Recent-Post

LightBlog
LightBlog

Build vs Buy: Why ServiceNow Bought Armis Instead of Building Exposure Management

Executive Intelligence · Build vs Buy Series | September 27, 2026

ServiceNow’s security business was already winning — $1 billion in ACV crossed in Q3 2025, and a record OT quarter the same year. Most companies would read that as permission to keep building. ServiceNow read it as permission to buy.


Build vs Buy: Why ServiceNow Bought Armis Instead of Building Exposure Management


The Thesis

ServiceNow agreed in December 2025 to pay $7.75 billion in cash for Armis, a cyber exposure management company most of its own customers had never had to think about twice. The deal closed roughly four months later, on top of roughly $1 billion for identity-security startup Veza in the same year. Two acquisitions in under a year, on top of a security business already growing organically, is a useful test of when “good momentum” still isn’t a reason to keep building.

The build case was real. ServiceNow owns a configuration management database that most enterprises treat as their asset system of record — arguably the best internal starting point any company could have. What it did not have was a decade of device-classification data. That distinction is what made the decision.

1. The Strategic Problem

GAP

ServiceNow’s platform is built to route work — detect an issue, assign it, track it, resolve it. But a workflow engine is only as good as what feeds it. The AI Control Tower and Context Engine can prioritize and automate a response to a cyber risk, but only for assets the platform actually knows exist.

Armis’s entire product exists to solve that visibility problem: agentless discovery across IT, OT, IoT, and medical devices — the unmanaged, often-invisible assets conventional security tools were never built to see. ServiceNow didn’t have a workflow gap. It had a signal gap. Its own Context Engine was only ever going to be as smart as the asset data flowing into it.

The CODEW Lens: A workflow platform can only be as intelligent as its inputs. ServiceNow did not lack orchestration capability — it lacked the raw signal the orchestration depended on.

2. The Build Case

BUILD

On paper, ServiceNow had the best possible starting point for building its own exposure-management layer. It already owns a configuration management database (CMDB) that most enterprises treat as their asset system of record — arguably the single strongest internal foundation any company could have. It also had real organic momentum: crossing $1 billion in ACV for security and risk is not a business struggling to grow on its own.

The build case rests on that CMDB foundation being extended with agentless discovery and OT/IoT-specific sensing — categories ServiceNow’s platform engineering team could plausibly have tackled over a multi-year roadmap. What building couldn’t replicate quickly is a decade of device-fingerprinting data. Armis, founded in 2015, has spent ten years building the specific classification models needed to identify unmanaged devices — medical infusion pumps, industrial controllers, IoT sensors — that don’t announce themselves the way a laptop or server does.

That’s not a workflow problem a sprint can solve. It’s a data problem that only gets solved by seeing enough devices, over enough years, across enough customer environments.

What It Means: Workflow layers can be built. Data moats cannot be rebuilt from scratch on a reasonable timeline. The build case was strong on architecture and weak on accumulated signal.

The CODEW Lens: This is the test the framework from my recent Buid vs Buy article, which  is designed to surface — separating capabilities a company can plausibly build from capabilities only years of field data can produce.

3. Why Partnership Wasn’t Enough

PARTNER

A partnership or resale arrangement was the lighter option, and ServiceNow already runs plenty of those. The Armis announcement itself came alongside a three-way arrangement with Fortinet, extending exposure data into network-security enforcement without ServiceNow needing to own Fortinet’s technology. That’s what partnership looks like when it works: Fortinet’s enforcement layer feeds ServiceNow’s Context Engine, and neither company had to acquire the other.

But a reseller or data-sharing relationship with Armis itself would have left ServiceNow dependent on a company that could just as easily have struck the same deal with a competitor — or been acquired by one. Palo Alto Networks, CrowdStrike, and Microsoft are all active consolidators in adjacent security categories.

For a capability ServiceNow wanted to make foundational to its entire security platform rather than one integration among several, partnership left too much of the roadmap outside its control.

What It Means: Partnership works for modular layers where a competitor having the same access doesn’t matter. It fails when the capability is meant to be foundational and exclusivity is the point.

The CODEW Lens: The Fortinet deal is partnership done right. The Armis situation was partnership done at the wrong layer — which is why the same company used both approaches in the same announcement.

4. The Acquisition Case

ACQUIRE

ServiceNow paid $7.75 billion in cash — funded through cash on hand and debt — for a company with roughly $340 million in annual recurring revenue and about 950 employees. That’s an implied multiple of about 23x ARR, a price that only makes sense if the acquisition is valued as a platform foundation, not a revenue line.

Executives were explicit about the logic. Combining Armis’s real-time asset visibility with the identity intelligence from the earlier Veza deal lets exposure data flow directly into the Context Engine and AI Control Tower, turning detection into automated remediation with governance and an audit trail built in at every step. ServiceNow said the deal would more than triple its addressable market for security and risk products.

The acquisition wasn’t sized to match Armis’s current revenue — it was sized to match how central exposure data becomes to every other product ServiceNow sells once it’s fully embedded.

What It Means: The price is a bet on platform centrality, not on Armis’s standalone financials. The market-tripling claim is the real justification — and the real thing to measure against.

The CODEW Lens: A ~23x ARR multiple is defensible when the asset becomes an input to everything else. It is indefensible when the asset stays one product among many.

5. Cost & Complexity

COST

The deal was announced in December 2025 and closed roughly four months later — fast for a $7.75 billion transaction, and notably quicker than the year-long regulatory review Google’s Wiz deal required. Likely because exposure management is a narrower, less horizontally dominant category than cloud security.

The harder cost is integration, not approval. Folding a 950-person, decade-old company’s device-classification technology into ServiceNow’s CMDB and Context Engine without breaking either system is real engineering work — on top of the roughly $8.75 billion ServiceNow has now committed across the Veza and Armis deals in under a year.

That’s a company betting a meaningful chunk of its balance sheet that two acquisitions integrate faster and better than a multi-year internal build would have. The bet only pays off if the combined platform genuinely ships the “see, decide, and act” loop ServiceNow is promising — not just two separate products under one sales team.

Metric Value
Deal value (all-cash) $7.75 billion
Armis annual recurring revenue (at announcement) $340 million+
Implied revenue multiple ~23x ARR
Armis employees joining ServiceNow ~950
Armis founded 2015
ServiceNow security & risk ACV (Q3 2025) $1 billion+
Prior deal: Veza (identity security, 2025) ~$1 billion
Combined Veza + Armis spend (under 12 months) ~$8.75 billion
Time from announcement to close ~4 months

The CODEW Lens: Fast regulatory clearance is not fast integration. The four-month close is the easy part — combining two acquisitions into one coherent platform surface is the part that takes years.

6. Strategic Trade-Offs

THE FRAMEWORK

The four options ServiceNow weighed map cleanly against the CODEW decision framework from Article #2 of the series.

Factor Build Buy Partner Acquire
Speed Low High High Medium
Control High Low Low High
Upfront cost Medium (CMDB head start) Low Low Very high
Data/classification depth Low (starting from zero) Medium Medium High
Platform integration depth High Medium Medium High
Talent access Low Low Low High (~950 engineers)
Roadmap control High Low Low (vendor can defect) High

What It Means: No option dominates. Build won on integration depth and control. Partner won on speed and cost. Acquire won on data depth, talent, and long-term roadmap control. The decision hinged on which of those factors was the actual constraint.

7. Strategic Priorities

WHAT TO TAKE AWAY
  • Separate the workflow layer from the data layer before deciding to build. ServiceNow’s CMDB gave it a real head start on workflow, but Armis’s decade of device-classification data was a different asset entirely — one organic growth in the workflow layer couldn’t shortcut.
  • Existing momentum isn’t proof that building the next layer will work. A $1 billion ACV security business crossing that milestone organically was still judged insufficient reason to skip acquiring the visibility layer feeding it.
  • Watch multiple acquisitions in one category as a sequencing signal. Veza (identity) then Armis (assets) in under a year reads as a deliberate two-piece platform build, not opportunistic dealmaking — worth mapping before assuming the next move is random.
  • Price the acquisition against future platform value, not current revenue. A ~23x ARR multiple only makes sense if the asset becomes foundational to products well beyond its own category. The market-tripling claim is the real justification, not Armis’s standalone financials.
  • Fast regulatory clearance doesn’t mean fast integration. The deal closed in about four months. Folding two acquisitions’ worth of new technology into one coherent “see, decide, act” platform is the part that takes longer and is harder to verify from outside.

8. Build vs Buy vs Acquire: The CODEW Verdict

THE VERDICT

Build when the missing piece is workflow, not data. ServiceNow’s CMDB meant it never needed to acquire its way into asset workflow orchestration — that part it could, and did, build. The build case fails specifically where deep, years-accumulated classification data is the product, not where a company merely lacks a feature.

Buy when the capability is genuinely modular and a competitor having the same access doesn’t erode your position. The Fortinet arrangement is exactly that — network enforcement data flowing in without ServiceNow needing to own Fortinet, because that layer isn’t what makes ServiceNow’s platform distinctive.

Acquire when the target’s data moat is what makes your own platform’s core promise credible. ServiceNow’s entire pitch — detect, prioritize, remediate, automatically — was only as good as the asset visibility feeding it. Armis wasn’t a bolt-on feature. It was the input the rest of the platform’s value depended on, and that’s worth a premium multiple to own outright.

The CODEW Lens: This is the Acquire case in the Build vs Buy framework — the option that buys control outright when a platform’s credibility depends on a capability the market won’t let you rent.

9. What to Watch Next

SIGNAL

Three things will tell you whether the Armis bet is paying off — and whether the acquisition pattern continues.

Signal What It Would Tell You
A third security acquisition within twelve months Two deals in one category in under a year is a pattern. Three would confirm it as a deliberate platform-consolidation strategy rather than opportunistic purchases.
CMDB and Armis data shipping as one product surface The integration claim is the whole thesis. If customers still buy and deploy them separately eighteen months from now, the “see, decide, act” loop was marketing, not architecture.
A competitor moving on remaining independent exposure-management vendors If Palo Alto Networks, CrowdStrike, or Microsoft acquire the next Armis before ServiceNow can consolidate further, the moat narrows faster than the $7.75 billion price implies.

Continue the Build vs Buy Series

SERIES

This case study applies the framework developed across the Build vs Buy series. Related reading:

Role Article
Understand Build vs Buy: What Is the Right Technology Strategy?
Decide Build vs Buy Decision Framework: A Practical Guide
Build When Should a Company Build Its Own Technology?
Apply to AI Build vs Buy AI: Should Companies Build Their Own AI Systems?
See It in Practice Microsoft Build vs Buy
Case Study ServiceNow × Armis: Why ServiceNow Bought Instead of Built (this article)

The CODEW Lens: The ServiceNow case is the Acquire branch of the framework — the option that buys control outright when the platform’s credibility depends on a capability the market won’t let you rent.

Source Attribution

  1. ServiceNow Newsroom, “ServiceNow to acquire Armis to expand cyber exposure and security across the full attack surface.”
  2. ServiceNow Investor Relations, deal terms and financing disclosure.
  3. ITPro, “ServiceNow wraps up $7.75 billion Armis acquisition.”
  4. Yahoo Finance, “ServiceNow completes Armis acquisition, closing the gap between asset visibility and cyber risk.”
  5. Help Net Security, “ServiceNow to acquire Armis for $7.75 billion.”
  6. SC World, “ServiceNow makes $7.75B bet on Armis for AI security.”
  7. Stocktwits / Markets, “ServiceNow Acquires Armis In $7.75 Billion Deal To Strengthen AI-Powered Security Platform.”

The CODEW Stat

$7.75B · ~23x ARR · 950 employees · 4-month close ServiceNow paid $7.75 billion in cash — roughly 23x Armis’s $340 million ARR — for a company most of its own customers had never had to think about twice. The deal closed in four months, on top of roughly $1 billion for Veza in the same year, totaling ~$8.75 billion committed to security acquisitions in under twelve months. The price only makes sense if exposure data becomes foundational to every other product ServiceNow sells. The bet is on platform centrality, not on Armis’s standalone financials.

THE CODEW · BUILD VS BUY

Editorial Note

Build vs Buy is The CODEW’s decision-intelligence series examining how companies choose between building technology internally, buying it from a vendor, acquiring the company that built it, or partnering for ecosystem access — and what those decisions reveal about competitive strategy. This case study applies the framework to ServiceNow’s acquisition of Armis: a company that was already winning in security chose to buy the visibility layer its platform’s core promise depended on.

Deal values, timelines, and financial figures cited in this piece are drawn from public disclosures, SEC and investor filings, and reporting current as of publication, and should be read in the context of the cited sources and reporting period. Educational content only. Not investment or business advice. Some products referenced may be affiliate partners — see our Affiliate Disclosure for full details.

Build vs Buy: Why ServiceNow Bought Armis Instead of Building Exposure Management Build vs Buy: Why ServiceNow Bought Armis Instead of Building Exposure Management Reviewed by Erwin Castro on Sunday, September 27, 2026 Rating: 5

No comments:

LightBlog