One platform for
the entire CTEM loop
CVEasy AI is the first platform on Apple hardware to run all 5 stages of Gartner's Continuous Threat Exposure Management framework in a single local-first application: proprietary TRIS™ scoring, BASzy™ attack validation, and a built-in AI engine that runs 100% on your hardware. No cloud, no agents on targets, no per-asset fees.
Discover · Validate · Remediate
What is Continuous Threat Exposure Management?
A definition first, the product later. CTEM is the program Gartner defined; CVEasy is one way to run it. This section is the part you can take into any vendor call, including ours.
Continuous Threat Exposure Management (CTEM) is a five stage program introduced by Gartner in 2022 for continuously discovering, prioritizing, validating, and remediating the exposures an attacker would actually use against your organization. It is a framework, not a product category. It exists because traditional vulnerability management is losing: scanners produce tens of thousands of CVSS-scored findings, teams patch by severity label, and attackers exploit the mediums nobody got to.
CTEM flips the model. Instead of asking "what vulnerabilities do we have," it asks "which exposures can actually be exploited here, what would that cost us, and did the fix work." Scope, discover, prioritize, validate, mobilize, then loop.
Run well, the program converges on unified exposure management: every finding from every scanner, cloud account, and identity source in one place, deduplicated onto one asset graph, and ranked by what an attacker can actually reach. That single ranked queue, not another dashboard, is the deliverable.
- CTEM is a five stage program (Scope, Discover, Prioritize, Validate, Mobilize), not a product category. Gartner defined it in 2022.
- It covers the full exposure surface: CVEs, misconfigurations, identity risk, cloud posture, and attack paths. Scanner findings are only one input.
- Prioritization uses exploitability, active threat activity, and business impact instead of raw CVSS labels.
- Validation, the stage most vendors skip, proves an exposure is exploitable before it consumes remediation budget.
- The loop only closes when the fix is verified. Mobilization means owners, exact remediation steps, SLAs, and re-validation.
"By 2026, organizations that prioritize their security investments based on a continuous threat exposure management program will be three times less likely to suffer a breach." Gartner, Implement a Continuous Threat Exposure Management (CTEM) Program, 2022
It is 2026. That prediction came due. Most vendors sell you one or two stages of the loop and call it CTEM. CVEasy AI ships all five, local-first, on hardware you already own.
The CTEM loop: five stages, one continuous instrument.
Five stages, run continuously; the output of Mobilize feeds the next Scope. Left column: what Gartner asks of each stage and the CVEasy instrument that runs it. Right column: one real-shaped exposure traced through the whole loop.
Define what matters
Pick the business slice worth defending first: crown jewels, critical assets, the compliance boundary. Not the whole estate on day one.
Runs on: asset auto-classificationcrown jewels FIN-SRV-02 +2 · PCI-DSS
One graph, every source
Consolidate every scanner, cloud console, and BASzy finding into a single deduplicated asset and attack-path graph.
Runs on: 152 connectors, one graphgraph 3,181 raw → 764 exposures
Rank by real risk
Score each exposure against exploitability, threat activity, controls, and business impact, not the global CVSS average.
Runs on: TRIS™ 12-layer scoringevidence KEV listed · EPSS 0.94
Prove exploitability
Run the real attack against the real control stack. An exposure only jumps the queue when the technique actually lands.
Runs on: BASzy™ · 158,271 payloadscontrol gap EDR missed step 2
Fix, verify, close
Hand IT the exact command, the verification step, and the rollback. Then re-run the attack to prove the door is closed.
Runs on: AI remediation + patch orchestrationre-attack failed · exposure closed ✓
The trace is a worked example, shaped like production output. Every value on the right is a first-class object in CVEasy: scopes, source-merged findings, TRIS™ bands, BASzy™ chains, and verified closures.
Define what matters.
Identify your crown jewels, business-critical assets, and attack surface boundaries. CVEasy automatically classifies assets by criticality and maps them to business units.
- Crown jewel identification (databases, DCs, payment systems)
- Asset criticality auto-classification
- Business unit and owner mapping
- Public-facing vs. internal segmentation
- Compliance framework scoping (PCI, HIPAA, SOC 2)
- 86 controls across 9 compliance frameworks
Most CTEM programs die in stage 1 because scoping becomes a six month committee exercise. Start with one business-critical slice: the payment path, the domain controllers, the customer-facing edge. CVEasy's auto-classification gives you a defensible first scope in hours, and the loop widens it every cycle.
One graph, every source
CVEasy is a second source of truth for your attack surface. Agentless. It consolidates the exports from the scanners you already run, adds a lightweight local service sweep and BASzy findings, then deduplicates everything into one asset, exposure, and attack-path graph. No agents on target hosts. This is not a replacement enterprise scanner; it is the layer that consolidates and enriches what you already have.
- Agentless local service discovery (TCP service sweep, no host agents)
- Consolidates 152 integrations across 16 categories (Nessus, Qualys, Rapid7, Snyk, and more)
- Service and version fingerprinting
- BASzy™ attack findings folded into the same graph
- Cloud posture discovery across AWS, Azure, and GCP (agentless CSPM/CIEM)
- Unified, deduplicated asset and attack-path graph
- Device classification (server, workstation, IoT, printer)
- MAC vendor identification (60+ vendors)
- 361,000+ CVE database with auto-correlation
- Business context and asset criticality enrichment
Discovery is not "buy another scanner." You almost certainly have the data already, split across Nessus exports, cloud consoles, and EDR inventories that disagree with each other. The stage 2 problem is consolidation and dedup into one graph. That graph is what makes stages 3 through 5 possible.
Risk that actually means something.
TRIS™ v2 12-layer scoring goes beyond CVSS. It combines exploitability (EPSS), active exploitation (CISA KEV), threat actor targeting, asset criticality, business context, BASzy validation, attack-path blast radius, supply-chain propagation, defense efficacy, predictive trajectory, and FAIR-based financial impact into a single defensible score.
- TRIS™ v2 12-layer risk scoring (Patent Pending) (0-100)
- EPSS weaponization probability
- CISA KEV active exploitation flag
- Threat actor targeting correlation (49 APT groups)
- Asset criticality × vulnerability severity matrix
- Attack-path blast radius (graph-based lateral movement scoring)
- Supply-chain dependency propagation (SBOM-aware transitive risk)
- Defense efficacy coefficient (MITRE ATT&CK technique coverage)
- Predictive threat trajectory (forward-looking momentum forecast)
- Financial impact quantification (FAIR-based dollar loss)
- ACT / ATTEND / TRACK / MONITOR / INFORMATIONAL priority bands
- SLA deadlines calculated per asset tier and band
CVSS answers "how bad is this in a lab." It never answers "how bad is this on that host, in this network, for this business." Fewer than 6% of CVEs are ever exploited in the wild, so a severity-sorted queue wastes most of your remediation budget. Score the exposure in context or you are prioritizing blind. Try it yourself in the TRIS Calculator.
Prove it's exploitable, or prove it's not
The stage most "CTEM platforms" quietly skip, because it requires actually attacking things. BASzy™ runs real attack simulations: 158,271 payloads, 10 pre-built campaigns, 18 endpoint security tests. The result is proof, not a guess.
- 150 real attack modules (not simulated)
- 10 pre-built attack campaigns (Ransomware, APT29, AD, Cloud, and more)
- 18 endpoint security validation tests
- Attack chain engine (SQLi → creds → lateral → priv esc → exfil)
- Security control validation (EDR, firewall, DLP, SIEM)
- Security posture scoring (0-100)
- Continuous simulation scheduling (hourly/daily/weekly)
- MITRE ATT&CK coverage mapping
- Control effectiveness matrix
- Compliance evidence auto-generation
A prioritized list you never validated is still a guess. BASzy™ runs the real technique against the real control stack, so "critical" means "we proved it" and "resolved" means "we re-ran the attack and it failed."
Fix what matters and prove it's fixed
This is where every other vendor stops. Tenable tells you what's wrong. Qualys gives you a CVSS score. SafeBreach proves it's exploitable. None of them tell you how to fix it.
CVEasy AI™ generates exact remediation commands per vulnerability, per OS, per asset. Not "apply the latest patch": the actual apt-get command, the iptables rule, the Set-MpPreference PowerShell one-liner, the auditctl detection rule, the verification command to confirm the fix worked, and the rollback command if it breaks something. Upload your internal runbooks to the Knowledge Base and the AI references your standards, not generic advice.
- Exact remediation commands per CVE, per OS (Ubuntu, RHEL, Windows, macOS)
- Verification commands to confirm the fix worked
- Rollback commands if the fix causes issues
- Private RAG knowledge base. AI references your internal runbooks
- Asset-grouped remediation plans with owner assignment
- SLA tracking per asset criticality (P0 crown jewels = 24hr deadline)
- Risk acceptance workflow with approval chain
- AI patch orchestration: turn a CVE into a governed patch job in your own tooling
- Orchestrates the fix through Microsoft Intune, Automox, Tanium, Jamf Pro, and PDQ Connect, plus a universal webhook fallback
- Fail-closed with AES-GCM-encrypted connector credentials (CVEasy never pushes patches to endpoints itself)
- Closed-loop: re-validate with BASzy™ after remediation
- Board-ready executive reports with risk reduction narratives
Mobilization fails on handoff friction: security files a ticket that says "patch CVE-2026-XXXXX" and IT spends a day figuring out what that means on their fleet. Hand them the exact command, the verification step, and the rollback, and the same ticket closes in minutes. That is the difference between a report and a fix.
CTEM vs. traditional vulnerability management.
Vulnerability management is where most programs start and where most of them stall. The difference is whether the loop closes.
| Traditional VM | CTEM | |
|---|---|---|
| Cadence | Periodic scans (monthly, quarterly) | Continuous loop |
| Coverage | CVEs on scanned hosts | Full exposure surface: vulns, misconfigs, identity, cloud posture, attack paths |
| Prioritization | CVSS severity labels | Exploitability, threat activity, asset criticality, business impact |
| Proof | None. Assumes severity = risk | Validation: prove the exposure is exploitable before it jumps the queue |
| Output | A ranked list handed to IT | Mobilized remediation with owners, SLAs, and re-validation that the fix worked |
| Success metric | Vulns closed per month | Provable reduction in exploitable exposure and shorter time-to-remediate |
Deeper dive: the CTEM framework explained and a 90 day implementation plan.
CTEM vs. ASM, RBVM, BAS, pentesting, and CSPM.
None of these categories compete with CTEM. Each one is a partial input to it. Here is where every adjacent acronym fits in the loop, and what it misses on its own.
| Category | What it does | Where it fits in CTEM | What it misses alone |
|---|---|---|---|
| ASM / EASM | Maps internet-facing assets and shadow IT | Stage 2, Discover (external surface) | No prioritization, no validation, no fix loop |
| RBVM | Ranks scanner findings by risk instead of raw CVSS | Stage 3, Prioritize (partial) | Still CVE-only, never proves exploitability, stops at a list |
| BAS | Runs attack simulations against your controls | Stage 4, Validate | No asset context or prioritization ahead of it, no remediation behind it |
| Pentest / Red team | Point-in-time human-driven attack exercise | Stage 4, Validate (snapshot) | Expires the day the report lands. CTEM makes it continuous |
| CSPM / CIEM | Finds cloud misconfigurations and identity risk | Stage 2, Discover (cloud surface) | Cloud-only view, findings live outside the main risk queue |
| Patch management | Deploys updates across the fleet | Stage 5, Mobilize (execution arm) | No idea which patch matters. Burns cycles on unexploitable noise |
CVEasy AI folds all six into one loop: agentless discovery and CSPM in stage 2, TRIS™ scoring in stage 3, BASzy™ validation in stage 4, and patch orchestration in stage 5.
What a CTEM program actually buys you.
The benefits, in the order your board cares about them. And the honest challenges, with how CVEasy was built around each one.
- Provably lower breach likelihood (the Gartner 3x claim, measured, not asserted)
- Remediation budget spent on exploitable exposure, not CVSS noise
- Shorter exposure windows and faster mean time to remediate
- One defensible risk narrative across infra, cloud, and identity
- Compliance evidence generated as a byproduct, not a fire drill
- Security and IT working one queue with owners and SLAs
The honest challenges, and how CVEasy was built around them. Most CTEM programs stall on three things. Tool sprawl: the loop normally takes five products and three consoles, so CVEasy ships all five stages in one application. Data gravity: your exposure map is your most sensitive dataset, so CVEasy keeps it 100% local instead of in a vendor cloud. Team friction: security hands IT a PDF and hopes, so CVEasy hands IT the exact command, the verification step, and the rollback.
How to measure a CTEM program.
If you cannot measure the loop, you do not have a program, you have a subscription. These are the numbers that prove CTEM is working, and every one of them is a first-class object in CVEasy.
How to choose a CTEM platform: 8 questions.
Take these into every vendor call, including ours. CVEasy AI answers all eight, and number seven is the one no cloud vendor can match: the whole platform, AI included, runs on your hardware.
- Does it cover all five stages, or is it one stage wearing a CTEM sticker? Ask which stages require a second product.
- Can it consolidate the scanners you already own? Rip-and-replace discovery is a two year detour. Look for multi-format import and dedup into one graph.
- Is prioritization contextual? Exploitability, active threat campaigns, asset criticality, and business impact, not a re-weighted CVSS.
- Is validation real? Actual attack techniques against your actual controls, re-runnable on a schedule, not a questionnaire.
- Does mobilization produce fixes or tickets? Demand exact per-OS remediation steps, verification, and rollback, not "apply vendor patch."
- Does the loop close? After a fix, does the platform re-attack to prove it worked?
- Where does your exposure map live? If the answer is "our cloud," your complete attack surface is now someone else's breach problem.
- What does scale cost? Per-asset and per-agent pricing punishes you for discovering your own attack surface.
Why no one else does all 5 stages.
Stage by stage, against the incumbents. Every row below is a capability you would otherwise buy, integrate, and operate as a separate product.
| CTEM stage | CVEasy AI™ | Tenable | Qualys | Rapid7 | SafeBreach |
|---|---|---|---|---|---|
| 1. Scope (asset classification) | ✓ Auto | Manual | Manual | Manual | — |
| 2. Discover (agentless) | ✓ Agentless | ✓ Scanner | ✓ Scanner | ✓ Scanner | Needs agents |
| 3. Prioritize (beyond CVSS) | ✓ TRIS™ v2 12-layer (Patent Pending) | VPR | TruRisk | Risk Score | — |
| 4. Validate (exploit proof) | ✓ 150 modules | — | — | — | ✓ BAS |
| 5. Mobilize (AI remediation) | ✓ Exact commands + verify + rollback | — | — | Generic | — |
| Cloud posture (CSPM/CIEM) | ✓ AWS + Azure + GCP | Add-on | Add-on | Add-on | — |
| Patch orchestration | ✓ Intune, Automox, Tanium, Jamf, PDQ | — | — | — | — |
| Local-first (air-gapped) | ✓ 100% | Cloud | Cloud | Cloud | Cloud |
| Per-asset fees | ✓ None | Per asset | Per asset | Per asset | Per agent |
Go deeper on CTEM.
Free research, tools, and intel from the CVEasy team. No gate, no email wall.
The CTEM framework, explained
Gartner's five stages broken down for practitioners, with what each stage actually requires in tooling and process.
Read →Implementing CTEM in 90 days
A staged rollout plan: first scope, first loop, first board report. Built from real engagements, not analyst slides.
Read →Local-first CTEM architecture
Why the exposure graph, the scoring engine, and the AI should run on your hardware instead of a vendor's cloud.
Read →TRIS™ Calculator
Score any CVE against your environment with the 12-layer model and see how contextual risk differs from CVSS.
Try it →Weekly threat intel bundle
Signed IOC and exploit intelligence bundles, published weekly, free to ingest into any stack.
Ingest →This Week in Exposure
The week's exploited vulns and exposure trends, TRIS-scored and prioritized, in your inbox every Monday.
Subscribe →CTEM questions, answered.
The questions practitioners actually ask about Continuous Threat Exposure Management, answered without the analyst hedging.
Is CTEM a product I can buy?
No. CTEM is a program framework defined by Gartner in 2022. Vendors sell tools that support some or all of its five stages. Most cover one or two. CVEasy AI is built to run the entire loop in one application: scoping, discovery, TRIS™ prioritization, BASzy™ validation, and AI-driven mobilization.
How is CTEM different from vulnerability management?
Vulnerability management finds and ranks CVEs, usually by CVSS, on a periodic scan cycle. CTEM is continuous, covers the full exposure surface including misconfigurations, identity, and cloud posture, prioritizes by real-world exploitability and business impact, validates that exposures are actually exploitable, and closes the loop by verifying fixes landed.
Does CTEM replace my existing scanners?
No. Your scanners are stage 2 inputs. CVEasy consolidates findings from more than a hundred integrations (Nessus, Qualys, Rapid7, and others, spanning 43 file imports and 73 native API connectors), deduplicates them into one asset and attack-path graph, then runs prioritization, validation, and mobilization on top. You keep the scanning investment you already made.
What does the validation stage actually do?
Validation proves an exposure is exploitable before you spend remediation budget on it. BASzy™ runs real attack modules, 150 of them across 10 pre-built campaigns, against your environment and your controls (EDR, firewall, DLP, SIEM). After remediation, the same attack re-runs to prove the fix worked.
Why does local-first matter for CTEM?
A CTEM platform holds your complete exposure map: every asset, every weakness, every attack path. Cloud platforms ship that map to a third party, which makes the vendor a single point of catastrophic compromise. CVEasy runs 100% on your hardware, works air-gapped, and your exposure data never leaves your building.
What is the difference between CTEM and attack surface management (ASM)?
ASM maps what you have exposed, mostly from the outside in. That is stage 2 of CTEM, discovery of the external surface. CTEM wraps ASM with scoping, contextual prioritization, exploit validation, and a mobilization loop that verifies fixes. ASM tells you the doors exist; CTEM tells you which ones an attacker can open and gets them locked.
Is CTEM the same as risk-based vulnerability management (RBVM)?
No. RBVM improves stage 3 by ranking CVEs with threat intel instead of raw CVSS, but it stays CVE-shaped, never validates exploitability, and ends at a prioritized list. CTEM covers the full exposure surface including misconfigurations, identity, and cloud posture, proves exploitability in stage 4, and drives fixes to verified closure in stage 5.
Who needs CTEM? Is it only for large enterprises?
Any organization that patches by CVSS severity and hopes is a candidate. Mid-market teams arguably need it more: same attack surface classes, a fraction of the headcount, so wasted remediation effort hurts twice. CVEasy's local-first model was built for exactly that team, one application on hardware you own, no per-asset fees that grow with your own discovery.
What is a unified exposure management platform?
One platform that ingests findings from every tool you already run (network scanners, cloud posture, endpoint, identity), deduplicates them onto a single asset and attack-path graph, and produces one ranked queue of what to fix first. The alternative is four consoles with four contradictory severity scales. CVEasy does the consolidation locally: 152 integrations in, TRIS™ scoring across 12 layers, one prioritized queue out.
What metrics should a CTEM program report?
Validated exposure count trending down, MTTR by priority band, SLA compliance per asset tier, validation coverage of the scope, fix verification rate, control efficacy against MITRE ATT&CK, and financial exposure avoided. See the measurement section above for how each maps to CVEasy.
How long does it take to stand up a CTEM program?
With a scoped first slice, days, not quarters. CVEasy auto-classifies assets on import, scores findings immediately, and ships pre-built validation campaigns. A realistic first loop on a critical business segment runs inside the first week; broadening scope happens cycle by cycle. See our 90 day implementation plan.
Be the first to deploy a complete CTEM platform.
All five Gartner stages. One application. Hardware you already own.
100% local · zero cloud dependency · your data never leaves your building