LearnCTEM.com, Best CTEM Learning Platform
CTEM Basics

CTEM Roles and Responsibilities: Who Does What in the Program

CTEM is a team sport. Security leadership is accountable for the program. Security engineering runs discovery and validation. Exposure analysts drive prioritization. Asset owners across IT, cloud, application, and identity teams own the fixes. Business owners confirm scope. Leadership owns the outcome.

Last updated: July 24, 2026

A grid pattern with selected cells highlighted in red representing a RACI matrix of CTEM responsibilities.

Quick answer

Direct answer

A CTEM program needs an accountable security leader, an exposure analyst, security engineering, an offensive security capability, named asset owners, and engaged business leaders.

What you will learn

  • Every core role in a CTEM program and what it does
  • A vendor-neutral RACI matrix mapped to the five stages
  • How roles scale between small teams and large enterprises
  • Escalation paths when ownership is disputed
  • Where to put program management

Explanation

RACI legend

R = Responsible (does the work). A = Accountable (single owner of the outcome). C = Consulted (input before action). I = Informed (told after action).

Core roles

RoleWhat they do in CTEMWhere they sit
CISO or security leaderOwns program mandate, budget, and outcome; escalation of last resortSecurity leadership
Program managerRuns cadence, tracks stages, publishes reports, owns the register schemaSecurity operations
Exposure analystApplies prioritization signals to produce the ranked listSecurity engineering
Security engineerRuns discovery, integrates data sources, maintains toolingSecurity engineering
Offensive securityValidates top exposures with safe and controlled testsRed team or partner
Cloud teamOwns cloud misconfigurations and cloud identity fixesPlatform engineering
Identity teamOwns account, role, and access exposuresIdentity engineering
Application teamOwns code-level, library, and configuration fixesProduct engineering
IT operationsOwns endpoint, network, and infrastructure fixesIT
Business ownerConfirms scope; receives outcome reportingBusiness unit

RACI matrix across the five stages

StageAccountableResponsibleConsultedInformed
ScopeCISO or security leaderProgram managerBusiness owners, IT leadsBoard
DiscoverSecurity engineering leadSecurity engineers, posture teamsCloud, identity, app teamsProgram manager
PrioritizeExposure analystSecurity engineeringThreat intel, business ownersLeadership
ValidateOffensive security leadRed team, posture teamsAsset ownersProgram manager
MobilizeAsset ownerIT, cloud, identity, app teamsSecurity, change managementLeadership

Small team pattern

A two- to three-person security team can still run CTEM. One person plays program manager, exposure analyst, and security engineer. A second focuses on validation and remediation coordination. A third, if available, handles reporting. Asset owners still exist across the business; CTEM only formalizes them.

PersonRoles they play in a small team
Security leadCISO responsibilities plus program manager and reporting
Security engineerDiscovery, exposure analysis, prioritization, validation coordination
Part-time offensive contactValidation on top exposures; can be a rotating red team member or partner

Enterprise pattern

At enterprise scale, CTEM runs in overlapping cycles across many business services. The roles do not change, but they multiply. A common pattern is one program manager per region or business unit, a shared exposure analyst pool, a central security engineering platform team, and a shared offensive security team that services validation demand.

Business owner engagement

Business owners appear in two stages: Scope and reporting. Overloading them with intermediate detail is a common mistake. What they need is:

  • A clear statement of what is in scope this cycle and why.
  • A one-page report at the end of the cycle showing what changed.
  • A named escalation contact when Mobilize stalls on their service.

Escalation paths

Escalation is defined during Scope, not invented at the moment of conflict. A minimum escalation ladder looks like: asset owner, asset owner's manager, service owner, security engineering lead, CISO. Escalation is triggered by SLA breach on a validated exposure, not by preference.

Where to put program management

Program management is often the difference between a working CTEM program and a stalled one. Placement options:

PlacementAdvantagesTrade-offs
Inside security operationsClose to discovery and validation dataCan drift toward operational reporting only
Inside security governanceStrong link to risk reporting and leadershipMay be distant from engineering realities
Shared PMO with security leadBalanced with other security programsDepends on PMO seniority for CTEM to get airtime

To see the roles in action, read How CTEM Works in Real Life. For the metric set each role should track, see CTEM Metrics and KPIs.

How to apply this

  • Fill in the RACI matrix above with real names in your organization
  • Identify any stage that currently has no accountable role and appoint one
  • Publish an escalation ladder for the top three business services
  • Assign a program manager, even if only part-time, before the next cycle
  • Agree a one-page reporting template with your first business owner

Common mistakes

  • Leaving Mobilize with no named owner
  • Overloading business owners with intermediate detail
  • Combining Accountable and Responsible into the same role at every stage
  • Skipping escalation planning until conflict happens
  • Assuming a scanner tool replaces the program manager role

Key takeaways

  • CTEM needs accountable owners at every stage, not just one program lead.
  • A published RACI is the fastest way to remove ambiguity.
  • Small teams can play multiple roles, but not skip them.
  • Business owners belong in Scope and reporting, not in day-to-day work.
  • Escalation is defined during Scope, not invented under pressure.

Frequently asked questions

No. Most programs assemble existing security, IT, cloud, application, and identity roles into a single operating model. A dedicated program manager helps but is not strictly required for a first cycle.

Related pages

Next step

Next: CTEM metrics and KPIs

See what each role should measure and report.

Author

LearnCTEM Editorial Team

Practitioners and educators writing plain-English guides on Continuous Threat Exposure Management.

Reviewed by

Senior CTEM Practitioner Panel

Reviewed for accuracy against public CTEM guidance and real-world program experience.

Sources and further reading

  • Gartner, Implement a Continuous Threat Exposure Management (CTEM) Program (2022). Introduces the multi-team ownership model of CTEM.
  • NIST Cybersecurity Framework 2.0, Govern function. Public guidance on accountability structures compatible with CTEM.