“The organisations that succeed treat SecOps transformation as a business value journey, not just a technical project.”
About the Author

Abi Adesanya
Abi Adesanya, Wrangu’s Senior ServiceNow Security Specialist, is a Certified Master Architect with over 15 years’ experience driving successful SecOps implementations on the ServiceNow platform.
Executive Summary
Understanding the ServiceNow SecOps ecosystem is only the beginning. The critical next step is honestly assessing where your organisation stands in its security operations maturity and building a realistic roadmap for transformation. In my experience guiding organisations through this journey, I have learned one fundamental truth: technology never fails organisations, poor planning does.
The difference between transformational success and expensive disappointment comes down to three elements I have refined through experience: honest maturity assessment, strategic roadmapping, and architectural foundations that support growth. Organisations that achieve remarkable results follow a disciplined approach developed through trial and error. They resist the temptation to customise everything and instead leverage proven frameworks that scale with their evolving needs.
This is not just about implementing another security tool; it’s about building a security operations capability that adapts and grows with your organisation’s changing threat landscape and business requirements.
The SecOps Maturity Framework: Lessons from the Field
The Five Stages
Understanding organisational maturity is not about judging capability; it is about setting realistic expectations and planning implementation phases that build on each other while delivering increasing business value. Through my implementations, I have seen most organisations progress through five distinct stages, and trying to skip levels typically leads to both technical failure and missed business value opportunities.
Stage 0: Establishing Security Governance
Before any advanced tooling can deliver value, a clear governance backbone must exist. At this stage, the focus is on decision rights, ownership, and standards that guide how security work gets done. In practice, that means:
- Risk and risk appetite: Agree on how the business defines risk, what levels are acceptable, and who can accept residual risk. Make this explicit so analysts aren’t guessing in the middle of an incident.
- Framework alignment: Choose a lightweight, fit-for-purpose baseline (e.g. NIST CSF, CIS Controls, or ISO/IEC 27001) and translate it into analyst-friendly runbooks and SOPs rather than policy PDFs that no one reads.
- Prioritisation model: Map crown-jewel services, critical data classes, and privileged users so routing, escalation, and severity reflect business impact, not just technical severity.
- Roles and responsibilities: Define who owns what across security, IT, and cloud (service ownership, incident command, change approvals), and make escalation paths obvious.
- Foundational controls and hygiene: Establish minimum guardrails (identity, endpoint, logging, backup/restore) and treat CMDB/CSDM hygiene as a security control, not an admin task.
- Operating rhythm: Set up a cadence for reviews (runbook updates, tabletop exercises, blameless post-incident reviews) so the governance stays active and useful
Business Value: Creates the organisational and decision framework required to realize future ROI. While the direct financial impacts is indirect at this stage, the payoff is real: risk-aligned decisions, faster triage, cleaner escalations, predictable compliance, and a stable platform for scaling SecOps and automation.
Stage 1: Alert Aggregation
Organisations at this level focus on consolidating security alerts from multiple tools into a single interface. While this provides operational benefits by reducing tool-switching overhead, it does not address the fundamental problems of alert fatigue (multiple alerts that could have been easily merged into one single incident), inconsistent prioritisation (priority driven by each alert rather than by affected user or asset), or manual response processes.
I have seen many organisations get trapped here because they mistake alert aggregation for security orchestration. Aggregation puts all the alerts in one place; orchestration decides what to do with them. Aggregation is a cleaner inbox, so to speak. Orchestration enriches the signal with business context, correlates duplicates into a single incident, prioritises by the service and owner impacted, routes to the accountable team, and executes guarded actions (e.g. isolate, block, open change) from within the record. When teams stop at aggregation, they still rely on side-channel messages and manual steps. Queues may look tidy, but response remains slow and inconsistent.
It is also easy to fall into the trap of building more and more alerts, while trying to reduce the processing and storage requirements of the increasing incidents those alerts create. Without proper planning for advancement, these implementations deliver only marginal value while consuming significant resources to maintain. Furthermore, success metrics at this stage often focus more on consolidation than on efficiency improvements.
Characteristics of Stage 1:
- Basic alert ingestion from primary security tools
- Manual investigation and response processes
- Reporting-led workflows, mostly manual steps that live inside spreadsheet or Power BI dashboards, not in the response workflow
- Technical metrics focused on alert volume and response times
- Success measured by consolidation rather than business impact
Business Value at Stage 1:
- Time savings from reduced analyst tool-switching overhead
- Basic consolidation provides minimal cost savings through operational efficiency
- Limited visibility improvements for management reporting
- Foundation for future value realisation but minimal immediate business impact
Common Pitfalls: Organisations often become comfortable with basic alert aggregation and fail to advance to true orchestration capabilities that deliver significant business value.
Stage 2: Process Automation
In Stage 2, organisations begin automating repetitive security processes and standardising response workflows. Clear efficiency gains start to emerge, with less swivel-chair work, quicker handovers, and fewer missed steps. However, the posture remains largely reactive. Teams are still responding to what the tools raise rather than proactively hunting or correlating signals end-to-end.
Automation at this stage typically focuses on intake and triage (enrichment and assignment) and common playbooks for recurring scenarios. Yet the SOC remains heavily dependent on analyst judgement: people refer back to prior incidents, notes, or colleague memory when runbooks lack depth or clarity. The work is more consistent, but outcomes still depend heavily on expertise.
Characteristics of Stage 2:
- Automated alert enrichment with threat intelligence and asset context
- Standardised incident response playbooks for common threat types
- Basic integration with security and IT tools
- Automated task assignment based on incident characteristics
- Performance metrics tracking mean time to detect and respond
Business Value at Stage 2:
- Substantial improvements in incident response efficiency reduce operational costs
- Standardised processes improve consistency and reduce human error
- Better resource allocation through automated prioritisation
- Measurable improvements in security team productivity
- Initial risk reduction through faster, more consistent response times
Key Success Factor: At this stage, organisations see significant improvements in operational efficiency, with measurable ROI emerging soon after implementation.
Stage 3: Intelligent Orchestration (Run)
This stage represents the transformation to truly intelligent security operations. Organisations leverage machine learning, predictive analytics, and advanced automation to proactively identify and respond to sophisticated threats. In my implementations, they typically achieve substantial improvements in security effectiveness metrics while reducing analyst workload through intelligent automation.
Examples include alerts triggered by abnormal patterns in user traffic (spikes), event correlation that collectively reveals the beginnings of a cyber-attack, and playbook automation that provides immediate actions across all security solutions.
Characteristics of Stage 3:
- Predictive intelligence for automated incident classification and prioritisation
- Cross-functional workflow orchestration spanning security, IT, and business teams
- Advanced threat-hunting capabilities integrated with response workflows
- Real-time risk posture monitoring and automated remediation
- Business impact-based metrics and executive dashboards
Business Value at Stage 3:
- Proactive threat management reduces business-impacting incidents
- Intelligent automation enables security teams to focus on strategic initiatives
- Cross-functional orchestration improves business–security alignment
- Risk-based prioritisation optimises security investments
- Executive visibility enables data-driven security decisions
Transformation Indicator: Organisations at this stage shift from reactive response to proactive threat management, achieving dramatic improvements in business-relevant security effectiveness.

Stage 4: Adaptive Defence (Fly)
The most mature organisations I have worked with develop adaptive defence capabilities that learn from each security event to improve future responses. These organisations leverage artificial intelligence, continuous threat modelling, and predictive risk management to stay ahead of evolving threats.
The use of these solutions further enhances SOC capabilities. AI can easily summarise cases for analysts to act on quickly, machine learning has a greater ability to detect anomalies or correlate with previous incidents for faster responses, real-time information is readily gathered and shared across different levels of the organisation, intelligence from threat data drives efforts around emerging threat actors and their campaigns, and war rooms are swiftly deployed with the right people for time-sensitive decisions.
Characteristics of Stage 4:
- AI-driven threat prediction and proactive defence measures
- Continuous security process optimisation based on threat intelligence
- Advanced collaboration with external threat intelligence communities
- Integrated business continuity and disaster recovery orchestration
- Strategic security metrics aligned with business outcomes and competitive advantage
Business Value at Stage 4:
- Security operations become a competitive differentiator
- Predictive capabilities enable business risk management
- Strategic security initiatives support business growth and innovation
- Industry leadership in security operations excellence
Common Maturity Traps
1) The Technology-First Trap:
Organisations often focus exclusively on technical implementation without addressing underlying process and organisational issues. Through painful experience, I have learned that technology amplifies existing processes; good processes become excellent, delivering business value, but broken processes become faster failures that consume resources without producing results
My solution: Always conduct thorough process analysis before implementation. Document current incident response procedures, identify inefficiencies and inconsistencies, and redesign workflows to leverage automation capabilities before configuring the platform.
2) The Customisation Excess Trap:
ServiceNow’s flexibility can tempt organisations to over-customise, creating complex configurations that are difficult to maintain and upgrade. Excessive customisation also prevents teams from leveraging new platform capabilities as they are released.
My approach, based on experience: Follow the 80/20 rule religiously. Configure the platform to handle most use cases using out-of-the-box capabilities and carefully evaluate whether custom development provides sufficient business value to justify the ongoing maintenance cost.
3) The Pilot Purgatory Trap:
Some organisations become stuck in endless pilot phases, never progressing to full implementation because they cannot achieve perfect solutions for every edge case.
My solution: Define clear success criteria for pilot phases and set firm timelines for production deployment. Accept that initial implementations will not handle every possible scenario; plan for iterative improvement rather than perfection.
ServiceNow SecOps Implementation Roadmapping
Recommended Implementation Sequence Methodology
Based on the established ServiceNow implementation sequence methodology and practical experience, a phased approach builds capability incrementally and delivers measurable business value at each step. This methodology prevents overwhelming security teams while ensuring continuous progress towards advanced capabilities.
Foundation – Crawl Phase (Months 1–3): Building the Foundation
The initial phase focuses on establishing basic platform capabilities and integration with your most critical security tools. In my experience, the primary objectives include consolidating alerts from SIEM and EDR systems, implementing basic incident response workflows, and training core security personnel on platform operations.
Key deliverables include:
- Integration with primary security tools
- Basic incident response workflows for common alert types
- Initial user training and change management activities
- Baseline performance metrics collection
- Executive dashboards for security operations visibility
Success metrics for the crawl phase include measurable reductions in time spent switching between security tools and improvements in incident documentation consistency.
Walk Phase (Months 4–8): Process Standardisation
The walk phase expands integration scope and implements standardised response processes across all security operations activities. In my experience, this phase typically delivers the most significant efficiency improvements as manual processes evolve into automated workflows.
Advanced capabilities implemented include:
- Automated alert enrichment with threat intelligence feeds
- Standardised playbooks for major incident response scenarios
- Integration with vulnerability management and patch management systems
- Performance analytics and continuous improvement processes
- Cross-team collaboration workflows with IT operations
Walk phase success metrics include a substantial reduction in mean time to respond to security incidents and significant improvements in vulnerability remediation timelines.
Run Phase (Months 9–18): Intelligent Automation
This phase marks the shift from standardised, reactive playbooks to risk-aware, end-to-end orchestration. Related alerts are correlated into single incidents and normalised across SIEM, EDR/XDR, cloud, and VR. Prioritisation follows business impact using CSDM-aligned service ownership. Low-risk fixes execute automatically within the record, while higher-impact actions pause for approval with full context.
Threat Intelligence becomes critical at this stage, being fully ingested, normalised, and used for enrichment, sightings, and watchlists, while a hardened library of playbooks covers top use cases. Operational SLOs (time to confident first action, right-queue rate, remediation reliability) make progress visible and guide tuning.
Fly Phase (Months 18+): Adaptive Excellence
The focus becomes a proactive, learning SOC. Predictive and assistive workflows suggest classification, enrichment, and next steps, improving continually through analyst feedback. Threat Intelligence matures into modelling, campaign tracking, and TIP integration that informs prevention.
Teams conduct targeted hunts and feed exposure-reduction items into change management, with automation safeguarded by pre-checks, rollback paths, and planned change windows. A steady improvement cadence, council reviews, blameless post-incident learning, tabletop exercises, and rule hygiene keep noise low, while executive reporting frames results in service risk, impact avoided, and time returned to innovation.
Critical Success Factors
Executive Sponsorship That Goes Beyond Budget Approval Successful SecOps implementations require sustained executive commitment and clear alignment with business objectives. Through experience, I have learned that security leaders must articulate the business value proposition and maintain stakeholder engagement throughout the implementation journey. Well-funded projects fail when executives view them as “IT initiatives” rather than business transformations.
Cross-Functional Collaboration That Actually Functions SecOps success depends on effective collaboration between security, IT operations, business stakeholders, and external partners. Establish clear roles, responsibilities, and communication protocols before implementation begins. The most successful projects I have managed included dedicated collaboration time built into weekly schedules.
Change Management Excellence: Not Just Training, but Friction Reduction Technology implementation is often the most straightforward part of a SecOps transformation; the real challenge lies in changing established processes and ingrained user behaviours. True change management excellence goes beyond training – it is about actively reducing friction to make new workflows the path of least resistance.
Instead of simply teaching users a new process, invest in making that process demonstrably easier, faster, and more effective than the old way. By focusing on friction reduction, you shift from mandating compliance to driving organic adoption, as users naturally gravitate towards the more efficient workflow. Plan for resistance not just with communication, but with strategies that simplify the user experience and deliver immediate value.
Metrics That Drive Decisions, Not Just Reporting Establish baseline metrics before implementation and track progress consistently. Use data to drive continuous improvement decisions and demonstrate business value to stakeholders. The most successful organisations I work with review metrics weekly and adjust strategies monthly based on what they learn.
Building for Long-Term Success
With a clear understanding of your organisation’s maturity and a realistic roadmap for delivering business value, you are ready to tackle the technical challenges of integration. The organisations that succeed treat SecOps transformation as a business value journey, not just a technical project.
Coming Next: Connecting ServiceNow SecOps to Your Security Ecosystem
In Part 4, The Integration Imperative: Connecting SecOps with Your Security Ecosystem, we will explore the practical aspects of integrating ServiceNow SecOps with your security tools while maximising business value through intelligent orchestration.
Thanks to Ayner Perez for thoughtful review comments that helped shape this instalment.
About Wrangu
Wrangu’s SecOps implementation methodology has helped dozens of organizations successfully navigate the complexity of the ServiceNow security ecosystem while maximising business value. Our proven frameworks ensure that your SecOps applications work together as a unified platform rather than disconnected tools.