ServiceNow Pivots to Cybersecurity and Consumption Models Amid AI Disruption
Share
ServiceNow is fundamentally restructuring its business model to counter the disruption caused by artificial intelligence (AI) in the IT service management (ITSM) sector. The company is transitioning away from traditional seat-based subscriptions in favour of consumption-based pricing and an expanded focus on cybersecurity.
This strategic shift follows a period of market volatility. Despite strong revenue growth and record share prices in previous years, the emergence of AI agents and “vibe-coding” tools—which allow users to generate software solutions through natural language—has created anxiety regarding the future of the Software-as-a-Service (SaaS) model. The perception is that as AI automates complex workflows, the need for large numbers of human software “seats” may diminish.
The Shift from Seat-Based Subscriptions
The financial impact of this shift is already visible. During the company’s June 2026 Financial Analyst Day, it was confirmed that only 50% of ServiceNow’s Net New Annual Contract Value in 2025 was derived from seat-based subscriptions. Instead, revenue growth is increasingly driven by consumed services, including infrastructure, integrations, connectors, AI token consumption, and cybersecurity.
Industry analysts suggest that while the “SaaS apocalypse” may be exaggerated, the convergence of AIOps (Artificial Intelligence for IT Operations) and cybersecurity is inevitable. ServiceNow is positioning itself to lead this convergence by integrating AI directly into its workflow automation processes.
Strengthening the Asset Graph via Armis
A central component of this pivot is the $7.75 billion acquisition of Armis. Unlike previous acquisitions focused on specific security niches, the Armis agentless platform provides a comprehensive inventory of a company’s digital estate, including workstations, routers, firewalls, and the often-overlooked long tail of Internet of Things (IoT) and medical devices.
This acquisition aims to solve a chronic issue in ITSM: the inaccuracy of Configuration Management Databases (CMDB). Traditional workflows often rely on CMDBs that do not reflect the actual state of the network. By integrating Armis, ServiceNow can supercharge its automated workflows with accurate, real-time data, allowing the platform to not only identify assets but also orchestrate actions such as the isolation and blocking of compromised devices.
The move also changes the company’s customer profile. By expanding its visibility into critical infrastructure like hospitals and utilities, ServiceNow is engaging a new type of buyer: the Chief Information Security Officer (CISO).
New Risks in Consumption Pricing
While the move to consumption-based pricing offers flexibility, it introduces new financial complexities for enterprise customers. Analysts warn that while this model can be more efficient than paying for unused seats, it can also lead to unexpected costs if organisations do not closely monitor employee activity and AI token usage.
Furthermore, the loss of Armis’s previous neutrality—as it previously integrated with competing ITSM platforms—may alter the negotiating position for customers during contract renewals, as ServiceNow integrates these security capabilities more tightly into its core ecosystem.




Leave a Reply