What is CTEM? A Complete Guide to the 5 Phases

PentaTrail Team···11 min read
Contents

CTEM (Continuous Threat Exposure Management) is a security framework introduced by Gartner in 2022. It describes discovering, assessing, and remediating an organization's attack surface continuously, from the attacker's perspective.

The goal — fewer exploitable weaknesses — is the same as traditional vulnerability management. The shape of the work is not.

01 / CTEM widens the scope and the decision material, and keeps five steps cycling

Vulnerability management has commonly centred on periodic scanning of known assets and remediation. CTEM broadens both the scope and the material the decision rests on, including redrawing the scope from the attacker's side, and the five steps keep cycling.

A common traditional cycle and CTEM side by side. The traditional path runs scan, find, patch in a straight line and stops there. CTEM runs scope, find, rank, validate, act, with an arrow returning from the last step to the first so the cycle keeps going

Figure 1: An operation that reaches a milestone, against one that keeps cycling

02 / Each of the five steps produces something different

Set the scope, find the assets, rank them, test what is really exploitable, drive the fix. The single phrase "vulnerability management" hides the fact that each step hands over a different deliverable.

The five CTEM steps mapped to what each one produces. Setting the scope produces the assets and business scope, finding the assets produces domains IPs and technologies, ranking produces TER bands, testing for real produces confirmed versus unconfirmed findings, and driving the fix produces tasks with an owner

Figure 2: Each CTEM step, and what PentaTrail hands over at it

Deep dive: what each step actually involves

1. Scoping. Define the assets and business risks that need protection, going beyond IT assets to include SaaS applications, cloud environments, and supply chain dependencies. In PentaTrail this means registering your origin domains and applying BI tags (purpose, data classification, availability) to each asset. See Business Impact (BI) Score for details.

2. Discovery. Automatically discover all assets within the defined scope — domains, subdomains, IP addresses, ports, technologies, cloud storage, and anything else an attacker could find. Previously unmanaged assets that surface here are visualised as shadow IT risk. See ASM: A Beginner's Guide and Shadow IT.

3. Prioritization. Assign priority to discovered threats based on business impact and exploitability. PentaTrail derives the TDL (Threat Discovery Level) from CVSS and EPSS, derives the BI Score from asset tags, and combines both into the TER band (S/A/B/C/D). See TER, TDL, and CVSS, EPSS, and KEV.

4. Validation. Verify whether high-priority threats are actually exploitable. PentaTrail's AI Deep Scan combines industry-standard detection templates with AI guidance to actively validate high-priority findings, classifying them as confirmed or unconfirmed. Results feed back into the TER band in two directions: confirmed findings retain Evidence Grade A, and unconfirmed findings get their TDL lowered by one level.

5. Mobilization. Execute remediation based on validation results. PentaTrail generates AI remediation guidance per finding and breaks the work into tasks assigned to owning groups and individuals. Executives receive a weekly AI-summarised insight that surfaces remediation progress and shifts in risk posture at a glance.

03 / Five things change: perspective, scope, frequency, prioritisation, validation

Five things separate it from the typical operation. It looks from outside as an attacker rather than scanning from within, and covers cloud and SaaS rather than only known IT assets. It runs continuously rather than quarterly, weighs business impact rather than CVSS alone, and establishes exploitability rather than stopping at scan output.

Five axes on which CTEM differs from conventional vulnerability management. Perspective moves from inside to an attacker's eye, scope from known IT assets to cloud and SaaS, frequency from quarterly to continuous, prioritisation from CVSS alone to business impact as well, and validation from none to confirming exploitability

Figure 3: What swaps places on each of the five axes (the full comparison is in the appendix)

04 / What made it necessary is that the ground to defend moved outside

Cloud migration, remote work, and SaaS adoption pushed what has to be defended past the internal network. Keep defending the perimeter alone and the count of assets nobody tracks simply grows.

Two views of what has to be defended. Before, everything sat inside the internal network boundary. Now it spreads across cloud, SaaS, remote endpoints, and supplier connections, most of which is unlisted

Figure 4: The ground to defend spread outward, and most of the new ground is unlisted

The window between disclosure and exploitation is also shrinking year by year, which quarterly scanning cannot keep pace with (exposure windows have closed). Since treating every vulnerability with equal urgency is not affordable either, the work is to identify what is genuinely dangerous and concentrate limited people there.

05 / PentaTrail carries a capability for each of the five steps

PentaTrail/CTEM is designed around this framework, running scope registration, discovery, TER-band prioritisation, AI Deep Scan validation, and AI remediation guidance with owned tasks as one service.

The five CTEM steps against the PentaTrail capability that covers each. Scoping is origin domain registration and BI tagging, discovery is automatic subdomain discovery and shadow IT, prioritisation is the TER band, validation is the AI deep scan, and mobilisation is AI remediation guidance and remediation tasks

Figure 5: The capability that covers each step (deep-dive articles are in the appendix)

To get started with continuous attack surface management, start your 14-day free trial.

Appendix: the full comparison, and capabilities by step

Table 1: CTEM against traditional vulnerability management

Aspect Traditional VM CTEM
Approach Internal scanning Attacker's perspective
Scope Known IT assets All assets including shadow IT, cloud, SaaS
Frequency Periodic (monthly/quarterly) Continuous, real-time
Prioritization CVSS score-based Business impact + exploitability
Validation None (scan results only) Actual exploitability testing
Response Patch-centric Cross-functional mobilization

The left column describes a typical operation, not a definition of vulnerability management. Programmes built around periodic scanning may well include prioritisation and validation of their own.

Table 2: PentaTrail capabilities by step, with deep-dive articles

Phase Main PentaTrail capabilities Related articles
Scoping Origin domain registration, BI tagging on assets (purpose, data classification, availability) BI Score
Discovery Automatic subdomain discovery, port and technology stack detection, shadow IT visualization ASM Beginner's Guide / Shadow IT
Prioritization TER bands (S/A/B/C/D), TDL, BI Score, KEV boost, Evidence Grade TER / TDL / CVSS, EPSS, KEV
Validation AI Deep Scan, TDL adjustment based on confirmed/unconfirmed status AI Deep Scan
Mobilization AI Remediation guidance, task management, AI weekly insights (Dedicated article to follow)

Visualize your attack surface with PentaTrail CTEM/ASM

From discovery to vulnerability validation and remediation — all powered by the CTEM framework.

Get Started

See pricing/Compare and choose