Last week in Singapore during the Cyber Executive Circle, I posed standing next to a banner with Manuj, pointing at a single line that I think our industry badly needs to hear right now: "CTEM is a program. Not a tool."
It's a simple sentence. But after three decades in this industry, I can say it's one of the most misunderstood ideas in cybersecurity practice today.
What I'm Seeing in the Market
Every few months, a new vendor shows up claiming they have "solved" CTEM. Delve deeper, and what you usually find is a vulnerability scanner or a VAPT tool with a new coat of paint, or an attack-path visualization tool rebranded with the same acronym. Buy the license, plug it in, and apparently, you now "have CTEM."
That's not CTEM. That's a point tool cosplaying CTEM.
Continuous Threat Exposure Management is a five-stage program: Scoping, Discovery, Prioritization, Validation, and Mobilization. It was never meant to be a single SKU. But since it's easier to sell a rebadged tool than a comprehensive program, CISOs are the ones left holding point solutions that don't talk to each other, still asking the same question they asked five years ago: are we actually more secure?
Why This Matters More Now, Not Less
The data backs up the reality on the field. Mean time to remediate vulnerabilities still sits above 50 days, far longer than it takes an attacker to exploit them with automation. Even when organizations know which vulnerabilities are highly exploitable, those still take an average of 134 days to fix. That gap, "exposure window", is the real scoreboard, not the number of CVEs closed this quarter.
And with AI now easily accessible at scale, the gap keeps getting more dangerous. It's worth being precise here: AI isn't inventing brand-new categories of threats, it's collapsing the time and effort attackers need to find and exploit the weaknesses that were already there.
Discovery and offense now happen at machine speed. Remediation, in most organizations, still moves at the speed of static scoring models, manual approvals, and fragmented ownership across teams. This mismatch of machine-speed attack and human-speed defence — is the structural weakness in most VM/EM programs today, and no single tool closes it.
Building It Step-by-Step, Module-by-Module
This is exactly why I point at the banner message. CTEM isn't a switch you flip, it's a program you deliberately build, one capability at a time:
Each of these is a discipline. Bought as isolated tools, they produce isolated dashboards. Built as a connected program, they produce a single, defensible answer to the board's question: what are we exposed to, and how fast are we closing it?
What Can CISOs Do:
If you're a CISO evaluating your exposure management strategy this year, here's my advice:
1. Stop asking "which tool solves CTEM" and start asking "which capability are we missing." A program has gaps by design at the start, the job is to close them programmatically than buying everything at once.
2. Shift your metrics from volume to time. Total number of vulnerabilities you have matters less than how long critical ones stay exploitable to the attacker.
3. Close the loop. A program isn't complete until remediation is verified, not just assigned. Track completion and incorporate lessons back into the next cycle.
CTEM was never meant to be a purchase order. It's a discipline, and like every real discipline in security, it's built module by module, with the people, process, and validation to back it up.
Build the program. The tools will follow.
Discover our most-read articles packed with expert insights, trending topics, and essential cybersecurity updates.
Manuj Kumar
CO-FOUNDER & CRO
Is it about the change or the pace of change while designing a new-age and future-ready Security Operations Center (SOC)?...
READ MORE
Manuj Kumar
CO-FOUNDER & CRO
Part 2: From Vulnerability Management to CTEM – Building Unified Ownership and Continuous Discipline In Part 1, we explored why...
READ MORE
Manuj Kumar
CO-FOUNDER & CRO
Anthropic dropped another bomb with Project Glasswing and whatever myth we had about Vulnerability Management being the core of any...
READ MORE
Consolidates multiple CTI functions & tools in one single platform to improve productivity and enhance efficiencies. Helps optimize, manage, & measure security operations.