top of page
Marval - Colour.png
Lessons from the ServiceNow breach and why you should rethink platform loyalty in 2026

Lessons from the ServiceNow breach and why you should rethink platform loyalty in 2026

Here is what happened, why you can be rightfully worried, and how you can pivot from defending a vendor to protecting your business.

The recent security incident involving ServiceNow has officially crossed over from a technical headache to a critical client conversation. For consulting firms, managed service providers, and IT practices built entirely around a single platform, it’s not just an IT issue, but a direct threat to your retention and revenue.


Here is what happened, why you can be rightfully worried, and how you can pivot from defending a vendor to protecting your business.


The anatomy of the incident


A major unauthenticated API flaw allowed attackers to query data directly from customer instances. Because ServiceNow acts as the central system of record for many enterprises, the exposed data includes:

  • Internal IT and security tickets

  • Sensitive employee records

  • Critical access control data


While ServiceNow confirmed that internal tables were queried, they have yet to disclose exactly what data was exfiltrated.


Adding to the tension is how the disclosure was handled. ServiceNow received a confidential report of the flaw on 22nd April. A patch was issued on 5th June, but the advisory was placed behind a gated customer login portal around 9th June, meaning only directly affected clients were notified.


The regulatory trap for customers


This quiet, gated rollout creates a massive legal headache for enterprises. Under GDPR Article 33, the strict 72-hour data breach notification clock starts the moment an organisation becomes aware of a potential breach, not when the vendor finally decides to confirm it.


By delaying the public advisory and gating the information, the vendor inadvertently caused regulated clients to start their compliance obligations late. That is a board-level exposure with your name on it, not the vendor's.


Why this is your problem


When you run a single-platform practice, your only option during a crisis is to defend the vendor (that just exposed your client).


The moment you start making excuses for a compromised platform, you stop looking like a trusted advisor and start looking like a liability. That is the exact moment an established, lucrative account becomes contestable by your competitors.


The solution


You don't have to abandon your primary platform, but you do need to hedge your risk. The firms that emerge from this crisis stronger will be the ones that can offer their clients a credible, compliant alternative.

When customers ask hard questions about where their data lives, who has jurisdiction over it, and whether their software vendors prioritise transparency, you need an answer ready on the shelf.


Marval is one such option worth evaluating. As the original co-authors of ITIL, we offer distinct advantages that address today's sovereignty and audit concerns:


  • Data jurisdiction: client data is kept strictly under our own jurisdiction.

  • Deployment flexibility: available via both SaaS and secure on-premise deployments.


By putting a strong alternative in your portfolio, you change the conversation entirely and lead with proactive solutions that keep your business and your clients secure.


Let's start the conversation. 

Let's work
together.

info@marval.co.uk

+44 (0)1536 711999

  • Linkedin
  • Youtube
Marval - Coloured Mountains_edited.png

Marval Global Locations:

United Kingdom, Australia, Netherlands, Sweden, South Africa, Canada and Lithuania

Contact us

bottom of page