Independent · Vendor-neutral · Exposure management

Most exposure programs cannot name the ten things that matter this month.

CTEE is a field guide to Continuous Threat Exposure Management: what the five stages actually require, which tools cover which stage, and how mature your own program is. No vendor owns us.

Score your program Read the explainer
Attack path diagram A network of assets drawn as nodes. One chain of four exposures is highlighted in red, leading from an internet-facing host to a critical asset. INTERNET-FACING HOST STALE CREDENTIAL OVER-PRIVILEGED ROLE UNPATCHED SERVICE CRITICAL ASSET
  1. 01ScopingAgree what is in play
  2. 02DiscoveryFind every exposure, not just CVEs
  3. 03PrioritisationRank by attack path and impact
  4. 04ValidationProve it is exploitable
  5. 05MobilisationGet it fixed, and show it
01 / UNDERSTAND

The five stages, without the jargon

Scoping, discovery, prioritisation, validation, mobilisation. What each stage demands, where programs stall, and how CTEM differs from the vulnerability management you already run.

Read the explainer
02 / EVALUATE

Vendors, by what they actually cover

Every platform now sells a CTEM story. The directory records which stages each product genuinely serves and where the marketing outruns the software.

Open the directory
03 / MEASURE

Score your own program

Twenty statements, five minutes. A score per stage, a maturity level, and the three moves that would take you furthest. No sign-up required to see results.

Take the assessment

From the blog

Get the monthly Exposure Brief

One email a month: what changed in exposure management, which vendors moved, and one thing worth doing. No spam, unsubscribe any time.