
Understand the modern cyber threat landscape, challenges faced by SOCs, and how AI and automation revolutionize incident response.
Learn what SIR is, its role in the ServiceNow SecOps suite, and its core capabilities. Includes demo on Installing SIR Plugins.
Explore the strengths of AI in data analysis, pattern recognition, and response automation — and recognize its limitations.
Navigate the SIR workspace, dashboards, and analyst tools. Includes demo on Exploring the SIR Workspace.
Compare NIST Stateful and SANS Open process models and select the most appropriate for your organization. Includes demo on SIR Process Selection.
See how Now Assist and AI enhance compliance and streamline response workflows through insights and recommendations.
Understand how to manually or automatically create incidents, and learn the Major Security Incident Management (MSIM) process. Includes Major Security Incident Management demo.
Learn how users report phishing attempts using the Service Catalog. Includes demo on Use the SIR Catalog to Report a Phishing Email.
Explore how Now Assist generates instant summaries and recommendations during triage to accelerate analysis.
Understand threat intelligence concepts (IoCs, enrichment) and learn how to Manage the MITRE ATT&CK Framework in SIR.
Learn how to connect SIR with SIEMs, EDRs, and intel tools. Includes demo: Explore Integration Capabilities.
Explore IntegrationHub and REST APIs to build AI-driven custom integrations and enrich incident context automatically.
Configure calculator groups to align risk and criticality with business needs. Includes demo: SIR Calculator Groups.
Learn to define and apply security tags and automated tag rules for incident classification. Includes Define SIR Security Tags and Rules demo.
See how AI and Now Assist predict severity, urgency, and next steps to support faster escalation and better prioritization.
Automate security workflows using Flow Designer and IntegrationHub. Includes examples like phishing containment.
Automate security workflows using Flow Designer and IntegrationHub. Includes examples like phishing containment.
Apply machine learning to suggest new automations and align playbooks with evolving threats.
Learn how to perform PIRs, capture lessons learned, and configure surveys and assignment rules. Includes demo.
Gather post-incident feedback from users and analysts, analyze results using dashboards and Performance Analytics.
Use Now Assist to auto-generate incident summaries and RCA documentation for post-incident learning.
Use Now Assist to auto-generate incident summaries and RCA documentation for post-incident learning.
Use AI to prioritize vulnerabilities, simulate attack paths, and reduce exposure proactively.
Learn to implement continuous monitoring and adaptive AI-driven threat prevention.
Identify ethical, privacy, and accuracy challenges in AI-driven security operations.
Map AI-based workflows to frameworks like NIST, ISO 27001, and GDPR.
Explore how predictive, autonomous SOCs will reshape the analyst role and organizational resilience.
In today’s security landscape, SOC teams face an overwhelming volume of alerts, evolving threats, and increasing pressure to respond faster and more accurately than ever before. Traditional, manual incident handling models can no longer keep up — which is why AI-driven security and workflow automation have become essential.
This comprehensive course teaches you how to build modern, intelligent, and automated Security Incident Response capabilities using ServiceNow SecOps, Now Assist AI, and industry-leading frameworks such as MITRE ATT&CK and NIST.
Through real-world examples, hands-on demos, and clear step-by-step guidance, you’ll learn how to configure ServiceNow SIR from the ground up: creating incidents, designing process models, mapping attack techniques, configuring calculator groups, building automated playbooks, and integrating Now Assist to accelerate triage and response.
You’ll also discover how AI enhances security operations — from anomaly detection and incident summarization to automated recommendations, prioritization, and predictive threat modeling. By the end of the course, you will have built a complete AI-enhanced incident response framework that aligns with business risk, drives SOC efficiency, and supports continuous improvement.
Whether you’re a SOC analyst, security engineer, ServiceNow administrator, or an IT professional looking to break into security automation, this course equips you with the skills to confidently design, operate, and improve AI-powered incident response workflows.
Join me and learn how to transform your SOC into a proactive, adaptive, and intelligent security operation.