A company with 80 employees now faces many of the same attackers as a company with 8,000. The smaller company usually has one or two IT people, no dedicated security staff, and a patch backlog that grows every month. That imbalance shows up in the breach data: ransomware appeared in 88% of breaches involving small and mid-sized businesses in Verizon's 2025 Data Breach Investigations Report.
In This Article:
Continuous Threat Exposure Management (CTEM) gives smaller organizations a structured way to find and close the weaknesses attackers use before those weaknesses turn into an incident. This article explains the five stages of CTEM and what each one asks of a business. It also shows why the model matters even more. It then walks through four real breaches at organizations in the 20 to 300 employee range and explains how Compass's closed-loop model puts all five CTEM stages under one accountable team.
CTEM is a repeating five-stage cycle for reducing the ways an attacker can get into your business. Gartner introduced the model in 2022, and CTEM.org defines the cycle as Scoping, Discovery, Prioritization, Validation, and Mobilization. The most important word in the name is "continuous." A traditional security program runs an assessment once a year, files the report, and starts over twelve months later. CTEM treats exposure management as a never-ending loop.
Each stage has a specific job:
CTEM also covers more than software bugs. CTEM.org notes that the model applies to any exposure that puts data, identity, or infrastructure at risk, including leaked credentials, lookalike domains, misconfigurations, and infected devices. That wider view matters for small businesses, where a reused password or a misconfigured file share can cause as much damage as an unpatched server.
Gartner's own forecast gave the model much of its reputation. The firm predicted that organizations prioritizing their security investments through a CTEM program would be three times less likely to suffer a breach by 2026. That figure is a forecast, so treat it as direction rather than proof. The breach data in the next section explains why the direction makes sense.
The data from the past two years points in one direction. Attackers are getting in through known weaknesses faster than ever, and smaller companies have less time and fewer people to respond.
Vulnerability exploitation overtook stolen credentials as the most common way attackers gained initial access in Verizon's 2026 report, the first time that has happened in the report's 19-year history. Organizations are also falling behind on the fixes that matter most. Only 26% of vulnerabilities in CISA's Known Exploited Vulnerabilities catalog were fully remediated, down from 38% the year before. The same report found that the median time to fully patch a vulnerability rose to 43 days, up from 32 days. That delay matters because regular software updates close the specific vulnerabilities attackers use to get in.
Mandiant's M-Trends 2026 report estimates the mean time to exploit a vulnerability at negative seven days. In practice, attackers routinely use a flaw before the vendor has even released a patch. Defenders once had about two months to respond. Mandiant measured the average time to exploit at 63 days in 2018 and 2019, then five days in 2023. A quarterly scan and an annual penetration test cannot keep pace with that timeline. A continuous program can.
Ransomware is the threat most likely to put a small business out of operation. Ransomware appeared in 88% of breaches involving small and mid-sized businesses in the 2025 DBIR. A year later, ransomware had grown to 48% of all breaches, and the median ransom paid was $139,875. For a 60-person firm, that payment alone can erase a year of profit before anyone counts the downtime.
Forty percent of ransomware victims in Sophos's 2025 survey said attackers exploited a security gap the organization did not know existed. The same survey found that exploited vulnerabilities were the top technical root cause of ransomware attacks for the third year in a row. A company cannot fix a weakness it has never found, and Discovery is the CTEM stage most small businesses skip.
Breaches involving a third party increased 60% in a year and reached 48% of all breaches in the 2026 DBIR. Small businesses depend on outside software, cloud platforms, payroll services, and IT providers. Their exposure extends well past the office network, and a CTEM program has to account for those connections.
Related Article: Your IT Provider Was Breached: What to Do in the First 24 Hours
IBM's 2026 Cost of a Data Breach Report puts the global average cost of a breach at a record $4.88 million, and the U.S. average reached $11.5 million. A smaller company will usually see a smaller bill, but it also has far less cash, credit, and staff to absorb one.
Regulators do not adjust expectations for company size either. HHS made the point directly in a 2025 enforcement action when it stated that small providers must also conduct accurate and thorough risk analyses to protect patient data.
To calculate how much a breach might cost your business, use our cybersecurity breach calculator.
Most small and mid-sized businesses already perform parts of CTEM. The program usually fails between the stages, and it fails most often between finding a problem and fixing it.
Consider a typical company with 120 employees. This company likely pays for a vulnerability scanner, buys an annual penetration test, and contracts with a security vendor for after-hours monitoring. Each of those services produces a report. Every report lands on the desk of an internal IT manager who also resets passwords, onboards new hires, and keeps the phones working. The scanner flags 400 findings, the penetration tester flags 30, and the monitoring vendor sends alerts but has no authority to change a firewall rule or push a patch.
That arrangement creates three gaps:
Verizon's data shows how long these gaps stay open. In the 2026 DBIR, weak passwords and permission misconfigurations at third parties took close to eight months to fix for half of all findings. Each of those months gave attackers another opportunity.
CTEM works only when the Mobilization stage has an owner with both the authority and the technical access to act. For most companies under 300 employees, the practical question is who that owner will be.
Compass runs managed IT and cybersecurity with one team, so the people who find an exposure are the same people who can fix it. Compass defines a closed-loop security system as one where every security event follows a clear path from detection to resolution, and lessons from each event feed back into stronger defenses. That definition lines up with the CTEM cycle stage for stage.
Mobilization is highlighted because it is the stage where separate vendors most often stall and where one team makes the largest difference.
A Compass vCISO works with leadership to identify critical systems, regulated data, and compliance obligations such as HIPAA, CMMC, NYDFS, and SOC 2. The vCISO maps risks, sets priorities, and builds a security roadmap aligned with business goals and risk tolerance. Scoping becomes a business conversation with a named owner instead of a technical exercise nobody finishes.
Because Compass also manages the IT environment, the asset inventory already exists as part of daily operations. The team manages the endpoints, user accounts, servers, and cloud tenants, so a new laptop or a forgotten test server does not go unseen for long. Compass also runs continuous security assessments and give leadership real-time visibility into gaps, which replaces the once-a-year snapshot with a view that stays current.
The vCISO and the security operations center rank findings by two questions. Are attackers exploiting this weakness right now, and what would it cost the business if they did? An exposed remote access gateway in front of client files moves to the top of the list. A low-risk finding on an isolated test machine waits its turn. The vCISO's knowledge of the business supplies the context an outside scanner lacks.
Compass provides penetration testing, vulnerability scanning, and incident response planning, so the business learns whether its controls hold before an attacker tests them. Findings from each test go straight into the remediation queue of the team that manages the systems.
The closed-loop makes its biggest difference at this stage. When the Compass SOC detects a threat, the team has the authority and technical context to isolate affected systems and begin remediation rather than forwarding an alert and waiting. The same infrastructure team patches the server, changes the configuration, and confirms the fix. Compass also integrated digital forensics and incident response into its Core and Apex Security tiers, which removes the delay that occurs when an internal team has to hand evidence to a third party after an incident.
|
CTEM stage |
Separate IT and security vendors |
Compass Closed-Loop |
|---|---|---|
|
Scoping |
Often skipped or done once for an audit |
vCISO owns it and revisits it with leadership |
|
Discovery |
Scanner results live apart from the IT inventory |
Inventory and assessments come from the team that runs the environment |
|
Prioritization |
The security vendor ranks findings without business context |
vCISO and SOC rank findings using business context |
|
Validation |
Annual test, report delivered, little follow-through |
Test findings flow into the same team's work queue |
|
Mobilization |
Findings wait for an internal IT manager with other priorities |
The team that found the issue fixes it and verifies the result |
The four organizations below ranged from roughly 60 to 300 employees. Each one broke down at a specific CTEM stage, and in each case the warning signs were available before the damage occurred.
01Grubman Shire Meiselas & Sacks is a New York entertainment and media law firm whose clients have included Lady Gaga, Madonna, and Bruce Springsteen. Business directory data lists the firm at about 65 employees.
In May 2020, operators of the REvil ransomware encrypted the firm's systems and demanded $21 million for the return of 756 gigabytes of stolen data. When the firm refused, the gang released legal documents tied to Lady Gaga and raised the demand to $42 million. The firm never publicly confirmed how the attackers got in. However, security researchers reported that the attack may have started through a Pulse Secure VPN server that had not been patched against a well-known vulnerability. The vendor had released a fix months earlier, and REvil affiliates were already known to deploy ransomware through unpatched Pulse Secure systems.
This case sits in Discovery and Prioritization. A continuous external scan would have flagged an internet-facing VPN running vulnerable firmware. Prioritization would have moved it to the top of the list because criminal groups were actively exploiting that exact flaw. Mobilization would have required more than a patch, because this vulnerability exposed stored credentials. The fix needed a password reset for every VPN user as well.
When the same team monitors threats and manages the VPN appliance, a critical advisory does not sit in someone's inbox. The team patches the device, resets credentials, and confirms the result in one motion. Law firms of every size now face the same scrutiny from insurers and corporate clients, and Compass vCISO Richard Mendoza explains what that standard requires of smaller practices.
BST & Co. CPAs is a public accounting and advisory firm based in Albany, New York. The firm reported 105 employees in 2018 and added 19 more staff through an acquisition that year.
On December 7, 2019, BST discovered that ransomware had infected part of its network and affected protected health information belonging to a healthcare client. Coverage of the case reports that a phishing email triggered the attack. Federal investigators determined that BST had failed to conduct an accurate and thorough risk analysis, and in August 2025 BST agreed to a $175,000 settlement and a two-year corrective action plan. The consequences arrived nearly six years after the attack.
This case is a Scoping failure. BST acted as a HIPAA business associate, which meant a client's health data lived inside an accounting firm's network. A scoping exercise would have named that data as regulated and high-risk. That decision would have triggered stronger email filtering, multifactor authentication, network segmentation, and regular phishing simulations as part of Validation.
A vCISO who sets scope and maintains compliance documentation works alongside the team that deploys the controls. The risk analysis becomes a living document tied to real systems instead of a binder on a shelf.
Deer Oaks is a San Antonio behavioral health provider serving residents of long-term care and assisted living facilities. Company profile data puts its headcount at roughly 280 to 300 employees.
A coding error in a discontinued pilot patient portal left discharge summaries publicly accessible and cached by search engines from at least December 2021 until May 2023. Then, in August 2023, an attacker breached the Deer Oaks network, stole data on 171,871 people, and demanded payment to keep it off the dark web. Investigators found that Deer Oaks had not conducted a comprehensive and accurate risk analysis, and the company paid $225,000 to settle.
This case is a Discovery failure. A discontinued pilot project is the textbook example of an asset that drops off everyone's list while it stays connected to the internet. Continuous discovery of internet-facing systems would have found the exposed pages within days, not 17 months. CTEM.org catalogs this category as a system exposure.
When the team that manages infrastructure also runs discovery, a retired project gets decommissioned properly. The team shuts down the server, removes the DNS record, and asks search engines to purge cached pages.
The Heritage Company was a telemarketing and fundraising firm in Sherwood, Arkansas, that had operated for more than 60 years. It employed about 300 people.
Ransomware hit the company's servers in October 2019, and the CEO told employees the company paid the attackers for a decryption key. Recovery still failed. Restoration that leadership expected to take a week dragged on for two months, the company lost hundreds of thousands of dollars, and more than 300 employees were sent home days before Christmas.
Public reports never identified how the attackers got in, so the clearest lesson sits in Validation. The company learned during a live crisis that its recovery plan did not work. Regular restore drills and tabletop exercises would have exposed that gap while it was still cheap to fix. Paying the ransom did not substitute for a tested recovery process.
Compass's guidance on ransomware recovery for small and mid-sized businesses builds on the NIST Recover function. With one team responsible for backups, response, and restoration, a failed restore test becomes a work order for the same team.
|
Organization |
Approximate size |
CTEM stage that failed |
Control that would have helped |
|---|---|---|---|
|
Grubman Shire Meiselas & Sacks |
About 65 employees |
Discovery and Prioritization |
External scanning and fast patching of an exploited VPN flaw |
|
BST & Co. CPAs |
About 125 employees |
Scoping |
A risk analysis that treated client health data as regulated |
|
Deer Oaks |
About 280 to 300 employees |
Discovery |
Continuous discovery of internet-facing systems, including retired projects |
|
The Heritage Company |
About 300 employees |
Validation |
Tested backups and practiced recovery |
A business owner does not need to understand every technical detail of CTEM to start one. The six steps below map to the five stages and take a few hours of leadership time.
If those questions produce vague answers, a vCISO assessment from Compass can map the gaps and turn them into a prioritized roadmap.
Want a short checklist first? Start with the minimum security standards every CEO should be able to verify.