Federal Agency: 8-Minute MTTR with ServiceNow SecOps + Automated SOAR Playbooks
A federal agency consolidated security operations across 12 departments on ServiceNow SecOps. Mean time to respond dropped to 8 minutes; FISMA evidence collection runs continuously.
May 9, 2026·2 min read·By admin
At a glance
Industry
Public Sector
Topics
SecOps / GRC · Servicenow
Published
May 2026
The challenge
A federal agency operating across 12 department-level sub-units faced two related pressures: increasing sophistication of threat activity targeting the agency, and tightening FISMA / continuous-monitoring requirements that the legacy SOC could not satisfy without doubling staff.
The CIO’s mandate: modernize security operations on a FedRAMP-aligned platform, automate the top alert patterns, and produce continuous compliance evidence — without expanding headcount.
The Mergen approach
Mergen designed and deployed ServiceNow SecOps across the agency, federated by department but unified at the platform level. The first 90 days focused on the top 20 alert categories representing 73% of historical volume — each got a SOAR playbook for triage, enrichment, and where appropriate, automated remediation.
What we built
SOAR playbooks for the top 20 alert categories — phishing, suspicious login, lateral-movement signal, endpoint compromise, etc.
Continuous controls monitoring against NIST 800-53 — automated evidence collection from 240+ controls
Executive dashboards with real-time security posture per department
Identity-graph integration with PIV/CAC for authenticated workflow approvals
The outcomes
Mean time to respond: 8 minutes (down from 4 hours pre-deployment)
30,000+ employee hours reclaimed annually from automated SOAR
100% FISMA audit pass rate for two consecutive years
Continuous compliance evidence — no annual audit “scramble”
92% of incidents caught proactively (before user reported)
SOC analyst headcount: held flat while alert volume grew 40%
The platform principle
The key architectural choice: SecOps and ITSM share the same CMDB and identity graph. When a security incident relates to an asset, the incident enriches automatically with that asset’s service map, owner, and operational status. When ITSM detects an unusual change pattern, it can flag a security review without leaving the platform. This is impossible with point security tools.