Quick answer
Direct answer
What you will learn
- A 30/60/90-day plan for starting a CTEM program
- How to pick the first business service to scope
- What to do in each 30-day block
- How to prove early value to leadership
- Common early-stage mistakes and how to avoid them
Explanation
Rule zero
Before day one: pick the first service
The first service should score well on three criteria: it matters to the business, it has data you can actually pull, and it has an owner who will engage. If it is also visible to leadership, that helps with sustained support. Do not pick a service just because it is easy; ease alone will not create the story you need for cycle two.
| Criterion | Why | What good looks like |
|---|---|---|
| Business importance | Creates a clear risk story | Customer-facing, revenue-generating, or regulated |
| Data availability | Discovery needs signal | Scanner, cloud, and identity data are already flowing |
| Engaged owner | Mobilize needs a partner | Business owner meets with security regularly |
| Bounded surface | Fits in one cycle | A handful of assets, not the entire platform |
Days 1 to 30: run a first cycle
The first 30 days follow the five-stage loop end to end on the chosen service. See How CTEM Works in Real Life for a day-by-day scenario. The goal is not perfection; it is to close the loop once with evidence.
| Days | Stage | Output |
|---|---|---|
| 1 to 3 | Scope | One-page scope brief |
| 3 to 8 | Discover | Exposure register |
| 8 to 11 | Prioritize | Ranked short list of top exposures |
| 11 to 14 | Validate | Evidence for each priority exposure |
| 14 to 21 | Mobilize | Closed tickets with evidence |
| 21 to 30 | Report and retrospective | One-page report and top three improvements |
Days 31 to 60: run cycle two and lock the model
The second cycle on the same service is where the operating model becomes real. Time to closure should drop. The register should carry over. Retrospective improvements should be applied. This is also when the program formalizes:
- A written cadence for each stage.
- An escalation ladder.
- The minimum viable metric set from CTEM Metrics and KPIs.
- A one-page reporting template for the business owner.
- A named program manager, even if part-time.
Days 61 to 90: scale to more services
Add two more services in the third month. Do not add more until the second cycle on the first service completes on time. Scaling too early replays the boil-the-ocean problem. What scales:
| Element | How it scales |
|---|---|
| Exposure register | Same schema, more rows, tagged by service |
| Cadence | Same weekly rhythm; more services in parallel |
| Ownership map | Extend RACI to new services' owners |
| Reporting | Same template per service, plus a rolled-up view for leadership |
| Validation | Same methods; may need a partner if internal capacity is limited |
How to prove early value
Leadership judges early CTEM by whether the loop closed on something real. Show:
- The critical exposures closed with evidence on the first service.
- The mean age at closure and how it compares to the previous approach.
- One clear risk story that would have been ignored under the old process.
- The specific operational improvements the retrospective produced.
Common early-stage mistakes
| Mistake | Why it happens | How to avoid |
|---|---|---|
| Scoping the whole environment | Pressure to be comprehensive | Pick one service; treat the rest as future scope |
| Buying a platform first | Vendor pitch pressure | Prove the loop with existing tools; buy later if a real gap remains |
| Skipping Validation | Time pressure | Validation is non-negotiable; nothing goes to Mobilize without it |
| No named program manager | Assumed the security lead can do it all | Nominate a program manager even if part-time |
| Reporting activity metrics | Easier to produce | Publish outcome metrics from cycle one |
Sponsor conversation script
When pitching CTEM to a sponsor, keep it short: the problem is signal, not data. We already have thousands of findings. CTEM turns those into a small ranked list of exposures that are reachable, exploitable, tied to important assets, and owned. We will prove it on one service in 30 days and report the result. If it works, we will scale.
Once the program is running, deepen with the CTEM Framework, Roles and Responsibilities, and Metrics and KPIs.
How to apply this
- Pick one business service that meets all four selection criteria
- Draft a 30-day plan mirroring the day-by-day table above
- Publish a one-page scope brief before day three
- Set a maximum of five items on the first ranked list
- Book the day-30 report review with your sponsor before day one
Common mistakes
- Scoping the entire environment on the first cycle
- Buying a new platform before running one cycle
- Skipping validation to save time
- Delaying the retrospective until things go wrong
- Reporting activity metrics instead of the closed loop
Key takeaways
- Start small, prove the loop, then scale in 30-day blocks.
- Cycle one closes the loop; cycle two locks the model; days 60 to 90 scale.
- You do not need to buy a new platform to start.
- A sponsor senior enough to unstick Mobilize is essential.
- The retrospective is what turns cycles into a program.
Frequently asked questions
Related pages
How CTEM Works in Real Life
How CTEM Works in Real Life: A Practical End-to-End Scenario
A realistic CTEM story: internet-facing system, weak access, unclear ownership, prioritization, validation, remediation, closure evidence, and reporting.
CTEM Roles and Responsibilities
CTEM Roles and Responsibilities: Who Does What in the Program
A simple RACI-style view of CTEM roles across security, IT, cloud, application, identity, risk, and leadership teams.
CTEM Metrics and KPIs
CTEM Metrics and KPIs: What to Measure and How to Report
Practical CTEM metrics and KPIs with what each one means, why it matters, and how each one can be misused if reported without context.
Free CTEM Certifications
Best Free CTEM Certification: Beginner to Leader
A free CTEM certification path with three levels: Beginner, Practitioner, and Program Leader. Free study material, sample exam, and certificate.
Next step
Next: CTEM metrics and KPIs
Set up the metric set the sponsor will see after day 30.
Author
LearnCTEM Editorial Team
Practitioners and educators writing plain-English guides on Continuous Threat Exposure Management.
Reviewed by
Senior CTEM Practitioner Panel
Reviewed for accuracy against public CTEM guidance and real-world program experience.
Sources and further reading
- ▸Gartner, Implement a Continuous Threat Exposure Management (CTEM) Program (2022). Frames the phased adoption model used in this plan.
- ▸NIST SP 800-40, Guide to Enterprise Patch Management Planning. Public guidance aligned with CTEM Mobilize practices.

