Documentation Index

Fetch the complete documentation index at: https://docs.safe.security/llms.txt

Use this file to discover all available pages before exploring further.

Implementing the CTEM Cycle with Balbix

Prev Next

Continuous Threat Exposure Management (CTEM) is a proactive cybersecurity framework designed to systematically and iteratively identify, assess, prioritize, and mitigate potential threats and vulnerabilities within an organization's digital infrastructure. Unlike traditional vulnerability management approaches that often rely on periodic assessments, CTEM emphasizes continuous monitoring and improvement, ensuring that security measures evolve in tandem with emerging threats.

The CTEM Cycle

Step 1: Scoping

In implementing a continuous threat exposure management program, we begin with scoping. This critical first step requires us to define our attack surface comprehensively, looking beyond traditional infrastructure. We must understand that our attack surface isn't limited to just servers and endpoints, but extends to everything that could provide an entry point for attackers. This includes our cloud assets, SaaS applications, supply chain connections, social media presence, and code repositories. During scoping, we need to make strategic decisions about where to focus our initial efforts. The key is to avoid the common pitfall of trying to boil the ocean - instead, we need to scope based on business risk and potential impact, creating a manageable starting point for our continuous threat exposure management journey.

Operational Implementation

These are the related functions in the Balbix Platform:

Connectors List

Connectors

Configure Connectors

Configure Sensors

Data Aggregator Deployment

BX5 Asset Analysis

Step 2: Discovery

The discovery phase builds upon our initial scoping, but goes much deeper. During discovery, we systematically identify both visible and hidden assets, finding not just the obvious systems and applications, but also discovering shadow IT, forgotten assets, and unknown dependencies. We look for vulnerabilities, misconfigurations, and other types of security weaknesses across our defined scope. But here's a crucial point: success in discovery isn't measured by how many assets or vulnerabilities we find. Instead, we need to understand what we're discovering in the context of business risk and potential impact. This means going beyond simple asset counting to understand relationships between assets, their business purpose, and their role in critical processes. Discovery must be continuous, as our technology landscape constantly changes with new deployments, decommissioned systems, and ongoing reconfigurations.

Operational Implementation

These are the related functions in the Balbix Platform:

Assets

Apps

Group Management

Inventory Settings

Create asset filters

Set owners for predefined groups

Create user-defined groups and assign owners

Configure asset and apps automations

Configure asset and apps dashboards

Also review the following technical reference articles:

Asset Roles

Unified Enterprise Asset Classification Model

Telemetry

Consolidating Operating Systems and Software: A Unified Approach

Understanding Data Lifecycle in Balbix

Step 3: Prioritization

Prioritization moves us beyond merely identifying issues to making informed decisions about what to fix first. We must recognize that we can't fix every security issue immediately, so we need sophisticated prioritization that considers multiple factors. How urgent is the issue? What security controls do we already have in place? What's our tolerance for residual risk? Most importantly, what level of risk does each issue pose to our high-value business assets? This isn't just about technical severity scores. Instead, we need to understand the full context: is this vulnerability on a critical business system? Is it exposed to the internet? Do we have evidence of active exploitation? By answering these questions, we can focus our limited remediation resources where they'll have the greatest impact on reducing business risk. This context-aware prioritization ensures we're not just fixing vulnerabilities, we're systematically reducing our most significant exposures.

Operational Implementation

These are the related functions in the Balbix Platform:

Cyber Risk Summary

Board Reporting

Risk Analytics

Risk Settings

Asset Vulnerabilities

Appsec Findings

Hierarchy-Based Reports

Remediations & Mitigations

Exceptions

Exposure Simulations

EM Settings

Create vulnerability filters

Configure risk settings

Also review the following technical reference articles:

Exposure Management Concepts

Understanding Mean Time to Patch (MTTP)

Understanding Mean Time to Remediate (MTTR)

Understanding Mean Open Vulnerability Age (MOVA)

Using the Exposure Score Simulator

EM Analytics

Balbix Exposure Simulator Use Cases

Vulnerability Inference

Mitigation Efficacy Overview

Step 4: Validation

The validation phase is where we move from theoretical risk to practical reality. Here, we verify our assumptions about security issues by understanding how real attacks might unfold. Could an attacker actually exploit this vulnerability given our current security controls? What are all the possible attack paths to reach our critical assets? Are our incident response plans adequate for the types of attacks we might face? Validation isn't just a technical exercise, it requires alignment with business stakeholders to agree on what triggers remediation actions. We need to understand not just if an attack is possible, but how it might impact business operations, what our detection capabilities are, and whether our response would be fast enough to prevent significant damage. This validation process helps us refine our prioritization and ensures we're focusing on real, exploitable risks rather than theoretical vulnerabilities.

Operational Implementation

These are the related functions in the Balbix Platform:

Findings

Validation Summary

Reports

Step 5: Mobilization

The mobilization phase of continuous threat exposure management is where planning transforms into action. While automated remediation has its place, particularly for straightforward issues, successful mobilization requires coordinating people, processes, and technology. We need to break down complex remediation tasks into manageable projects, assign clear ownership, and establish metrics to track progress. Security findings must be translated into actionable tasks for system owners, with clear communication about risk context and remediation priorities. We need efficient workflows that remove obstacles to remediation, streamline approval processes, and enable quick deployment of fixes. Documentation of these workflows is crucial, especially when remediation requires coordination across multiple teams. The goal isn't just to fix individual issues, but to create sustainable processes for continuous risk reduction. Effective mobilization turns our security insights into measurable risk reduction, moving us from identifying problems to actually solving them.

Operational Implementation

These are the related functions in the Balbix Platform:

Create tickets

Create remediation projects

Create automations