlideRecord queries, and confirmed exploitation paths.
Production-Ready ScriptsExact table names, field names, and API patterns — verified against real instances.
From the Author

Securing ServiceNow

Securing ServiceNow: A CISO's Field Guide — book cover

Securing ServiceNow: A CISO's Field Guide

248 pages. Platform hardening, API defense, and EU regulatory readiness — written by the founder of Nowisor.

Read on Leanpub →Buy on Amazon →
How It Works

Three Steps

1

Ask Your Question

Describe your concern in plain language — ACL gaps, integration risks, compliance requirements, attack paths.

2

Get Expert Analysis

Receive attack chains, detection scripts, and compliance mappings specific to your ServiceNow configuration.

3

Fix and Evidence

Deploy scripts, close gaps, and generate auditor-ready compliance evidence.

WHEN NEEDED
4

Escalate to a Specialist

Bring in a senior practitioner. Your full session context transfers automatically.

Alongside ServiceNow, not instead of it

Where Nowisor fits

ServiceNow's Shared Responsibility Model draws the line: ServiceNow secures the platform, and you are responsible for how your instance is configured, who can reach what, and proving it to a regulator. Nowisor works entirely on your side of that line.

%

We start from your Security Center score

When you connect an instance, Nowisor reads your Security Center hardening score and the settings behind it, and treats them as the authoritative platform baseline. It does not recompute what ServiceNow already scores.

[ ]

We run inside Instance Scan

The detection engine installs as a scoped application and runs as a suite scan in ServiceNow's own Instance Scan framework. Findings land in your instance and remain there whether or not you ever connect the advisor.

/*

We cover what a checklist cannot

A settings-comparison framework cannot read the syntax of your custom Script Includes, Business Rules, and UI Actions, and it has no concept of an out-of-the-box ACL that was edited last night. Those two gaps are structural — they are where the detection engine's static analysis and drift checks sit.

!

We help you land ServiceNow's mandated changes

When ServiceNow sets a platform deadline — the Basic Auth API restriction (KB3025707 / KB3055080) is the current one — the pack ships readiness checks, so you can evidence where you stand before enforcement rather than after it.

European by design

Your data is hosted in Europe

Nowisor is built and run for organisations that answer to NIS2, DORA, and GDPR. Where your data lives, where it is processed, and who controls the stack are design decisions — not afterthoughts.

EU

Hosted in the EU

Accounts, scan snapshots, and your ServiceNow configuration values are stored and scanned on EU infrastructure in Amsterdam. AI answer-generation uses a US provider by default; on Enterprise you can keep that in the EU too — see below.

AI

Optional EU-only AI processing

On Enterprise, AI analysis runs on Claude served from EU data centres in Frankfurt, through an EU-hosted gateway governed by a signed GDPR Article 28 DPA. The gateway endpoint and the region-pinned model are what keep processing in the EEA — that part is enforced in code. Prompt and output logging is switched off on our gateway account, so under that DPA no copy is kept there. The model behind it is served by AWS Bedrock in Frankfurt under its own terms, which makes this EU-resident processing with no gateway-side logging rather than end-to-end zero retention. Retention and model-training terms come from that DPA rather than from a setting in this product.

!->

No silent US fallback

When EU processing is selected, the system fails closed: if the EU route is ever unavailable, the request is refused — never quietly rerouted to a US endpoint. Jurisdiction is enforced in code, not just in a policy document.

{ }

No vendor lock-in

The detection engine is open source under Apache-2.0, and the AI backend is swappable by design. You keep European control over the stack — inspect it, fork it, run the detection yourself without depending on nowisor.com at all.

What You Get

What Every Query Delivers

OK

Verified against live ServiceNow

Every property name, table reference, and detection script is verified against a real ServiceNow instance — a Zurich Patch 6 PDI — not generated from training data. Australia has been GA since May 2026 and our baseline has not moved to it yet, so we name the release we actually tested rather than the newest one. If a configuration claim cannot be proven on a live PDI, Nowisor does not ship it.

{}

Independent verification, attack-chain framing

ServiceNow’s own security tooling scores your configuration against ServiceNow’s checklists. Nowisor audits the same substrate independently and frames it as cross-domain attack chains — empty ACLs combined with scoped-app cross-scope grants and AI agent role-mask gaps, not isolated checklist items. Independence is the point: a platform vendor’s own dashboard is a weak audit artifact when a regulator asks who verified it.

>>

Attacker-relevant analysis

Findings are framed as attack paths an adversary would actually exploit, not as generic policy violations. Cross-scope privilege records, AI agent role-mask gaps, fabricated property recommendations from older guides — Nowisor surfaces what matters to an attacker.

§

Mapped to NIS2, DORA, ISO 27001

Every finding maps to specific framework articles — NIS2 Article 21 sub-points, DORA Article 9, ISO 27001 Annex A controls. Coverage scope is declared honestly: comprehensive where it is, partial where it is, never overclaimed.

>_

Detection scripts you can run yourself

Every finding includes the exact ServiceNow Background Script that produced it. Copy, paste, run on your own instance — no black box, no vendor dependency. The methodology is the deliverable as much as the findings.

=

Audit-ready evidence trail

Reports include verified configuration values, framework citations, and verification scripts — auditable artifacts your assessor or regulator can validate independently. Built for the moment a CISO has to defend a finding under questioning.

~

Exercised risk vs dormant misconfiguration

Findings tell you what is misconfigured; the twin-sensor log-export tells you which misconfigurations are actually being exercised. A sustained brute-force against an unprotected admin endpoint is not the same risk class as a dormant un-audited table. The Active Risk Report correlates each finding against 7 days of runtime activity (sys_audit, sysevent, syslog_transaction) and marks every verdict EXERCISED, DORMANT, NOISE, or INVESTIGATE — qualified by log-export coverage at every step.

Why nowisor can be trusted

Verification methodology, not promises

nowisor is built by Rachid Harrando — author of Securing ServiceNow, former Principal Security Advisor at ServiceNow's Office of the CISO, co-founder and Review Board member of Black Hat Arsenal. Twenty-five years in security — ten of them inside that office — encoded into a system that refuses to ship anything it cannot prove against a live ServiceNow instance.

The verification methodology is public: every property reference is checked against a version-pinned ServiceNow schema dump (Zurich Patch 6, 3,585 properties, captured and archived). Every detection script is tested against a live PDI before it ships. Every finding cites its evidence.

The detection engine is open source under Apache-2.0 at github.com/nowisor/instance-scan-pack. Every check the advisor reads from your instance was produced by code you can inspect, fork, or run on your own without depending on nowisor.com at all. The advisor is the value-add; the detection is the floor — and the floor is yours.

Why You Can Trust The Answer

Guardrails, Not Guesswork

{}

Schema-Verified Scripts

Generated code is bound to a release-pinned catalog — 143 ServiceNow table schemas and 90 system properties, drawn from the full 3,585-property Zurich Patch 6 dump. Fabricated tables, fields, or API names are caught at the bind step, before any script is generated.

9x

Hallucination Detectors

Every answer passes through nine automated detectors — uncited claims, unknown KB IDs, self-contradictions, prescriptions without diagnosis — before it reaches you.

=

Cited To The KB

Claims link back to specific knowledge-base articles with IDs validated post-response. If the source isn't there, the citation doesn't ship.

[]

Bound To Your Instance

On Enterprise, your tenant's actual schema is extracted on connect so scripts target your customizations — not a generic template.

X

Render-Time Redaction

Fabricated property names and unsupported claims are stripped before display — not quietly flagged in a log you'll never read.

#

Per-Message Scoring

Every response carries a quality signature tracked in the admin console. Regressions are visible; drift is auditable.

What's at Stake

Real Attack Scenarios From Real Instances

A SAML misconfiguration chained with a side-door endpoint giving an external attacker admin access
Integration credentials stored in plain text, one API call from lateral movement into your directory
A prompt injection that escalates through your AI agent to server-side code execution
A malicious code package promoted to production because no one reviewed the embedded scripts
For Consulting Teams

Scale Your ServiceNow Security Practice

>>

Deliver Faster

Run a full security assessment in hours, not weeks. Pre-built attack paths and detection scripts across 14 domains.

=

Consistent Methodology

Every engagement uses the same adversarial framework — repeatable, auditable, defensible.

§

Compliance-Ready Deliverables

Generate NIS2, DORA, and ISO 27001 evidence mapped to each client's configuration.

Access

Priced per instance. Not per message.

One ServiceNow security assessment by hand is three to five days of senior consultant time. Nowisor delivers it in hours — connect an instance, get attack-chain findings and auditor-ready NIS2/DORA/ISO 27001 evidence. Pay for the instances you audit, not the keystrokes.

Free

Recon

For practitioners and evaluators who want to see a real finding first.

€0

No credit card required

25 queries · no instance connection

  • All 14 security domains
  • 1 attack-path chain
  • Detection scripts — copy & run on your own instance
  • NIS2, DORA, ISO 27001 mappings
  • Open-source detection engine (Apache-2.0)
Start Free

Solo

Practitioner

For platform owners and solo security architects hardening one instance.

€149/ month

or €1,490/year — two months free

1 connected instance · unlimited scans

  • Everything in Recon
  • Unlimited attack-path chains
  • Unlimited on-demand scans
  • Instance integration (OAuth, read-only)
  • Interactive report + PDF export
Start 14-Day Trial

Managed · Regulated

Enterprise

For regulated enterprises that need their ServiceNow posture managed and evidenced continuously — not another tool to run.

Custom — managed engagements from €4,500/mo

Scoped to your instances, regulatory cycle, and Vault footprint

Managed posture assurance — we operate it, you get the evidence

  • Everything in Practice
  • Continuous 200-point scanning we operate for you
  • Attack-path evaluation against every scan
  • Active Risk Report with log-export correlation
  • Quarterly CISO-ready posture report (NIS2 / DORA / ISO 27001)
  • Production instance · SSO & scoped access set up at onboarding
Talk to the founder — 30 min, no pitch

Add-ons

Human expertise on top of any paid plan. Both are included in Enterprise.

Specialist On-Call+€199 / month

Written responses from a senior practitioner within 48 hours.

  • Ask from inside chat — your conversation goes with the question
  • Answers grounded in your connected instance, not generic advice
  • Unlimited questions
Expert Review+€399 / month

Monthly 60-minute live session plus unlimited async Q&A.

  • Everything in Specialist On-Call
  • Monthly 60-min live review of your findings and roadmap
  • Second opinion before an audit or a board update

Added to an existing subscription — ask in chat or talk to the founder.

What a managed engagement can include

  • Additional managed instances (dev / test / regional)
  • ServiceNow Vault assurance & configuration review
  • Monthly reporting cadence
  • Named-response SLA + on-demand reporting
  • Remediation advisory
  • Audit-evidence support per reporting cycle

Engagements scoped on a short discovery call. Annual terms; complementary to ServiceNow native security and your implementation partner.

The math — in numbers you can check

Anchored on published EU rates: senior ServiceNow security consulting runs €1,500–2,500/day, and a meaningful audit takes 5–15 days.

One instance

A manual security review: €5,000–7,500 in senior consultant time. Once.

Practitioner — €1,490/year, unlimited scans.

3–5× return on the first assessment. Every re-scan after it is included.

A consulting practice

One enterprise config-review engagement: €15,000–40,000 of billable senior days.

Practice — €4,990/year across 3 client instances, white-label deliverables.

A year of tooling for less than one engagement — each client instance becomes repeatable margin.

A regulated enterprise

The annual point-in-time review is stale by Q2 — and audit evidence is still weeks of screenshot-collection.

Enterprise — from €4,500/mo, operated for you.

Findings close only when a re-scan proves the fix; evidence per reporting cycle is a generated report, and "were we exploited?" (NIS2 Art. 23 / DORA Art. 19) has a same-day answer.

What goes away: 5–15 consultant days per audit cycle · Weeks of GRC screenshot-collection per reporting cycle · The fire-drill hours after a ServiceNow CVE drops

All plans include the open-source detection engine. Annual billing available on every paid tier. Switch or cancel anytime. EU data hosting · EU-only AI processing (Enterprise) · DPA available.

FAQ

Common Questions

Know Your Exposure

25 free queries. No credit card.

ASK YOUR FIRST QUESTION