Quel est votre niveau d'exposition depuis votre dernier pentest ?

Un pentest est un instantané, et le risque ne s'arrête pas une fois qu'il est livré. L'Exposure Clock montre exactement combien de vulnérabilités, y compris celles exploitables depuis l'extérieur, sont apparues depuis votre dernière évaluation.

No items found.
Tendances des menaces
-
3
mins read
-
August 6, 2026

What is CTEM? The 5 stages explained

-
- -
What is CTEM? The 5 stages explained

CTEM (continuous threat exposure management) is a five-stage cybersecurity framework introduced by Gartner in 2022. It helps organizations continuously scope, discover, prioritize, validate, and mobilize against exposures across their attack surface. Unlike a periodic vulnerability scan that produces a report and a backlog, CTEM is an ongoing cycle aligned to business risk rather than a one-time project.

What is CTEM (continuous threat exposure management)?

CTEM is a program and operating model, not a product you buy. Gartner defines it as a set of processes and capabilities that let an organization continually evaluate the accessibility, exposure, and exploitability of its digital and physical assets. The point is to move security from a point-in-time activity, where a team runs a scan, hands IT a list, and waits, to a repeating cycle that keeps pace with a changing environment.

The reason CTEM exists is that most breaches no longer start with a neatly cataloged software flaw. They start with a misconfiguration, a leaked credential, an over-permissioned identity, or an exposed asset no one was tracking. Verizon's 2025 Data Breach Investigations Report found that exploitation of vulnerabilities as an initial access step rose to 20% of breaches, a 34% increase in a single year. CTEM widens the lens beyond CVEs to the full range of exposures an attacker can use, and it insists on testing whether those exposures are actually reachable.

Practitioners often describe the framework as two phases. The first three stages, scoping, discovery, and prioritization, form the diagnosis. The last two, validation and mobilization, turn that diagnosis into action.

What are the 5 stages of CTEM?

The five stages of CTEM are scoping, discovery, prioritization, validation, and mobilization. They run as a continuous loop, where the output of each stage feeds the next and the lessons from mobilization sharpen the next round of scoping.

Stage What happens Output
1. Scoping Define what the program protects, based on business impact and likely attack paths, not technology silos An agreed scope tied to risk appetite
2. Discovery Find assets and exposures across that scope: vulnerabilities, misconfigurations, identity risks, shadow IT, and leaked credentials A full inventory of exposures
3. Prioritization Rank exposures by real risk, using exploitability, business context, and attack-path reachability rather than severity scores alone A short list of what to fix first
4. Validation Confirm which exposures an attacker could genuinely reach and exploit, and whether existing controls hold Evidence of real, exploitable risk
5. Mobilization Coordinate people and processes to remediate, with clear ownership and communication Reduced exposure, and lessons that feed the next cycle

Scoping comes first because you cannot assess everything at once. This stage identifies the business services, assets, identities, and data that matter most, along with the attack scenarios most relevant to them. Gartner's guidance is to scope around threat vectors or business projects, such as the external attack surface, rather than a single piece of infrastructure.

Discovery then finds what is actually exposed inside that scope. It goes well beyond scanning for known CVEs to capture misconfigurations, identity and permission risks, shadow IT, and exposed credentials across on-premises, cloud, and internet-facing systems.

Prioritization narrows the field. No team can fix everything, so exposures are ranked by the risk they carry in context, weighing how reachable and exploitable each one is against the value of the asset behind it. A high-severity flaw on an isolated system can matter less than a moderate one on a public-facing application.

Validation is the stage most programs skip, and the one that separates CTEM from a longer to-do list. It confirms whether a prioritized exposure is genuinely exploitable, how an attacker would chain it, and whether current controls would stop them. Validation is what turns a list of theoretical issues into evidence of real risk.

Mobilization closes the loop by turning findings into fixes. It depends on clear ownership, communication, and workflow rather than technology alone. Gartner has noted that security leaders who build cross-team mobilization into their exposure program gain 50% more security optimization than those relying only on automated remediation.

CTEM vs vulnerability management: what's the difference?

CTEM and vulnerability management are related but not the same. Vulnerability management starts from a known list of assets and asks which carry software flaws that need patching. CTEM starts from business risk, covers a broader set of exposures, and adds validation so teams act on what is real rather than on raw severity.

Vulnerability management CTEM
Scope Known assets and their CVEs All exposures: CVEs, misconfigurations, identity risks, shadow IT
Cadence Point-in-time scans Continuous, repeating cycle
Prioritization Severity scores (CVSS) Exploitability, business context, attack-path reachability
Core question Which flaws need patching? Which exposures actually put the business at risk?

The two are complementary. Vulnerability management remains essential for the systems you already track, while CTEM supplies the scope, validation, and business context that a list of CVEs cannot.

How does agentic AI operationalize the validation stage?

Validation is where CTEM tends to stall, because confirming exploitability by hand does not scale to a surface that changes daily. This is where automation, and specifically agentic AI, changes the economics. Agentic AI can run real attacker techniques against exposures across a large environment on an ongoing basis, confirming which ones are reachable and chaining them the way an attacker would, rather than assuming every finding is urgent.

That validation depends on good discovery, which is why external attack surface management feeds the front of the cycle. Our guide to external attack surface management covers the discovery layer, and our breakdown of automated penetration testing explains how attacker techniques are run at scale to validate exposures.

How do you start a CTEM program?

Start narrow. Gartner's own advice is to run a focused first cycle rather than trying to cover everything, and the external attack surface is a natural place to begin because it is what an attacker sees first. Scope that surface, discover what is exposed, prioritize by real risk, validate what is exploitable, and mobilize the fixes, then repeat and widen the scope as the program matures.

The payoff is measurable over time. Gartner predicted that organizations prioritizing their security investments around a CTEM program would be three times less likely to suffer a breach by 2026. The value is not in generating more findings; it is in continuously reducing the exposures that genuinely put the business at risk.

{{related-article}}

What is CTEM? The 5 stages explained

{{quote-1}}

,

{{quote-2}}

,

Articles associés.

Tous les articles

Recherche

Beyond EPSS: Redefining Validation in CTEM

Beyond EPSS: Redefining Validation in CTEM

Solutions de sécurité

Why automated penetration testing is essential for CTEM

Why automated penetration testing is essential for CTEM

Related articles.

All resources

Tendances des menaces

The good, the bad, and the ugly of your exposure management programme

The good, the bad, and the ugly of your exposure management programme

Tendances des menaces

Attack surface management: how it works and where it fits

Attack surface management: how it works and where it fits

Tendances des menaces

What is the attack surface in cybersecurity?

What is the attack surface in cybersecurity?

get a 15 min demo

Start your journey today

Hadrian’s end-to-end offensive security platform sets up in minutes, operates autonomously, and provides easy-to-action insights.

What you will learn

  • Monitor assets and config changes

  • Understand asset context

  • Identify risks, reduce false positives

  • Prioritize high-impact risks

  • Streamline remediation

The Hadrian platform displayed on a tablet.
No items found.