CTEM 101: Moving From Spreadsheets to Continuous Risk Reduction

CTEM 101: Moving From Spreadsheets to Continuous Risk Reduction

Share

TL;DR
CTEM treats vulnerability management as a continuous cycle, not a one-time event, moving through five recurring stages: scoping, discovery, prioritization, validation, and mobilization. The real shift is not more tools, it's better triage, weighing each finding against the value of the asset it lives on, not just its severity score. Whether you're building a program from scratch or refining an existing one, the discipline matters more than the tooling: assess your maturity, set concrete targets, and get an executive sponsor before you start.

If you work in cybersecurity, you have probably been asked some version of this question: what business are we actually in? Offensive security? Penetration testing? Red and Blue teaming? Threat hunting and intelligence? Those are all common answers, but they miss the real point. The actual business we are all in is risk reduction. Every role in security, whether offensive or defensive, exists to reduce risk for the organization.

That framing matters because it is the foundation of a framework that has been gaining traction across the industry: Continuous Threat Exposure Management, or CTEM. This post walks through what CTEM is, why it exists, and why it represents a meaningful upgrade over traditional Vulnerability Management.


The Problem with Traditional Vulnerability Management

For years, vulnerability management (VM) has looked roughly the same at most organizations. A small group of practitioners is handed the job of managing vulnerabilities, and the inputs come from everywhere at once: internal scans, external pen test reports, bug bounty submissions, and beyond. The result are piles of vulnerabilities tracked across multiple spreadsheets that hardly ever get routed to the correct team for remediation, which in turn creates chaos for the whole organization.

Think of it this way. Vulnerabilities are like grains of sand, and most teams are stuck with piles of them everywhere. Security teams have historically been understaffed, trying to clear those piles with a tablespoon, while the people generating findings are working with shovels. That imbalance alone makes VM feel unmanageable.

Then AI entered the chat. The asymmetry that used to grow slowly is now growing exponentially. If a tablespoon could not keep up with a shovel, it has no chance against a front loader. Meanwhile, security budgets have not scaled at anywhere near the same pace.

On top of the volume problem, traditional VM has three structural weaknesses:

  • It is reactive by nature. Teams respond to whatever gets reported rather than proactively hunting for exposure.
  • It lacks real prioritization. Everything with a CVE gets treated as if it deserves attention, regardless of actual business impact.
  • It is narrowly focused on known CVEs, which ignores an entire category of risk like misconfigurations, exposed identities, and third-party exposure.

Some teams respond by trying to fix everything. And some get so lost, they can’t fix anything. That approach does not scale, and it is not a strategy.


Enter CTEM: A Framework, Not a Product

CTEM was coined by Gartner around 2022. Some people call it a framework, others call it an operating model, and honestly, the label matters less than the outcome. The most important thing to understand about CTEM is this: you cannot buy it off the shelf. There is no single vendor or tool called “CTEM” that you install and walk away from. You have to implement it.

What you can buy are individual services, tools, and data sets that help you address specific parts of CTEM coverage. But the framework itself is something your organization builds and operates continuously, not something you procure once.

CTEM is made up of five distinct stages. Moving through all five stages in an agreed upon window of time constitutes one CTEM cycle, and the cycle repeats on an ongoing basis, which is where the “continuous” in the name comes from.


The Five Stages of CTEM

  1. Scoping. Find your assets by any means necessary. Internal and external endpoints, cloud identities, domain registrations, DNS records, all of it. Inventory those assets and group them. When you identify an asset, tag it with an indicator of its perceived business value right away. That early tagging saves significant time later during prioritization.
  2. Discovery. Scan your assets on a regular cadence. If scoping was done well, the output from discovery scans is much easier to triage because you already understand what you are looking at and why it matters.
  3. Prioritization. This is where a pile of potential vulnerabilities gets sorted by more than just a CVSS score. A 9.8 severity finding on a static marketing site does not carry the same real-world risk as a 9.0 on a publicly accessible admin interface that hands out a shell to anyone who asks. Prioritization must weigh both the vulnerability and the asset it lives on. A new CVE with an existing exploit, a high CVSS score, and a crown jewel asset attached to it is the kind of combination that should make you cancel lunch.
  4. Validation. Validation goes a step further than confirming a vulnerability exists. It means determining the true blast radius. If there is a remote code execution vulnerability on a host that is fully isolated with no meaningful data on it, that might reasonably get deprioritized in favor of something with real exposure. This stage also includes validating that your existing security controls are actually doing what they are supposed to do.
  5. Mobilization. Findings are only useful if they reach the right people fast enough to act on them. Mobilization is about identifying who owns the fix and building the integrations and workflows that get vulnerability reports to that person or team quickly, shrinking the gap between discovery and remediation.

Each of these five verticals has its own technical challenges, and getting all five stages to 100%through a single vendor is close to unrealistic. Expect to combine multiple tools, teams, and processes to cover the full cycle.


CTEM vs. Traditional VM: The Real Upgrade

Here is the shift that matters most. Traditional VM is reactive. CTEM is both proactive and reactive. VM has historically waited for scan results and reports to show up before anything happens. CTEM builds continuous scoping and discovery into the process, so exposure is being surfaced and evaluated on an ongoing basis rather than in response to a single event.

The scope of what gets tracked also expands. VM has mostly focused on known CVEs. CTEM focuses on CVEs, plus anything else that could cause damage to the environment, including misconfigurations, exposed identities, and third-party or brand related risk.

Even if your organization already runs a well implemented VM program, CTEM is not something to dismiss. It adds a layer of validation and mobilization that turns raw findings into measurable, trackable risk reduction rather than a growing backlog of open tickets.

In short, CTEM does not throw away vulnerability management. It absorbs it, expands its scope, and gives it structure and momentum it never had on its own. That is the real value of the framework. It takes the chaos that has defined VM for years and replaces it with an ongoing, prioritized, and accountable cycle.


Getting Started

A few practical takeaways if you are considering CTEM for your own organization:

  • CTEM is not about buying more tools. It is about doing more with what you already have.
  • Set realistic goals. Something concrete like eliminating all critical findings on crown jewel assets within 90 days, or reducing high severity issues by 70%across edge devices, is far more useful than a vague goal of “fixing everything.”
  • Find an executive sponsor. Remediation requires cooperation from other teams, and a senior sponsor makes it much harder for a mid-management stakeholder to keep pushing back on your requests.
  • Assess your maturity first. Look honestly at where your organization stands, identify the gaps, and prioritize which gaps to close first. Just as you cannot fix every vulnerability at once, you cannot close every maturity gap at once either.
  • Do not buy blindly. Understand the true value of any service, tool, or data set before adding it to your stack, and make sure it actually helps reduce risk rather than just adding noise.

If you want to go deeper and see how we continuously discover your assets, validate and test exposures, and track emerging threats so your CTEM program never falls behind, visit bishopfox.com/services/continuous-threat-exposure-management.


The Bottom Line

Vulnerability management got the industry this far, but it was built for a slower, smaller version of the problem than the one most teams face today. CTEM is not a magic fix, but it is a real upgrade. It takes the reactive, unprioritized chaos that has defined VM and replaces it with a continuous, structured cycle that is proactive by design.

For teams drowning in findings with no clear sense of what matters most, that shift from reactive firefighting to continuous, prioritized risk reduction is exactly the order CTEM is built to bring.


Ori Zigindere

By Ori Zigindere

Staff Technical Product Manager

Ori Zigindere is an offensive security professional with a background in software engineering. He currently serves as a Staff Technical Product Manager at Bishop Fox, where he leads platform design and innovation for the Cosmos Attack Surface Management platform.

Ori works with organizations across a wide range of industries to strengthen their security posture against evolving threats. He has deep expertise in Attack Surface Management (ASM), Vulnerability Management, and Continuous Threat Exposure Management (CTEM), and is passionate about helping organizations reduce risk by identifying and remediating exposed, vulnerable systems.

Subscribe to our blog

Be first to learn about latest tools, advisories, and findings.