Why Excel and email reach their limits in information security and compliance
The requirements for information security, risk management and compliance are continuously increasing. With NIS2, DORA, the EU AI Act and other regulatory requirements, organizations must not only establish technical security measures, but also reliably manage processes, responsibilities and evidence.
Especially in critical and regulated organizations, it is therefore no longer sufficient to manage information and measures across individual Excel files, emails or isolated tools. What matters is making the connections visible: Which systems and processes are affected? What risks exist? Which measures have been defined – and are they actually effective? An integrated platform provides a common data and process foundation for this.
Information security is more than a technical task
Protecting critical infrastructure and sensitive areas of an organization does not begin with the technical protection of systems. People, organization and technology need to work together. Responsibilities must be clearly defined, information must be transparently available, and security-related tasks must be managed in a traceable way. At the same time, regulatory requirements need to be integrated into existing business processes and their implementation continuously monitored.
This is exactly where traditional approaches based on Excel spreadsheets, email distribution lists and disconnected individual solutions reach their limits. Information is stored in different locations, responsibilities are not always clearly defined, and changes can only be tracked with considerable manual effort. The result: valuable time is spent on coordination and documentation, while the actual value – identifying risks at an early stage and reducing them effectively – takes a back seat.
One platform for integrated processes
As its technological foundation, iTSM Group relies on ServiceNow. The Now Platform enables cross-functional processes, services and information to be mapped in digital workflows, connected and automated. What started as an IT service management platform can now be used far beyond traditional IT processes. In addition to IT workflows, processes from HR, customer service, legal and other business areas can be mapped on a shared platform. This creates a central foundation where information no longer needs to be viewed in isolation. Instead, processes, responsibilities, risks and measures can be connected.
Identifying risks and managing measures
Integrated risk management creates transparency around risks and their impact on the organization. Risks can be linked to the affected processes, services, applications and responsibilities. Measures can be derived directly from identified risks, assigned to responsible owners, and tracked in terms of both implementation and effectiveness. Regulatory requirements can also be integrated into these processes. This makes it possible, for example, to track which requirements exist, which measures result from them and where further action is needed.
With ServiceNow GRC, Integrated Risk Management and Security Operations, information security, risk management and compliance can be addressed holistically. Requirements arising from NIS2 or the EU AI Act can also be integrated into corresponding governance and compliance processes. This not only creates greater transparency for those responsible. Audits and assessments can also be supported more efficiently through traceable documentation of requirements, measures and responsibilities.
Processes instead of individual solutions
Risks rarely arise in isolation. They are connected to business processes, IT services, applications, infrastructure and organizational responsibilities. An integrated process landscape makes these dependencies visible. For example, it can be determined how the failure of an IT system would affect a critical business process and which measures are planned to reduce the risk or maintain operations.
Business continuity management and risk management also work hand in hand. Risks are not considered in isolation, but evaluated and managed in the context of actual business operations. This transforms a collection of individual security and compliance measures into a holistic process.
Making AI manageable: Governance for the use of artificial intelligence
The use of artificial intelligence is creating a new class of assets in many organizations – AI agents, language models, copilots, prompts and datasets. They are often introduced in a decentralized manner, sometimes without coordination with IT, information security or compliance. This raises the same questions as with any other critical component of enterprise IT: What is being used? Who is responsible? What data is being processed? And which regulatory requirements apply?
The EU AI Act further intensifies these questions. Providers and operators of AI systems need to classify use cases, assess risks, document measures and demonstrate their effectiveness. Managing this through Excel lists or distributed documentation reaches its limits even faster than with traditional compliance topics – simply because the AI landscape within an organization is constantly changing.
With the AI Control Tower, ServiceNow provides a centralized governance layer within the platform. AI assets can be identified and managed in a shared inventory – including ServiceNow capabilities such as Now Assist as well as models and agents from third-party providers or cloud and hyperscaler environments. By connecting with the CMDB, these assets can be linked to the affected services, processes and responsibilities. Governance workflows and compliance gates can also be mapped, including requirements related to the EU AI Act and the NIST AI Risk Management Framework.
The key point from the perspective of regulated organizations: AI governance does not remain a separate topic alongside information security, risk management and compliance. Instead, it becomes part of the same process landscape. Risks arising from AI use cases can be assessed like other risks, linked to measures, and documented transparently for audit purposes.
Digitalization step by step
Such a transformation does not have to happen all at once. On the contrary, a step-by-step approach is particularly advisable for complex organizations. Clearly defined use cases make it possible to achieve initial results quickly, gain experience and continuously develop the solution. At the same time, employees can be involved in the new digital ways of working at an early stage. It is important not to focus solely on technology. Successful digitalization takes processes, roles and responsibilities into account equally. A platform can only realize its full potential if it supports the organization's actual way of working rather than simply digitizing existing processes.
Digital sovereignty as part of the security strategy
For organizations with particularly high security and compliance requirements, the question of where and under what conditions a platform is operated is becoming increasingly relevant. Depending on individual requirements, factors such as data location, security standards, regulatory requirements and operational sovereignty can all play an important role. This makes the choice of operating model an important component of a holistic security strategy – alongside integrated processes and modern technology.
From a security project to an integrated business process
The digitalization of information security and compliance should not be viewed as an isolated IT project. Rather, it is part of a holistic digital transformation. When people, processes and technologies are brought together on a shared platform, new opportunities emerge: information becomes more transparent, responsibilities more traceable, and workflows can be automated in a targeted manner. This transforms information security from an isolated specialist topic into an integrated part of everyday business processes. And that is precisely the decisive step away from Excel silos and email distribution lists: it is not individual tasks that are being digitized, but the relationships between them that become visible and manageable.
