CTEM IN PRACTICE

From annual scan to continuous exposure management

With CTEM, Gartner describes an ongoing cycle: know what you have, know what is vulnerable, fix the truly dangerous first, and be able to prove it happened. monsys brings that cycle to your servers: Windows and Linux, EU-hosted, starting with 5 free agents.

The five CTEM stages, mapped to monsys

CTEM (Continuous Threat Exposure Management) is a five-stage programme approach. Here is how monsys covers each stage, limits included.

  1. Scoping
    Multi-tenant structure, groups, tags and network maps define what belongs to your attack surface. Uptime checks and status pages show what is internet-facing.
  2. Discovery
    Agents continuously inventory hosts, services, applications and dependencies. CVE matching on three levels: application dependencies, OS packages and kernel (backport-aware). Plus SBOM export per host.
  3. Prioritization
    Not every CVE is equally urgent. monsys weighs blast radius (what is internet-facing, what depends on it), Trust Score and correlations such as lateral movement. The truly dangerous first.
  4. Validation
    On-host detection validates what attackers actually attempt: auth-log analysis, honeypots, GeoIP. Honestly: we do not do automated attack simulation (BAS); a periodic pentest remains complementary.
  5. Mobilization
    From signal to fix: a controlled remediation flow where the operator approves every action (TOTP), with an attestation chain and Ed25519-signed reports as evidence.

CTEM is an approach described by Gartner. Gartner does not endorse any vendor, product or service; monsys has not been evaluated or certified by Gartner.

One platform, not three contracts

Monitoring, vulnerability management and compliance evidence normally live in separate tools. monsys delivers the whole CTEM cycle in one product, from €3 per server per month.

Evidence an auditor can verify independently

Every step of the cycle ends in signed evidence: audit packs, reports and a transparency log with Ed25519 signatures. Verifiable offline, without having to trust us.

EU-sovereign

Hosted in Belgium, no US SaaS in the critical path. For organisations under NIS2, CRA or DORA that is not a detail but a precondition.

Frequently asked questions

What exactly is CTEM?

Continuous Threat Exposure Management is a programme approach described by Gartner, in five stages: scoping, discovery, prioritization, validation and mobilization. The core idea: exposure management is not an annual project but an ongoing cycle.

Is monsys a complete CTEM platform?

Discovery, prioritization and mobilization are covered fully, scoping and validation largely. What we deliberately do not do: automated attack simulation. A pentest or BAS tool remains complementary. We would rather name that limit ourselves than have an auditor find it.

How is this different from a vulnerability scanner?

A scanner gives you a list. CTEM gives you a cycle: the same list, but prioritised by real impact, connected to a controlled fix flow and closed with signed evidence that the fix is really in place.

How does CTEM relate to NIS2?

NIS2 expects continuous, demonstrable risk management. A CTEM cycle delivers exactly that rhythm, and monsys makes every step demonstrable with signed reports. monsys does not give legal advice; what suffices for your sector is something you determine with your auditor.

Want to see where your attack surface stands today?

Install the agent with one command. The first 5 agents are free, forever.

Further reading
NIS2 monitoringFor auditorsWhitepaper
WHITEPAPER

The full story in 25 pages

Architecture, Trust Score formula, supply-chain pipeline, NIS2 / AI Act / CRA mapping. Free PDF after a short form.

Download whitepaper →