[{"data":1,"prerenderedAt":166},["ShallowReactive",2],{"wissen-en-continuous-threat-exposure-management":3,"wissen-related-en-continuous-threat-exposure-management":156},{"id":4,"title":5,"body":6,"description":135,"extension":136,"lang":137,"meta":138,"navigation":139,"path":140,"related":141,"seo":146,"short":147,"sitemap":148,"stem":149,"synonyms":150,"updated":154,"__hash__":155},"wissenEn\u002Fen\u002Fwissen\u002Fcontinuous-threat-exposure-management.md","Continuous Threat Exposure Management (CTEM)",{"type":7,"value":8,"toc":123},"minimark",[9,13,18,21,25,60,63,67,70,74,77,81,84,88,91,95],[10,11,12],"p",{},"Continuous threat exposure management (CTEM) is a programme described by Gartner in 2022 that continuously reduces a company's attack surface in five repeating phases: scoping, discovery, prioritisation, validation and mobilisation. CTEM is not a product but a way of working that binds tools such as attack surface management, vulnerability scanners, dark web monitoring and penetration tests into one shared cycle.",[14,15,17],"h2",{"id":16},"why-ctem-matters","Why CTEM matters",[10,19,20],{},"Classic vulnerability management produces long lists of CVSS scores that hardly anyone can work through. At the same time, risks outside the CVE world remain invisible: misconfigurations, exposed identities, leaked credentials, unprotected cloud resources. CTEM addresses both problems. It widens the view from \"vulnerabilities\" to \"exposure\", meaning everything attackers could exploit, and forces prioritisation by actual exploitability and business impact instead of raw severity. Gartner predicts that organisations aligning their security investments with a CTEM programme will suffer significantly fewer breaches. The reasoning is plausible: whoever continuously knows what is reachable and exploitable closes the gaps attackers actually use.",[14,22,24],{"id":23},"the-five-phases-of-ctem","The five phases of CTEM",[26,27,28,36,42,48,54],"ol",{},[29,30,31,35],"li",{},[32,33,34],"strong",{},"Scoping",": Define which systems, business processes and data are in view, from the external attack surface through SaaS and cloud to the supply chain.",[29,37,38,41],{},[32,39,40],{},"Discovery",": Find assets, vulnerabilities, misconfigurations and exposed identities within the defined scope, including what nobody documented.",[29,43,44,47],{},[32,45,46],{},"Prioritisation",": Rank findings by exploitability (EPSS, CISA KEV, available exploits), reachability, asset criticality and existing compensating controls.",[29,49,50,53],{},[32,51,52],{},"Validation",": Check whether an attack is actually possible, for example through automatic proof-of-concept scans or manual penetration tests.",[29,55,56,59],{},[32,57,58],{},"Mobilisation",": Organise remediation: ownership, tickets, deadlines, evidence via retest.",[10,61,62],{},"Then the cycle starts again, because scope, assets and threat landscape change constantly.",[14,64,66],{"id":65},"how-blacklensio-implements-ctem","How blacklens.io implements CTEM",[10,68,69],{},"blacklens.io maps the cycle in one platform: scope management with automatic suggestions (scoping), external, internal and cloud discovery including dark web matching (discovery), rating by EPSS, CISA KEV, exploit availability and CVSS (prioritisation), automatic PoC verification of new threats in the Threat Center plus optional manual pentests (validation), and a finding workflow with assignment, Jira\u002FServiceNow integration, retest scans and automatic closure (mobilisation). The AI remediation plan groups open findings by shared root cause and orders them by risk reduction.",[14,71,73],{"id":72},"is-ctem-the-same-as-vulnerability-management","Is CTEM the same as vulnerability management?",[10,75,76],{},"No. Vulnerability management is one part of it. CTEM additionally covers discovery of unknown assets, exposure beyond CVEs (configuration, identities, dark web) and the explicit validation step.",[14,78,80],{"id":79},"does-ctem-require-a-soc-of-its-own","Does CTEM require a SOC of its own?",[10,82,83],{},"Not necessarily. With a platform that bundles discovery, prioritisation and workflow, the cycle can be run by small teams or via an MSSP. What matters is that someone owns the mobilisation phase.",[14,85,87],{"id":86},"how-do-you-start-with-ctem","How do you start with CTEM?",[10,89,90],{},"With a small, clear scope, usually the external attack surface of the main domains. Once discovery and prioritisation are running there, extend the scope step by step to cloud, internal networks and the supply chain.",[14,92,94],{"id":93},"related-terms","Related terms",[96,97,98,105,111,117],"ul",{},[29,99,100],{},[101,102,104],"a",{"href":103},"\u002Fen\u002Fwissen\u002Fattack-surface-management","Attack Surface Management (ASM)",[29,106,107],{},[101,108,110],{"href":109},"\u002Fen\u002Fwissen\u002Fvulnerability-management","Vulnerability Management",[29,112,113],{},[101,114,116],{"href":115},"\u002Fen\u002Fwissen\u002Fepss","EPSS",[29,118,119],{},[101,120,122],{"href":121},"\u002Fen\u002Fwissen\u002Fpenetration-testing-as-a-service","Penetration Testing as a Service (PTaaS)",{"title":124,"searchDepth":125,"depth":125,"links":126},"",3,[127,129,130,131,132,133,134],{"id":16,"depth":128,"text":17},2,{"id":23,"depth":128,"text":24},{"id":65,"depth":128,"text":66},{"id":72,"depth":128,"text":73},{"id":79,"depth":128,"text":80},{"id":86,"depth":128,"text":87},{"id":93,"depth":128,"text":94},"CTEM explained: the five phases scoping, discovery, prioritisation, validation and mobilisation, why Gartner recommends the programme and how blacklens.io maps it.","md","en",{},true,"\u002Fen\u002Fwissen\u002Fcontinuous-threat-exposure-management",[142,143,144,145],"attack-surface-management","vulnerability-management","epss","penetration-testing-as-a-service",{"title":5,"description":135},"CTEM is a programme described by Gartner with five phases (scoping, discovery, prioritisation, validation, mobilisation) that reduces the attack surface continuously instead of at points in time.",{"loc":140},"en\u002Fwissen\u002Fcontinuous-threat-exposure-management",[151,152,153],"CTEM","Exposure management","Threat exposure management","2026-09-14","Lcj1OzOkcfUvcj0U-fwZfZRNgKZNskW8NbIHhnj7MDY",[157,159,162,164],{"path":103,"title":104,"short":158},"Attack surface management is the continuous discovery, assessment and reduction of every point through which an attacker can reach a company: external, internal and in the cloud.",{"path":115,"title":160,"short":161},"EPSS (Exploit Prediction Scoring System)","EPSS is a scoring system by FIRST that estimates for every CVE the probability that it will actually be exploited within the next 30 days, as a value between 0 and 1.",{"path":121,"title":122,"short":163},"PTaaS delivers manual penetration tests through a platform instead of a PDF: findings appear continuously, retests are built in, and tests repeat on a regular schedule.",{"path":109,"title":110,"short":165},"Vulnerability management is the ongoing process of detecting vulnerabilities in systems, prioritising them by risk, fixing them and evidencing the fix.",1789638255679]