CTEM can give your security team a contextual edge

Tags:

Traditional vulnerability management is accelerating toward a reset, with many security organizations considering continuous threat exposure management (CTEM) to better align their operations with the pace of change — and attacks — today.

Whereas traditional vulnerability management relies on periodic assessments, with security teams scanning environments, identifying vulnerabilities, and implementing fixes as necessary, CTEM takes a more agile approach, while also broadening beyond vulnerabilities with the aim to continuously understand an organization’s risk exposure across endpoints, networks, identities, cloud environments, applications, and users.

“CTEM brings something different to the table in three key areas,” highlights Fernando Maldonado, principal analyst at Foundry Spain.

The first, he points out, is scope. In addition to vulnerable software, CTEM also focuses on misconfigurationsidentity risks, excessive permissions, and leaked credentials —gateways attackers are increasingly putting to use.

“The second is validation, because instead of relying on a score, [CTEM] verifies whether the exposure is truly exploitable and whether current controls would prevent it,” Maldonado adds.

The third difference, he says, is mobilization, because the CTEM framework assigns a specific person the responsibility for fixing each issue, which is where things traditionally get bogged down. “The metric shifts from how many vulnerabilities I’ve found to how many real attack vectors I’ve closed,” he concludes.

One-off scans are no longer enough

The current threat landscape makes it clear that one-off scans are no longer sufficient.

Today’s infrastructures are constantly changing. Cloud environments, distributed applications, API integrations, continuous deployments, and automation are constantly changing an organization’s attack surface.

“A single snapshot can provide useful information, but it quickly becomes outdated,” says Luis Uribe, offensive security engineer at Factum. “New assets, configuration changes, exposed services, or modifications to permissions can alter the level of risk in a matter of hours or days.”

Moreover, attackers are operating increasingly more quickly to exploit very narrow windows of opportunity. “As a result, organizations need a continuous ability to identify, contextualize, and prioritize the vulnerabilities that could actually be used in an attack,” Uribe says.

That speed is a key reason why security organizations should consider shifting to CTEM, Foundry Spain’s Maldonado adds. Otherwise, they may be operating blind.

“Between assessments, there’s a long period of uncertainty, and attackers, increasingly relying on AI, are taking less time to exploit new vulnerabilities,” he says. “Simply patching and doing nothing is no longer enough.”

Volume is another issue, Maldonado says. Tens of thousands of vulnerabilities are published each year, generating unmanageable backlogs where important issues are buried under countless minor findings.

And finally, there is coverage to consider, he adds.

“Scanners see vulnerable software, but not the identity, the SaaS, misconfigurations, or attack vectors, which is precisely where the attackers gain entry. A scan reveals what is vulnerable, but not what is exploitable or what truly matters to the business. This part of the argument holds true without needing to trust any vendor, because these are structural facts of the environment,” he explains.

The role of automation and contextual intelligence

Factum’s Uribe notes that automation and contextual intelligence are two essential pillars of the CTEM model. In his opinion, the former allows for continuous visibility into assets, configurations, vulnerabilities, and changes in the environment, facilitating the early detection of new exposures.

And while Agustín Serralta, director of services and CISO at SCC España, states that automation is key, it doesn’t replace human judgment.

“In complex environments, it’s impossible to manage large volumes of data without automation,” he says. “However, completely delegating decision-making to algorithms can be risky, especially if those models aren’t reviewed or become obsolete.”

As a result, contextual intelligence must combine technical context (exploitability, exposure, existing measures) with business context (which systems support critical processes, legal obligations, or contractual commitments), he says.

“Without that combination, there is no real risk management, only prioritization based on technical needs,” he says.

Javier Castillo, operations director of Secure&IT, says it’s important to note that CTEM doesn’t replace penetration testing  or red team activities, which “remain fundamental services for identifying complex vulnerabilities, design errors, logical failures, or advanced attack techniques that can hardly be detected through automated processes,” he says.

Therefore, he adds, continuous monitoring and offensive assessments should be understood as complementary capabilities within a mature cybersecurity strategy.

The shift from a reactive strategy to continuous exposure management

José de la Cruz, technical director of TrendAI Iberia, says automation plays a fundamental role in enabling organizations to implement the five phases of CTEM — scoping, discovery, prioritization, validation, and mobilization — in an agile and efficient manner.

With automation in place, “the human becomes an analyst who supervises (human-in-the-loop) the correct functioning of the model and validates the data it produces, thus guaranteeing an effective and reliable implementation,” he says.

Enterprises should first aim those efforts at achieving a comprehensive view of their attack surface, including all the organization’s assets: traditional infrastructures, cloud environments, applications, digital identities, connected devices, and services exposed to third parties, Secure&IT’s Castillo explains.

“You cannot protect what you do not know, and many organizations still lack a complete vision of all the elements that make up their ecosystem,” he says.

From there, organizations should work toward establishing continuous processes for risk identification, validation, prioritization, and remediation.

“This involves incorporating continuous monitoring capabilities and solutions that automate the collection and correlation of information, establish risk-oriented metrics, and create collaboration mechanisms between the various technical and business teams,” he adds.

CTEM adoption challenges

Companies face many challenges in switching to CTEM, chief among them reducing fragmentation, SCC España’s Serralta says, because “we have too many tools, consoles, reports, and data that it’s simply impossible to manage.”

At an organizational level, Serralta believes silos also remain a significant barrier. “When it’s unclear who decides or who is responsible, security is compromised. At a cultural level, several natural resistances converge: lack of time, an exclusive focus on ‘compliance,’ or an overreliance on tools.”

Foundry Spain’s Maldonado believes “the cultural aspect is the hardest.”

“It involves changing the mindset from finding and reporting vulnerabilities to validating and reducing business risk, resisting the urge to keep hunting them down one by one, and accepting that CTEM is not a capability delivered by a vendor, but an operational model that the organization has to design and adopt,” he says. “That’s the point that sinks most programs, because the tool is purchased expecting it to bring the culture with it, and that never works that way.” From a regulatory point of view, Serralta believes CTEM fits well with the risk management principle required by European regulations, “but only if it is implemented with governance, traceability and human control, in line with the corporate security policies, as well as acceptable use policies for technology, data, and AI, that we must define and distribute to all personnel in the organization.”

Categories

No Responses

Leave a Reply

Your email address will not be published. Required fields are marked *