Start here
The shortest path through exposure management.
If you have been told to "stand up a CTEM program" and are not sure what that means in practice, read these in order. About forty minutes end to end, most of it the assessment.
- 01ScopingAgree what is in play
- 02DiscoveryFind every exposure, not just CVEs
- 03PrioritisationRank by attack path and impact
- 04ValidationProve it is exploitable
- 05MobilisationGet it fixed, and show it
- STEP 1 · 10 MIN
Understand the five stages
What CTEM is, where the term comes from, how it differs from the vulnerability management you already run, and what it is not.
- STEP 2 · 2 MIN
Take the quick check
Five questions, one per stage, answered in your head. Tells you which stage is your weakest before you invest twenty minutes in the full assessment.
- STEP 3 · 20 MIN
Score your program
Twenty statements across the five stages. A score per stage, a maturity level, and the three moves that would take you furthest. Save it and re-take next quarter.
- STEP 4 · AS NEEDED
Fill the gaps with the right tools
The directory shows which products genuinely cover which stage. Go to it with your weakest stage in mind, not a vendor's pitch.
- STEP 5 · MONTHLY
Keep the cycle running
Practical notes on the blog and one email a month with what changed, which vendors moved, and one thing worth doing.