CTEM · Industry first

One platform for
the entire CTEM loop

CVEasy AI is the first platform on Apple hardware to run all 5 stages of Gartner's Continuous Threat Exposure Management framework in a single local-first application: proprietary TRIS™ scoring, BASzy™ attack validation, and a built-in AI engine that runs 100% on your hardware. No cloud, no agents on targets, no per-asset fees.

Discover · Validate · Remediate

All 5 Gartner CTEM stages 361,000+ CVEs indexed 12 TRIS™ scoring layers 158,271 attack payloads 152 integrations
01 · The framework

What is Continuous Threat Exposure Management?

A definition first, the product later. CTEM is the program Gartner defined; CVEasy is one way to run it. This section is the part you can take into any vendor call, including ours.

Continuous Threat Exposure Management (CTEM) is a five stage program introduced by Gartner in 2022 for continuously discovering, prioritizing, validating, and remediating the exposures an attacker would actually use against your organization. It is a framework, not a product category. It exists because traditional vulnerability management is losing: scanners produce tens of thousands of CVSS-scored findings, teams patch by severity label, and attackers exploit the mediums nobody got to.

CTEM flips the model. Instead of asking "what vulnerabilities do we have," it asks "which exposures can actually be exploited here, what would that cost us, and did the fix work." Scope, discover, prioritize, validate, mobilize, then loop.

Run well, the program converges on unified exposure management: every finding from every scanner, cloud account, and identity source in one place, deduplicated onto one asset graph, and ranked by what an attacker can actually reach. That single ranked queue, not another dashboard, is the deliverable.

Key takeaways
  • CTEM is a five stage program (Scope, Discover, Prioritize, Validate, Mobilize), not a product category. Gartner defined it in 2022.
  • It covers the full exposure surface: CVEs, misconfigurations, identity risk, cloud posture, and attack paths. Scanner findings are only one input.
  • Prioritization uses exploitability, active threat activity, and business impact instead of raw CVSS labels.
  • Validation, the stage most vendors skip, proves an exposure is exploitable before it consumes remediation budget.
  • The loop only closes when the fix is verified. Mobilization means owners, exact remediation steps, SLAs, and re-validation.
less likely to suffer a breach for organizations that prioritize security investment through a CTEM program.
Gartner, 2022 CTEM research
1 in 5
breaches now begin with vulnerability exploitation as the initial access vector, and the share keeps growing year over year.
Verizon DBIR
<6%
of published CVEs are ever exploited in the wild. Prioritizing by CVSS alone means most of your patching effort targets the other 94%.
EPSS / exploit prediction research
"By 2026, organizations that prioritize their security investments based on a continuous threat exposure management program will be three times less likely to suffer a breach." Gartner, Implement a Continuous Threat Exposure Management (CTEM) Program, 2022

It is 2026. That prediction came due. Most vendors sell you one or two stages of the loop and call it CTEM. CVEasy AI ships all five, local-first, on hardware you already own.

02 · The loop

The CTEM loop: five stages, one continuous instrument.

Five stages, run continuously; the output of Mobilize feeds the next Scope. Left column: what Gartner asks of each stage and the CVEasy instrument that runs it. Right column: one real-shaped exposure traced through the whole loop.

Stage 1 · Scope

Define what matters

Pick the business slice worth defending first: crown jewels, critical assets, the compliance boundary. Not the whole estate on day one.

Runs on: asset auto-classification
scope payment path · 214 assets
crown jewels FIN-SRV-02 +2 · PCI-DSS
Stage 2 · Discover

One graph, every source

Consolidate every scanner, cloud console, and BASzy finding into a single deduplicated asset and attack-path graph.

Runs on: 152 connectors, one graph
finding CVE-2026-30157 · 3 sources agree
graph 3,181 raw → 764 exposures
Stage 3 · Prioritize

Rank by real risk

Score each exposure against exploitability, threat activity, controls, and business impact, not the global CVSS average.

Runs on: TRIS™ 12-layer scoring
CVSS 9.8 → TRIS 9.3 · band ACT
evidence KEV listed · EPSS 0.94
Stage 4 · Validate

Prove exploitability

Run the real attack against the real control stack. An exposure only jumps the queue when the technique actually lands.

Runs on: BASzy™ · 158,271 payloads
chain SQLi → creds → lateral · proved
control gap EDR missed step 2
Stage 5 · Mobilize

Fix, verify, close

Hand IT the exact command, the verification step, and the rollback. Then re-run the attack to prove the door is closed.

Runs on: AI remediation + patch orchestration
fix patch + WAF rule · owner: infra
re-attack failed · exposure closed ✓
↻ Mobilize feeds the next Scope · the loop re-runs continuously

The trace is a worked example, shaped like production output. Every value on the right is a first-class object in CVEasy: scopes, source-merged findings, TRIS™ bands, BASzy™ chains, and verified closures.

CTEM stage 01 · Scope

Define what matters.

Identify your crown jewels, business-critical assets, and attack surface boundaries. CVEasy automatically classifies assets by criticality and maps them to business units.

  • Crown jewel identification (databases, DCs, payment systems)
  • Asset criticality auto-classification
  • Business unit and owner mapping
  • Public-facing vs. internal segmentation
  • Compliance framework scoping (PCI, HIPAA, SOC 2)
  • 86 controls across 9 compliance frameworks
Practitioner note

Most CTEM programs die in stage 1 because scoping becomes a six month committee exercise. Start with one business-critical slice: the payment path, the domain controllers, the customer-facing edge. CVEasy's auto-classification gives you a defensible first scope in hours, and the loop widens it every cycle.

CTEM stage 02 · Discover

One graph, every source

CVEasy is a second source of truth for your attack surface. Agentless. It consolidates the exports from the scanners you already run, adds a lightweight local service sweep and BASzy findings, then deduplicates everything into one asset, exposure, and attack-path graph. No agents on target hosts. This is not a replacement enterprise scanner; it is the layer that consolidates and enriches what you already have.

  • Agentless local service discovery (TCP service sweep, no host agents)
  • Consolidates 152 integrations across 16 categories (Nessus, Qualys, Rapid7, Snyk, and more)
  • Service and version fingerprinting
  • BASzy™ attack findings folded into the same graph
  • Cloud posture discovery across AWS, Azure, and GCP (agentless CSPM/CIEM)
  • Unified, deduplicated asset and attack-path graph
  • Device classification (server, workstation, IoT, printer)
  • MAC vendor identification (60+ vendors)
  • 361,000+ CVE database with auto-correlation
  • Business context and asset criticality enrichment
Practitioner note

Discovery is not "buy another scanner." You almost certainly have the data already, split across Nessus exports, cloud consoles, and EDR inventories that disagree with each other. The stage 2 problem is consolidation and dedup into one graph. That graph is what makes stages 3 through 5 possible.

CTEM stage 03 · Prioritize

Risk that actually means something.

TRIS™ v2 12-layer scoring goes beyond CVSS. It combines exploitability (EPSS), active exploitation (CISA KEV), threat actor targeting, asset criticality, business context, BASzy validation, attack-path blast radius, supply-chain propagation, defense efficacy, predictive trajectory, and FAIR-based financial impact into a single defensible score.

  • TRIS™ v2 12-layer risk scoring (Patent Pending) (0-100)
  • EPSS weaponization probability
  • CISA KEV active exploitation flag
  • Threat actor targeting correlation (49 APT groups)
  • Asset criticality × vulnerability severity matrix
  • Attack-path blast radius (graph-based lateral movement scoring)
  • Supply-chain dependency propagation (SBOM-aware transitive risk)
  • Defense efficacy coefficient (MITRE ATT&CK technique coverage)
  • Predictive threat trajectory (forward-looking momentum forecast)
  • Financial impact quantification (FAIR-based dollar loss)
  • ACT / ATTEND / TRACK / MONITOR / INFORMATIONAL priority bands
  • SLA deadlines calculated per asset tier and band
Practitioner note

CVSS answers "how bad is this in a lab." It never answers "how bad is this on that host, in this network, for this business." Fewer than 6% of CVEs are ever exploited in the wild, so a severity-sorted queue wastes most of your remediation budget. Score the exposure in context or you are prioritizing blind. Try it yourself in the TRIS Calculator.

CTEM stage 04 · Validate

Prove it's exploitable, or prove it's not

The stage most "CTEM platforms" quietly skip, because it requires actually attacking things. BASzy™ runs real attack simulations: 158,271 payloads, 10 pre-built campaigns, 18 endpoint security tests. The result is proof, not a guess.

  • 150 real attack modules (not simulated)
  • 10 pre-built attack campaigns (Ransomware, APT29, AD, Cloud, and more)
  • 18 endpoint security validation tests
  • Attack chain engine (SQLi → creds → lateral → priv esc → exfil)
  • Security control validation (EDR, firewall, DLP, SIEM)
  • Security posture scoring (0-100)
  • Continuous simulation scheduling (hourly/daily/weekly)
  • MITRE ATT&CK coverage mapping
  • Control effectiveness matrix
  • Compliance evidence auto-generation
Practitioner note

A prioritized list you never validated is still a guess. BASzy™ runs the real technique against the real control stack, so "critical" means "we proved it" and "resolved" means "we re-ran the attack and it failed."

CTEM stage 05 · Mobilize

Fix what matters and prove it's fixed

This is where every other vendor stops. Tenable tells you what's wrong. Qualys gives you a CVSS score. SafeBreach proves it's exploitable. None of them tell you how to fix it.

CVEasy AI™ generates exact remediation commands per vulnerability, per OS, per asset. Not "apply the latest patch": the actual apt-get command, the iptables rule, the Set-MpPreference PowerShell one-liner, the auditctl detection rule, the verification command to confirm the fix worked, and the rollback command if it breaks something. Upload your internal runbooks to the Knowledge Base and the AI references your standards, not generic advice.

  • Exact remediation commands per CVE, per OS (Ubuntu, RHEL, Windows, macOS)
  • Verification commands to confirm the fix worked
  • Rollback commands if the fix causes issues
  • Private RAG knowledge base. AI references your internal runbooks
  • Asset-grouped remediation plans with owner assignment
  • SLA tracking per asset criticality (P0 crown jewels = 24hr deadline)
  • Risk acceptance workflow with approval chain
  • AI patch orchestration: turn a CVE into a governed patch job in your own tooling
  • Orchestrates the fix through Microsoft Intune, Automox, Tanium, Jamf Pro, and PDQ Connect, plus a universal webhook fallback
  • Fail-closed with AES-GCM-encrypted connector credentials (CVEasy never pushes patches to endpoints itself)
  • Closed-loop: re-validate with BASzy™ after remediation
  • Board-ready executive reports with risk reduction narratives
Practitioner note

Mobilization fails on handoff friction: security files a ticket that says "patch CVE-2026-XXXXX" and IT spends a day figuring out what that means on their fleet. Hand them the exact command, the verification step, and the rollback, and the same ticket closes in minutes. That is the difference between a report and a fix.

Category line 1 of 2

CTEM vs. traditional vulnerability management.

Vulnerability management is where most programs start and where most of them stall. The difference is whether the loop closes.

Traditional VM CTEM
CadencePeriodic scans (monthly, quarterly)Continuous loop
CoverageCVEs on scanned hostsFull exposure surface: vulns, misconfigs, identity, cloud posture, attack paths
PrioritizationCVSS severity labelsExploitability, threat activity, asset criticality, business impact
ProofNone. Assumes severity = riskValidation: prove the exposure is exploitable before it jumps the queue
OutputA ranked list handed to ITMobilized remediation with owners, SLAs, and re-validation that the fix worked
Success metricVulns closed per monthProvable reduction in exploitable exposure and shorter time-to-remediate

Deeper dive: the CTEM framework explained and a 90 day implementation plan.

Category line 2 of 2

CTEM vs. ASM, RBVM, BAS, pentesting, and CSPM.

None of these categories compete with CTEM. Each one is a partial input to it. Here is where every adjacent acronym fits in the loop, and what it misses on its own.

Category What it does Where it fits in CTEM What it misses alone
ASM / EASMMaps internet-facing assets and shadow ITStage 2, Discover (external surface)No prioritization, no validation, no fix loop
RBVMRanks scanner findings by risk instead of raw CVSSStage 3, Prioritize (partial)Still CVE-only, never proves exploitability, stops at a list
BASRuns attack simulations against your controlsStage 4, ValidateNo asset context or prioritization ahead of it, no remediation behind it
Pentest / Red teamPoint-in-time human-driven attack exerciseStage 4, Validate (snapshot)Expires the day the report lands. CTEM makes it continuous
CSPM / CIEMFinds cloud misconfigurations and identity riskStage 2, Discover (cloud surface)Cloud-only view, findings live outside the main risk queue
Patch managementDeploys updates across the fleetStage 5, Mobilize (execution arm)No idea which patch matters. Burns cycles on unexploitable noise

CVEasy AI folds all six into one loop: agentless discovery and CSPM in stage 2, TRIS™ scoring in stage 3, BASzy™ validation in stage 4, and patch orchestration in stage 5.

Outcomes

What a CTEM program actually buys you.

The benefits, in the order your board cares about them. And the honest challenges, with how CVEasy was built around each one.

  • Provably lower breach likelihood (the Gartner 3x claim, measured, not asserted)
  • Remediation budget spent on exploitable exposure, not CVSS noise
  • Shorter exposure windows and faster mean time to remediate
  • One defensible risk narrative across infra, cloud, and identity
  • Compliance evidence generated as a byproduct, not a fire drill
  • Security and IT working one queue with owners and SLAs

The honest challenges, and how CVEasy was built around them. Most CTEM programs stall on three things. Tool sprawl: the loop normally takes five products and three consoles, so CVEasy ships all five stages in one application. Data gravity: your exposure map is your most sensitive dataset, so CVEasy keeps it 100% local instead of in a vendor cloud. Team friction: security hands IT a PDF and hopes, so CVEasy hands IT the exact command, the verification step, and the rollback.

Measurement

How to measure a CTEM program.

If you cannot measure the loop, you do not have a program, you have a subscription. These are the numbers that prove CTEM is working, and every one of them is a first-class object in CVEasy.

M1Validated exposure countExposures proven exploitable, trending down
M2TRIS™ posture scoreContextual risk across the estate, trending down
M3MTTR by priority bandTime to remediate ACT vs. ATTEND vs. TRACK
M4SLA compliance per asset tierCrown jewels fixed inside 24 hours
M5Validation coverageShare of the scope BASzy™ has actually attacked
M6Fix verification rateRemediations re-attacked and confirmed closed
M7Control efficacyMITRE ATT&CK techniques your stack provably blocks
M8Financial exposureFAIR-based dollar loss avoided, for the board slide
Buyer's guide

How to choose a CTEM platform: 8 questions.

Take these into every vendor call, including ours. CVEasy AI answers all eight, and number seven is the one no cloud vendor can match: the whole platform, AI included, runs on your hardware.

  1. Does it cover all five stages, or is it one stage wearing a CTEM sticker? Ask which stages require a second product.
  2. Can it consolidate the scanners you already own? Rip-and-replace discovery is a two year detour. Look for multi-format import and dedup into one graph.
  3. Is prioritization contextual? Exploitability, active threat campaigns, asset criticality, and business impact, not a re-weighted CVSS.
  4. Is validation real? Actual attack techniques against your actual controls, re-runnable on a schedule, not a questionnaire.
  5. Does mobilization produce fixes or tickets? Demand exact per-OS remediation steps, verification, and rollback, not "apply vendor patch."
  6. Does the loop close? After a fix, does the platform re-attack to prove it worked?
  7. Where does your exposure map live? If the answer is "our cloud," your complete attack surface is now someone else's breach problem.
  8. What does scale cost? Per-asset and per-agent pricing punishes you for discovering your own attack surface.
Vendor matrix

Why no one else does all 5 stages.

Stage by stage, against the incumbents. Every row below is a capability you would otherwise buy, integrate, and operate as a separate product.

CTEM stage CVEasy AI™ Tenable Qualys Rapid7 SafeBreach
1. Scope (asset classification)✓ AutoManualManualManual
2. Discover (agentless)✓ Agentless✓ Scanner✓ Scanner✓ ScannerNeeds agents
3. Prioritize (beyond CVSS)✓ TRIS™ v2 12-layer (Patent Pending)VPRTruRiskRisk Score
4. Validate (exploit proof)✓ 150 modules✓ BAS
5. Mobilize (AI remediation)✓ Exact commands + verify + rollbackGeneric
Cloud posture (CSPM/CIEM)✓ AWS + Azure + GCPAdd-onAdd-onAdd-on
Patch orchestration✓ Intune, Automox, Tanium, Jamf, PDQ
Local-first (air-gapped)✓ 100%CloudCloudCloudCloud
Per-asset fees✓ NonePer assetPer assetPer assetPer agent
FAQ

CTEM questions, answered.

The questions practitioners actually ask about Continuous Threat Exposure Management, answered without the analyst hedging.

Is CTEM a product I can buy?

No. CTEM is a program framework defined by Gartner in 2022. Vendors sell tools that support some or all of its five stages. Most cover one or two. CVEasy AI is built to run the entire loop in one application: scoping, discovery, TRIS™ prioritization, BASzy™ validation, and AI-driven mobilization.

How is CTEM different from vulnerability management?

Vulnerability management finds and ranks CVEs, usually by CVSS, on a periodic scan cycle. CTEM is continuous, covers the full exposure surface including misconfigurations, identity, and cloud posture, prioritizes by real-world exploitability and business impact, validates that exposures are actually exploitable, and closes the loop by verifying fixes landed.

Does CTEM replace my existing scanners?

No. Your scanners are stage 2 inputs. CVEasy consolidates findings from more than a hundred integrations (Nessus, Qualys, Rapid7, and others, spanning 43 file imports and 73 native API connectors), deduplicates them into one asset and attack-path graph, then runs prioritization, validation, and mobilization on top. You keep the scanning investment you already made.

What does the validation stage actually do?

Validation proves an exposure is exploitable before you spend remediation budget on it. BASzy™ runs real attack modules, 150 of them across 10 pre-built campaigns, against your environment and your controls (EDR, firewall, DLP, SIEM). After remediation, the same attack re-runs to prove the fix worked.

Why does local-first matter for CTEM?

A CTEM platform holds your complete exposure map: every asset, every weakness, every attack path. Cloud platforms ship that map to a third party, which makes the vendor a single point of catastrophic compromise. CVEasy runs 100% on your hardware, works air-gapped, and your exposure data never leaves your building.

What is the difference between CTEM and attack surface management (ASM)?

ASM maps what you have exposed, mostly from the outside in. That is stage 2 of CTEM, discovery of the external surface. CTEM wraps ASM with scoping, contextual prioritization, exploit validation, and a mobilization loop that verifies fixes. ASM tells you the doors exist; CTEM tells you which ones an attacker can open and gets them locked.

Is CTEM the same as risk-based vulnerability management (RBVM)?

No. RBVM improves stage 3 by ranking CVEs with threat intel instead of raw CVSS, but it stays CVE-shaped, never validates exploitability, and ends at a prioritized list. CTEM covers the full exposure surface including misconfigurations, identity, and cloud posture, proves exploitability in stage 4, and drives fixes to verified closure in stage 5.

Who needs CTEM? Is it only for large enterprises?

Any organization that patches by CVSS severity and hopes is a candidate. Mid-market teams arguably need it more: same attack surface classes, a fraction of the headcount, so wasted remediation effort hurts twice. CVEasy's local-first model was built for exactly that team, one application on hardware you own, no per-asset fees that grow with your own discovery.

What is a unified exposure management platform?

One platform that ingests findings from every tool you already run (network scanners, cloud posture, endpoint, identity), deduplicates them onto a single asset and attack-path graph, and produces one ranked queue of what to fix first. The alternative is four consoles with four contradictory severity scales. CVEasy does the consolidation locally: 152 integrations in, TRIS™ scoring across 12 layers, one prioritized queue out.

What metrics should a CTEM program report?

Validated exposure count trending down, MTTR by priority band, SLA compliance per asset tier, validation coverage of the scope, fix verification rate, control efficacy against MITRE ATT&CK, and financial exposure avoided. See the measurement section above for how each maps to CVEasy.

How long does it take to stand up a CTEM program?

With a scoped first slice, days, not quarters. CVEasy auto-classifies assets on import, scores findings immediately, and ships pre-built validation campaigns. A realistic first loop on a critical business segment runs inside the first week; broadening scope happens cycle by cycle. See our 90 day implementation plan.

Be the first to deploy a complete CTEM platform.

All five Gartner stages. One application. Hardware you already own.

Request a Demo → See public pricing

100% local · zero cloud dependency · your data never leaves your building