Quick answer
Direct answer
What you will learn
- Every core role in a CTEM program and what it does
- A vendor-neutral RACI matrix mapped to the five stages
- How roles scale between small teams and large enterprises
- Escalation paths when ownership is disputed
- Where to put program management
Explanation
RACI legend
Core roles
| Role | What they do in CTEM | Where they sit |
|---|---|---|
| CISO or security leader | Owns program mandate, budget, and outcome; escalation of last resort | Security leadership |
| Program manager | Runs cadence, tracks stages, publishes reports, owns the register schema | Security operations |
| Exposure analyst | Applies prioritization signals to produce the ranked list | Security engineering |
| Security engineer | Runs discovery, integrates data sources, maintains tooling | Security engineering |
| Offensive security | Validates top exposures with safe and controlled tests | Red team or partner |
| Cloud team | Owns cloud misconfigurations and cloud identity fixes | Platform engineering |
| Identity team | Owns account, role, and access exposures | Identity engineering |
| Application team | Owns code-level, library, and configuration fixes | Product engineering |
| IT operations | Owns endpoint, network, and infrastructure fixes | IT |
| Business owner | Confirms scope; receives outcome reporting | Business unit |
RACI matrix across the five stages
| Stage | Accountable | Responsible | Consulted | Informed |
|---|---|---|---|---|
| Scope | CISO or security leader | Program manager | Business owners, IT leads | Board |
| Discover | Security engineering lead | Security engineers, posture teams | Cloud, identity, app teams | Program manager |
| Prioritize | Exposure analyst | Security engineering | Threat intel, business owners | Leadership |
| Validate | Offensive security lead | Red team, posture teams | Asset owners | Program manager |
| Mobilize | Asset owner | IT, cloud, identity, app teams | Security, change management | Leadership |
Small team pattern
A two- to three-person security team can still run CTEM. One person plays program manager, exposure analyst, and security engineer. A second focuses on validation and remediation coordination. A third, if available, handles reporting. Asset owners still exist across the business; CTEM only formalizes them.
| Person | Roles they play in a small team |
|---|---|
| Security lead | CISO responsibilities plus program manager and reporting |
| Security engineer | Discovery, exposure analysis, prioritization, validation coordination |
| Part-time offensive contact | Validation on top exposures; can be a rotating red team member or partner |
Enterprise pattern
At enterprise scale, CTEM runs in overlapping cycles across many business services. The roles do not change, but they multiply. A common pattern is one program manager per region or business unit, a shared exposure analyst pool, a central security engineering platform team, and a shared offensive security team that services validation demand.
Business owner engagement
Business owners appear in two stages: Scope and reporting. Overloading them with intermediate detail is a common mistake. What they need is:
- A clear statement of what is in scope this cycle and why.
- A one-page report at the end of the cycle showing what changed.
- A named escalation contact when Mobilize stalls on their service.
Escalation paths
Escalation is defined during Scope, not invented at the moment of conflict. A minimum escalation ladder looks like: asset owner, asset owner's manager, service owner, security engineering lead, CISO. Escalation is triggered by SLA breach on a validated exposure, not by preference.
Where to put program management
Program management is often the difference between a working CTEM program and a stalled one. Placement options:
| Placement | Advantages | Trade-offs |
|---|---|---|
| Inside security operations | Close to discovery and validation data | Can drift toward operational reporting only |
| Inside security governance | Strong link to risk reporting and leadership | May be distant from engineering realities |
| Shared PMO with security lead | Balanced with other security programs | Depends on PMO seniority for CTEM to get airtime |
To see the roles in action, read How CTEM Works in Real Life. For the metric set each role should track, see CTEM Metrics and KPIs.
How to apply this
- Fill in the RACI matrix above with real names in your organization
- Identify any stage that currently has no accountable role and appoint one
- Publish an escalation ladder for the top three business services
- Assign a program manager, even if only part-time, before the next cycle
- Agree a one-page reporting template with your first business owner
Common mistakes
- Leaving Mobilize with no named owner
- Overloading business owners with intermediate detail
- Combining Accountable and Responsible into the same role at every stage
- Skipping escalation planning until conflict happens
- Assuming a scanner tool replaces the program manager role
Key takeaways
- CTEM needs accountable owners at every stage, not just one program lead.
- A published RACI is the fastest way to remove ambiguity.
- Small teams can play multiple roles, but not skip them.
- Business owners belong in Scope and reporting, not in day-to-day work.
- Escalation is defined during Scope, not invented under pressure.
Frequently asked questions
Related pages
CTEM Framework
CTEM Framework: The Complete Operating Model Explained
The full CTEM framework: five stages, inputs, outputs, roles, cadence, and how scope, discovery, prioritization, validation, and mobilization connect.
How CTEM Works in Real Life
How CTEM Works in Real Life: A Practical End-to-End Scenario
A realistic CTEM story: internet-facing system, weak access, unclear ownership, prioritization, validation, remediation, closure evidence, and reporting.
CTEM Metrics and KPIs
CTEM Metrics and KPIs: What to Measure and How to Report
Practical CTEM metrics and KPIs with what each one means, why it matters, and how each one can be misused if reported without context.
How to Start a CTEM Program
How to Start a CTEM Program: A 30/60/90-Day Roadmap
A practical 30/60/90-day roadmap for starting a CTEM program: what to do first, what to avoid, how to choose scope, and how to show early progress.
Next step
Next: CTEM metrics and KPIs
See what each role should measure and report.
Author
LearnCTEM Editorial Team
Practitioners and educators writing plain-English guides on Continuous Threat Exposure Management.
Reviewed by
Senior CTEM Practitioner Panel
Reviewed for accuracy against public CTEM guidance and real-world program experience.
Sources and further reading
- ▸Gartner, Implement a Continuous Threat Exposure Management (CTEM) Program (2022). Introduces the multi-team ownership model of CTEM.
- ▸NIST Cybersecurity Framework 2.0, Govern function. Public guidance on accountability structures compatible with CTEM.

