Breaking
SecurityDeveloping Story

CTEM shifts security focus from scans to attack paths

Continuous threat exposure management broadens security beyond vulnerabilities, emphasizing validation and accountability.

··3 hours ago·6 min read
black flat screen computer monitor
Photo by Eduardo Pastor on Unsplash

Security teams are increasingly looking beyond traditional vulnerability management as a way to keep pace with both the speed of attacks and the constant evolution of IT environments. Continuous threat exposure management (CTEM) is emerging as an approach that expands the scope of what gets monitored — moving from periodic scans to a more dynamic, ongoing assessment of an organization's risk exposure.

Beyond the vulnerability scan

Traditional vulnerability management typically involves periodic assessments, with teams scanning environments, identifying vulnerabilities, and implementing fixes as necessary. CTEM, by contrast, is designed to continuously understand risk exposure across endpoints, networks, identities, cloud environments, applications, and users — not just vulnerable software.

According to Fernando Maldonado, principal analyst at Foundry Spain, CTEM brings three key differences to the table. The first is scope: in addition to vulnerable software, CTEM also focuses on misconfigurations, identity risks, excessive permissions, and leaked credentials — gateways attackers are increasingly using.

“The second is validation, because instead of relying on a score, [CTEM] verifies whether the exposure is truly exploitable and whether current controls would prevent it,” Maldonado said. The third difference is mobilization, he said, because the CTEM framework assigns a specific person the responsibility for fixing each issue — an area where traditional processes often stall. “The metric shifts from how many vulnerabilities I’ve found to how many real attack vectors I’ve closed,” he added.

Why a single snapshot no longer suffices

The current threat landscape makes it clear that one-off scans are no longer sufficient, according to several security experts interviewed for this story. Infrastructures are constantly changing: cloud environments, distributed applications, API integrations, continuous deployments, and automation are always altering an organization's attack surface.

“A single snapshot can provide useful information, but it quickly becomes outdated,” said Luis Uribe, offensive security engineer at Factum. “New assets, configuration changes, exposed services, or modifications to permissions can alter the level of risk in a matter of hours or days.”

Attackers are also operating more quickly to exploit narrow windows of opportunity. “As a result, organizations need a continuous ability to identify, contextualize, and prioritize the vulnerabilities that could actually be used in an attack,” Uribe said.

The cost of operating blind

Maldonado said that speed is a key reason for shifting to CTEM. Otherwise, organizations may be operating blind. “Between assessments, there’s a long period of uncertainty, and attackers, increasingly relying on AI, are taking less time to exploit new vulnerabilities,” he said. “Simply patching and doing nothing is no longer enough.”

Volume adds to the challenge: tens of thousands of vulnerabilities are published each year, generating unmanageable backlogs where important issues are buried under countless minor findings. Coverage is another problem, Maldonado said. “Scanners see vulnerable software, but not the identity, the SaaS, misconfigurations, or attack vectors, which is precisely where the attackers gain entry. A scan reveals what is vulnerable, but not what is exploitable or what truly matters to the business. This part of the argument holds true without needing to trust any vendor, because these are structural facts of the environment,” he explained.

Automation and human judgment

Uribe noted that automation and contextual intelligence are two essential pillars of the CTEM model. Automation enables continuous visibility into assets, configurations, vulnerabilities, and changes in the environment, facilitating early detection of new exposures. But Agustín Serralta, director of services and CISO at SCC España, cautioned that automation does not replace human judgment.

“In complex environments, it’s impossible to manage large volumes of data without automation,” Serralta said. “However, completely delegating decision-making to algorithms can be risky, especially if those models aren’t reviewed or become obsolete.”

Contextual intelligence must therefore combine technical context (exploitability, exposure, existing measures) with business context (which systems support critical processes, legal obligations, or contractual commitments). “Without that combination, there is no real risk management, only prioritization based on technical needs,” he said.

Complement, not replace, offensive testing

Javier Castillo, operations director of Secure&IT, stressed that CTEM does not replace penetration testing or red team activities. These, he said, “remain fundamental services for identifying complex vulnerabilities, design errors, logical failures, or advanced attack techniques that can hardly be detected through automated processes.”

Continuous monitoring and offensive assessments should be understood as complementary capabilities within a mature cybersecurity strategy, he added.

Implementing the five phases

José de la Cruz, technical director of TrendAI Iberia, said automation plays a fundamental role in enabling organizations to implement the five phases of CTEM — scoping, discovery, prioritization, validation, and mobilization — in an agile and efficient manner. With automation in place, “the human becomes an analyst who supervises (human-in-the-loop) the correct functioning of the model and validates the data it produces, thus guaranteeing an effective and reliable implementation,” he said.

Castillo said enterprises should aim first at achieving a comprehensive view of their attack surface, including all assets: traditional infrastructures, cloud environments, applications, digital identities, connected devices, and services exposed to third parties. “You cannot protect what you do not know, and many organizations still lack a complete vision of all the elements that make up their ecosystem,” he said.

From there, organizations should work toward continuous processes for risk identification, validation, prioritization, and remediation. “This involves incorporating continuous monitoring capabilities and solutions that automate the collection and correlation of information, establish risk-oriented metrics, and create collaboration mechanisms between the various technical and business teams,” Castillo added.

Challenges on the road to CTEM

Serralta cited fragmentation as a chief challenge, noting “we have too many tools, consoles, reports, and data that it’s simply impossible to manage.” At an organizational level, he said silos remain a significant barrier. “When it’s unclear who decides or who is responsible, security is compromised. At a cultural level, several natural resistances converge: lack of time, an exclusive focus on ‘compliance,’ or an overreliance on tools.”

Maldonado agreed that “the cultural aspect is the hardest.” He elaborated: “It involves changing the mindset from finding and reporting vulnerabilities to validating and reducing business risk, resisting the urge to keep hunting them down one by one, and accepting that CTEM is not a capability delivered by a vendor, but an operational model that the organization has to design and adopt. That’s the point that sinks most programs, because the tool is purchased expecting it to bring the culture with it, and that never works that way.”

From a regulatory standpoint, Serralta said CTEM fits well with the risk management principle required by European regulations, “but only if it is implemented with governance, traceability and human control, in line with the corporate security policies, as well as acceptable use policies for technology, data, and AI, that we must define and distribute to all personnel in the organization.”

Weighing the business impact

The central argument for CTEM is that it gives security teams a way to prioritize based on what actually matters to the business, rather than drowning in a sea of vulnerabilities. By validating whether an exposure is truly exploitable and assigning ownership for fixes, the approach aims to close the gap between technical findings and business risk. For organizations, the potential benefit is a more efficient use of security resources — focusing on the attack vectors that could actually be used, rather than chasing every single issue that appears in a scan.

At the same time, the adoption challenges are not trivial. Cultural resistance, fragmented tooling, and unclear accountability can all derail a CTEM program. The experts quoted here stress that CTEM is not a product to be bought but a process to be lived. As Maldonado put it, buying a tool and expecting it to bring the culture with it “never works that way.”

#ctem#vulnerability management#risk management#security operations#attack surface

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories