FAQ
Frequently asked questions
VM finds known CVEs on known assets. CTEM is the program that decides which of those — and everything else exposed — actually gets fixed.
What is CTEM? →What is the difference between CTEM and vulnerability management?
Vulnerability management (VM) scans known assets for known CVEs on a schedule and ranks them, usually by CVSS. CTEM is the continuous program around that data: it also discovers unknown assets, prioritizes by exploitability and business impact, validates that an exposure is reachable, and mobilizes a named owner until the fix is re-verified. VM answers "what is vulnerable?" CTEM answers "what can be exploited, who owns it, and is it staying fixed?"
Does CTEM replace vulnerability management tools?
No. CTEM still needs vulnerability scanning — that is how the discovery stage finds published CVEs. What CTEM changes is everything after the scan: business-context ranking, exploitability validation, and ticket-to-fix mobilization, so scan output becomes reduced exposure instead of a growing backlog.
Why isn't a CVSS score enough to prioritize vulnerabilities?
CVSS describes theoretical severity, not whether an attacker can reach the asset, whether a working exploit exists, or whether the system matters to the business. Without that context, teams spend cycles on high-score findings that were never exploitable and miss lower-score issues that are internet-facing and already in exploit kits.
Can vulnerability management find shadow IT and unknown assets?
Not by itself. VM scans what is already on the asset list. It cannot see the forgotten subdomain, the unregistered cloud bucket, or the staging host that never made inventory. CTEM's discovery stage — often fed by external attack surface management — is what brings those unknown assets into the same prioritization and validation loop.
When should a security team adopt CTEM instead of relying on VM alone?
Adopt CTEM when scan volume outruns the team, when breaches keep starting from known unpatched assets, or when leadership wants risk in business language rather than a raw finding count. You keep the scanner; you add continuous discovery, exploitability validation, and an accountability loop so findings close instead of accumulating.
Scan smarter, fix faster
Trusteed pairs exploitability-aware vulnerability scanning with the full CTEM loop — so every finding gets prioritized, validated, and mobilized.