Quick answer
Direct answer
What you will learn
- The full CTEM operating model and its five stages
- Inputs and outputs at each stage
- Roles and cadence across the loop
- How the framework connects existing tools into one program
- How to adapt the framework to a small or large organization
Explanation
The framework in one line
The full five-stage loop
The CTEM framework moves through five practical stages. The point of naming them is not bureaucracy; it is to make sure every exposure has a clear stage owner and a clear next action. See The 5 Stages of CTEM for a beginner walkthrough of each stage.
| Stage | Main question | Example output |
|---|---|---|
| Scope | What are we protecting this cycle and why? | A one-page scope brief with services, assets, and business owner. |
| Discover | What actually exists in scope, including forgotten items? | A live exposure register with each finding, source, and asset. |
| Prioritize | Which of these should we fix first and why? | A ranked short list with reasoning attached. |
| Validate | If an attacker tried this today, would it work? | Validation notes and evidence per high-priority exposure. |
| Mobilize | Who owns the fix, by when, and how do we know it worked? | Closed tickets with owner, timestamp, and proof of remediation. |
Inputs and outputs
Each stage consumes generic inputs and produces specific outputs. The point is not to name a tool for each input, but to make sure the data actually reaches the next stage.
| Stage | Common inputs | Expected outputs |
|---|---|---|
| Scope | Business service catalogue, asset inventory, business criticality ratings | A written scope with services, assets, and owners |
| Discover | Vulnerability data, cloud configuration data, identity data, application context, external surface data, third-party data | An exposure register with source, asset, and initial context per finding |
| Prioritize | Exposure register, asset importance, threat activity, reachability, control coverage | A ranked short list with reasoning per exposure |
| Validate | Ranked exposures, test environment access, safe validation methods | Validation evidence for each priority exposure, including retest results |
| Mobilize | Validated exposures, ownership map, remediation SLAs, ticketing system | Closed tickets with owner, timestamp, evidence, and exceptions where needed |
Roles across the loop
CTEM is a team sport. The framework does not assume any specific org chart, but it does assume every stage has a clear owner. A common baseline distribution:
| Stage | Accountable | Responsible | Consulted | Informed |
|---|---|---|---|---|
| Scope | Security leadership | Program manager | Business owners, IT leads | Board |
| Discover | Security engineering | Detection and posture teams | Cloud, identity, app teams | Program manager |
| Prioritize | Exposure analyst | Security engineering | Business owners, threat intel | Leadership |
| Validate | Offensive security | Detection and posture teams | Asset owners | Program manager |
| Mobilize | Asset owner | IT, cloud, app, identity teams | Security, change advisory board | Leadership |
See CTEM Roles and Responsibilities for a fuller RACI treatment.
Cadence
The framework runs on cadence. Different stages naturally run at different speeds:
- Discovery runs continuously as new data lands from scanners, cloud tools, identity systems, and external surface tools.
- Prioritization runs at least weekly, ideally daily for critical services.
- Validation runs on demand, with mandatory retest after remediation.
- Mobilization operates against SLAs by exposure severity and asset importance.
- Scope is reviewed monthly or quarterly, and revisited after any major change to the business.
Metrics that show the framework is working
The framework needs measurement, or leadership cannot tell whether the loop is closing risk or just spinning. See CTEM Metrics and KPIs for the full list. At the framework level, the minimum viable metric set is:
| Metric | Purpose | Failure signal |
|---|---|---|
| Critical exposure count on top services | Shows the current attack surface that matters most | Number grows quarter over quarter |
| Mean exposure age at closure | Shows program speed | Age trends up |
| Validated exposure rate | Shows how much of the register is proven vs assumed | Below fifty percent for critical items |
| Reopened exposure rate | Shows quality of remediation | Frequently above ten percent |
| Risk reduction on top services | Shows business outcome | Flat or negative trend |
Adapting the framework
The framework is deliberately generic. Two small teams can run it on a single service. A global bank can run parallel loops per region and per business unit. What does not change:
- Five stages, in order, on a cadence.
- Named owner at every stage.
- A single exposure register that spans the loop.
- Evidence attached to every closure.
- Reporting that translates exposure into risk for leadership.
Connecting existing tools
Most organizations already own the tools needed for CTEM. The framework connects them; it does not replace them.
| Existing tool category | CTEM stage it feeds | How it plugs in |
|---|---|---|
| Vulnerability scanner | Discover, Prioritize | Feeds software vulnerabilities into the exposure register. |
| Cloud security posture (CSPM) | Discover, Prioritize | Feeds misconfigurations and identity issues. |
| Identity governance | Discover, Validate, Mobilize | Provides account and access data; drives access remediation. |
| External attack surface (EASM) | Scope, Discover | Finds unknown internet-facing assets and third-party exposures. |
| Breach and attack simulation | Validate | Confirms whether exposures are exploitable in the current environment. |
| Ticketing and ITSM | Mobilize | Tracks owners, SLAs, and closure evidence. |
| SIEM and detection | Validate, Mobilize | Provides telemetry for compensating controls and retest. |
Continue with The 5 Stages of CTEM for a beginner walkthrough, or jump to How to Start a CTEM Program for a 30/60/90-day plan.
How to apply this
- Map your existing tools to the seven categories above and note gaps
- Draw the loop on one page with your named owners at each stage
- Pick one business service and run a first cycle end to end
- Adopt the minimum viable metric set within the next quarter
- Publish a cadence commitment for each stage and review it monthly
Common mistakes
- Trying to buy the framework as a single product
- Skipping Scope and jumping straight to Discovery
- Skipping Validation because it feels like extra work
- Running Mobilize without a real ownership map
- Reporting activity metrics instead of outcome metrics
Key takeaways
- The framework is a five-stage loop, run on a cadence, with named owners.
- Inputs and outputs at every stage keep the loop from breaking.
- Metrics are what prove the framework is working.
- Most organizations already own the tools; the framework connects them.
- The same framework scales from a two-person team to a global enterprise.
Frequently asked questions
Related pages
What is CTEM?
What is CTEM? Continuous Threat Exposure Management Explained
CTEM (Continuous Threat Exposure Management) explained in plain English: definition, why it exists, and how it works as an operating model, not a tool.
5 Stages of CTEM
The 5 Stages of CTEM Explained for Beginners
A beginner-friendly walkthrough of the five CTEM stages, scoping, discovery, prioritization, validation, and mobilization, using one running example.
CTEM Roles and Responsibilities
CTEM Roles and Responsibilities: Who Does What in the Program
A simple RACI-style view of CTEM roles across security, IT, cloud, application, identity, risk, and leadership teams.
CTEM Metrics and KPIs
CTEM Metrics and KPIs: What to Measure and How to Report
Practical CTEM metrics and KPIs with what each one means, why it matters, and how each one can be misused if reported without context.
Next step
Next: The 5 stages of CTEM explained
A beginner walkthrough of each stage in the loop.
Author
LearnCTEM Editorial Team
Practitioners and educators writing plain-English guides on Continuous Threat Exposure Management.
Reviewed by
Senior CTEM Practitioner Panel
Reviewed for accuracy against public CTEM guidance and real-world program experience.
Sources and further reading
- ▸Gartner, Implement a Continuous Threat Exposure Management (CTEM) Program (2022). Original description of the five-stage CTEM operating model.
- ▸NIST Cybersecurity Framework 2.0. Public framework whose functions align with the CTEM loop.
- ▸ISO/IEC 27001:2022, Information security management systems. Provides governance context compatible with CTEM.

