ServiceNow completed its acquisition of cyber-exposure specialist Armis for about $7.75 billion in cash on April 20, 2026. Fortune reported the closed transaction on April 23, 2026 alongside ServiceNow's first-quarter results. The purchase is the largest in the enterprise-software company's history and adds technology that continuously discovers devices, identifies their operational context and highlights security risk.

Armis was founded in Israel and built a platform for assets that conventional software inventories often miss. These include industrial controls, medical equipment, warehouse sensors and other connected devices that cannot always run a traditional security agent. ServiceNow intends to combine this visibility with its automated workflows so customers can move from discovering exposure to assigning and tracking a response.

A sunlit smart factory contains separate industrial medical and computing assets under subtle cyber-risk inspection light
Armis adds visibility across industrial, medical and connected equipment that may sit outside conventional software inventories.

The deal connects asset visibility with automated response

Large organisations may operate thousands of devices across offices, factories, hospitals and logistics sites. Security teams cannot protect an asset they do not know exists, yet the inventory changes whenever equipment is installed, moved, updated or connected by a supplier. Armis observes activity without requiring software on every device and builds a continuously updated picture of the environment.

ServiceNow's existing strength is workflow: recording an issue, sending it to the responsible team, enforcing approval steps and measuring resolution. Combining discovery with workflow can shorten the distance between a warning and an accountable action. A risky industrial controller, for example, can be matched with its owner, business importance and maintenance window before a remediation task is created.

Capabilities the buyer is adding

  • Continuous discovery of information-technology, operational and internet-connected assets.
  • Risk prioritisation based on device behaviour, vulnerabilities and business context.
  • Coverage for equipment that cannot accept a conventional endpoint-security agent.
  • A path from detection to assignment, approval, remediation and audit evidence.
  • Additional security data for governing automated systems and artificial-intelligence agents.

A record acquisition changes ServiceNow's capital profile

The price makes execution financially important. ServiceNow used a $4 billion term loan to fund part of the cash consideration, while the remainder drew on other liquidity. Management must now integrate products and sales without allowing financing costs or duplicated operations to overwhelm the expected growth. The company also needs to retain specialists whose knowledge supports the acquired platform.

The strategic wager is that cyber exposure becomes a natural extension of enterprise service management. Instead of selling another isolated security console, ServiceNow can offer one operating layer for asset records, incidents, risk decisions and corrective work. This could increase the number of products bought by existing customers, but only if the combined data is accurate and the workflow remains understandable.

Measures that will show whether the deal works

  1. Growth in security-related annual contract value and the number of joint customer deployments.
  2. Retention of Armis customers, engineers and channel partners after integration.
  3. Time required to discover an exposed asset and complete the appropriate response.
  4. Gross-margin and free-cash-flow effects after financing and integration costs.
  5. Evidence that customers consolidate tools rather than adding another layer of complexity.

Cybersecurity growth must justify concentration risk

ServiceNow is based in the United States and has been expanding beyond service-desk software into artificial intelligence, identity and security. That wider platform can make the company more important to customers, but it also raises the cost of mistakes. A shared system that coordinates many critical processes needs strong access controls, resilient data integration and clear separation of duties.

Armis brings a distinctive asset-discovery capability, not an automatic guarantee of lower cyber losses. Customers still need reliable ownership records, maintenance capacity and authority to interrupt risky equipment. In factories and hospitals, taking a device offline can affect production or care, so security recommendations must be balanced against operational consequences.

The acquisition therefore represents more than a revenue purchase. ServiceNow is betting that enterprises will pay for a unified view of assets, exposure and response as connected equipment and automated agents multiply. The return will depend on product integration, disciplined financing and measurable improvements in customer outcomes. If those elements align, the deal can turn security into a major growth pillar; if they do not, its record price will magnify the gap between strategic ambition and operational delivery.