# UiPath for security teams - what UiPath's own security function runs on its platform

> How UiPath's security team uses its own platform: agents investigating SIEM alerts, vulnerabilities in context, a NIST CSF 2.0 map and control over the bots

- Source: https://snok.ai/en/news/blog/uipath-for-cybersecurity-teams/
- Author: Jacek Bugajski
- Published: 2026-10-06

---
In October 2025, UiPath CISO Scott Roberts said that a threat analyst agent his team had built on the UiPath platform had saved **more than 13,000 hours** of alert-response work. In the same conversation he added two details: one of the workflows is a swarm of 61 agents working in parallel, and in some cases an investigation that used to take up to four hours now takes about a minute and a half. In February 2026 he described the whole set-up as an orchestration of more than 60 agents that investigate SIEM alerts end to end and produce structured incident write-ups.

This is a vendor's own claim, not an independent measurement, and we read it as such. Its value lies in the specifics: it describes a mechanism in use inside the security function of the company that sells the platform, and it shows where an automation platform earns a place in a team that already runs a SIEM, EDR and SOAR.

**In short:**

**1/** UiPath's security team (TrustOps) uses its own platform to triage alerts, score vulnerabilities in the context of its products and have agents check the output of other agents,

**2/** in a cybersecurity team UiPath does not replace the SIEM - the vendor itself now calls its offering a SOAR layer, one that acts where there is no API, takes over the work that surrounds an incident or an audit, and hands high-impact actions to a human for approval,

**3/** SAP security is where the manual work is heavy and published automation patterns are scarcest: access reviews, bot accounts, SAP Security Patch Day notes,

**4/** the precondition is control over the bots themselves - a bot in a security role holds a combination of privileges you would never give one person.

<figure class="blog-video">
  <video autoplay muted loop playsinline controls preload="metadata" poster="/images/blog/uipath-cyber-petla-poster-en.webp" width="1920" height="1080" style="width:100%;height:auto;border-radius:0.75rem;border:1px solid rgba(255,255,255,0.1);">
    <source src="https://snok.ai/images/blog/uipath-cyber-petla-en.mp4" type="video/mp4" />
    Your browser does not support video playback. <a href="/images/blog/uipath-cyber-petla-en.mp4">Download the video (MP4)</a>.
  </video>
  <figcaption style="font-size:0.85rem;color:rgba(255,255,255,0.6);margin-top:0.5rem;">A 24-second silent loop: from a SIEM alert, through UiPath agents, to the six NIST CSF 2.0 functions. Figures in the animation: UiPath security team, 2025-2026; the SIEM console is illustrative.</figcaption>
</figure>

## What UiPath's security team runs on its own platform

The most detailed accounts come from three sources: Scott Roberts in conversation with Averlon (21 October 2025), the Shift AI podcast (21 February 2026), and a post by Kevin Mooney, UiPath's Field CISO, published on 9 July 2026 and based on a discussion among four members of TrustOps. Together with a Dropzone AI case study, they point to four uses.

**A threat analyst agent.** An alert from the SIEM goes to an orchestration of more than 60 agents. They investigate the event end to end and produce a structured incident write-up. It is this agent that Roberts credits with the 13,000 hours saved.

![UiPath's threat analyst agent - from a SIEM alert to the analyst's decision](https://snok.ai/images/blog/uipath-cyber-agent-analityka-en.webp)

**Agents checking agents.** Where model output is non-deterministic, the team uses what it calls judge agents: one agent produces a result and a second checks it before the next step. In our view it is the easiest pattern to adopt elsewhere, because it answers the first objection to AI in security - that the model will get it wrong and nobody will notice.

**Vulnerabilities scored in context.** Roberts puts the inflow at around 500 new open-source vulnerabilities a week. A typical scanner matches a component's name and version against a CVE database and repeats the database score. According to Mooney's post, UiPath's team combined RPA to collect the data with generative agents that read the vulnerability description and the vendor's advisory, plus continuous scanning and exploitability analysis, all orchestrated by UiPath agents and robots. The output is a CVSS score with base, temporal and environmental metrics, backed by exploitability analysis - a measure of how much a flaw matters in the context of a specific product.

Roberts described a separate case in his conversation with Averlon. After a critical zero-day, the scanners reported tens of thousands of occurrences - Roberts speaks of around 20,000 instances to patch within a two-hour window. Averlon's tooling narrowed that down to the paths an attacker could actually reach, and the team patched those within hours. It is the same principle - exploitability matters more than the mere presence of a component - delivered with another vendor's tool.

**First-line triage.** Dropzone AI handles first-line triage, closing simple alerts and escalating harder ones, with their context intact, to the agentic SOC UiPath has built. The results block of a case study published by Dropzone AI lists 86% fewer false positives and more than 700 analyst hours saved over six months.

The July post says the security automation UiPath now offers customers is "the leading edge of what the UiPath TrustOps team already runs on itself". The post does not say which of these mechanisms are already products, so availability needs checking case by case.

## Where UiPath fits in a cybersecurity team

For the wider picture, we have mapped potential uses against the six functions of NIST CSF 2.0. Each function contains work that falls between systems and outside the scope of the SIEM, the EDR and the GRC tool.

![UiPath across the six NIST CSF 2.0 functions](https://snok.ai/images/blog/uipath-cyber-nist-csf-en.webp)

**Govern.** Audit evidence for ISO 27001, SOX or NIS2 consists largely of screenshots, exports and user lists. A robot can collect it on a schedule, stamped with date and source, rather than by hand before each audit. Supplier assurance under DORA belongs here as well; our proposed flow fetches a supplier's SOC 2 or SOC 3 report, reads the auditor, period and scope, and checks them against your requirements. UiPath has demonstrated the first part with UiPath ScreenPlay in December 2025: a robot finds a supplier's SOC 3 report and extracts the auditor, coverage period, report type and scope.

**Identify.** Vulnerabilities scored in context, as at TrustOps, and inventory reconciliation: does every device in the CMDB have an EDR agent, and does the scanner see everything it should?

**Protect.** The account lifecycle - joiner, mover, leaver - plus password resets and account unlocks. In 2022 UiPath reported that automating user management in its own IT team cut ITSM ticket handling from two hours to two minutes. According to a case study published by UiPath, Jana Small Finance Bank, facing 300-400 password reset requests a day, brought that work down from three to four hours a day to under an hour. Add access reviews, with the owner's sign-off routed through UiPath Action Center.

**Detect.** Robot and agent logs in the SIEM. Since release 2025.10 a unified audit log gathers events from every platform service in one place and, in UiPath's words, provides the link between automation activity and observability systems such as Splunk or Microsoft Sentinel. Every agent runs under its own identity, with permissions assigned the same way as for people and robots.

**Respond.** Alert triage by agents, and the actions a SIEM cannot take because the firewall or the legacy system has no API: blocking an address, quarantining a file, isolating a device. In 2022 UiPath said its own automations were blocking more than 20,000 brute-force attacks a year. A draft incident notification to the CSIRT also fits here - facts, deadlines, a version ready for sign-off. Deciding that an incident is significant stays with a person.

**Recover.** Post-incident reporting, a lessons-learned log, corrective actions assigned to owners in the ticketing system. Here automation mainly makes sure the follow-up reaches the people who own it.

## Where UiPath stops

UiPath does not replace the SIEM and is not a security operations platform in the mould of Splunk SOAR or Cortex XSOAR, although in 2022 it wrote that it enables full-scale SOAR, and in 2026 it calls its offering a SOAR layer and publishes a SOAR accelerator on its Marketplace. Security operations tools are building their own AI agents - Splunk, Torq, Tines, Swimlane and a crop of specialist start-ups. UiPath comes in where those tools stop: in systems without APIs, in the business processes around an incident, and in human approval.

Most of the ready-made connectors today cover the Microsoft stack. UiPath Integration Service has connectors for Microsoft Sentinel, Defender for Cloud, Sentinel Threat Intelligence, Entra ID and ServiceNow, and the Marketplace adds VirusTotal, AbuseIPDB, urlscan.io, Shodan, Defender for Endpoint and CrowdStrike. In March 2026 UiPath announced a collaboration with Microsoft in which Defender for Cloud scans files moving through business processes, Sentinel receives the incident with business context, and a robot quarantines the file or pauses the process.

We found no ready-made connector for Splunk or Splunk SOAR. Integration has to be designed over the REST API - for instance, a Splunk alert starting a process in Orchestrator and a robot writing the result back. That is an integration project in its own right.

## SAP: heavy manual work, few ready-made patterns

SAP security involves a great deal of manual work, yet little has been published on automating it. A question about automating SAP GRC, posted on the UiPath forum in April 2022, has close to 1,500 views, and the replies go no further than a general note that any SAP interface can be automated. In the material we reviewed, SAP security vendors make no mention of UiPath, and UiPath has no official write-up on automating SAP GRC or SAP Security Patch Day - only a general community post on SAP compliance and audit automation from October 2024. On 29 September 2026 UiPath and BDO USA announced internal audit accelerators with always-on access review, validation of provisioning and deprovisioning, and segregation-of-duties monitoring across ERP and cloud systems. For now it is an announcement with no deployment described.

In SAP we would start with three uses.

**SAP Security Patch Day notes in context.** Every month SAP publishes security notes, and the team has to work out which ones apply to its releases, components and configuration. The TrustOps pattern - a robot collects the data, an agent reads the note, exploitability is assessed - can be applied to SAP notes, with [SecurityBridge](https://snok.ai/en/offer/sap-security/securitybridge/) supplying the system state. The output would be a list of notes, each with an owner and a deadline.

**Bot accounts in SAP.** A robot working through SAP GUI needs a dialog user, while a robot calling BAPIs can run on a system user. Each carries a different risk, and RFC integration needs additional authorisations that have to be granted deliberately and reviewed. A bot account without a named owner can be missed in the access review, because nobody signs off its authorisations.

**Access reviews and audit evidence.** A robot can collect dated exports and screenshots, compare them with the approved access list and route discrepancies to the owner. Once an attack path is known - from a tool such as [SAPMAP](https://snok.ai/en/news/blog/sapmap-bloodhound-for-sap/), for example - the same mechanism can check that removed authorisations do not creep back.

## The precondition: bots under the security team's control

A bot in a security role needs broad read access - the identity provider, the EDR, the scanner, the CMDB - and often the right to change things too: lock an account, close a ticket, isolate a device. No single person would be given that combination. Automation in a security team therefore starts with control over the bots.

The best-documented example of what happens without it is an audit by the US General Services Administration's Inspector General, published on 6 August 2024. The agency's RPA programme did not meet its own IT security requirements, and system security plans were not consistently updated to cover bot access. Rather than fix these gaps, programme management removed or relaxed the requirements. There was also no process for removing access once a bot was retired: 55 of the 56 custodians of decommissioned bots kept their access beyond the 14 days the agency's policy allows.

![Bots under control - five conditions](https://snok.ai/images/blog/uipath-cyber-boty-pod-kontrola-en.webp)

Five preconditions:

**1/** a dedicated account for every bot, with a named business owner and never a shared login,

**2/** credentials in a vault - Orchestrator integrates with CyberArk as a PAM system and with secret stores such as Azure Key Vault and HashiCorp Vault,

**3/** least privilege and segregation of duties between the bot and the person who supervises it,

**4/** robot and agent logs in the SIEM, so every bot action leaves a trail,

**5/** access for the bot, its custodians and its developers revoked on the day the bot is retired, through the same process as a leaver.

The same applies to AI agents. High-impact actions go through a human approval gate - we covered this in [HITL gates in UiPath Maestro and the AI Trust Layer](https://snok.ai/en/news/blog/hitl-gates-uipath-maestro-ai-trust-layer/).

## How we work with cybersecurity teams

SNOK brings three things to this work: SAP security, a UiPath Platinum partnership and our own ISO 27001-certified information security management system. For security teams we propose four stages:

**1/** an inventory of bots and agents - accounts, privileges, owners, credentials, logs; this is the [AI security review](https://snok.ai/en/offer/ai-automation/ai-security/) that comes before any further rollout,

**2/** choosing the two or three processes that take the most manual effort, such as gathering audit evidence, access reviews and account handling,

**3/** implementing them in [UiPath Maestro](https://snok.ai/en/offer/ai-automation/uipath-maestro/), with human approval for high-impact actions and timings measured before and after,

**4/** extending the work to SAP - [SAP Security Patch Day](https://snok.ai/en/offer/sap-security/sap-security-patch-day/), bot accounts, access reviews - and evidence for a [NIS2 and DORA audit](https://snok.ai/en/offer/sap-security/nis2-dora-audit/).

There is more in our [cybersecurity offer](https://snok.ai/en/offer/cybersecurity/) and on the [UiPath at SNOK](https://snok.ai/en/uipath-snok/) page. For an earlier take on UiPath in security operations, see [UiPath as an agentic cybersecurity guardian](https://snok.ai/en/news/blog/uipath-agentic-cybersecurity-guardian/).

## Where to start

The first step needs no new licence. It is a list of every bot and agent running in your organisation today, with its account, its privileges and its owner. If that list exists and is current, you are in a position to hand security work to bots. If it still has to be built, that is where to start.

[Get in touch](https://snok.ai/en/contact/) - we will show you what a bot inventory and a first security process in UiPath look like.

## Sources

- UiPath, Kevin Mooney, "When AI finds everything, the trick is knowing which vulnerabilities matter", 9 July 2026, [uipath.com](https://www.uipath.com/blog/ai/how-ai-is-changing-vulnerability-management) (accessed 5 October 2026).
- Averlon, webinar "Inside UiPath: How Agentic AI is Redefining Security in the AI Era" with Scott Roberts, 21 October 2025, [averlon.ai](https://www.averlon.ai/webinars/inside-uipath-redefining-security-ai-era) (accessed 5 October 2026).
- Shift AI Podcast, "Securing Agentic Automation in the Enterprise with UiPath CISO Scott Roberts", 21 February 2026, [YouTube](https://www.youtube.com/watch?v=T_V3kbYVeXE) (accessed 5 October 2026).
- Dropzone AI, "How UiPath Extended Its Agentic SOC with AI SOC Analysts", [dropzone.ai](https://www.dropzone.ai/case-studies/how-uipath-extended-its-agentic-soc-with-ai-soc-analysts) (accessed 5 October 2026).
- UiPath, Jagjit Dhaliwal, "How is UiPath Automating Cybersecurity Operations?", 24 May 2022, [uipath.com](https://www.uipath.com/blog/automation/automating-cybersecurity-operations) (accessed 5 October 2026).
- UiPath, Andrei Oros, "Are your enterprise automation workflows connected to your security stack?", 18 March 2026, [uipath.com](https://www.uipath.com/blog/product-and-updates/are-enterprise-automation-workflows-connected-security-stack) (accessed 5 October 2026).
- UiPath, Andrei Hinodache, "Governance and security for the agentic enterprise: new in the 2025.10 release", 19 November 2025, [uipath.com](https://www.uipath.com/blog/product-and-updates/agentic-enterprise-governance-and-security-2025-10-release) (accessed 5 October 2026).
- UiPath, Jana Small Finance Bank case study, [uipath.com](https://www.uipath.com/resources/automation-case-studies/jana-small-finance-bank) (accessed 5 October 2026).
- UiPath, "UiPath Expands Partnership with BDO", 29 September 2026, [uipath.com](https://www.uipath.com/newsroom/uipath-expands-partnership-with-bdo) (accessed 5 October 2026).
- GSA Office of Inspector General, "GSA Should Strengthen the Security of Its Robotic Process Automation Program", report A230020/B/T/F24004, 6 August 2024, [oversight.gov](https://www.oversight.gov/reports/audit/gsa-should-strengthen-security-its-robotic-process-automation-program) (accessed 5 October 2026).
- NIST, "The NIST Cybersecurity Framework (CSF) 2.0", 26 February 2024, [nist.gov](https://www.nist.gov/cyberframework) (accessed 5 October 2026).
- UiPath Forum, "UiPath Studio With SAP GRC", 27 April 2022, [forum.uipath.com](https://forum.uipath.com/t/uipath-stuido-with-sap-grc/418670) (accessed 5 October 2026).
- UiPath Community Blog, Ashish Pandey (RPATech), "Automating SAP compliance and audit processes with UiPath", 3 October 2024, [uipath.com](https://www.uipath.com/community-blog/tutorials/automating-sap-compliance-and-audit-processes) (accessed 6 October 2026).
