Drowning in CVEs and thirsty for answers? Try CTEM
Cybersecurity boards are moving beyond simple patching updates to demanding proof that organisations are genuinely secure, a shift traditional vulnerability management cannot satisfy. The article argues that the conventional approach of cataloguing flaws via CVEs and rating them with CVSS scores is breaking down, as the sheer volume of vulnerabilities, unhelpful severity ratings, and the rise of AI-driven exploit discovery combine to overwhelm security teams, prompting growing interest in an alternative framework called Continuous Threat Exposure Management (CTEM).
The piece cites Horizon3's Drew Vanover noting a single Microsoft patch cycle contained over 500 fixes, making thorough vetting impractical, while the US National Vulnerability Database has been backlogged for years, leading NIST to effectively concede defeat in April. A US Department of Commerce report in May further criticised CVSS scores as too subjective and disconnected from real business context, even suggesting they be scrapped. With AI tools now surfacing and weaponising zero-days faster than organisations can patch them, Gartner-endorsed CTEM offers a five-stage alternative—scoping, discovery, prioritisation, validation and mobilisation—that ties vulnerability management to actual business risk rather than raw technical severity.
- Boards now demand proof of security, not just patching reports
- CVE overload and flawed CVSS scores make triage unreliable
- CTEM framework prioritises fixes by real business risk, not just severity