
What is CTEM (Continuous Threat Exposure Management)?
Continuous Threat Exposure Management (CTEM) is an operating model for reducing exploitable exposure across an environment on an ongoing basis, rather than assessing it at fixed intervals.Gartner introduced CTEM as a five stage program: scope, discover, prioritise, validate and mobilise.
The defining property is that it runs as a loop. Each cycle re-scopes, re-discovers and re-validates, against an environment that has changed since the last pass.
CTEM is not a product category. It is an assembly of disciplines, asset discovery, attack surface management, prioritisation, exposure validation and remediation orchestration, coordinated into are repeatable process. Individual tools address individual stages, but no single tool is CTEM.
Exposure is not the same as vulnerability
A vulnerability is a known weakness, typically a CVE, present on an asset. An exposure is a weakness that is actually reachable and exploitable in your specific environment, in a way that leads to impact. The distinction matters because most vulnerability inventories are dominated by findings
that are not reachable, not exploitable, or not consequential.
CTEM is organised around exposure, not raw vulnerability count. A critical CVSS score on an internal asset with no network path to it is a lower exposure than a medium severity misconfiguration on an internet facing service that chains into an identity with lateral movement rights. Traditional severity ranking inverts that priority. CTEM corrects it by incorporating reachability, exploitability and business impact.
Why point in time assessment falls short
Attack surface is non stationary. It changes with every deployment, cloud resource, new SaaS integration, identity grant and third party connection. A quarterly assessment describes a state that no longer holds by the time the report is delivered. The consequence is a persistent gap between
assessed posture and actual posture.
CTEM addresses this by making discovery and validation continuous processes rather than scheduled events. The exposure view is intended to track the live environment, not a snapshot.
The five stages
1. Scope
Scoping defines the boundary of the current cycle in business terms. This is typically driven by crown jewel analysis: identifying the assets, data stores, identities and third party connections whose compromise would produce material impact. Scope is deliberately narrower than the full estate at first and expands as the program matures.
2. Discover
Discovery enumerates assets and weaknesses inside the scope. It draws on several tooling
categories:
• EASM (External Attack Surface Management) for internet facing assets, discovered through passive DNS, certificate transparency, ASN and IP range enumeration, and external port and service identification.
• CAASM (Cyber Asset Attack Surface Management) for internal asset correlation, typically by aggregating data from cloud provider APIs, EDR, CMDB, identity providers and vulnerability scanners.
•Vulnerability scanning for known CVEs on discovered assets.
•Identity discovery for accounts, entitlements and over permissioned roles.
Discovery is continuous. The output is an asset and weakness inventory, not yet prioritised.
3. Prioritise
Prioritisation ranks discovered weaknesses by the likelihood and consequence of exploitation.
Mature prioritisation blends several signals rather than relying on CVSS alone:
• CVSS for base severity.
• EPSS (Exploit Prediction Scoring System) for the probability that a vulnerability will be exploited in
the wild.
• CISA KEV and threat intelligence for known active exploitation.
• Reachability and attack path analysis for whether the weakness is actually accessible and
what it chains into.
• Business context from the scoping stage for impact weighting.
The output is a short, ranked list of exposures that warrant attention, mapped where possible to
adversary techniques in MITRE ATT&CK.
4. Validate
Validation tests whether prioritised exposures are genuinely exploitable, rather than assuming a
scanner result is accurate. Methods include:
•Penetration testing for manual, context aware exploitation.
•Breach and Attack Simulation (BAS) for automated, repeatable testing of controls against known techniques.
•Attack path validation for confirming that a theorised chain from entry point to impact actually holds.
•Purple teaming for testing detection and response alongside exploitability.
Validation is the stage that most distinguishes CTEM from vulnerability management, and the stage
most tools skip. Its purpose is to remove unexploitable findings from the remediation queue.
5. Mobilise
Mobilisation converts validated exposures into remediation that gets done. This involves routing findings into ticketing and workflow systems, assigning owners, setting remediation SLAs by exposure tier, and tracking closure. Reporting expresses exposure reduction over time and maps it to
control frameworks. Findings and metrics feed back into the next scoping cycle.
What a CTEM program measures
Useful CTEM metrics are outcome oriented rather than volume oriented:
Counting open vulnerabilities is not a CTEM metric. It measures scanner output, not risk.
Relationship to adjacent disciplines
CTEM sits above and coordinates several disciplines. Vulnerability management and ASM feed discovery. BAS and penetration testing feed validation. Exposure management is the broader category CTEM operationalises. For the boundary with attack surface management, see the attack surface management guide. For the specific contrast with periodic scanning, see CTEM vs vulnerability management.
Business Impact of Secure Segmentation
Is CTEM a tool you can buy?
No. CTEM is a program that coordinates several tool categories across five stages. Vendors sell tools that support individual stages; the program is the operating model around them.
Does CTEM replace vulnerability management?
No. Vulnerability scanning feeds the discovery stage. CTEM adds continuous cadence, exploitability based prioritisation, validation and mobilisation on top.
What is the difference between an exposure and a vulnerability?
A vulnerability is a known weakness. An exposure is a weakness that is reachable and exploitable in context, leading to impact. CTEM prioritises exposures, not raw vulnerability counts.
Crossbow runs CTEM as a managed program, with the validation stage performed by a CREST accredited testing team


