Continuous Threat Exposure Management (CTEM)
Continuous Threat Exposure Management (CTEM) is an ongoing program with which organizations systematically record their attack surface, prioritize exposures, verify their exploitability and steer countermeasures. The term was coined by the analyst firm Gartner and describes not a single tool but a recurring process.
CTEM is usually described in five phases: scoping (defining the area under consideration), discovery (recording assets and vulnerabilities), prioritization (assessment by exploitability and business impact), validation (checking whether exposures are actually exploitable) and mobilization (implementing the measures in the teams involved). CTEM thus goes beyond classic vulnerability management, which is frequently limited to counting and patching known vulnerabilities.
In the validation phase, methods such as Automated Security Validation are used, which test attack paths under real conditions. CTEM builds on Attack Surface Management and provides a reliable basis for measurably improving the organization's own Security Posture.