Definition · External Attack Surface Management
What is Continuous Threat Exposure Management?
Continuous threat exposure management (CTEM) is a programme framework, introduced by Gartner, for continuously identifying and reducing an organisation’s exposure to attack. Where traditional vulnerability programmes run periodic scans and produce long remediation lists, CTEM is an ongoing cycle that prioritises exposures by real-world exploitability and business impact.
The five stages of CTEM
- Scoping — define which parts of the business and attack surface the programme covers
- Discovery — identify assets and their exposures: vulnerabilities, misconfigurations, and identity weaknesses
- Prioritisation — rank exposures by exploitability, threat activity, and business criticality, not just CVSS score
- Validation — confirm that exposures are actually exploitable and that controls would detect or block an attack
- Mobilisation — get remediation done by making findings actionable for the teams that own the affected systems
CTEM and EASM
External attack surface management is a core enabling technology for CTEM: it provides the discovery stage for internet-facing assets, finding the domains, services, and misconfigurations that make up an organisation’s external exposure. CTEM then extends beyond discovery into prioritisation and validation.
Related concepts
CTEM builds on and coordinates existing practices, including vulnerability management, asset discovery, and security testing approaches such as DAST and penetration testing.