True Industry Story About Insider Threat and Data Loss
A few years ago, an IT consulting firm offering ServiceNow professional services to healthcare providers discovered they had a bad actor internally who had been deleting transaction logs.
When the firm needed that data for a client request and could not find it, they launched an investigation. While they found and fired the bad actor, the data they needed was gone forever.
Ask Your ServiceNow Team How Far Back They Can Actually Restore
What ServiceNow’s Native Backup Protects, and What You Are on the Hook For
Native ServiceNow backup holds 14 days of weekly fulls and 7 days of differentials. It was built to rebuild a failed instance, not to hand a regulator a clean record from 90 days ago. If your retention window ends before your audit period starts, you already have a gap. Close it before an examiner finds it for you.
Most ServiceNow customers do not know this because most customers never look at their platform-level backup until the day they need it. That is the wrong day to find out how it works. And most missed the quiet change on May 8, 2023, when ServiceNow cut the retention window from 28 days to 14.
What ServiceNow Provides Natively
ServiceNow’s Advanced High Availability (AHA) architecture generates two types of backups automatically for every production instance:
- Full backups every 7 days, retained for 14 days
- Differential backups every 24 hours, retained for 7 days
That is the entire native offering. You can view your backup catalog on the Now Support Portal via the “List of backups for the instance” Service Catalog item. If you need to restore, you open a case with ServiceNow, as restore is not a self-service operation, and per ServiceNow’s own guidance, “it should be a last resort due to potential data loss and instance unavailability.”
The restoration process itself is not for the faint of heart: you need to block all non-admin users from the instance, export delta data, initiate the restoration, and create fresh backups afterward. Total restore time is “at least as long as a full instance clone,” which for large enterprise instances is generally measured in hours to days, not minutes.
What that architecture is designed for
None of this is a knock on ServiceNow. The AHA backup layer is engineered exactly for what it does well: infrastructure disaster recovery (DR). If a data center fails, if a hypervisor corrupts, if the platform itself has a bad day, AHA is what brings the instance back. That is a hard problem, and ServiceNow solves it well.
But infrastructure DR is not compliance backup. It is not surgical recovery. It is not an evidence layer for regulators. And ServiceNow themselves have said so, in the same community article that documented the May 2023 change:
“ServiceNow’s native backup architecture isn’t designed for archival purposes. Organizations requiring prolonged retention periods should explore purpose-built solutions.”
That is the vendor’s own guidance, published on the ServiceNow community. Scroll down to the comments on that article, and a real ServiceNow admin asks the follow-on question that every compliance leader eventually asks:
“Does ServiceNow offer customers the opportunity to archive copies of backups so they can have an immutable offline copy?”
The answer is no, ServiceNow does not offer this service.
The three questions the 14-day ceiling cannot answer
If you are a security leader, compliance officer, or ServiceNow platform owner, this is the shape of the gap the native window leaves you to close on your own.
“Show me the state of this record ninety days ago.” DORA, NYDFS Part 500, HIPAA, SOX, and FINRA all expect retention measured in years, not days.
“Roll back just the four thousand records this misfired workflow corrupted last Thursday, but leave the rest of the instance untouched.” The native restore is a full-instance operation. There is no surgical, record-level, or field-level restore inside AHA.
“Prove that this Now Assist decision was based on un-tampered data, and reverse the changes it made if we need to.” The 14-day window predates the mainstream deployment of agentic AI inside ServiceNow. AHA has no concept of pre-state and post-state capture for AI-driven changes, and no reversibility layer for automated workflows.
What compliance-grade backup actually looks like
The gap the 14-day ceiling leaves is exactly the gap Rezilient Restore is designed to close:
Continuous, schema-aware capture — not weekly fulls and daily differentials, but every change to every protected table, in real time.
Immutable, off-platform, zero-knowledge storage encrypted end-to-end with AES-256 keys held by the customer. Rezilient can never read your data, as it has no key.
Surgical restore at the record, field, table, or workflow level — fast, precision recovery, and no full-instance rollback that disrupts every other team on the platform.
Retention aligned to the regulation, not to the platform — six years for HIPAA, seven years for SOX and FINRA, and the long-horizon reconstructability DORA now expects from critical financial services workloads.
AI governance for Now Assist and agentic workflows — pre-state and post-state capture for every automated change, with reversibility and a chain of custody your regulator will accept.
This is the “purpose-built solution” ServiceNow itself points customers toward. It is also what the Shared Responsibility Model has always assumed customers have in place.
Beyond the ceiling
The 14-day ceiling is not a problem, it was a design decision: an infrastructure-DR window, engineered by ServiceNow. Under its Shared Responsibility Model, everything above that ceiling sits squarely in the customer’s column: data retention, surgical recovery, immutability, AI governance, and the evidence layer your auditor will ask for.
Ask your platform team how far back they can actually restore. If the answer is 14 days, and your regulator wants seven years, close the gap before an examiner finds it for you.
Our new white paper, The Shared Responsibility Gap, walks through the compliance mapping, the seven requirements for compliance-grade backup, and how Rezilient Restore closes the gap in a way your CISO, your GRC lead, and your regulator can all sign off on.
Read The Shared Responsibility Gap at rezilient.co →
Back Up Now. Restore Anytime. Always Rezilient.