The reference desk / In practice

CTEM

A program for repeatedly finding, prioritizing, and reducing exposed attack surface rather than running a yearly scan.

Continuous threat exposure management

What it means

CTEM is a recurring program for understanding and reducing exposures that matter to the organization. The term comes from Gartner’s research, but the practical work depends on people, ownership, and follow-through rather than a particular purchase. It broadens attention beyond a periodic list of software flaws to include configurations, identity permissions, business services, and plausible attack paths. Continuous means regularly revisiting the problem as conditions change; it does not require testing every asset every second or conducting unrestricted attacks against production.

AN ILLUSTRATIVE SCENARIO

Protecting a manufacturer’s remote maintenance service

A manufacturer starts with remote maintenance because its loss or misuse could disrupt production. The team discovers related gateways, accounts, and vendor access, prioritizes the most consequential paths, and validates assumptions through approved configuration checks and limited tests. The plant owner then schedules changes and confirms their effect. Next month, a new maintenance supplier changes the scope, so the team repeats the assessment instead of filing the old report as finished.

Put it to work

  1. Choose a meaningful business service and agree its boundaries, owners, and desired outcomes. Identify the systems, identities, and dependencies that make the service work.
  2. Find and prioritize exposures using reachability, credible threat information, and business impact. Validate important assumptions with safe, authorized methods suited to the environment.
  3. Assign treatment work, remove blockers with asset owners, and verify the result. Review recurring causes and repeat the cycle when services, access, or threats change.

How to check your work

Follow one significant exposure from discovery through an owned decision to verified improvement. Explain what changed for the business service, which assumptions were checked, and how the team will notice if the same condition returns.

Connect the ideas

  • ASM

    The ongoing discovery, assessment, and reduction of ways an attacker could reach or affect an organization’s assets. Its scope may include external, internal, and cloud environments.

  • Exposure

    Whether and how a vulnerability or service can actually be reached in this environment.

  • Risk

    The potential for harm, assessed using what could happen, how likely it is, its impact, and what remains uncertain.

  • Patch

    A vendor or internal change that removes or reduces a vulnerability in running software.

Explore a field lesson

Find your next idea.

Tip: press / to open search. Escape closes this window.