For security architects, GRC analysts, and ServiceNow platform owners
An independent, attacker's-eye audit of your ServiceNow configuration. Every finding ships with the detection script that proves it — instance-specific technical evidence, not a generic policy PDF.
Empty ACLs, scoped-app cross-scope grants, AI agent role-mask gaps, audit forensic blind spots — mapped to NIS2, DORA, and ISO 27001 at the article level.
No signup · no instance access · pick your release and get an instant CVE verdict.
Detection engine is open source — github.com/nowisor/instance-scan-pack · Apache-2.0
Misconfigured ACLs, exposed endpoints, and sys_properties that create exploitation paths invisible to standard reviews.
NIS2, DORA, and ISO 27001 require instance-specific technical evidence — not generic policy documents.
Every integration, MID Server, and OAuth token is a potential lateral movement path.
After ten years as Principal Security Advisor in ServiceNow's Office of the CISO, I saw every enterprise hit the same blind spots. Nowisor — a virtual subject-matter expert (SME) for ServiceNow security — makes that expertise accessible on demand.
Describe your concern in plain language — ACL gaps, integration risks, compliance requirements, attack paths.
Receive attack chains, detection scripts, and compliance mappings specific to your ServiceNow configuration.
Deploy scripts, close gaps, and generate auditor-ready compliance evidence.
Bring in a senior practitioner. Your full session context transfers automatically.
ServiceNow's Shared Responsibility Model draws the line: ServiceNow secures the platform, and you are responsible for how your instance is configured, who can reach what, and proving it to a regulator. Nowisor works entirely on your side of that line.
When you connect an instance, Nowisor reads your Security Center hardening score and the settings behind it, and treats them as the authoritative platform baseline. It does not recompute what ServiceNow already scores.
The detection engine installs as a scoped application and runs as a suite scan in ServiceNow's own Instance Scan framework. Findings land in your instance and remain there whether or not you ever connect the advisor.
A settings-comparison framework cannot read the syntax of your custom Script Includes, Business Rules, and UI Actions, and it has no concept of an out-of-the-box ACL that was edited last night. Those two gaps are structural — they are where the detection engine's static analysis and drift checks sit.
When ServiceNow sets a platform deadline — the Basic Auth API restriction (KB3025707 / KB3055080) is the current one — the pack ships readiness checks, so you can evidence where you stand before enforcement rather than after it.
Nowisor is built and run for organisations that answer to NIS2, DORA, and GDPR. Where your data lives, where it is processed, and who controls the stack are design decisions — not afterthoughts.
Accounts, scan snapshots, and your ServiceNow configuration values are stored and scanned on EU infrastructure in Amsterdam. AI answer-generation uses a US provider by default; on Connected and above you can keep that in the EU too — see below.
On Connected and above, AI analysis runs on Claude served from EU data centres in Frankfurt, through an EU-hosted gateway governed by a signed GDPR Article 28 DPA. The gateway endpoint and the region-pinned model are what keep processing in the EEA — that part is enforced in code. Prompt and output logging is switched off on our gateway account, so under that DPA no copy is kept there. The model behind it is served by AWS Bedrock in Frankfurt under its own terms, which makes this EU-resident processing with no gateway-side logging rather than end-to-end zero retention. Retention and model-training terms come from that DPA rather than from a setting in this product.
When EU processing is selected, the system fails closed: if the EU route is ever unavailable, the request is refused — never quietly rerouted to a US endpoint. Jurisdiction is enforced in code, not just in a policy document.
The detection engine is open source under Apache-2.0, and the AI backend is swappable by design. You keep European control over the stack — inspect it, fork it, run the detection yourself without depending on nowisor.com at all.
Every property name, table reference, and detection script is verified against a release-pinned ServiceNow instance, not generated from training data. Current pin and verification methodology are on the trust page. If a configuration claim cannot be proven on a live instance, Nowisor does not ship it.
ServiceNow’s own security tooling scores your configuration against ServiceNow’s checklists. Nowisor audits the same substrate independently and frames it as cross-domain attack chains — empty ACLs combined with scoped-app cross-scope grants and AI agent role-mask gaps, not isolated checklist items. Independence is the point: a platform vendor’s own dashboard is a weak audit artifact when a regulator asks who verified it.
Findings are framed as attack paths an adversary would actually exploit, not as generic policy violations. Cross-scope privilege records, AI agent role-mask gaps, fabricated property recommendations from older guides — Nowisor surfaces what matters to an attacker.
Every finding maps to specific framework articles — NIS2 Article 21 sub-points, DORA Article 9, ISO 27001 Annex A controls. Coverage scope is declared honestly: comprehensive where it is, partial where it is, never overclaimed.
Every finding includes the exact ServiceNow Background Script that produced it. Copy, paste, run on your own instance — no black box, no vendor dependency. The methodology is the deliverable as much as the findings.
Reports include verified configuration values, framework citations, and verification scripts — auditable artifacts your assessor or regulator can validate independently. Built for the moment a CISO has to defend a finding under questioning.
Findings tell you what is misconfigured; log-export correlation tells you which misconfigurations are actually being exercised. A sustained brute-force against an unprotected admin endpoint is not the same risk class as a dormant un-audited table. The Active Risk Report correlates each finding against 7 days of runtime activity (sys_audit, sysevent, syslog_transaction) and marks every verdict EXERCISED, DORMANT, NOISE, or INVESTIGATE — qualified by log-export coverage at every step.
nowisor is built by Rachid Harrando — author of Securing ServiceNow, former Principal Security Advisor at ServiceNow's Office of the CISO, co-founder and Review Board member of Black Hat Arsenal. Twenty-five years in security — ten of them inside that office — encoded into a system that refuses to ship anything it cannot prove against a live ServiceNow instance.
The verification methodology is public: every property reference is checked against a version-pinned ServiceNow schema dump (Zurich Patch 6, 3,585 properties, captured and archived). Every detection script is tested against a live PDI before it ships. Every finding cites its evidence.
The detection engine is open source under Apache-2.0 at github.com/nowisor/instance-scan-pack. Every check the advisor reads from your instance was produced by code you can inspect, fork, or run on your own without depending on nowisor.com at all. The advisor is the value-add; the detection is the floor — and the floor is yours.
Generated code is bound to a release-pinned catalog — 143 ServiceNow table schemas and 90 system properties, drawn from the full 3,585-property Zurich Patch 6 dump. Fabricated tables, fields, or API names are caught at the bind step, before any script is generated.
Every answer passes through nine automated detectors — uncited claims, unknown KB IDs, self-contradictions, prescriptions without diagnosis — before it reaches you.
Claims link back to specific knowledge-base articles with IDs validated post-response. If the source isn't there, the citation doesn't ship.
On Connected, your tenant's actual schema is extracted on connect so scripts target your customizations — not a generic template.
Fabricated property names and unsupported claims are stripped before display — not quietly flagged in a log you'll never read.
Every response carries a quality signature tracked in the admin console. Regressions are visible; drift is auditable.
Run a full security assessment in hours, not weeks. Pre-built attack paths and detection scripts across 15 domains.
Every engagement uses the same adversarial framework — repeatable, auditable, defensible.
Generate NIS2, DORA, and ISO 27001 evidence mapped to each client's configuration.
Access
Every plan finds real weaknesses in your ServiceNow configuration and spells out the chain an attacker would follow, mapped to NIS2, DORA and ISO 27001. Three plans run inside your own tenant. Connected watches a live instance and keeps checking. You pay per instance you defend, not per question you ask.
Free
Recon
Find out in an afternoon whether your instance has a problem worth escalating.
No credit card required
25 queries · nothing to connect
Solo
Practitioner
For the person who owns the tenant and gets the call when something is wrong with it.
Billed monthly · 14-day trial · cancel anytime
Runs in your tenant or from pasted output — no connection to your instance
Multi-client
Practice
For a practice whose reputation rides on the same answer being right at every client.
Billed monthly · 14-day trial · cancel anytime
Runs in your tenant or from pasted output — no connection to your instance
Live instance
Connected
For a production instance where "we think it is fine" is not an answer you can give.
Billed annually — €34,800 invoiced
1 connected instance · unlimited scans
When the answer has to hold up in front of a regulator, a named security SME carries it with you: multi-instance estates, regulated entities, and audit support, delivered as an annual retainer. Engagements from €90,000/yr.
Senior ServiceNow security consulting runs €1,500–€2,500/day. Per year, per instance.
| Obligation | Senior days | At day rate |
|---|---|---|
| Annual configuration and access review (NIS2 Art. 21, ISO 27001 A.8) | 5–15 | €7,500–€37,500 |
| Exposure assessment per ServiceNow CVE — several a year | 1–3 × 4–8 a year | €6,000–€60,000 |
| Audit evidence per reporting cycle (DORA Art. 9–10, ISO 27001) | 4–8 | €6,000–€20,000 |
| "Were we exploited?" answer after a disclosed flaw (NIS2 Art. 23 / DORA Art. 19) | 2–5 | €3,000–€12,500 |
| A year of obligations, done by hand | €22,500–€130,000 | |
Day rates and day counts from Nowisor engagement experience at published EU rates.
What goes away: The 5–15 consultant days an audit cycle takes off your calendar · The weeks of screenshot-collecting before every reporting deadline · The fire drill that starts the morning a ServiceNow CVE lands
All plans include the open-source detection engine. Monthly plans switch or cancel anytime. EU data hosting · EU-only AI processing (Connected and above) · DPA available.
No credit card.
Start free — 25 queries