Quick answer
Direct answer
What you will learn
- How to choose a first scope that is small enough to finish and important enough to matter
- What to build in the first 30 days without new tooling
- How to run a full prioritization and validation cycle in the second month
- What to report at day 90 so the program earns its next phase
Explanation
Days 1 to 30: scope and see
Pick one business service that leadership already cares about. Payments, customer portal, or the primary internet facing application all work. Write down what the service is made of: applications, hosts, cloud accounts, identities with privileged access, and the third parties in the path. Name a technical owner for each component. This list is your first exposure register, and it will be incomplete. That is expected.
Pull whatever exposure data already exists for those components. Scanner output, cloud posture findings, identity review results, and open audit items all count. Do not clean the data yet. The goal in month one is a single view of one service, not a perfect one.
Avoid this
Days 31 to 60: prioritize, validate, fix
Rank the register using business impact, exploitability, current threat activity, and whether an attacker could actually reach the component. Take the top ten only. For each one, prove it is real: confirm the path is reachable, test whether existing controls stop it, and record the evidence. Validation is what separates CTEM from a scanner queue, and it is also what makes remediation requests credible with engineering teams.
Route each validated exposure to its named owner with a deadline that reflects the proven risk rather than a generic severity label. Track blockers openly. Most delays in month two are ownership disputes and change windows, not technical difficulty.
Days 61 to 90: prove it and expand
Report three numbers: how many validated exposures existed at day 30, how many are closed with evidence, and how long closure took. Add the process failures you hit, because those are the argument for the next phase. Then add a second service to scope and run the same cycle. A program that repeats a small cycle reliably will outperform one that attempts full coverage in its first year.
How to apply this
- Name the first scope in writing and get the service owner to acknowledge it
- Build the exposure register from existing data sources in week one
- Cap the first remediation batch at ten validated exposures
- Record validation evidence for every exposure you ask someone to fix
- Book the day 90 readout with leadership before day 30 so the deadline is real
Common mistakes
- Chasing complete asset coverage before running a single full cycle
- Prioritizing on severity score alone with no reachability check
- Sending findings to a team queue instead of a named owner
- Reporting activity counts such as scans run rather than validated exposures closed
- Buying a platform in month one, before you know which gap it needs to close
Key takeaways
- A narrow first scope is a feature of the plan, not a compromise
- One complete cycle beats partial coverage of everything
- Validation evidence is what turns a finding into a funded fix
- The day 90 report should show closure, not activity
Frequently asked questions
Related pages
How to Start a CTEM Program
How to Start a CTEM Program: A 30/60/90-Day Roadmap
A practical 30/60/90-day roadmap for starting a CTEM program: what to do first, what to avoid, how to choose scope, and how to show early progress.
Maturity Model
CTEM Maturity Model: From Ad Hoc to Optimized
A CTEM maturity model with levels, evidence, metrics, and improvement actions to move from ad hoc to optimized.
Lifecycle Overview
CTEM Lifecycle: The Five Stages Explained
A practical walkthrough of the five-stage CTEM lifecycle with worked examples, common pitfalls, and links to a deep-dive page for each stage.
CTEM Metrics and KPIs
CTEM Metrics and KPIs: What to Measure and How to Report
Practical CTEM metrics and KPIs with what each one means, why it matters, and how each one can be misused if reported without context.
Next step
Get certified free
Test what you know with the free CTEM Beginner certification exam.
Author
LearnCTEM Editorial Team
Practitioners and educators writing plain-English guides on Continuous Threat Exposure Management.
Reviewed by
Senior CTEM Practitioner Panel
Reviewed for accuracy against public CTEM guidance and real-world program experience.
