Okay, so here’s the thing that happened in July 2025, and if you blinked, you missed it: Gartner quietly stopped publishing its long-running annual Market Guide for Vulnerability Assessment and replaced it with a Magic Quadrant for Exposure Assessment Platforms.
That’s not a rebrand. That’s a funeral.
The vulnerability scanner as the centerpiece of your security program just got officially declared a legacy category. Gartner didn’t just rename the report for fun, they restructured an entire market category around a concept they first started talking about in 2023: Continuous Threat Exposure Management, or as the rest of us call it, “stop trying to patch everything and fix what actually matters.”
Before we dig into the five phases and the vendor leaderboard, here’s what you actually need to know:
Key Takeaways
Gartner replaced the annual Market Guide for Vulnerability Assessment with a Magic Quadrant for Exposure Assessment Platforms, formally marking the end of CVSS-score-driven, point-in-time scanning as the industry standard.
The shift is driven by a brutal reality: over 40,000 CVEs were disclosed in 2024, but less than 1% of vulnerabilities are ever targeted by real-world attackers, meaning teams are burning hours on phantom risks while missing the few that actually matter.
The five-phase CTEM loop (scope, discover, prioritize, validate, mobilize) is designed to close the gap between “we know about this threat” and “we’ve proven we can stop it,” and the biggest implementation hurdles aren’t technical, they’re context, permissions, and safe change management.
Table of Contents
Why Gartner made the call
Here’s the timeline that matters. In 2017, Tenable’s co-CEO Mark Thurmond said his company recognized that “big changes needed to happen in how the industry at large was approaching cybersecurity.” They started pushing this idea of “exposure management” as something broader than vulnerability scanning. Nobody really listened.

In 2023, Gartner analyst Jeremy D’Hoinne formally defined the concept: exposure management is a systemic approach to continuously refine priorities and balance two modern security realities. He hit the nail on the head with the follow-up: Organizations can’t fix everything, nor can they be certain which vulnerability remediation they can safely postpone.
That’s the whole ballgame right there. You can’t patch everything. You can’t know with certainty what you can skip. So you need a system that helps you walk that tightrope.
By 2025, Gartner made it official. The Market Guide for Vulnerability Assessment is gone, replaced by the Magic Quadrant for Exposure Assessment Platforms. The message to every security team: the old way of doing business, periodic scans, CVSS-severity-driven patching, and hoping for the best, is no longer the benchmark.
And they backed it with data. Gartner predicts that by 2027, organizations integrating exposure assessment data into IT and business workflows will see 30% less unplanned downtime from exploited vulnerabilities than those relying on isolated vulnerability management tools. That’s a very specific, very measurable bet on this category.
So what does “exposure management” actually mean? It’s a continuous, business-context security evaluation loop. You discover attack surfaces, assess and prioritize potential exposures based on business impact, validate the top risks, and mobilize remediation efforts. The key word here is continuous.
This isn’t a quarterly scan project. It’s a living process.
And here’s the critical distinction: exposure management is a process, not a product.
You can’t buy a box, plug it in, and call it done. Each organization has to define the scope of its own exposure-management focus before any platform becomes useful. The tool automates the heavy lifting, but the strategic decisions are on you.
The Five Phases of Gartner’s CTEM Framework
Gartner breaks the process down into five distinct phases, and it’s worth understanding each one because they build on each other. This is a loop, not a linear checklist, the output of each phase feeds back into the next cycle.

Scoping: Decide what matters before you scan
This is the phase most people skip, and it’s the one that makes everything else work. Scoping means identifying and defining your assets in alignment with business relevance. What actually matters to this organization? What would hurt most if it went down or got compromised?
If you skip this step, you’ll end up with an “everything is critical” problem. Everything becomes priority one, which means nothing is actually prioritized. Get this wrong and every subsequent phase inherits the mistake.
Discovery: Map what’s actually out there
Discovery targets the assets and risk profiles you identified during scoping. This means continuous discovery and inventory of attack surfaces, verifying known assets, finding unknown ones, and building a real picture of what’s connected to your network.
Here’s a number that should scare you: one health board found 65,000 to 70,000 unknown IP-connected devices when they actually looked at their network traffic. Not 65 to 70. Sixty-five thousand. That’s the reality of modern attack surface expansion. You can’t protect what you don’t know exists.
Prioritization: Base it on risk, not just severity
This is where the magic happens. Prioritization should be based on urgency, severity, compensating controls, risk appetite, and risk level. But here’s the crucial nuance: exposure risk is specific to each organization’s assets, environment, threat profile, and risk appetite.
A CVSS 9.8 vulnerability that no attacker is actively exploiting is less urgent than a CVSS 7 finding that’s actively being used in three campaigns right now. The whole point is to stop treating every critical-severity CVE like an emergency and start asking “what can actually hurt us, given who’s targeting us?”
Validation: Prove the risk is real
This is the phase that separates CTEM from every previous approach. Validation tests whether attackers could actually exploit the exposures you’ve prioritized, and whether your monitoring and control systems would even notice.
The uncomfortable truth: most teams assume their security tools would detect an adversary exploiting an exposure. The data says otherwise. Fewer than 40% of organizations have achieved continuous, automated, intelligence-driven validation. Security controls that worked yesterday may not work today, configurations drift, rules get stale, attackers find new paths.
So, what is exposure management? It’s the convergence of vulnerability management, attack surface management, and threat intelligence into a continuous, business-aligned practice, exactly the kind of validation most teams still lack.
Mobilization: Close the loop
Mobilization is about reducing friction in approval, implementation, and mitigation deployments. Yes, this means connecting to ServiceNow or Jira so findings become tickets. But more importantly, it means getting the right information to the right teams fast enough that they can act.
This is the phase where most programs stumble. You can have perfect visibility, brilliant prioritization, and solid validation, and still fail because the remediation work dies in a queue somewhere. According to Gartner, EAPs help with this through “prioritized visualizations and treatment recommendations,” identifying the various teams involved in mitigation and remediation.
Vulnerability Management vs. Exposure Management: The CVSS Trap
Let’s talk about why the old way stopped working. Traditional vulnerability management is periodic, reactive, and manual. You run a scan, get a report, and try to patch everything the scanner flags as critical. The whole system centers on CVSS scores, a point-in-time snapshot of severity that ignores context entirely. That’s where exposure management vs vulnerability management comes in: instead of just patching known CVEs, exposure management prioritizes based on real-world exploitability and business impact, shifting the goal from “patch everything” to “reduce what matters.”
Here’s the problem. Over 40,000 new CVEs were disclosed in 2024. But less than 1% of all vulnerabilities are ever targeted by real-world attackers. Traditional scanners label thousands of vulnerabilities as critical without providing the context to determine which ones are actually exploitable in your environment.
A CVSS 9.8 that nobody’s exploiting is noise. A CVSS 7 in a system exposed to active campaigns is a real problem. CVSS measures severity, not risk. Risk is a function of severity and exploitability and business impact.
This isn’t just a Gartner talking point. John Bambenek, president of Bambenek Consulting, puts it this way: CTEM shifts organizations from patching based on CVSS scores to an approach that better evaluates risks and focuses responses on threats that matter. The emphasis there is on threats that matter, not threats that score well on a rubric.
The industry consensus is that prioritization is the key enabler of effective threat response. Yet teams are still wasting close to half their operational capacity on risks that don’t matter. That’s not a tool problem. That’s a framework problem.
Anatomy of an Exposure Assessment Platform
So what does Gartner actually expect these tools to do? The Magic Quadrant defines the core purpose: EAPs provide a consolidated view of high-risk exposures enabling organizations to take proactive actions to prevent breaches.
More specifically, Gartner requires exposure management platforms to offer:
- Discovery across internal, external, cloud, and end-user attack surfaces, plus digital assets and artifacts actively abused by external threat actors (like lookalike domains and leaked credentials)
- Reporting covering endpoints, network hardware and software, identity systems, containers, IoT/OT devices, and cloud, on-prem, and hybrid software and infrastructure
- Prioritization based on business context, security-control context, vulnerability severity, threat intelligence, and, importantly, potential attack paths through analysis or breach-and-attack simulation
- Mobilization through integrations with IT service management systems like ServiceNow or Jira, plus faster remediation by connecting with security operations tools like SIEM or SOAR solutions
Think of these platforms as an orchestration layer. They’re not just fancy scanners. They connect raw vulnerability data to business context, threat intelligence, and remediation workflows. The goal is to give you a consolidated picture of what’s actually dangerous, not a list of everything that’s wrong.
Cost is the question every security leader asks first, and the answer is rarely a simple price tag. EAPs are typically priced on asset count and modules, with enterprise contracts ranging from six figures to over a million annually. To build a business case, anchor the investment to Gartner’s prediction that organizations integrating exposure assessment data into workflows will see 30% less unplanned downtime from exploited vulnerabilities by 2027. That 30% reduction translates directly into avoided incident response costs, lost productivity, and regulatory fines, numbers finance teams can model. Pair that with the efficiency gain of cutting the 50% of operational capacity wasted on non-critical risks, and the ROI story writes itself.
The Leaderboard: Four Vendors on the Same Destination
The inaugural Magic Quadrant for Exposure Assessment Platforms named four Leaders, each arriving from a different starting point. That’s actually the most interesting part, they’re converging on the same destination from four different directions.
Tenable took the top spot, ranked highest for Ability to Execute and furthest for Completeness of Vision. Their Tenable One platform claims to deliver the most complete view of risk across the modern attack surface, including AI, cloud, IT, identity, third-party, web apps, and OT. With over 44,000 clients and more than 300 integrations, they’ve been pushing this narrative since 2017. They also landed Leader positions in IDC MarketScape and Forrester Wave, so it’s not just a Gartner fluke.
Rapid7 earned its Leader spot through Exposure Command, their unified exposure management solution. The key differentiator is threat-validated prioritization backed by real threat intelligence and continuous red teaming services. They’ve also integrated AI-driven remediation hooks, which means the platform doesn’t just tell you what’s broken, it helps you fix it.

Armis came at this from an OT/IoT asset intelligence angle. Their Centrix platform focuses on understanding physical-digital environments, think airlines, health systems, cities, and universities. Their customer case studies (United Airlines, Main Line Health, City of Las Vegas, Grand Canyon University) show environments where tens of thousands of devices are connected and most of them aren’t traditional IT endpoints.
Filigran is the interesting one. Founded in France in 2022, they’re the “intelligence-first” pure play. Their eXtended Threat Management (XTM) platform bundles threat intelligence, exposure validation, and cyber risk quantification on what they call an “agentic foundation.” They integrate OpenCTI for threat knowledge and OpenAEV for attack simulation, building a genuinely intelligence-driven CTEM loop. They got picked for the Leader quadrant as relative newcomers because their approach matches the intelligence-driven philosophy behind CTEM.
Where Threat Intelligence Earns Its Place
Exposure management in cybersecurity unifies asset discovery, vulnerability assessment, attack path analysis, and threat intelligence into one continuous process. Without that integrated view, your EAP is just a scanner with better prioritization math. exposure management in cybersecurity unifies asset discovery, vulnerability assessment, attack path analysis, and threat intelligence into one continuous process. Without that integrated view, you’re still guessing about what matters.
Gartner’s framework requires prioritization based on threat intelligence, not just severity. And the mechanism for making that work is something called Priority Intelligence Requirements, or PIRs.
PIRs are structured questions your organization needs threat intelligence to answer, based on your actual business risks and threat landscape. Instead of subscribing to a generic threat feed and hoping it’s relevant, you ask specific questions. For example: “Which ransomware groups are currently targeting manufacturing organizations in Europe, and what initial access techniques are they using?”
That’s a PIR. It turns threat intelligence from a passive feed into an active driver of your security program. When intelligence answers your PIRs, you can make informed decisions about prioritization.
The payoff: prioritization becomes a continuously updated view rather than a weekly spreadsheet exercise. For CISOs specifically, it means prioritization decisions can be explained that this exposure is at the top because this specific group is actively exploiting this technique against their industry, rather than just pointing at a CVSS score.
Structured intelligence is what makes this work. Without it, you’re still drowning in data, just with slightly better filters.
The Validation Bottleneck: Knowing vs. Proving
Here’s the uncomfortable question that CTEM forces you to answer: would your security tools actually detect an adversary exploiting a priority vulnerability? Most teams assume yes. The data says otherwise.
Only about 40% of organizations have continuous validation capabilities, and a significant chunk of them are validating without any intelligence context at all. If you’re running generic phishing simulations or random MITRE ATT&CK techniques, you’re not validating, you’re just checking boxes on generic exercises that don’t map to what your actual adversaries are doing.
The gap between “we know about this threat” and “we have proven we can stop it” is where most security programs fall short. You can have all the vulnerability data in the world, but if you can’t demonstrate that your controls actually catch the exploitation attempt, you’re operating on faith.
This is where you need to be testing against the specific techniques your real adversaries use, not generic TTPs. And you need to be doing it continuously, because security controls that worked yesterday may not work today. Configurations drift. Rules expire.
Attackers evolve. The attack that was blocked last month might walk right through tomorrow.
The validation stage is also a ransomware prevention tool. Data exfiltration is how attackers force your hand. Continuous validation doesn’t just test whether your EDR alerts on the initial access, it tests whether you’d actually notice when a database starts bleeding data.
The handoff from threat intelligence to validation is critical. If your intelligence says the current wave of attacks is using a specific phishing lure followed by a specific PowerShell payload, that’s exactly what you need to be testing. Pulling that intelligence directly into your validation process closes the loop between knowing and proving.
The Implementation Hurdles No Vendor Can Solve for You
Here’s the reality check. The hardest part of CTEM has nothing to do with picking the right platform. According to the experts, the three biggest challenges are context, permissions, and safe change management.
Context: Scanners have limited context about your organization. They produce false positives because they don’t understand what’s deliberate and what’s a problem. That open port on the firewall might be intentional. That exposed database might be the backup system that’s supposed to be reachable. Without organizational context, your EAP will generate noise, and noise breeds alert fatigue.
Permissions: The teams responsible for CTEM often lack the permissions to actually fix what they find. Security finds the vulnerability, but the remediation requires root access on systems security doesn’t own. The findings go into a ticket, and then they sit there because the team that needs to act has other priorities.
Safe change management: Every response action in security can have side effects. The firewall rule that blocks the attacker might also take down a business-critical application. The patch that fixes the vulnerability might break the service it protects. Security teams rarely know if a change will break something else, so they hesitate. And hesitating on remediation is how high-priority findings become breach post-mortems.
The “no good deed goes unpunished” problem is real. You find and fix a critical vulnerability, and then someone asks why the application broke in production. That’s why the mobilization phase is so important, and why it’s so hard to get right.
The broader implementation challenges are visibility (especially across cloud, on-prem, hybrid, and AI-related assets), information overload (continuous programs generate massive telemetry that can’t be handled manually), and the human element. Most of these challenges are with policies and people, not technology. Setting expectations and aligning stakeholders is a major part of the job.
Curtis Dukes, from the Center for Internet Security, summarized the situation well: tools help, but there are no silver bullets. The platform is the easy 20%. The organizational change is the hard 80%.
Real-World Adoption: It Doesn’t Sound Like a Checklist
Here’s the funny thing about actual CTEM adoption: nobody describes their work as running a Continuous Threat Exposure Management program. But when you look at what successful organizations are doing, it maps almost perfectly to the five phases. Take CTM Health Board, for example: their hospitals discovered 65,000 to 70,000 unknown IP-connected devices when they expanded visibility into network traffic, a concrete outcome that shows the discovery phase in action.
The CTM Health Board’s hospitals discovered 65,000 to 70,000 unknown IP-connected devices when they expanded their visibility into network traffic. That’s the discovery phase in action. They didn’t know what was on their network until they started looking, and the volume was a shock.
An international airport that lacked security governance couldn’t rank its assets by business impact until they built the scoping process. After implementing it, their mean time to detect and respond improved significantly. That’s scoping and prioritization working together.
PGP Glass was increasingly concerned about IP theft and data leaks. They implemented validation to confirm whether their security controls would detect data exfiltration attempts, giving them the confidence that their defenses actually worked.
Armis’s implementation at CTM Health Board initially focused on critical departments and specific use cases, then expanded once teams built confidence in the platform and the process. That’s the “start small, prove value, then scale” pattern that makes CTEM programs succeed.
The Future Is a Journey, Not a Destination
Gartner projects that CTEM will reduce breaches by two-thirds by 2026. That’s a big number. But there’s a catch buried in the fine print: CTEM is only as effective as your ability to act. As Rosario Mastrogiacomo noted, CTEM must be paired with robust detection and response capabilities to truly deliver on its promise.
Yet it’s worth acknowledging the contrarian view: Gartner made a similar prediction about two-thirds fewer breaches, and many teams still struggle with the same data overload they did before. The industry has largely treated CTEM as a product category to buy rather than a process discipline to practice, which is why the promise hasn’t fully materialized for everyone.
You can buy the best EAP on the market, follow the five phases perfectly, and still fail if your organization can’t execute on the remediation side. The platform doesn’t fix broken workflows. It doesn’t give you permissions you don’t have. It doesn’t make IT prioritize security tickets.
What it does do is give you a clear picture of what matters, why it matters, and what to do about it. The rest is on you.
The continuous loop of CTEM, scope, discover, prioritize, validate, mobilize, then start over, isn’t a one-time project. It’s an ongoing cost of maintaining a dynamic, expanding attack surface. The threat landscape shifts every week. New vulnerabilities get disclosed every day.
New attackers enter the game constantly. Researchers recently demonstrated this reality by building a worm that reasons about hosts it infects, powered by open-weight models, a notable development in the evolving threat landscape.
The good news is that the industry is finally converging on a framework that makes sense of the chaos. Gartner’s shift from vulnerability assessment to exposure assessment platforms is more than a report title change. It’s an acknowledgment that the old way of doing things was never going to scale. At the same time, excessive agency has climbed the list of concerns, a rising issue especially after recent security incidents.
The bad news is that the hard part, the people, the process, the organizational change, doesn’t come in a box. But that’s also the opportunity. The teams that figure out the human side of exposure management are the ones that will actually see the 30% reduction in unplanned downtime that Gartner is betting on.
The tools are ready. The framework is clear. The question is whether your organization is ready to walk the tightrope.
People Also Ask
What is exposure management?
Exposure management is a continuous, business-context security evaluation loop that discovers attack surfaces, assesses and prioritizes potential exposures based on business impact, validates the top risks, and mobilizes remediation efforts. It’s a process, not a product, and it shifts the focus from patching everything to reducing what actually matters.
What are the five phases of Gartner’s CTEM framework?
The five phases are scope, discover, prioritize, validate, and mobilize. Scoping defines what matters to the business, discovery maps the actual attack surface, prioritization ranks risks based on business context and threat intelligence, validation tests whether attackers could exploit the exposures and whether your controls would detect it, and mobilization gets the right teams to act on the findings.
What are the biggest challenges in implementing exposure management?
The hardest parts are context, permissions, and safe change management. Scanners lack organizational context, so they generate false positives. Security teams often lack the permissions to fix what they find, and every remediation action risks breaking something else. These are people and process problems, not technology problems—the platform is the easy 20%, the organizational change is the hard 80%.
