What Is CTEM? Exposure Management and Attack Surface Management
What is CTEM? Learn attack surface management, the five CTEM stages, exposure management vs vulnerability management, key metrics and how to get started.
By NetGuardUpdated: 7 min readنسخه فارسی

CTEM (Continuous Threat Exposure Management) is an ongoing program, described by Gartner, that helps organizations find, prioritize, validate and fix the exposures attackers could actually use. It builds on attack surface management, the continuous discovery of everything an attacker can reach: forgotten subdomains, services exposed to the internet, expired certificates and servers nobody owns.
Why does it matter? Classic vulnerability management only sees assets that are already in the inventory, and it usually produces a long list of CVEs ranked by severity. Many intrusions start with things that are in no inventory at all. CTEM closes that gap by looking from the outside in, prioritizing by real-world threat and adding validation, so effort goes where risk actually is.
What is attack surface management?
The attack surface is the sum of all assets, services, identities and configurations an attacker could reach. External attack surface management (EASM) focuses on the part visible from the internet and asks one question: what can an attacker see of us from outside?
What the external attack surface includes
- Shadow IT: a test server spun up by developers, a cloud service a department bought without telling IT, or an admin panel opened "temporarily" and never closed.
- Forgotten subdomains: a subdomain whose DNS record still points to a deleted cloud resource can lead to subdomain takeover. Certificate Transparency logs often reveal subdomains IT does not know about.
- Exposed services: RDP, SSH, database ports, device management panels and unauthenticated APIs that should never face the internet directly.
- Expired or weak certificates: an expired TLS certificate causes outages and is a strong sign of an unowned asset; outdated protocols and ciphers belong to the same problem.
- Outdated, vulnerable versions: unpatched web servers, VPNs and edge devices, which are frequently the first target.
A few quick command-line checks
For an initial look at assets you own, these commands are useful. Only port-scan assets you own or have written permission to test.
# TLS certificate expiry date for a host
echo | openssl s_client -connect www.example.com:443 -servername www.example.com 2>/dev/null | openssl x509 -noout -enddate
# Where an old subdomain's CNAME points (possible subdomain takeover)
dig +short CNAME old.example.com
# Common open ports on an address you own
nmap -Pn --top-ports 100 203.0.113.10
Manual checks are a good start, but the attack surface changes daily. Without continuous, automated discovery your picture goes stale quickly.
What is CTEM?
CTEM is not a tool; it is a program. An "exposure" is broader than a vulnerability: anything that makes an attack path possible, from an unpatched CVE to a misconfiguration, excessive access or a service that should not be on the internet. CTEM manages exposures in a repeating cycle, each round focused on a defined slice of the business.
The five CTEM stages

1. Scoping
Rather than "everything", pick a scope that matters to the business, such as the external attack surface, the payment environment or Active Directory. The scope should be meaningful to executives.
2. Discovery
Identify assets, vulnerabilities, weak configurations and risky identities within that scope, including assets that appear in no inventory.
3. Prioritization
Severity alone is not enough. Known exploitation (such as the CISA KEV catalog), exploitation probability (EPSS), asset criticality, internet exposure and compensating controls all count. Our article on CVSS, EPSS and KEV explains these signals.
4. Validation
Confirm whether an attacker could really use the exposure, what the impact would be and whether existing controls stop it. Penetration testing and attack simulation belong here; see vulnerability assessment vs penetration testing.
5. Mobilization
Hand findings to the owning teams, make approval and exception paths clear, and confirm fixes with a rescan. Without this stage, even the best prioritization stays on paper.
Exposure management vs vulnerability management
CTEM does not replace the vulnerability management lifecycle; it contains it and widens its scope and purpose.
| Dimension | Classic vulnerability management | Exposure management (CTEM) |
|---|---|---|
| Scope | Known, inventoried assets | Entire attack surface, including unknown and external assets |
| Finding types | Mostly CVEs | CVEs, misconfigurations, identity and access, exposed services, certificates |
| Prioritization | Mostly CVSS severity | Real exploitation, asset criticality and attack paths |
| Validation | Usually not part of the process | A formal stage of the cycle |
| Output | Long list of findings | Short list of material exposures with clear owners |
| Ownership | Security or infrastructure team | Shared across security, IT, development and business |
| Cadence | Periodic scans | Continuous cycle over successive scopes |
Metrics for an exposure management program
Without metrics you cannot tell whether CTEM is working. These are good starting points:
- Unowned external assets: assets discovered but missing from the official inventory; a falling trend means better control of shadow IT.
- Mean time to remediate (MTTR) critical exposures, especially on internet-facing assets.
- Exposure window for exploited vulnerabilities: the time between a KEV-listed vulnerability being found on your asset and its fix.
- SLA compliance: the share of exposures fixed within the agreed deadline.
- Recurrence rate: findings that come back after being fixed, usually a sign of missing secure baselines and durable hardening.
- Expired or soon-to-expire certificates: a simple indicator of asset management maturity.
How to get started
- Pick a small, valuable first scope. The external attack surface is usually best, because attackers start there too.
- Discover external assets. Find domains, subdomains, IP addresses, open ports and certificates, and compare them with the official inventory.
- Assign an owner to every asset. Unowned assets are either handed to a team or shut down.
- Assess vulnerabilities and configuration. Run vulnerability scans and hardening audits on what you discovered.
- Prioritize by risk. Use real exploitation and asset criticality, not severity alone.
- Validate the important items and define remediation SLAs and an exception path.
- Report to leadership and start the next scope, such as Active Directory or your cloud environment.
How NetGuard helps with exposure management
NetGuard supports the discovery, prioritization and follow-up stages of CTEM: external attack surface discovery of domains, subdomains, open ports and TLS certificates; authenticated and unauthenticated vulnerability scanning; web application and API scanning; configuration audits against CIS Benchmarks; cloud misconfiguration and Kubernetes checks; and prioritization based on known-exploited vulnerabilities, public exploits and asset criticality. Rescans verify fixes, and reports are available in English and Persian. Learn more on the platform page or contact us.
Frequently asked questions
What is CTEM?
CTEM, or Continuous Threat Exposure Management, is a program described by Gartner for managing security exposures in a continuous cycle. The cycle has five stages: scoping, discovery, prioritization, validation and mobilization. Its goal is to focus effort on exposures that are actually exploitable and have business impact, rather than working through an ever-growing list of every finding.
What is attack surface management?
Attack surface management is the continuous discovery, inventory and monitoring of every asset and service an attacker could reach. External attack surface management (EASM) looks at the organization from the internet and finds forgotten subdomains, exposed services, expired certificates and shadow IT. In practice it forms the discovery stage of a CTEM program.
What is the difference between exposure management and vulnerability management?
Classic vulnerability management focuses mainly on CVEs in known assets, ranked by CVSS severity. Exposure management widens the scope to unknown assets, misconfigurations, identities and exposed services, prioritizes by real exploitation and asset criticality, and formally adds validation and team mobilization to the process. Vulnerability management is part of CTEM, not a competitor to it.
Is CTEM a product?
No. CTEM is a program and a management approach, and no single product covers every stage on its own. Organizations typically combine attack surface discovery, a vulnerability scanner, configuration auditing, penetration testing or attack simulation, and management processes such as SLAs and reporting. Getting the scope right and involving asset-owning teams matter more than the tooling.
How do I start with attack surface management?
Start with the external attack surface. Discover all domains, subdomains, IP addresses, open ports and TLS certificates and compare them with your official asset inventory. Assign an owner to every asset, shut down what nobody uses, and run vulnerability scans and configuration audits on the rest. Then add risk-based prioritization and remediation SLAs.
- #what is CTEM
- #continuous threat exposure management
- #exposure management vs vulnerability management
- #attack surface management
- #EASM
- #external attack surface




