From Reactive Response to Proactive Defense: The Importance of CTEM
- Siwoo Lee

- Jun 9
- 5 min read
PAGO Gartner Security & Risk Management Summit On Site Report
PAGO attended the 2026 Gartner Security & Risk Management Summit in National Harbor, Maryland, and sharing key insights from the security sessions discussed on site. This report examines Outlook for Exposure Management: Accelerating CTEM Adoption, presented by Steven Santos, and explores how Exposure Management is expanding beyond vulnerability identification into validation, mobilization, and risk-based decision making.

"Finding vulnerabilities is actually the easy part. That is not the real challenge of Exposure Management."
Steven Santos opened the session with this observation. Most organizations already use a variety of tools to identify vulnerabilities, exposed services, cloud misconfigurations, and identity related risks.
The remaining challenge is determining whether those exposures can realistically lead to an attack and ensuring that the organization takes the necessary action to reduce the associated risk.
This is the foundation of Continuous Threat Exposure Management (CTEM). Rather than focusing solely on identifying vulnerabilities, CTEM focuses on validating which exposures matter most, prioritizing them based on business impact, and connecting findings to meaningful action.
CTEM and the Identification of Attack Paths
Continuous Threat Exposure Management (CTEM) was presented as an approach for identifying and managing exposures that are both likely to be exploited and capable of creating significant business impact.

According to Santos, successful exposure management depends on what happens after discovery. The goal is not to find more exposures. The goal is to validate whether identified exposures can realistically be used by attackers and connect those findings to action across the organization.
Traditional Vulnerability Management often prioritizes remediation based on CVE and CVSS scores. CTEM follows a broader and more continuous operating cycle.
Organizations must consider:
Which assets are most important to the business
Whether those assets are externally accessible
Whether monitoring and access controls are in place
Whether the exposure can realistically be exploited
Most importantly, those assessments must lead to actions that reduce risk. Finding risks and reducing risks are two different activities. This distinction explains why Gartner highlighted Validation and Mobilization as key priorities throughout the session.
Mobilization: The Essential Step in Exposure Management
Identifying and prioritizing exposures does not automatically reduce risk. Organizations must determine which issues require remediation, which risks can be accepted, and where mitigation measures should be applied. This process is known as Mobilization.

Mobilization goes beyond creating remediation tickets. It is the process of determining appropriate actions and ensuring that responsible teams execute them.
The correct response is not always immediate remediation. Some assets may require urgent patching. Others may face operational constraints, service dependencies, or business considerations that make immediate remediation difficult.
In these situations, organizations may choose:
Remediation
Risk Acceptance
Mitigation
Mitigation differs from remediation. Rather than fixing the vulnerability directly, mitigation reduces the likelihood of exploitation through measures such as access restrictions, enhanced monitoring, or compensating controls. The objective is not simply to patch faster. The objective is to determine which actions are appropriate based on attack likelihood and business impact. Mobilization is often more of an organizational challenge than a technical one.
If asset owners do not understand why action is required, or if ownership and approval processes are unclear, risks remain unresolved. Security teams can identify risks and establish priorities, but execution frequently depends on infrastructure, cloud, application, network, and business system owners.
The success of CTEM ultimately depends on whether identified risks result in action.
The Role of the Mobilization Coordinator
According to Santos, organizations need a role that bridges the gap between risk identification and risk reduction. The Mobilization Coordinator acts as a facilitator across security teams, IT operations, GRC functions, and business stakeholders. The role extends beyond ticket management.

For example:
Regulatory or audit related exposures may require coordination with GRC teams
Infrastructure and cloud vulnerabilities may require collaboration with IT operations teams
New indicators of compromise (IoCs) and attack techniques may need to be correlated with existing exposure data
The objective is to align priorities, responsibilities, and execution plans across multiple teams.
Santos noted that organizations with dedicated Mobilization Coordinators can reduce the time required to translate identified risks into action compared to organizations relying solely on traditional vulnerability remediation processes.
This reinforces an important point: CTEM is not simply a technology initiative. It is an operational framework built around accountability and execution.
Extending Exposure Data into TDIR
Santos explained that Exposure Data can also play an important role in TDIR (Threat Detection, Investigation, and Response). Exposure data provides insight into which assets are vulnerable, which configurations present risk, and which attack paths may be available to an adversary. TDIR, on the other hand, focuses on detecting, investigating, and responding to threats based on alerts and security events.

When these two areas are connected, the way SOC teams evaluate alerts begins to change. The same alert may require a very different response depending on whether it originated from a business critical asset, whether that asset is externally exposed, whether it is connected to a known attack path, and whether monitoring or access controls are already in place. According to Santos, integrating Exposure Data into TDIR can improve visibility, support more effective response decisions, strengthen detection logic, provide greater understanding of incident impact, and reduce triage time.
This message is particularly important from a security operations perspective. When analysts review an alert, they need more than an answer to the question, “Is this malicious?” They also need to understand whether the event involves a critical asset, whether an attacker could move to the next stage of an attack, whether immediate containment is necessary, or whether additional monitoring is sufficient.
Exposure data can provide the context needed to support those decisions. Ultimately, the integration of Exposure Management and TDIR supports a more proactive approach to security operations. Rather than assessing asset criticality and exposure only after an alert is generated, organizations can use existing exposure information to prioritize alerts and determine response actions more quickly. This demonstrates how CTEM can extend beyond risk identification and become an operational foundation that improves the quality of detection, investigation, and response decisions.
Conclusion
CTEM is not simply a methodology for finding more vulnerabilities. Most organizations already have visibility into external attack surfaces, cloud configurations, application vulnerabilities, and credential related risks. The real value of Exposure Management lies in prioritizing exposures based on attack likelihood and business impact, then ensuring those findings result in meaningful action.
From PAGO's perspective, this message closely aligns with the principles applied in MDR operations. Alerts should not be evaluated as isolated events. Organizations should also consider external exposure, attack path potential, and business context when determining response priorities.
The objective is to help organizations understand which risks require immediate attention and why. Ultimately, the value of CTEM is realized when identified exposures are validated, translated into action, and used to improve detection, investigation, and response decisions. When that happens, Exposure Management becomes more than a risk identification exercise. It becomes a measurable contributor to security operations outcomes.

Written by: Siwoo Lee Threat Analyst | DeepACT MDR Center



