{"id":9243,"date":"2026-08-28T08:25:00","date_gmt":"2026-08-28T08:25:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9243"},"modified":"2026-08-28T08:25:00","modified_gmt":"2026-08-28T08:25:00","slug":"ctem-can-give-your-security-team-a-contextual-edge","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9243","title":{"rendered":"CTEM can give your security team a contextual edge"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Traditional vulnerability management is accelerating toward a reset, with many security organizations considering <a href=\"https:\/\/www.csoonline.com\/article\/3979418\/what-is-ctem.html\">continuous threat exposure management\u00a0(CTEM)<\/a> to better align their operations with the pace of change \u2014 and attacks \u2014 today.<\/p>\n<p class=\"wp-block-paragraph\">Whereas traditional vulnerability management relies on periodic assessments, with security teams scanning environments, identifying vulnerabilities, and implementing fixes as necessary, CTEM takes a more agile approach, while also broadening beyond vulnerabilities with the aim to continuously understand an organization\u2019s risk exposure across\u00a0endpoints, networks, identities,\u00a0cloud\u00a0environments, applications, and users.<\/p>\n<p class=\"wp-block-paragraph\">\u201cCTEM brings something different to the table in three key areas,\u201d highlights\u00a0Fernando Maldonado,\u00a0principal analyst at Foundry Spain.<\/p>\n<p class=\"wp-block-paragraph\">The first, he points out, is scope. In addition to vulnerable software, CTEM also focuses on <a href=\"https:\/\/www.csoonline.com\/article\/3623709\/nail-the-software-setup-and-avoid-attacks-with-the-top-10-cybersecurity-misconfiguration-list.html\">misconfigurations<\/a>,\u00a0<a href=\"https:\/\/www.csoonline.com\/article\/4042464\/enterprise-passwords-becoming-even-easier-to-steal-and-abuse.html\">identity risks<\/a>, <a href=\"https:\/\/www.csoonline.com\/article\/4123184\/always-on-privileged-access-is-pervasive-and-fraught-with-risks.html\">excessive permissions<\/a>, and leaked credentials \u2014gateways attackers are increasingly putting to use.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe second is validation, because instead of relying on a score, [CTEM] verifies whether the exposure is truly exploitable and whether current controls would prevent it,\u201d Maldonado adds.<\/p>\n<p class=\"wp-block-paragraph\">The third difference, he says, is mobilization, because the CTEM framework assigns a specific person the responsibility for fixing each issue, which is where things traditionally get bogged down. \u201cThe metric shifts from how many vulnerabilities I\u2019ve found to how many real attack vectors I\u2019ve closed,\u201d he concludes.<\/p>\n<h2 class=\"wp-block-heading\">One-off scans are no longer enough<\/h2>\n<p class=\"wp-block-paragraph\">The current threat landscape makes it clear that one-off scans are no longer sufficient.<\/p>\n<p class=\"wp-block-paragraph\">Today\u2019s infrastructures are constantly changing.\u00a0Cloud\u00a0environments, distributed applications, API integrations, continuous deployments, and automation are constantly changing an organization\u2019s attack surface.<\/p>\n<p class=\"wp-block-paragraph\">\u201cA single snapshot can provide useful information, but it quickly becomes outdated,\u201d says Luis Uribe, offensive security engineer at Factum. \u201cNew assets, configuration changes, exposed services, or modifications to permissions can alter the level of risk in a matter of hours or days.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Moreover, attackers are operating increasingly more quickly to exploit very narrow windows of opportunity. \u201cAs a result, organizations need a continuous ability to identify, contextualize, and prioritize the vulnerabilities that could actually be used in an attack,\u201d Uribe says.<\/p>\n<p class=\"wp-block-paragraph\">That speed is a key reason why security organizations should consider shifting to CTEM, Foundry Spain\u2019s Maldonado adds. Otherwise, they may be operating blind.<\/p>\n<p class=\"wp-block-paragraph\">\u201cBetween assessments, there\u2019s a long period of uncertainty, and attackers, increasingly relying on AI, are taking less time to exploit new vulnerabilities,\u201d he says. \u201cSimply patching and doing nothing is no longer enough.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Volume is another issue, Maldonado says. Tens of thousands of vulnerabilities are published each year, generating <a href=\"https:\/\/www.csoonline.com\/article\/4159882\/nist-cuts-down-cve-analysis-amid-vulnerability-overload.html\">unmanageable backlogs<\/a> where important issues are buried under countless minor findings.<\/p>\n<p class=\"wp-block-paragraph\">And finally, there is coverage to consider, he adds.<\/p>\n<p class=\"wp-block-paragraph\">\u201cScanners see vulnerable software, but not the identity, the SaaS, misconfigurations, or attack vectors, which is precisely where the attackers gain entry. A scan reveals what is vulnerable, but not what is exploitable or what truly matters to the business. This part of the argument holds true without needing to trust any vendor, because these are structural facts of the environment,\u201d he explains.<\/p>\n<h2 class=\"wp-block-heading\">The role of automation and contextual intelligence<\/h2>\n<p class=\"wp-block-paragraph\">Factum\u2019s Uribe notes that automation and contextual intelligence are two essential pillars of the CTEM model. In his opinion, the former allows for continuous visibility into assets, configurations, vulnerabilities, and changes in the environment, facilitating the early detection of new exposures.<\/p>\n<p class=\"wp-block-paragraph\">And while\u00a0Agust\u00edn Serralta, director of services and CISO at SCC\u00a0Espa\u00f1a, states that automation is key, it doesn\u2019t replace human judgment.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIn complex environments, it\u2019s impossible to manage large volumes of data without automation,\u201d he says. \u201cHowever, completely delegating decision-making to algorithms can be risky, especially if those models aren\u2019t reviewed or become obsolete.\u201d<\/p>\n<p class=\"wp-block-paragraph\">As a result, contextual intelligence must combine technical context (exploitability, exposure, existing measures) with business context (which systems support critical processes, legal obligations, or contractual commitments), he says.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWithout that combination, there is no real risk management, only prioritization based on technical needs,\u201d he says.<\/p>\n<p class=\"wp-block-paragraph\">Javier Castillo, operations director of Secure&amp;IT,\u00a0says it\u2019s important to note that CTEM doesn\u2019t replace penetration testing\u00a0 or red team activities, which \u201cremain fundamental services for identifying complex vulnerabilities, design errors, logical failures, or advanced attack techniques that can hardly be detected through automated processes,\u201d he says.<\/p>\n<p class=\"wp-block-paragraph\">Therefore, he adds, continuous monitoring and offensive assessments should be understood as complementary capabilities within a mature cybersecurity strategy.<\/p>\n<h2 class=\"wp-block-heading\">The shift from a reactive strategy to continuous exposure management<\/h2>\n<p class=\"wp-block-paragraph\">Jos\u00e9 de la Cruz, technical director of TrendAI\u00a0Iberia, says automation plays a fundamental role in enabling organizations to implement the five phases of CTEM \u2014 scoping, discovery, prioritization, validation, and mobilization \u2014 in an agile and efficient manner.<\/p>\n<p class=\"wp-block-paragraph\">With automation in place, \u201cthe human becomes an analyst who supervises (human-in-the-loop) the correct functioning of the model and validates the data it produces, thus guaranteeing an effective and reliable implementation,\u201d he says.<\/p>\n<p class=\"wp-block-paragraph\">Enterprises should first aim those efforts at achieving a comprehensive view of their attack surface, including all the organization\u2019s assets: traditional infrastructures, cloud environments, applications, digital identities, connected devices, and services exposed to third parties, Secure&amp;IT\u2019s Castillo explains.<\/p>\n<p class=\"wp-block-paragraph\">\u201cYou cannot protect what you do not know, and many organizations still lack a complete vision of all the elements that make up their ecosystem,\u201d he says.<\/p>\n<p class=\"wp-block-paragraph\">From there, organizations should work toward establishing continuous processes for risk identification, validation, prioritization, and remediation.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThis involves incorporating continuous monitoring capabilities and solutions that automate the collection and correlation of information, establish risk-oriented metrics, and create collaboration mechanisms between the various technical and business teams,\u201d he adds.<\/p>\n<h2 class=\"wp-block-heading\">CTEM adoption challenges<\/h2>\n<p class=\"wp-block-paragraph\">Companies face many challenges in switching to CTEM, chief among them reducing fragmentation, SCC\u00a0Espa\u00f1a\u2019s Serralta says, because \u201cwe have too many tools, consoles, reports, and data that it\u2019s simply impossible to manage.\u201d<\/p>\n<p class=\"wp-block-paragraph\">At an organizational level, Serralta believes silos also remain a significant barrier. \u201cWhen it\u2019s unclear who decides or who is responsible, security is compromised. At a cultural level, several natural resistances converge: lack of time, an exclusive focus on \u2018compliance,\u2019 or an overreliance on tools.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Foundry Spain\u2019s Maldonado believes \u201cthe cultural aspect is the hardest.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u201cIt involves changing the mindset from finding and reporting vulnerabilities to validating and reducing business risk, resisting the urge to keep hunting them down one by one, and accepting that CTEM is not a capability delivered by a vendor, but an operational model that the organization has to design and adopt,\u201d he says. \u201cThat\u2019s the point that sinks most programs, because the tool is purchased expecting it to bring the culture with it, and that never works that way.\u201d From a regulatory point of view, Serralta believes CTEM fits well with the risk management principle required by European regulations, \u201cbut only if it is implemented with governance, traceability and human control, in line with the corporate security policies, as well as acceptable use policies for technology, data, and AI, that we must define and distribute to all personnel in the organization.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Traditional vulnerability management is accelerating toward a reset, with many security organizations considering continuous threat exposure management\u00a0(CTEM) to better align their operations with the pace of change \u2014 and attacks \u2014 today. Whereas traditional vulnerability management relies on periodic assessments, with security teams scanning environments, identifying vulnerabilities, and implementing fixes as necessary, CTEM takes a [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9244,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9243","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9243"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9243"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9243\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9244"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9243"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9243"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9243"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}