Tenable
Continuous Threat Exposure Management (CTEM)
Continuous Threat Exposure Management (CTEM) is not a single product. It is a way of working that Gartner defined in 2022: a repeating cycle in which the organisation scopes what matters, discovers its assets and weaknesses, prioritises the ones attackers can realistically exploit, validates that assumption, and mobilises the teams that fix them. Tenable One is the exposure management platform that supports each stage of that cycle.
What it is
Traditional vulnerability management produces a long list of findings sorted by severity score. The list grows faster than any team can work through it, and a high score says little about whether an attacker can actually reach the asset, whether an existing control already blocks the path, or how much it matters to the business.
CTEM replaces the list with a programme. Instead of asking “how many critical vulnerabilities do we have”, it asks “which exposures give an attacker a path to the things we care about, and have we closed them”. Exposure is a wider term than vulnerability: it covers misconfigurations, weak or over-privileged identities, exposed internet-facing services, risky cloud settings and the way these combine along an attack path.
The programme runs in five stages, repeated continuously:
- Scoping. Decide which systems, assets and business processes the cycle covers, starting with what is critical to the business.
- Discovery. Find the assets inside that scope and the exposures on them: vulnerabilities, misconfigurations, insecure credentials, unknown devices and external services.
- Prioritisation. Rank exposures by how likely they are to be exploited and what the impact would be, taking existing controls into account.
- Validation. Confirm that the prioritised exposures are reachable and exploitable in practice, through attack path analysis, penetration testing or red and purple team exercises.
- Mobilisation. Get the fixes done by the teams that own the systems, with clear ownership, workflows and measurement.
How Tenable One supports each stage
Tenable One brings the data for the whole cycle into one platform instead of spreading it across separate tools.
- Scoping: Asset Inventory and Exposure View. One inventory across IT, OT, IoT, cloud, AI, identity, code repositories and web applications. Tags and exposure cards let you define scope by business unit, application or asset class, and Exposure View shows how exposed each scope is.
- Discovery: Tenable sensors and Connectors. Tenable’s own scanners and agents cover vulnerabilities, cloud, identity, OT and the external attack surface. Connectors bring in findings from third-party scanners, cloud providers, endpoint and asset management tools, so discovery is not limited to what Tenable sees.
- Prioritisation: Exposure Signals and the Vulnerability Priority Rating. The Vulnerability Priority Rating (VPR) ranks vulnerabilities by the likelihood of exploitation rather than CVSS alone. Exposure Signals go further and flag toxic combinations, where a vulnerability, an identity, installed software and an asset together create a risk that none of them would on their own.
- Validation: Attack Path Analysis and controls validation. Attack Path Analysis maps viable attack routes across more than 150 attack techniques and shows the chokepoints that break lateral movement. Active security controls such as EDR, MFA, firewalls and DLP are mapped onto those paths, so exposures that an existing control already neutralises can be deprioritised. Penetration test results can be fed in through the Tenable One Open Connector to confirm what is exploitable.
- Mobilisation: Hexa AI and remediation workflows. Hexa AI orchestrates multi-step remediation workflows, and exposure analytics track risk reduction over time in business terms. With Tenable Patch Management, prioritised vulnerabilities are correlated to the right patch and deployed under policy, closing the loop from finding to fix.
Every stage feeds the next, and the cycle starts again as the environment changes. That is what makes the programme continuous rather than a periodic assessment.
Who it’s for
CTEM with Tenable One is for organisations that have outgrown a scan-and-report approach to vulnerability management. It suits security teams that need to show which risks they are actually reducing, not just how many findings they have, and that want IT, cloud, identity and OT exposure handled in one programme rather than in silos. It is also the structure regulators and frameworks such as NIS2 increasingly expect: a documented, repeatable process for identifying, prioritising and treating risk.