The category

What is continuous threat exposure management (CTEM)?

Continuous threat exposure management (CTEM) is a program that keeps finding, ranking, checking and fixing the ways an attacker could get into an organization. It runs five stages on a loop: scope, discover, prioritize, validate and mobilize. The aim is to put effort where an attacker could actually get in, instead of working through a list that never ends.

Five stages

CTEM, stage by stage

Gartner defined CTEM and its five stages. Choose a stage to see what it means, and what Outerwall does there.

What it means

Decide which parts of the business matter, and what losing them would cost.

What Outerwall does

Starts from one domain. Research maps the estate, the suppliers and the rules your client answers to. Your client confirms what’s theirs.

FTC Safeguards · Regulation S-P · NYDFS 500

What it means

Find the assets and their exposures, including the unlisted ones.

What Outerwall does

Five public surfaces, read without scanning: infrastructure, records, events, workforce and vendor references. Hosts, suppliers and lookalike domains your client didn’t know about are flagged before any scan.

Within the hour of adding a client

What it means

Rank exposures by how likely they are to be used and what they would hit.

What Outerwall does

Ranked by blast radius and live threat: known-exploited flaws, breach notices, ransomware mentions. Every rule is tested code, so the same data always gives the same answer.

No AI model decides a finding

What it means

Confirm an attacker could use the exposure, and how far it would go.

What Outerwall does

Non-destructive checks on approved assets turn a likely finding into a confirmed one, or drop it. Then Outerwall traces the path an attacker would take, and what it would reach.

Approved assets only

What it means

Get the fix done by the people who own it.

What Outerwall does

Findings are escalated to your service desk as tickets, ranked by blast radius, with the evidence attached and a plain-language note for your client.

ConnectWise · Autotask · HaloPSA

For MSPs

What CTEM means for an MSP

For an MSP, CTEM means running that loop for every client you manage, from one view, with the fixes landing in your PSA. Your clients get evidence every month, which the FTC Safeguards Rule, SEC Regulation S-P and NYDFS Part 500 increasingly expect, and you get recurring work you can price per client.

Most tools cover one or two stages. Outerwall is built to run all five, for every client, through you.

How Outerwall worksThe rules your clients answer to

Terms

How is CTEM different from scanning and EASM?

TermWhat it does
Vulnerability scanningChecks the assets you list for known flaws. Anything missing from the list is never checked.
External attack surface management (EASM)Finds internet-facing assets from the outside, including unlisted ones. Ranking and fixing are left to you.
Continuous threat exposure management (CTEM)The program around both: scope what matters, discover exposures, prioritize by real risk, validate what an attacker could use, and mobilize the people who fix it. It runs on a loop.

Run CTEM for every client you manage.

Outerwall is in pilot with a small group of US MSPs and MSSPs.