Tooling advanced

CTEM: Real Security Program or Vendor Rebrand?

CTEM is not new, the integration is genuinely valuable, and the 'CTEM platform' is mostly rebranded BAS/ASM/RBVM. Buy the operating model, not the acronym.

· 14 min read · Gowthamaraj Rajendran

Every acronym Gartner ships arrives with the same two reactions, and both are wrong. Vendors say it’s a new category and quote you a platform price. Skeptics say it’s the same old scanning with a fresh logo and roll their eyes. Continuous Threat Exposure Management is getting both treatments right now, and neither is honest, because the useful answer requires separating three questions that the marketing deliberately blurs into one.

The three questions: Is the practice new? Is the integration valuable? Is the product category real? They have different answers (no, yes, and mostly-no) and if you collapse them into a single yes or no you will either overpay for a “CTEM platform” you already own the parts of, or dismiss the one genuinely underserved capability the framework points at. This is the same analytical move I made about non-human identity security in The Category Is Consolidating Before It Learned to Detect: the label is not the thing, and buying the label instead of the thing is the expensive mistake.

Let me take the three questions in order.


Question 1: Is the practice new? No.

CTEM is a five-stage loop: Scoping, Discovery, Prioritization, Validation, Mobilization [1][2]. Read the stages honestly and every one of them is a discipline that existed, had its own tools, and had its own conference track before Gartner named the loop in July 2022 [1].

  • Scoping is asset management and business-criticality mapping. Decades old.
  • Discovery is attack surface management and vulnerability discovery: ASM and vuln scanning.
  • Prioritization is risk-based vulnerability management. RBVM as a term predates CTEM, and even the vendors admit RBVM maps essentially to this one stage [3].
  • Validation is breach-and-attack simulation, automated pentesting, and purple teaming: proving an exposure is actually exploitable rather than theoretically present.
  • Mobilization is remediation ownership and workflow: the part everyone has always been bad at.

Gartner is unusually candid about this. Their own framing is that CTEM “is a program that reduces cyber security exposures via five stages,” explicitly “rather than a particular product or service” [2]. That sentence is the whole tell. CTEM is not a new capability. It is a named arrangement of existing capabilities into a continuous cycle. The novelty is the ordering and the word “continuous,” not the ingredients.

So when a vendor tells you CTEM is a new frontier you need net-new tooling for, they are describing a repackaging as a discovery. Hold that thought. It matters most for Question 3.


The “3x” that was never measured

There is one number you will see on every CTEM landing page, and it deserves its own paragraph because it is the load-bearing stat for the entire market and it is not what it looks like.

In the 2022 research that introduced the term, Gartner predicted that organizations prioritizing their security investments through a CTEM program would be “three times less likely to suffer a breach by 2026” [1]. Read that carefully. It is a forward-looking prediction made in 2022 about 2026: an analyst’s directional bet, not a measured outcome. To my knowledge no independent study has ever gone back and tested it. There is no cohort of CTEM adopters and non-adopters with a validated 3-to-1 breach ratio between them. The number is a projection that got quoted so many times it started to sound like a finding.

This is the exact failure I wrote about in Your Threat Intel Program Is Measuring the Wrong Thing: a headline metric that everyone repeats and no one instrumented. The honest version of the claim is “an analyst firm predicted a large risk reduction and it sounds plausible.” That is a very different sentence from “CTEM makes you 3x safer,” and the gap between those two sentences is where a lot of budget gets approved. When you evaluate CTEM, throw the 3x out entirely. It is not evidence. It is marketing that borrowed an analyst’s authority.

What does have data behind it is adoption, and that data is the strongest argument for Question 2.


Question 2: Is the integration valuable? Yes, and this is the honest half.

Here is where the skeptics go wrong. “It’s all pre-existing disciplines” is true and also misses the point, because the disciplines pre-existed in separate silos that never talked to each other. Your vuln management team runs Prioritization. Your red team runs Validation. A cloud or ASM team runs Discovery. They report to different leaders, use different tools, and, critically, do not share a prioritization model. The vuln team’s “critical” and the red team’s “actually exploitable” are different lists, and nobody reconciles them.

CTEM’s real contribution is that it forces those functions into one loop with one prioritization spine. And the adoption data says almost nobody has actually done this. In 2026 research across 128 enterprise security decision-makers, 87% recognized CTEM’s importance but only 16% had operationally implemented it [4]. That 71-point gap is the whole story. This is not a mature practice with a new name slapped on. It is a widely-endorsed operating model that the overwhelming majority of organizations have never actually run, because running it means breaking down silos that org charts defend.

Two parts of the loop are where the integration pays off, and both connect directly to detection engineering.

Prioritization by exploitable attack path, not CVSS. The genuine upgrade RBVM-inside-CTEM makes is ranking exposures by whether they sit on a real path to a crown-jewel asset (attack-path analysis and choke-point identification) rather than by a static severity score [3]. This is precisely the blast-radius thinking I argued for in Identity Creep: Instrument the Blast Radius: what matters is not that a weakness exists but what it lets an attacker reach. A CVSS 9.8 on an isolated box with no path to anything is noise; a CVSS 6 on a choke point every attack path traverses is the one to fix first.

Mobilization is the genuinely underserved stage. This is the part I want detection and program owners to hear. Of the five stages, Mobilization (actually getting validated exposures remediated by the teams that own the assets) is consistently the one that kills programs, because it depends on organizational accountability the security team does not control. Scope, discover, prioritize, and validate flawlessly, and you still fail if the ticket ping-pongs between teams for three weeks because nobody owns the asset. Every other stage has a dozen well-funded vendors. Mobilization has almost none, because it is a process-and-ownership problem, not a scanning problem, and process problems don’t have a SKU. If CTEM does one thing for your program, let it be forcing a named owner and an SLA onto remediation. That is the part the acronym is actually good for.

So: the integration is real, the silo-breaking is real, and mobilization is a genuine gap the framework usefully names. That is the honest half of the verdict, and I concede it fully. Now the uncomfortable half.


Question 3: Is the product category real? Mostly not.

There is no such thing as a “CTEM tool” the way there is a firewall or an EDR. CTEM is a program that spans five disciplines. No single product does all five well. So watch what actually happens when you shop for a “CTEM platform”: every vendor maps the product they already sold you last year onto the five stages and calls the result CTEM. The heritage shows through the paint every time.

  • XM Cyber was an attack-path and choke-point company. Its CTEM story is attack-path analysis reframed as Prioritization-plus-Validation [3]. Good product. Same product.
  • Cymulate is breach-and-attack-simulation heritage. It literally markets itself as “putting the T in CTEM,” which is an admirably honest way of saying its BAS engine is the Validation stage and the rest is positioning [5].
  • Pentera is automated penetration testing. In CTEM language, automated pentest is the Validation stage’s execution engine: real attacks against reachable assets, chained into paths [6]. The product didn’t change; the stage got a name.
  • Tenable One is vulnerability management and ASM unified into an exposure platform, now narrated across all five stages [7]. It’s the RBVM/ASM incumbent claiming the whole loop.
  • CrowdStrike Falcon Exposure Management is exposure and vulnerability management riding on the agent telemetry CrowdStrike already collects, mapped to continuous exposure evaluation [8]. Real capability, entirely built from the existing platform.

None of these are bad tools. Several are excellent at their heritage discipline. The point is that “CTEM platform” is not a product category with new capabilities. It is a marketing overlay that BAS, ASM, RBVM, and pentest vendors each apply to the product they already had, extended one or two stages in whichever direction their heritage makes cheapest. This is the identical move I dissected in the NHI landscape: a label stretched over several genuinely different products, sold as one unified thing, so that buyers purchase a category and discover they bought a feature. Buy XM Cyber for attack paths because it’s a great attack-path tool, not because it “is CTEM.” The acronym should never be the reason.


The steelman: “CTEM is explicitly not a rebrand”

The strongest counterargument comes from the people who built the framework and the practitioners who run it well, and it deserves a straight answer rather than a dunk.

The Gartner authors (Jeremy D’Hoinne, Pete Shoard, Mitchell Schneider) were emphatic that CTEM is an operating model, not a product, and pointed at exactly the silo problem I described above [1][2]. Practitioners echo it. Filigran, writing skeptically about the hype, still argues CTEM is fundamentally an internal operating model and not a tool vendors can “deliver,” and puts the real problem plainly: “very few programs today go beyond visibility and run a continuous, threat-led loop” [9]. Their case: even if every ingredient pre-existed, most organizations never integrated them (vuln management, red team, and ASM lived on different teams with no shared prioritization) and a Gartner-named framework gives a CISO the language and the budget line to consolidate those silos and finally own mobilization. On this view the label is the alignment mechanism, and alignment is the actual bottleneck, not tooling. Naming the loop is what gets it funded.

That argument is largely correct, and I’ve already conceded most of it in Question 2: the consolidation value is real and it is the honest half of this verdict. But concede it fully and the novelty claim still doesn’t survive, for one reason: naming a loop does not make the loop happen. The 16% implementation rate is the proof [4]. Four years of a well-marketed, budget-attracting Gartner acronym, and five in six organizations still haven’t run the program. If the label were the alignment mechanism, alignment would be further along than one org in six. The label helps CISOs ask for consolidation; it does not perform the consolidation, and it does not build the integration. That is still organizational work no acronym does for you.

And here is the part the steelman can’t wave off. The exact critique the industry now levels at legacy vulnerability management (polished diagrams over rebranded scanning) applies word-for-word to the “CTEM platform” market. The same vendors who sold you RBVM and BAS are selling you CTEM, with the same engines and better slides. Conceding that the operating model is valuable does not oblige you to accept that the product category is new. Those are Question 2 and Question 3, and keeping them separate is the entire discipline of buying this well.


What a detection team does Monday

Most CTEM writing stops at the strategy layer and never tells a detection engineer what changes on their queue. Here is the payload competitors leave out: CTEM stages 3 and 4 are a purple-teaming feedback loop, and that loop should feed your detection coverage directly.

Validation is where a BAS or automated-pentest engine proves an exposure is exploitable. That same execution is a detection test. When Pentera or Cymulate chains a real attack path through your environment [5][6], the question for the SOC is not only “is this exposure real” but “did we generate a detection when the technique ran, and did it fire?” Every validated attack path is a labeled adversary emulation you can measure your detection catch rate against. Wire the Validation stage’s output into your detection backlog and stage 4 stops being a vuln-team artifact and becomes the coverage-gap generator I described in The Detection Funnel: it tells you exactly which techniques ran unseen. That handoff, Validation to detection coverage, is the most valuable thing a detection team can extract from a CTEM program, and almost nobody wires it up.

So concretely, Monday: (1) get your team a seat at the Validation stage and treat every simulated attack path as a detection test with a pass/fail; (2) push Prioritization to rank by exploitable attack path and blast radius, not CVSS, so the exposures you build detections for are the ones that actually reach crown jewels; and (3) if you own program strategy, put a named owner and an SLA on Mobilization, because that is the stage with no vendor coming to save you.


The verdict

Buy the operating model. Don’t buy the “CTEM platform” as if it were a new category.

The practice is not new. It’s a named arrangement of RBVM, ASM, BAS, and purple teaming you already recognize. The integration is genuinely valuable: most organizations never broke down these silos, only 16% run the loop, and mobilization is a real gap the framework usefully forces you to own. The product category is mostly a rename: XM Cyber, Cymulate, Pentera, Tenable One, and CrowdStrike each map their existing product onto the five stages, and every one is worth buying for what it actually is rather than for the acronym it now wears.

Pay for the discipline, not the acronym. Adopt the loop, wire Validation into your detection coverage, put a name on remediation, and buy each tool for its heritage strength with clear eyes about which stage it really covers. And when a rep tells you their platform “is CTEM,” remember that’s the same sentence legacy VM vendors used to say their scanner was a security program. It wasn’t then. It isn’t now. The loop is real; the platform is a label. Buy the first one.


Resources

  1. Implement a Continuous Threat Exposure Management (CTEM) Program. Gartner, 21 July 2022 (doc 4016760; authors Jeremy D’Hoinne, Pete Shoard, Mitchell Schneider). Introduced the CTEM term and five stages. The often-quoted “three times less likely to suffer a breach by 2026” is a 2022 forward-looking prediction, not an independently measured outcome. Treat it as an analyst projection, not evidence.
  2. CTEM 101: Go Beyond Vulnerability Management with Continuous Threat Exposure Management. The Hacker News (renders the five stages; “CTEM is a program… rather than a particular product or service”).
  3. CTEM vs. Risk-Based Vulnerability Management. XM Cyber (RBVM maps to the Prioritization stage; attack-path and choke-point prioritization).
  4. The CTEM Divide: Market Research. Reflectiz, 2026 (128 enterprise decision-makers: 87% recognize CTEM’s importance, only 16% have operationally implemented it).
  5. Cymulate CTEM Platform: Exposure Validation and Prioritization. Cymulate (breach-and-attack-simulation heritage; “putting the T in CTEM”).
  6. Pentera: Security Validation Platform. Pentera (automated penetration testing as the Validation stage’s execution engine, chaining real attack paths).
  7. Tenable One Exposure Management Platform. Tenable (vulnerability management and ASM unified across the five CTEM stages).
  8. CrowdStrike Falcon Exposure Management: Make CTEM Real Time. CrowdStrike (exposure/vulnerability management built on existing agent telemetry, mapped to continuous CTEM).
  9. CTEM, But Without the Hype: Turning Intel and Validation Into Outcomes. Filigran (“very few programs today go beyond visibility and run a continuous, threat-led loop”; CTEM as an internal operating model, not a tool vendors deliver).