Key takeaways
- Continuous threat exposure management (CTEM) is a program described by Gartner that runs five repeating stages: scoping, discovery, prioritisation, validation and mobilisation.3
- Gartner predicted that by 2026, organisations that set security spending based on a CTEM program would see a two-thirds reduction in breaches.1
- 48,185 CVEs were published in 2025, about 132 a day, so no team can fix everything and ranking by real risk is the only way to keep up.7
- In the Verizon 2026 DBIR, exploiting vulnerabilities became the top way into breaches at 31%, yet only 26% of known exploited flaws were fully fixed, with a median fix time of 43 days.910
- Validation is the stage most programs skip. It proves which exposures an attacker can really use, through breach and attack simulation, automated pentesting or red teaming.16
- A first CTEM cycle can run in about 90 days if you start with one narrow scope, a written ranking rule and a named owner for every fix.
Monday morning. The scanner report lands with thousands of open findings, many marked high or critical. The IT team can fix a few dozen this month. Somewhere in that pile are the handful an attacker will actually use, and nobody can say which ones. Next quarter the pile is bigger. That is the problem continuous threat exposure management was built to solve: stop treating security as a string of one-off episodes, and run a loop that finds, proves and fixes what matters most.
Last reviewed on 12 October 2026 against Gartner research and press releases, the Verizon 2026 DBIR, VulnCheck exploitation data and the 2025 CVE record.
What is continuous threat exposure management (CTEM)?
Continuous threat exposure management (CTEM) is a repeating security program, described by Gartner, that helps an organisation find the exposures an attacker could use, rank them by business risk, prove which ones are exploitable, and get them fixed. CTEM runs in five stages and restarts every cycle, so the picture never goes stale.
Gartner calls CTEM "a pragmatic and systemic approach organizations can use to continually evaluate the accessibility, exposure and exploitability of digital and physical assets."2 In plain words: keep asking what an attacker can reach, what they could break, and whether they could really use it.
- Exposure
- Any weakness an attacker can reach and use. That includes a software flaw (a CVE), a misconfiguration, a weak or over-powered account, a leaked secret, a risky third-party connection, or a gap in what your team can detect. A vulnerability is one kind of exposure. CTEM looks at all of them.
CTEM is a program, not a product
You cannot buy CTEM in a box. It is a way of running security work, with owners, rules and a rhythm. Tools help at each stage. Gartner now tracks two tool groups that support it: exposure assessment platforms, which "continuously identify and prioritize exposures,"14 and adversarial exposure validation, which tests those exposures the way an attacker would.15
What "continuous" really means
Continuous does not mean scanning every minute. It means the loop never stops. When one cycle ends, its lessons feed the next scope. Compare that with the old model: a yearly penetration test, a PDF report, a burst of fixes, then months of silence. As we showed in The 363-Day Blind Spot, an annual pentest leaves most of the year untested. CTEM is built to close that gap.
Why did Gartner create CTEM?
Gartner created CTEM because traditional vulnerability management was drowning. Scanners produce more findings than teams can fix, severity scores do not show what attackers really use, and yearly tests go stale fast. CTEM shifts the goal from closing the most findings to cutting the exposures most likely to cause a breach.
The vulnerability overload problem
The numbers keep climbing. In 2025, 48,185 CVEs were published, up 20.6% from 39,962 in 2024.7 Of those, 3,984 were rated critical and 15,003 high. That is 18,987 critical or high flaws in one year, or about 52 every day (our calculation from the same data).7 No IT team patches 52 serious flaws a day, every day, on top of its real job.
Yet only a small slice of flaws is ever used in real attacks. VulnCheck counted 884 known exploited vulnerabilities (KEVs) that were first seen exploited in 2025.8 The hard part is that attackers are fast. In 2025, 28.96% of those KEVs were exploited on or before the day their CVE was published, up from 23.6% in 2024.8 Mandiant's M-Trends 2026 puts the mean time to exploit at minus 7 days, which means that on average, flaws are used before a patch even exists.13
Fixing is not keeping up
The Verizon 2026 Data Breach Investigations Report found that 31% of breaches now start with a software vulnerability, beating stolen passwords as the top way in.9 At the same time, only 26% of CISA known exploited vulnerabilities were fully fixed, down from 38% the year before, and the median fix time grew from 32 to 43 days.10 Tenable's review of the report notes a nearly 50% rise in the number of CISA KEV flaws that teams had to patch in 2025.11
So the problem is not a lack of data. It is a lack of focus. Teams spend effort on flaws that look scary on paper while the few that attackers are using stay open for weeks.
What Gartner predicted
Gartner named CTEM a top strategic technology trend for 2024 and made a bold forecast: "By 2026, Gartner predicts that organizations prioritizing their security investments based on a CTEM program will realize a two-thirds reduction in breaches."1 Gartner repeated the same line in its top cybersecurity trends for 2024.2 Earlier Gartner research on building a CTEM program was widely quoted as saying such organisations would be "three times less likely to suffer from a breach," which is the same idea in different words.3
Read the forecast with care. The two-thirds figure is a prediction, not a measured result. Gartner's 2025 research on CTEM also warns that enterprises fail to reduce exposure when they rely on "unrealistic, siloed and tool-centric approaches."5 The benefit comes from running the loop well, not from buying a tool with CTEM on the box.
A scanner tells you what is broken. CTEM tells you what an attacker can reach, and whether they can use it.From this article
What are the five stages of CTEM?
The five stages of CTEM are scoping, discovery, prioritisation, validation and mobilisation. Scoping decides what matters, discovery finds assets and weaknesses, prioritisation ranks them by real risk, validation proves what an attacker can exploit, and mobilisation gets the right people to fix it. Then the cycle starts again.
Gartner's research describes these five stages as a cycle that helps organisations identify, prioritise and fix the threats that pose the most risk to them.3 Its 2025 strategic roadmap frames CTEM as the way to move from narrow technology vulnerability management to a broader, more dynamic program.6 The graphic below shows each stage, the question it answers, and what goes in and comes out.
Stage 1: Scoping
Scoping answers one question: what do we care about most, and what does an attacker see when they look at us? Start with the business, not the network. Which systems move money, hold customer data, or would stop operations if they went down? Those are your crown jewels. The scope is the set of assets, identities, cloud services and third parties that could lead an attacker to them.
Keep the first scope small. "Internet-facing systems that handle payments" is a good scope. "Everything" is not.
Stage 2: Discovery
Discovery finds what is really inside the scope. That means assets you know about, assets you forgot, and the weaknesses on each. Good discovery looks past software flaws to misconfigurations, weak or unused accounts, exposed secrets and risky links to vendors.
Identity deserves special care. In many breaches the attacker does not break in, they log in, as we covered in our post on credential-based attacks. An exposure inventory with no accounts in it is only half a picture.
Stage 3: Prioritisation
Prioritisation turns a long list into a short one. The aim is to rank exposures by how likely they are to be used and how much damage they could do, not by severity score alone. Useful signals include the CISA Known Exploited Vulnerabilities catalog, which lists flaws seen used in real attacks,19 and EPSS, a FIRST score that estimates how likely a flaw is to be exploited in the next 30 days.18
Stage 4: Validation
Validation asks: can an attacker really exploit this, how far could they get, and would we notice? It tests the top exposures the way an attacker would, often by mapping steps to MITRE ATT&CK, the public catalogue of real attacker techniques.20 Some items drop off the list because a control already blocks them. Others move up because they chain into a path to a crown jewel.
Stage 5: Mobilisation
Mobilisation gets the fix done. It is the people stage: agreeing who owns each fix, by when, and what happens if a fix is not possible. This stage matters because most exposure fixes are made by IT, cloud and app teams, not by security. Good mobilisation uses the ticket tools those teams already use and ends with a retest.
How is CTEM different from vulnerability management?
CTEM differs from vulnerability management in scope, ranking and proof. Vulnerability management scans assets and ranks software flaws by severity. CTEM starts from business priorities, covers every kind of exposure, ranks by real attacker use, proves exploitability through testing, and runs as a repeating loop with named fix owners outside the security team.
CTEM does not throw vulnerability management away. It wraps around it. Gartner's 2024 research makes this point directly: vulnerability management alone is not enough, and security teams should grow it into a CTEM program to scope and fix exposures better.4
| Dimension | Traditional vulnerability management | CTEM |
|---|---|---|
| Starting point | Asset list and scanner output | Business priorities and the attacker's view |
| What counts | Mostly software CVEs | CVEs, misconfigurations, identities, SaaS, third parties, detection gaps |
| How items are ranked | CVSS severity | Real exploitation, threat activity, business impact, reachability |
| Proof | Assumed from the score | Tested through validation |
| Main output | A long list of findings | A short list of proven exposures with owners |
| Rhythm | Scan cycles plus a yearly pentest | A repeating loop, rescoped every cycle |
| Success measure | Number of findings closed | Risk removed from crown jewels and time to fix what matters |
| Who is involved | Mainly the security team | Security, IT, cloud, app owners and business heads |
If you are still sorting out the basics, start with the difference between a vulnerability assessment and a penetration test. In CTEM terms, the assessment feeds discovery and prioritisation, and the penetration test is one way to run validation.
Why does the validation stage matter most?
The validation stage matters most because it replaces guesses with proof. A high score says a flaw could be dangerous. Validation shows whether an attacker can reach it, exploit it, and move toward something valuable. That evidence shrinks the fix list, convinces IT owners to act, and shows whether your controls and monitoring really work.
Speed is the other reason. CrowdStrike's 2026 Global Threat Report puts average eCrime breakout time, the time from first access to moving to other systems, at 29 minutes, with the fastest case at 27 seconds.12 When close to three in ten newly exploited flaws are used by the day they are disclosed,8 a test run once a year cannot tell you what is exposed today.
Gartner gave validation its own market
In its 2024 Hype Cycle for Security Operations, Gartner grouped breach and attack simulation, automated pentesting and red teaming into one category called adversarial exposure validation (AEV).16 Gartner then published a Market Guide for AEV on 11 March 2025.15 According to a vendor summary of that guide, Gartner expects that "by 2027, 40% of organizations will have adopted formal exposure validation initiatives."17
| Method | Question it answers | Common rhythm | Strength | Limit |
|---|---|---|---|---|
| Breach and attack simulation (BAS) | Do our controls block and detect known techniques? | Continuous or weekly | Safe, repeatable, mapped to ATT&CK | Runs set scenarios; does not hunt for new paths |
| Automated penetration testing | Can an attacker chain real weaknesses to reach key systems? | Monthly and after major changes | Finds real attack paths across hosts and identities at scale | Weaker on business logic flaws |
| Manual penetration testing | What would a skilled human find in this app or network? | Yearly, or per major release | Depth, creativity, business logic | A snapshot; slow and costly to repeat |
| Red teaming | Would our people and processes catch a real attack? | Yearly or less often | Tests detection and response end to end | Narrow, expensive, not built for coverage |
How to combine them
Most mature programs mix methods. Automated testing gives breadth and frequency. Manual testing gives depth where logic and context matter. Our guide to automated vs manual penetration testing covers where each one wins. Two areas deserve their own validation plan. Identity paths found through Active Directory penetration testing often reveal the shortest route to domain control. And if your teams are building AI agents, the OWASP Top 10 for Agentic Applications shows new exposures that belong in scope.
Validate safely. Testing on live systems needs written rules of engagement, agreed time windows, production-safe techniques, and a named approver who can stop the test. Validation that breaks production will not get a second chance.
What metrics prove CTEM is working?
The metrics that prove CTEM is working measure risk removed, not tickets closed. Track how many crown-jewel systems are in scope, how fast known exploited flaws are fixed, how many proven attack paths stay open, how often fixes pass retest, and how many simulated attacks your security team detected.
Pick five to seven metrics, report the trend each cycle, and explain the reason behind each change. A falling count of open findings means little if the proven paths to your payment system stay open.
| Metric | What it tells you | How to measure |
|---|---|---|
| Scope coverage | Whether the loop covers what matters | Share of crown-jewel systems inside an active CTEM scope |
| KEV fix time | Speed on flaws attackers already use | Median days to fully fix KEV items on in-scope assets. Outside yardstick: 43 days, with 26% fully fixed, in the Verizon 2026 DBIR10 |
| Time to fix validated exposures | How fast proof turns into action | Days from proven exploit to a fix that passes retest |
| Open attack paths to crown jewels | Real risk left at the end of a cycle | Count of proven paths still open, by business area |
| Retest pass rate | Whether fixes hold | Share of closed findings that stay closed on retest |
| Detection rate | Whether the SOC sees attacks | Share of simulated ATT&CK techniques that raised an alert |
| Exception age | Whether accepted risk is managed | Number of risk exceptions past their expiry date |
Boards and risk committees respond best to two or three of these, shown as trends with a short story: what was exposed, what was proven, what was fixed, and what is still open with an owner and a date.
How do you start CTEM in 90 days?
Start CTEM in 90 days by running one full cycle on one narrow scope. Pick a crown-jewel area, build its asset list, write a simple ranking rule, validate the top exposures, and send proven findings to named owners with deadlines. Report the results to leadership, then widen the scope in the next cycle.
Before you plan, check where you stand. The maturity check below takes about a minute.
CTEM maturity check
For each stage, pick the level that best matches how your team works today. The score, chart and next steps update as you choose.
You run parts of the loop, but some stages depend on people remembering to do them.
Weakest stage
Validation (level 0)
- Test your top 10 exposures with a scoped penetration test this quarter.
- Map one likely attack path to a crown-jewel system using MITRE ATT&CK techniques.
Indicative only. This check is a simple self-assessment based on the five CTEM stages described in this article. It is not a Gartner maturity model or an audit.
Talk to Arxiis about continuous validation →The 90-day plan
- Days 1 to 15: choose one scope. List your crown jewels and pick one area, such as internet-facing apps that handle payments or customer data. Name a business owner and a security lead. Write the scope on one page.
- Days 10 to 30: discover. Pull asset data from your CMDB, cloud accounts and directory. Run an external attack surface scan. Record weak accounts and misconfigurations, not only CVEs. Note how many assets have no owner.
- Days 25 to 45: set ranking rules. Write a one-page rule: KEV items first, then high EPSS on reachable, business-critical assets. Agree fix deadlines for each priority tier with IT.
- Days 40 to 70: validate. Test the top exposures and at least one attack path to a crown jewel. Use automated testing for breadth and manual testing where logic matters. Record what your SOC detected.
- Days 60 to 85: mobilise. Send proven findings through the ticket system IT already uses, with evidence and a due date. Set up an exception process with an expiry date and an approver. Retest every critical fix.
- Days 80 to 90: report and rescope. Share three to five metrics with leadership. Write down what worked and what did not. Pick the next scope, such as Active Directory or a key cloud account, and start cycle two.
CTEM does not replace required testing. Regulators still set their own VAPT rules. See our guides to the RBI Cyber Security Directions 2026 and SEBI CSCRF VAPT requirements. A CTEM loop helps you meet those rules with fresher evidence between audits. This is not legal advice; check the latest text of each rule.
What are the most common CTEM mistakes?
The most common CTEM mistakes are treating it as a tool purchase, starting with a scope that is too big, ranking by severity score alone, skipping validation, and sending findings to teams with no owner or deadline. Each one breaks the loop, so the program produces reports but does not reduce real exposure.
- Buying a platform and calling it CTEM. Tools support the stages. They do not agree scope with the business or chase fixes. Gartner flags "tool-centric" approaches as a cause of failure.5
- Scoping everything at once. A huge first scope means discovery never ends and nobody sees results. Start narrow and widen each cycle.
- Ranking by CVSS alone. Severity describes a flaw, not your risk. Add KEV, EPSS, asset value and reachability.
- Skipping validation. Without proof, the ranked list is still a guess, and IT teams push back on fixes they do not believe in.
- No owners outside security. Most fixes are made by IT, cloud and app teams. If they did not agree the deadlines, the deadlines will slip.
- Measuring activity, not outcomes. "Findings closed" can rise while the real attack paths stay open.
- Letting the loop stop. One good cycle followed by a year of silence is just another episode.
Frequently asked questions
What is CTEM in simple terms?
CTEM, or continuous threat exposure management, is a repeating program for finding and fixing the weaknesses an attacker is most likely to use. It has five stages: decide what matters, find the weaknesses, rank them by real risk, test whether they can be exploited, and get them fixed. Then it starts again, so your view of risk stays current instead of going stale after an annual test.
What are the 5 stages of CTEM?
The five stages of CTEM are scoping, discovery, prioritisation, validation and mobilisation. Scoping sets what matters to the business. Discovery finds assets and exposures. Prioritisation ranks them using signals such as the CISA KEV list and EPSS. Validation tests whether an attacker could really exploit them. Mobilisation assigns owners and deadlines, confirms fixes with retests, and feeds lessons into the next cycle.
Is CTEM a tool or a framework?
CTEM is a program, not a single tool. It describes how to run exposure work with owners, rules and a repeating rhythm. Tools support each stage, such as exposure assessment platforms for discovery and ranking, and adversarial exposure validation tools for testing. Buying a tool without agreeing scope, ranking rules and fix owners will not give you the benefits Gartner describes.
What is the difference between CTEM and vulnerability management?
Vulnerability management scans assets and ranks software flaws, mostly by severity score. CTEM wraps around it. CTEM starts from business priorities, covers more kinds of exposure such as misconfigurations and weak identities, ranks by real attacker activity, proves exploitability through testing, and involves IT and business owners in fixing. Gartner advises growing vulnerability management into a CTEM program rather than replacing it.
What is adversarial exposure validation?
Adversarial exposure validation, or AEV, is Gartner's name for tools and services that test exposures the way an attacker would. It brings together breach and attack simulation, automated penetration testing and red teaming. AEV supports the validation stage of CTEM by showing which exposures are really exploitable, which attack paths lead to key systems, and whether your defences detect the attempt.
How long does it take to implement CTEM?
A first CTEM cycle can run in about 90 days if you keep the scope narrow. Spend the first weeks on scope and discovery, then set ranking rules, validate the top exposures, and route proven findings to owners. A full program covering all crown jewels takes several cycles, because each cycle adds a new scope and improves the rules based on what testing proved.
Does CTEM replace penetration testing?
No. Penetration testing is one way to run the CTEM validation stage, and many regulators and standards still require periodic pentests. CTEM changes how pentests are used: they target the exposures ranked highest, run more often through automation, and feed results straight into fixing and rescoping. Manual testing still matters for complex applications and business logic.
Is CTEM only for large enterprises?
No. Smaller teams can run CTEM by keeping each scope small and using the tools they already have. Start with internet-facing systems and your most important accounts, rank fixes using the free CISA KEV catalog and EPSS scores, validate the top items, and agree deadlines with IT. The loop matters more than the size of the budget.
Arxiis runs the validation stage, every day
Most CTEM programs stall at validation. Scanners and ranking tools produce a good list, but proving which items an attacker can really use still depends on a yearly test and a PDF that arrives weeks later. By then the list has changed.
Arxiis is an autonomous AI red teaming and penetration testing platform built for that gap. It tests your top exposures the way an attacker would and hands mobilisation the evidence it needs. Your company gets defended every day, not once a year.
- Breadth for validation: 26 security modules across 6 attack vectors: ransomware, Active Directory, cloud, web applications, containers and credentials.
- Attacker-style testing: a multi-agent AI crew for OSINT, exploitation, lateral movement and reporting.
- Evidence for mobilisation: CVSS-scored, MITRE ATT&CK-mapped findings with compliance overlays for 11 frameworks, including RBI, CERT-In, SEBI CSCRF, PCI DSS and ISO 27001.
- Speed and control: a pentest report in hours instead of weeks, fully on-premise deployment so data never leaves your environment, and an MIT-licensed open-source core.
Sources
- Gartner, "Gartner Identifies the Top 10 Strategic Technology Trends for 2024," 16 October 2023. gartner.com
- Gartner, "Gartner Identifies the Top Cybersecurity Trends for 2024," 22 February 2024. gartner.com
- SafeBreach, "Gartner Report: Implement a Continuous Threat Exposure Management (CTEM) Program," summary of Gartner research first published in 2022. safebreach.com
- Gartner, "How to Grow Vulnerability Management Into Exposure Management," 8 November 2024. gartner.com
- Gartner, "Use Continuous Threat Exposure Management to Reduce Cyberattacks," 16 July 2025. gartner.com
- Gartner, "Strategic Roadmap for Continuous Threat Exposure Management," 26 August 2025. gartner.com
- Jerry Gamblin, "2025 CVE Data Review," 1 January 2026. jerrygamblin.com
- VulnCheck, "State of Exploitation 2026," 21 January 2026. vulncheck.com
- Verizon, "2026 Data Breach Investigations Report," May 2026. verizon.com
- Help Net Security, "Verizon DBIR: Vulnerability exploitation is the dominant initial access vector," 20 May 2026. helpnetsecurity.com
- Tenable, "Key findings from the Verizon DBIR 2026," 19 May 2026. tenable.com
- CrowdStrike, "2026 CrowdStrike Global Threat Report: AI Accelerates Adversaries and Reshapes the Attack Surface," 24 February 2026. crowdstrike.com
- Google Cloud (Mandiant), "M-Trends 2026: Data, Insights, and Strategies From the Frontlines," 23 March 2026. cloud.google.com
- Gartner Peer Insights, "Exposure Assessment Platforms" market definition, accessed October 2026. gartner.com
- Gartner, "Market Guide for Adversarial Exposure Validation," 11 March 2025. gartner.com
- The Hacker News, "CTEM in the Spotlight: How Gartner's New Categories Help to Manage Exposures," August 2024. thehackernews.com
- Picus Security, "Picus Security Announces Recognition in Gartner Market Guide for Adversarial Exposure Validation," 2 April 2025. picussecurity.com
- FIRST, "Exploit Prediction Scoring System (EPSS)," accessed October 2026. first.org
- CISA, "Known Exploited Vulnerabilities Catalog," accessed October 2026. cisa.gov
- MITRE, "MITRE ATT&CK," accessed October 2026. attack.mitre.org