Start here

The shortest path through exposure management.

If you have been told to "stand up a CTEM program" and are not sure what that means in practice, read these in order. About forty minutes end to end, most of it the assessment.

  1. 01ScopingAgree what is in play
  2. 02DiscoveryFind every exposure, not just CVEs
  3. 03PrioritisationRank by attack path and impact
  4. 04ValidationProve it is exploitable
  5. 05MobilisationGet it fixed, and show it
  1. STEP 1 · 10 MIN

    Understand the five stages

    What CTEM is, where the term comes from, how it differs from the vulnerability management you already run, and what it is not.

  2. STEP 2 · 2 MIN

    Take the quick check

    Five questions, one per stage, answered in your head. Tells you which stage is your weakest before you invest twenty minutes in the full assessment.

  3. STEP 3 · 20 MIN

    Score your program

    Twenty statements across the five stages. A score per stage, a maturity level, and the three moves that would take you furthest. Save it and re-take next quarter.

  4. STEP 4 · AS NEEDED

    Fill the gaps with the right tools

    The directory shows which products genuinely cover which stage. Go to it with your weakest stage in mind, not a vendor's pitch.

  5. STEP 5 · MONTHLY

    Keep the cycle running

    Practical notes on the blog and one email a month with what changed, which vendors moved, and one thing worth doing.

Get the monthly Exposure Brief

One email a month: what changed in exposure management, which vendors moved, and one thing worth doing. No spam, unsubscribe any time.