Self-assessment

CTEM maturity self-assessment

20 statements, about five minutes. Rate how true each one is for your organisation today. You get a score per stage, an overall maturity level, and the three actions that would move you furthest.

Nothing is sent anywhere until you choose to save your results at the end.

1. Scoping

We have a written definition of which assets and business processes are in scope for exposure management.
Business owners, not only security, agreed on what counts as a critical asset.
Scope is reviewed and adjusted on a defined cadence, at least quarterly.
External attack surface, SaaS and identity are explicitly included or excluded, not left undefined.

2. Discovery

We maintain an asset inventory that reconciles multiple sources (scanner, cloud, EDR, CMDB) and flags unknowns.
Discovery covers misconfigurations, exposed credentials and identity weaknesses, not only CVEs.
Internet-facing assets are enumerated continuously, including forgotten subdomains and shadow IT.
Third-party and supplier access paths into our environment are discovered and recorded.

3. Prioritisation

Exposures are ranked by exploitability in our environment and business impact, not by raw severity score.
We use attack-path analysis or equivalent reasoning to see how exposures chain to critical assets.
Threat intelligence on active exploitation (for example CISA KEV) feeds prioritisation automatically.
Existing compensating controls are considered before an exposure is escalated.

4. Validation

Top-priority exposures are validated as actually exploitable before remediation effort is committed.
We test whether detection and response controls fire when an exposure is exercised.
Validation uses tooling (breach and attack simulation, automated pentesting) rather than only annual manual tests.
Validation results change priorities: unexploitable findings are downgraded and documented.

5. Mobilisation

Every prioritised exposure has a named owner outside the security team and a target date.
Remediation is tracked to closure with time-to-fix measured per exposure class.
Findings reach remediation teams through their own workflow tools, not spreadsheets or email.
Progress is reported to leadership in business terms (risk reduced, processes protected), not counts of vulnerabilities.

0 of 20 answered