Security operations teams using ServiceNow for incident management often have to leave that workflow to investigate data loss prevention (DLP) alerts in a separate platform. This integration brings Cyberhaven DLP incidents directly into ServiceNow's DLP Incident Response (DLP-IR) module, so analysts can triage, assign, and resolve DLP incidents in the same workspace they already use for every other incident type.
When a Cyberhaven incident is created or updated, it appears in ServiceNow with the context, analysts need to make a decision: an AI-generated summary and severity assessment, and deep links to the underlying incident detail, event lineage, and user risk profile in Cyberhaven — with data evidence reachable from there as well. Analysts no longer have to context-switch to investigate every incident — only when they need deeper detail. Optional reverse sync keeps Cyberhaven current with resolution decisions made in ServiceNow — status, assignment, close reason, and close notes — so both platforms reflect the same state without manual double-entry.
The integration is built as a standard ServiceNow scoped application, with a guided setup wizard, admin-facing observability and diagnostics, and standard credential handling — designed to fit into existing ServiceNow operational practices rather than introduce a new one.
- Automatic incident ingestion — Cyberhaven DLP incidents flow into ServiceNow DLP-IR without manual entry
- Full context, no app-switching — AI-generated incident summaries, severity, and event links are visible directly on the ServiceNow record
- One-click navigation to Cyberhaven — Deep links to incident detail, event lineage, and user risk profile, with data evidence accessible from there
- Optional reverse sync — Keep Cyberhaven's incident status current with resolution work done in ServiceNow
- Built-in loop prevention — Sync logic prevents update loops between the two platforms
- Guided setup — A configuration wizard handles authentication and connection setup between both platforms
- Admin visibility — An observability page surfaces delivery health, sync failures, token validation and integration alerts
Initial release
- Bidirectional: A two-way integration between Cyberhaven DLP and ServiceNow DLP Incident Response (DLP-IR).
- DLP incident ingestion and updates: Cyberhaven incidents are automatically created and updated in DLP Incidents (sn_dlir_incident) and Cyberhaven DLP Incidents (x_cybe9_ch_dlp_cyberhaven_incident_detail) as they occur, with full field mapping including AI-generated summaries and severity. DLP Incidents holds the key details, while Cyberhaven DLP Incidents holds the additional Cyberhaven-specific fields — and is accessible directly from the DLP Incident record.
- Navigation to Cyberhaven: Deep links from each ServiceNow DLP incident to the corresponding Cyberhaven incident detail, event lineage, and user risk profile.
- Logging and Alerting: Integration activity written to Application Logs; persistent ITSM Alert Incidents raised, deduplicated, and auto-resolved for operational failures.
- Optional reverse sync: status changes, analyst assignment, close reason, and close notes made in ServiceNow are reflected back to Cyberhaven.
- Guided setup: A setup wizard for connecting the two platforms, including inbound authentication and reverse sync configuration.
- Observability dashboard: Admin page showing delivery health, alerting, token validation, and sync status.
Dependent plugin required: Data Loss Prevention Incident Response