# What is Continuous Threat Exposure Management (CTEM)?

> Continuous threat exposure management (CTEM) is a Gartner-defined, recurring program model for identifying, prioritizing, validating, and reducing exposures that could harm important business services.

- Canonical URL: https://yellowcube.eu/glossary/continuous-threat-exposure-management/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

The model comprises five stages: scoping, discovery, prioritization, validation, and mobilization. “Continuous” describes an ongoing, repeated management cycle; it does not necessarily mean nonstop scanning or automatic remediation.

CTEM treats exposure more broadly than a list of software vulnerabilities. It can include unsafe identities, cloud misconfiguration, reachable attack paths, exposed services, weak controls, supplier dependencies, and other conditions an attacker could use. Prioritization should combine technical evidence with business importance and current threat information.

### Key points

- **Scoping:** Choose business services, assets, boundaries, and measurable outcomes.
- **Discovery and prioritization:** Find relevant exposures and rank them using reachability, exploitability, threat activity, control context, and impact.
- **Validation:** Gather proportionate evidence that a priority exposure or attack path is plausible and that expected defenses work. This may use configuration evidence, safe emulation, manual assessment, or authorized penetration testing; it does not require exploiting every weakness in production.
- **Mobilization:** Assign decisions, remove blockers, remediate, accept or transfer risk, and verify closure.
- **Important limitation:** CTEM is not a product purchase; discovery without ownership and remediation simply creates another backlog.

### Related terms

[Attack surface management (ASM)](<https://yellowcube.eu/glossary/attack-surface-management/>) · [Breach and attack simulation (BAS)](<https://yellowcube.eu/glossary/breach-and-attack-simulation/>) · [Vulnerability management](<https://yellowcube.eu/glossary/vulnerability-management/>) · [Cyber risk](<https://yellowcube.eu/glossary/cyber-risk/>) · [Penetration testing](<https://yellowcube.eu/glossary/penetration-testing/>)

### Sources

[Gartner: Strategic Roadmap for CTEM](https://www.gartner.com/en/documents/6884566) · [CISA: Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) · [FIRST: Exploit Prediction Scoring System](https://www.first.org/epss/)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

