Manufactured urgency and Problems as a Service are too often packaged and marketed in the cybersecurity industry, and vulnerability management is squarely in the crosshairs.
Before I get into this, I want to acknowledge something: I’ve worked with some genuinely excellent vendors throughout my career, and strong partnerships with the people who support our programs matter. This is a challenge to an industry pattern where the most valuable strategies rarely get marketed to us at all.
As the threat landscape shifts, expanding the breadth of our scanner portfolios is a reasonable investment. However, detection, reporting, and remediation only describe a minimally viable vulnerability management program. That creates the opportunity for strategies that reduce time to value and drive ROI. Continuous Threat Exposure Management is one of them.
Continuous Threat Exposure Management
What data are you missing
Scanner findings provide a necessary starting point for vulnerability prioritization, but they don’t provide the full risk context needed to determine what should be addressed first. Exploitability intelligence, asset criticality, and compensating controls add dimensions the finding itself can’t provide, allowing vulnerabilities to be evaluated in the context of actual exposure.
CTEM exists to close that gap. Gartner’s framework breaks exposure management into five stages: scoping, discovery, prioritization, validation, and mobilization. Prioritization is where additional context becomes especially valuable, because effective prioritization depends on inputs beyond the finding itself.
The story of risk is written; the work is putting the chapters in the right order
Exploitability, compensating controls, and asset criticality tell the story of your actual risk exposure. They’re just scattered across sources that were never asked to talk to each other.
For vulnerability management, one of CTEM’s most useful implications is assembling and sequencing existing security context in a way that reflects what’s actually exploitable, on what actually matters, given what’s actually protecting it. This is how a small number of well-prioritized findings can replace a much larger queue of undifferentiated ones.
From CVSS to residual risk
Compensating controls: the missing component of risk
Every scanner can report a finding’s severity, but it can’t fully account for whether compensating controls change what that severity actually means. The result can be an asset with well-defined network, recovery, and monitoring controls ranked above a second asset with lower-severity findings but none of those protections.
Understanding real risk means calculating residual risk instead, and that’s where the incentives break down. Residual risk takes time and research to calculate with any confidence. The catch: a tool that promises deployment in four hours was never built to budget for that research.
Borrowing from FAIR: building a practical residual-risk model
FAIR provides a rigorous quantitative framework for decomposing information risk into measurable factors. Not every vulnerability management program needs full financial loss quantification to benefit from that way of thinking. A simpler FAIR-inspired model can combine asset impact, finding severity, exposure, and control effectiveness into a contextual prioritization score.
This example demonstrates how two assets with the same impact can have very different risk profiles:
- Asset A. More findings, low exposure, strong controls.
- Asset B. Fewer findings, high exposure, weak controls.
| Factor | Asset A | Asset B |
|---|---|---|
| Impact | 8 | 8 |
| Severity | 9 | 5 |
| Exposure | 0.3 | 0.8 |
| Inherent Risk (Impact × Severity × Exposure) | 21.6 | 32 |
| Control Effectiveness | 0.8 | 0.2 |
| Residual Risk | 4.3 | 25.6 |
Residual Risk = (Impact × Severity × Exposure) × (1 - Control Effectiveness)
Asset B ends up with roughly 6x the residual risk of Asset A, despite fewer and less severe findings, because exposure and control effectiveness dominate the calculation once impact is held equal.
That’s the exact scenario a scanner alone can’t see: on findings and severity alone, it would rank Asset A higher, and miss that Asset A’s controls are already absorbing most of its risk.
On precision This is a deliberately simplified model. Real implementations will weight factors differently and may include more of them. But the core point holds regardless of precision: residual risk, not finding count, is what should be driving prioritization.
The goal is risk reduction
Neither of these ideas requires a new tool, a new vendor, or a renewal invoice.
CTEM changes what enters the queue by filtering for what’s actually exploitable instead of everything a scanner can find. Residual risk changes how what remains gets ordered, replacing an opaque severity label with a score that accounts for the controls already in place.
Together, they attack the same underlying cost: undifferentiated findings, unnecessary context-switching, and remediation effort spent on issues that may contribute relatively little to residual risk.
The industry will continue selling problems. The solutions, it turns out, are free.
The goal isn’t to produce the most findings. It’s to reduce the most risk.