Continuous Threat Exposure Management for Small and Mid-Sized Businesses
Oct 1, 2026, 12:37:01 PM Richard Mendoza 21 min read
The exposure problem at 20 to 300 employees
A company with 80 employees now faces many of the same attackers as a company with 8,000. The smaller company usually has one or two IT people, no dedicated security staff, and a patch backlog that grows every month. That imbalance shows up in the breach data: ransomware appeared in 88% of breaches involving small and mid-sized businesses in Verizon's 2025 Data Breach Investigations Report.
In This Article:
- What CTEM means for a business owner
- Why small and mid-sized businesses need CTEM now
- Where CTEM breaks down for smaller companies
- How Compass's closed-loop model covers all five stages
- Four breaches CTEM could have prevented or contained
- Six steps to take with your IT provider this quarter
- Frequently asked questions
Continuous Threat Exposure Management (CTEM) gives smaller organizations a structured way to find and close the weaknesses attackers use before those weaknesses turn into an incident. This article explains the five stages of CTEM and what each one asks of a business. It also shows why the model matters even more. It then walks through four real breaches at organizations in the 20 to 300 employee range and explains how Compass's closed-loop model puts all five CTEM stages under one accountable team.
.gif?width=940&height=788&name=Copy%20of%20Stats%20-%20Blog%20(28).gif)
What CTEM Means for Business Owners
CTEM is a repeating five-stage cycle for reducing the ways an attacker can get into your business. Gartner introduced the model in 2022, and CTEM.org defines the cycle as Scoping, Discovery, Prioritization, Validation, and Mobilization. The most important word in the name is "continuous." A traditional security program runs an assessment once a year, files the report, and starts over twelve months later. CTEM treats exposure management as a never-ending loop.
Each stage has a specific job:
- Scoping defines what the business cannot afford to lose and identifying the crown jewels for the organization. For a medical practice, that list may include the electronic health record system and the imaging server. For a manufacturer, it may include the ERP system and the production floor network.
- Discovery builds and maintains an inventory of every device, account, cloud application, and internet-facing system inside that scope. The team then looks for weaknesses in each one.
- Prioritization ranks what Discovery found. Exposures that attackers are actively exploiting, and that touch critical systems, move to the top of the list.
- Validation tests whether the defenses actually work. Penetration tests, attack simulations, backup restore drills, and tabletop exercises all belong in this stage.
- Mobilization gets the problem fixed. Someone patches the system or changes the configuration, confirms the fix held, and records the result so the next cycle starts with better information.
CTEM also covers more than software bugs. CTEM.org notes that the model applies to any exposure that puts data, identity, or infrastructure at risk, including leaked credentials, lookalike domains, misconfigurations, and infected devices. That wider view matters for small businesses, where a reused password or a misconfigured file share can cause as much damage as an unpatched server.
Gartner's own forecast gave the model much of its reputation. The firm predicted that organizations prioritizing their security investments through a CTEM program would be three times less likely to suffer a breach by 2026. That figure is a forecast, so treat it as direction rather than proof. The breach data in the next section explains why the direction makes sense.
Why small and mid-sized businesses need CTEM now
The data from the past two years points in one direction. Attackers are getting in through known weaknesses faster than ever, and smaller companies have less time and fewer people to respond.
Attackers now favor unpatched systems
Vulnerability exploitation overtook stolen credentials as the most common way attackers gained initial access in Verizon's 2026 report, the first time that has happened in the report's 19-year history. Organizations are also falling behind on the fixes that matter most. Only 26% of vulnerabilities in CISA's Known Exploited Vulnerabilities catalog were fully remediated, down from 38% the year before. The same report found that the median time to fully patch a vulnerability rose to 43 days, up from 32 days. That delay matters because regular software updates close the specific vulnerabilities attackers use to get in.
The window between disclosure and attack has closed
Mandiant's M-Trends 2026 report estimates the mean time to exploit a vulnerability at negative seven days. In practice, attackers routinely use a flaw before the vendor has even released a patch. Defenders once had about two months to respond. Mandiant measured the average time to exploit at 63 days in 2018 and 2019, then five days in 2023. A quarterly scan and an annual penetration test cannot keep pace with that timeline. A continuous program can.
Ransomware hits smaller companies hardest
Ransomware is the threat most likely to put a small business out of operation. Ransomware appeared in 88% of breaches involving small and mid-sized businesses in the 2025 DBIR. A year later, ransomware had grown to 48% of all breaches, and the median ransom paid was $139,875. For a 60-person firm, that payment alone can erase a year of profit before anyone counts the downtime.
Most victims did not know about the gap attackers used
Forty percent of ransomware victims in Sophos's 2025 survey said attackers exploited a security gap the organization did not know existed. The same survey found that exploited vulnerabilities were the top technical root cause of ransomware attacks for the third year in a row. A company cannot fix a weakness it has never found, and Discovery is the CTEM stage most small businesses skip.
Vendors and partners widen the attack surface
Breaches involving a third party increased 60% in a year and reached 48% of all breaches in the 2026 DBIR. Small businesses depend on outside software, cloud platforms, payroll services, and IT providers. Their exposure extends well past the office network, and a CTEM program has to account for those connections.
Related Article: Your IT Provider Was Breached: What to Do in the First 24 Hours
A breach costs more than most small businesses can absorb
IBM's 2026 Cost of a Data Breach Report puts the global average cost of a breach at a record $4.88 million, and the U.S. average reached $11.5 million. A smaller company will usually see a smaller bill, but it also has far less cash, credit, and staff to absorb one.
Regulators do not adjust expectations for company size either. HHS made the point directly in a 2025 enforcement action when it stated that small providers must also conduct accurate and thorough risk analyses to protect patient data.
To calculate how much a breach might cost your business, use our cybersecurity breach calculator.

Where CTEM breaks down for smaller companies
Most small and mid-sized businesses already perform parts of CTEM. The program usually fails between the stages, and it fails most often between finding a problem and fixing it.
Consider a typical company with 120 employees. This company likely pays for a vulnerability scanner, buys an annual penetration test, and contracts with a security vendor for after-hours monitoring. Each of those services produces a report. Every report lands on the desk of an internal IT manager who also resets passwords, onboards new hires, and keeps the phones working. The scanner flags 400 findings, the penetration tester flags 30, and the monitoring vendor sends alerts but has no authority to change a firewall rule or push a patch.
That arrangement creates three gaps:
- The ownership gap appears when the vendor who finds a problem does not manage the affected system. The team that manages the system did not find the problem, so the finding waits in a queue.
- The context gap appears when an outside provider sees an alert without knowing which server runs payroll or which account belongs to the CFO. Prioritization becomes guesswork.
- The verification gap appears when nobody confirms that a fix worked. The same weakness then shows up again in next year's report.
Verizon's data shows how long these gaps stay open. In the 2026 DBIR, weak passwords and permission misconfigurations at third parties took close to eight months to fix for half of all findings. Each of those months gave attackers another opportunity.
CTEM works only when the Mobilization stage has an owner with both the authority and the technical access to act. For most companies under 300 employees, the practical question is who that owner will be.
How Compass's closed-loop model covers all five stages
Compass runs managed IT and cybersecurity with one team, so the people who find an exposure are the same people who can fix it. Compass defines a closed-loop security system as one where every security event follows a clear path from detection to resolution, and lessons from each event feed back into stronger defenses. That definition lines up with the CTEM cycle stage for stage.
Mobilization is highlighted because it is the stage where separate vendors most often stall and where one team makes the largest difference.
Scoping
A Compass vCISO works with leadership to identify critical systems, regulated data, and compliance obligations such as HIPAA, CMMC, NYDFS, and SOC 2. The vCISO maps risks, sets priorities, and builds a security roadmap aligned with business goals and risk tolerance. Scoping becomes a business conversation with a named owner instead of a technical exercise nobody finishes.
Discovery
Because Compass also manages the IT environment, the asset inventory already exists as part of daily operations. The team manages the endpoints, user accounts, servers, and cloud tenants, so a new laptop or a forgotten test server does not go unseen for long. Compass also runs continuous security assessments and give leadership real-time visibility into gaps, which replaces the once-a-year snapshot with a view that stays current.
Prioritization
The vCISO and the security operations center rank findings by two questions. Are attackers exploiting this weakness right now, and what would it cost the business if they did? An exposed remote access gateway in front of client files moves to the top of the list. A low-risk finding on an isolated test machine waits its turn. The vCISO's knowledge of the business supplies the context an outside scanner lacks.
Validation
Compass provides penetration testing, vulnerability scanning, and incident response planning, so the business learns whether its controls hold before an attacker tests them. Findings from each test go straight into the remediation queue of the team that manages the systems.
Mobilization
The closed-loop makes its biggest difference at this stage. When the Compass SOC detects a threat, the team has the authority and technical context to isolate affected systems and begin remediation rather than forwarding an alert and waiting. The same infrastructure team patches the server, changes the configuration, and confirms the fix. Compass also integrated digital forensics and incident response into its Core and Apex Security tiers, which removes the delay that occurs when an internal team has to hand evidence to a third party after an incident.
Separate vendors compared with one Closed-Loop
|
CTEM stage |
Separate IT and security vendors |
Compass Closed-Loop |
|---|---|---|
|
Scoping |
Often skipped or done once for an audit |
vCISO owns it and revisits it with leadership |
|
Discovery |
Scanner results live apart from the IT inventory |
Inventory and assessments come from the team that runs the environment |
|
Prioritization |
The security vendor ranks findings without business context |
vCISO and SOC rank findings using business context |
|
Validation |
Annual test, report delivered, little follow-through |
Test findings flow into the same team's work queue |
|
Mobilization |
Findings wait for an internal IT manager with other priorities |
The team that found the issue fixes it and verifies the result |
Four breaches CTEM could have prevented or contained
The four organizations below ranged from roughly 60 to 300 employees. Each one broke down at a specific CTEM stage, and in each case the warning signs were available before the damage occurred.
Case 1: An entertainment law firm and an unpatched VPN
Company profile
Grubman Shire Meiselas & Sacks is a New York entertainment and media law firm whose clients have included Lady Gaga, Madonna, and Bruce Springsteen. Business directory data lists the firm at about 65 employees.
What happened
In May 2020, operators of the REvil ransomware encrypted the firm's systems and demanded $21 million for the return of 756 gigabytes of stolen data. When the firm refused, the gang released legal documents tied to Lady Gaga and raised the demand to $42 million. The firm never publicly confirmed how the attackers got in. However, security researchers reported that the attack may have started through a Pulse Secure VPN server that had not been patched against a well-known vulnerability. The vendor had released a fix months earlier, and REvil affiliates were already known to deploy ransomware through unpatched Pulse Secure systems.
Where CTEM applies
This case sits in Discovery and Prioritization. A continuous external scan would have flagged an internet-facing VPN running vulnerable firmware. Prioritization would have moved it to the top of the list because criminal groups were actively exploiting that exact flaw. Mobilization would have required more than a patch, because this vulnerability exposed stored credentials. The fix needed a password reset for every VPN user as well.
How the closed-loop helps
When the same team monitors threats and manages the VPN appliance, a critical advisory does not sit in someone's inbox. The team patches the device, resets credentials, and confirms the result in one motion. Law firms of every size now face the same scrutiny from insurers and corporate clients, and Compass vCISO Richard Mendoza explains what that standard requires of smaller practices.
Case 2: A regional accounting firm with no risk analysis
Company profile
BST & Co. CPAs is a public accounting and advisory firm based in Albany, New York. The firm reported 105 employees in 2018 and added 19 more staff through an acquisition that year.
What happened
On December 7, 2019, BST discovered that ransomware had infected part of its network and affected protected health information belonging to a healthcare client. Coverage of the case reports that a phishing email triggered the attack. Federal investigators determined that BST had failed to conduct an accurate and thorough risk analysis, and in August 2025 BST agreed to a $175,000 settlement and a two-year corrective action plan. The consequences arrived nearly six years after the attack.
Where CTEM applies
This case is a Scoping failure. BST acted as a HIPAA business associate, which meant a client's health data lived inside an accounting firm's network. A scoping exercise would have named that data as regulated and high-risk. That decision would have triggered stronger email filtering, multifactor authentication, network segmentation, and regular phishing simulations as part of Validation.
How the closed-loop helps
A vCISO who sets scope and maintains compliance documentation works alongside the team that deploys the controls. The risk analysis becomes a living document tied to real systems instead of a binder on a shelf.
Related article: Read Our Comprehensive Guide on Phishing
Case 3: A behavioral health provider with a forgotten web portal
Company profile
Deer Oaks is a San Antonio behavioral health provider serving residents of long-term care and assisted living facilities. Company profile data puts its headcount at roughly 280 to 300 employees.
What happened
A coding error in a discontinued pilot patient portal left discharge summaries publicly accessible and cached by search engines from at least December 2021 until May 2023. Then, in August 2023, an attacker breached the Deer Oaks network, stole data on 171,871 people, and demanded payment to keep it off the dark web. Investigators found that Deer Oaks had not conducted a comprehensive and accurate risk analysis, and the company paid $225,000 to settle.
Where CTEM applies
This case is a Discovery failure. A discontinued pilot project is the textbook example of an asset that drops off everyone's list while it stays connected to the internet. Continuous discovery of internet-facing systems would have found the exposed pages within days, not 17 months. CTEM.org catalogs this category as a system exposure.
How the closed-loop helps
When the team that manages infrastructure also runs discovery, a retired project gets decommissioned properly. The team shuts down the server, removes the DNS record, and asks search engines to purge cached pages.
Case 4: A 300-person telemarketing firm that paid and still could not recover
Company profile
The Heritage Company was a telemarketing and fundraising firm in Sherwood, Arkansas, that had operated for more than 60 years. It employed about 300 people.
What happened
Ransomware hit the company's servers in October 2019, and the CEO told employees the company paid the attackers for a decryption key. Recovery still failed. Restoration that leadership expected to take a week dragged on for two months, the company lost hundreds of thousands of dollars, and more than 300 employees were sent home days before Christmas.
Where CTEM applies
Public reports never identified how the attackers got in, so the clearest lesson sits in Validation. The company learned during a live crisis that its recovery plan did not work. Regular restore drills and tabletop exercises would have exposed that gap while it was still cheap to fix. Paying the ransom did not substitute for a tested recovery process.
How the closed-loop helps
Compass's guidance on ransomware recovery for small and mid-sized businesses builds on the NIST Recover function. With one team responsible for backups, response, and restoration, a failed restore test becomes a work order for the same team.
The four cases at a glance
|
Organization |
Approximate size |
CTEM stage that failed |
Control that would have helped |
|---|---|---|---|
|
Grubman Shire Meiselas & Sacks |
About 65 employees |
Discovery and Prioritization |
External scanning and fast patching of an exploited VPN flaw |
|
BST & Co. CPAs |
About 125 employees |
Scoping |
A risk analysis that treated client health data as regulated |
|
Deer Oaks |
About 280 to 300 employees |
Discovery |
Continuous discovery of internet-facing systems, including retired projects |
|
The Heritage Company |
About 300 employees |
Validation |
Tested backups and practiced recovery |
Six steps to take with your IT provider this quarter
A business owner does not need to understand every technical detail of CTEM to start one. The six steps below map to the five stages and take a few hours of leadership time.
- Name the systems your business cannot run without. Write down the five applications, data sets, or devices that would stop revenue if they went offline for a week. That list is your first scope.
- Ask for a current list of everything your company exposes to the internet. The list should include firewalls, VPNs, remote desktop gateways, websites, cloud storage, and any old project servers. If nobody can produce it within a few days, Discovery is not happening.
- Ask how long critical patches take. The median time to fully patch a vulnerability in Verizon's 2026 data was 43 days. Your internet-facing systems should beat that number by a wide margin.
- Ask who fixes what the scans find. The answer should name a person or team with the access and authority to make the change. Then ask how you will know the fix worked.
- Restore one critical system from backup this quarter. Time the restore and write down what broke. The Heritage Company learned the answer to that test during a live attack. Compass's guide to ransomware recovery for small and mid-sized businesses explains what a working recovery plan should include.
- Compare your cyber insurance application with reality. Carriers now ask about multifactor authentication, endpoint detection, and backups. A mismatch between the application and your actual controls can put a claim at risk.
Want a short checklist first? Start with the minimum security standards every CEO should be able to verify.
YOU MAY NEED TO KNOW
Frequently Asked Questions
What is continuous threat exposure management?
Continuous threat exposure management is a five-stage cycle for finding and closing the weaknesses attackers use to get into a business. The stages are Scoping, Discovery, Prioritization, Validation, and Mobilization. Gartner introduced the model in 2022. The cycle repeats on an ongoing basis instead of once a year, so the company's picture of its own risk stays current.
How is CTEM different from vulnerability management?
Vulnerability management focuses on software flaws with CVE numbers and usually ends when the scan report is delivered. CTEM covers a wider set of exposures, including leaked passwords, lookalike domains, misconfigured cloud storage, and infected devices. CTEM also requires the Validation and Mobilization stages, which means someone tests the defenses and confirms each fix. Vulnerability scanning becomes one tool inside the Discovery stage.
Is CTEM only for large enterprises?
CTEM works for companies of any size. Large companies adopted it first because they had security teams to run it, but smaller companies face the same attackers with fewer resources. Ransomware appeared in 88% of breaches at small and mid-sized businesses in the 2025 DBIR. A managed provider can run the cycle on behalf of a company that has no internal security staff.
Do we need to buy new security tools to adopt CTEM?
Most businesses can start with what they have. They usually already own some of the pieces, such as a firewall, endpoint protection, a backup system, and possibly a vulnerability scanner. CTEM organizes those tools into a repeatable process with clear owners. The bigger investment is usually in people and process, since someone has to review findings, set priorities, and carry fixes through to completion.
How often should a small business run each stage?
Discovery and monitoring should run continuously. Prioritization should happen weekly, or immediately when a new vulnerability comes under active attack. Scoping should be revisited at least once a year and after major changes such as an acquisition, a new office, or a new core application. Penetration testing typically runs annually, and backup restore tests should run at least quarterly for critical systems. Get the full IT Director’s Cybersecurity Playbook for more guidelines.
Can CTEM stop attacks that use brand-new vulnerabilities?
CTEM cannot patch a flaw before the vendor releases a fix. It does reduce the damage those attacks cause. Mandiant estimates the mean time to exploit at negative seven days, so attackers often strike before patches exist. A CTEM program limits what an attacker can reach through segmentation, multifactor authentication, and least-privilege access. It also shortens the time to detect and contain an intrusion.
How does CTEM help with HIPAA, CMMC, or cyber insurance requirements?
Most regulations and insurance applications ask for the same core evidence: a current risk analysis, an asset inventory, documented controls, and proof that the organization fixes what it finds. CTEM produces that evidence as a normal part of each cycle. Two of the case studies above involved federal settlements in which investigators cited the lack of a thorough risk analysis. For more on what regulated businesses need to know about cybersecurity and compliance read our guide.
What is a closed loop security model?
A closed-loop security model puts detection, investigation, and remediation under one team and one process. Compass describes it as a system in which every security event follows a clear path from detection to resolution. The lessons from each event then feed back into stronger defenses. The model removes the handoff between the vendor that finds a problem and the team that fixes it.
We already have an MSP and a separate security vendor. Why would we consolidate?
Two vendors can work if their processes connect well, but the handoff between them is where findings stall. The security vendor sees the alert, while the MSP holds the admin credentials and the change process. Compass's model gives its SOC the authority and technical context to isolate affected systems and begin remediation without waiting on another provider. Consolidation also gives leadership one accountable party when something goes wrong.
How long does it take to get a CTEM program running?
CTEM.org publishes a 90-day roadmap for building a program. With a managed provider, much of the early work overlaps with onboarding. Compass's structured onboarding typically takes 30 to 60 days, and that period covers the asset inventory, initial risk assessment, and first remediation priorities. The first full cycle usually completes within the first quarter.
Richard Mendoza
Richard is the Director of vCISO services with CompassMSP. He has over twenty-five years of experience as an Information Security professional with hands-on experience in engineering process and information security, and IT audit disciplines. With a wide-ranging knowledge as a Systems Engineer, Information Security Officer, and Senior Auditor, Richard has expertise in managing internal and external audits focused on reducing overall risk exposure and infrastructure redundancy for organizations.