Vulnerability & exposure

What is Continuous threat exposure management (CTEM)?

Definition

A programme, described by Gartner, for continuously identifying, prioritising, validating and reducing the exposures attackers are most likely to use.

How it works

CTEM is usually described in five stages: scoping, discovery, prioritisation, validation and mobilisation. It combines vulnerability data, attack surface monitoring and testing into one ongoing cycle.

The emphasis is on validation and mobilisation: proving which exposures are actually exploitable and getting the right teams to fix them.

Key points

  • A continuous cycle, not a project
  • Five stages: scope, discover, prioritise, validate, mobilise
  • Combines scanning, EASM and testing
  • Measured by exposures closed, not found

Common questions

Is CTEM a product?

No. It is a programme approach that uses several tools and services together.

Where do we start?

Agree scope with the business, then get a single view of exposures across scanners and your external attack surface.

Talk to someone who does this every day

Questions about CTEM? Our team will give you a straight answer.

Contact us