CTEM's five phases run scoping, discovery, prioritization, validation, mobilization. Kai runs all five, then closes the two gaps where that cycle breaks down with two more phases, built directly into the sequence at the end. Auto-remediation sits at phase six: once a fix is assigned, Kai takes immediate action, instead of letting it wait in a queue.
Detection sits at phase seven: once remediation is underway, Kai Watch continuously monitors telemetry to identify active exploitation and deploys validated detection rules to contain risk across the environment while fixes are in progress.
1.
Auto-remediation, so fixes stop waiting on tickets.
This phase sits after mobilization, closing the loop before the cycle begins again. Once a fix has been assigned, Kai executes it directly for the majority of confirmed findings, no cross-team meeting, no delay. For the complex few that need human review, Kai builds the complete remediation plan, identifies the right owner, and stages it for approval.
2.
Detection, so exposure windows stay narrow.
This phase closes the cycle after auto-remediation. Even as fixes are being executed, new exposures surface and attackers continue to probe. Kai analyzes existing detection coverage, generates validated detection rules, and deploys them automatically across SIEM, EDR, and XDR, so the environment stays watched and contained continuously as the cycle repeats.
CTEM does not fail at discovery. Most organizations are drowning in results from scanners, code analysis tools, and cloud posture checks. Programs fail downstream, in the phases that are supposed to turn a finding into a closed ticket. Ownership goes unassigned because nobody owns the process of assigning it. Teams operate in silos because security, infrastructure, and operations answer to different priorities and different metrics. Prioritization leans on generic severity scores because building real business context takes more work than most teams have time for.
Validation, the step that requires simulating real attacker behavior, rarely happens with any rigor because most teams lack the time and tooling to run it consistently, so a finding marked "confirmed" often just means someone looked at it once. Tool sprawl compounds every other problem, more dashboards and more alerts, but no shared context to make sense of them. None of this is a technology gap. It is where organizational process fails to keep pace.
Continuous Threat Exposure Management is Gartner's framework for moving security programs from reactive scanning to continuous, risk-driven action. Instead of running periodic audits or chasing every possible finding, CTEM asks security teams to build an ongoing cycle that connects business priorities to real exposure and to a fix. It replaces static point-in-time assessments with a living process teams repeat continuously.
CTEM succeeds or fails based on process, ownership, and coordination across teams, not on the assessment technology alone. Most organizations struggle hardest in the final two phases, before diagnosis turns into action. The framework spans five phases, each building on the one before it.
Scoping
Not a technical exercise. This step is strategically aligned with business relevance from the outset, narrowing focus to what's most critical and what impacts warrant collaborative remedial effort.
Discovery
This targets the relevant assets and risk profiles identified in the prior phase, and extends beyond vulnerabilities to misconfigurations, counterfeit assets, and other weaknesses.
Prioritization
Not about remediating every issue. This step identifies threats most likely to be exploited, weighing exploit prevalence, available controls, mitigation options, and business criticality.
Validation
This confirms how attackers could actually exploit an exposure and how monitoring and control systems would react, using controlled simulation of attacker techniques.
Mobilization
The coordinated organizational effort to operationalize identified exposures through cross-functional teams, defined workflows, and business-aligned remediation priorities.