Definition · Threat exposure

What is threat exposure management?

The term is recent, the practice is not: leaks, lookalike domains and infected devices open accesses, so someone must watch the outside. What the expression covers, and where to start.

Guide
Definition
Reading
7 min read
Published
5 Sept 2026
Last updated
5 Sept 2026

In one sentence

Threat exposure management (TEM, or CTEM in its continuous form) consists of identifying at all times what an organisation exposes on the outside, qualifying what is genuinely exploitable and treating the exploitable first, as a complement to internal protection, never in its place.

An organisation protects itself from the inside: firewalls, endpoint detection, identity management, backups. But a growing share of the risk plays out where those tools see nothing: at an employee whose personal computer is infected, at a contractor who left a database on a public port, at a registrar where someone has just registered a domain that imitates yours.

Threat exposure management names the work of watching that outside continuously, keeping only what is exploitable against you and handing it over in a form that supports action. Gartner described its continuous form, CTEM (Continuous Threat Exposure Management), in 2022, in five stages: scope, discover, prioritise, validate, mobilise.

What the expression covers

Three families of things leak past the perimeter: access (credentials, sessions, infected devices), a brand (lookalike domains, fake profiles, forum mentions) and people (executives, families, suppliers). Exposure management watches all of them, because an attacker combines them: a leaked password is all the more useful when a lookalike domain has just copied your login page.

The important word is “exposure”: the point is not to detect an attack in progress but what makes it possible before it starts. The delay between the moment a piece of information becomes exploitable and the moment you handle it is the only quantity this discipline genuinely acts on.

What it is not

It is not a SOC or an EDR: those watch the inside of your systems and react to what happens there. It is not a penetration test: nobody exploits anything, one observes what answers from the internet and what circulates. Nor is it a vulnerability scanner, which lists versions without saying whether anyone cares about them.

The three complement one another. External monitoring brings the SOC what it cannot see, and the SOC turns the alert into an action in the systems. An organisation without a SOC benefits too, provided someone can reset a password or close a port when the alert arrives.

Scope, discover, prioritise, validate, mobilise

Scoping means declaring a perimeter and proving its ownership: domains, addresses, brands, suppliers, consenting executives. Discovering means matching that perimeter against everything that circulates: leaks, stealer logs, domain registries, forums, exposed surface.

Prioritising means ranking by what is exploitable now: a usable password on an SSO ranks above an address in an old compilation. Validating means an analyst confirms the case and writes the expected action. Mobilising means the action reaches the person who can carry it out, in the tool they already use, with the evidence for the auditor.

Where to start

With the credentials of your domains: the most frequent initial access vector and the simplest to handle, since the answer is a reset. Then the domains that imitate yours, because they are prepared days before they are used. Then the exposed surface and the suppliers, whose breach touches you without you being attacked.

Decide from the start who receives what, at which threshold, and how you will measure the result: the number of exposures handled and the median delay between their appearance and their handling. A week without an alert is information, not an outage.

How to measure it

An exposure score, from 0 to 100, summarises the open exposures weighted by their severity, their freshness and the criticality of the asset touched; its ninety-day curve says whether the organisation is improving. It exists to follow one organisation over time, never to compare two.

The other measures are delays: between a credential entering circulation and its revocation, between the registration of a lookalike domain and the takedown request, between a supplier being listed on a leak site and the notification of your teams. Those delays are what a posture report must show a board.

Frequently asked questions

  • TEM, CTEM, DRP, EASM: what is the difference?

    Threat exposure management (TEM) is the discipline; CTEM stresses its continuous form, in five stages. Digital risk protection (DRP) is its side turned towards the brand and people; external attack surface management (EASM) its side turned towards the infrastructure reachable from the internet. VesperID covers both in one platform.

  • Do you need a SOC to do it?

    No. You need someone who can act on the alert: reset an access, revoke a session, request a takedown, close a port. A three-person team gets as much out of it as a thirty-person operations centre, because the work delivered is already qualified.

  • When do the first results appear?

    As soon as an asset is verified: the available history is pulled in immediately, and that is often where the first findings are, for instance a password exposed two years ago and never changed. After that, the pace depends on your actual exposure.

See your own exposure, not a definition

A one-hour scoping call with an analyst says what your perimeter already shows from the outside, and whether monitoring is justified.

Bespoke offering: no public price, no packages.