About
About CTEE
CTEE stands for Continuous Threat Exposure Evaluation. The site exists because exposure management is now a budgeted category, every vendor claims it, and buyers need an independent reference.
What we do
- Explain CTEM in plain language for practitioners and the people who approve their budgets.
- Maintain an editorial directory of vendors with honest coverage notes.
- Publish a free maturity self-assessment so teams can score their own program.
- Send one short newsletter a month.
Who is behind it
CTEE is written and maintained by Dan Swihart. It is run independently: not owned by, funded by, or affiliated with any security vendor or analyst firm. Vendor summaries and assessment advice are the author's own and are revised when shown to be wrong.
Method
- Vendor entries are compiled from public documentation, product demos where available, and practitioner reports. Each entry records the CTEM stages we believe the product genuinely serves. We mark what we have not verified hands-on.
- The self-assessment maps four statements to each of Gartner's five CTEM stages. Statements are scored 0 to 4; stage scores are the percentage of points earned; the overall score is the mean of the five stages. Maturity levels are quintiles of that score.
- Saved assessment results are stored to send the scorecard and, in aggregate and anonymised, to publish benchmarks. Quick-check answers are never stored.
- Every page carries a last-updated date. Corrections are logged on the page they affect.
Disclosure
Some links to vendor sites may be referral links, and vendors may in future pay for a clearly labelled listing tier. Neither changes what we write. Editorial summaries in the directory are ours, unpaid, and corrected when we are shown to be wrong.
Contact
Corrections, tips and partnership enquiries: hello@ctee.org.