Connect with us

Business & Technology

building a modern CTEM program

Published

on


Cybersecurity leaders aren’t struggling with visibility as much as they are with prioritisation.

With cloud-native apps, identity, SaaS, OT, and more, the attack surface today is much broader than the one traditional programs were designed to address. The consequence is all too familiar: thousands of alerts, disjointed insights, and still, no clear answer to what should be an obvious question: what matters most to the business today?

This is where exposure management and AI-driven exposure assessment enter the picture, with the operational model being Continuous Threat Exposure Management (CTEM).

Why CTEM matters

What problem is CTEM solving?

Traditional security tools are very good at identifying vulnerabilities, but not as good at identifying those vulnerabilities that are actually exploitable and have a significant impact. This issue has become more pronounced as the environment becomes more distributed and interconnected.

CTEM provides a new approach that is continuous and risk-based. It changes the paradigm from detection to exposure. Rather than relying on regular scans and scores that do not change over time, it’s all about the process of discovery, analysis, validation, and action.

At a high level, the benefits of CTEM are:

  • The ability to focus on what is actually reachable and exploitable
  • A way to focus on business risk rather than technical severity
  • Having continuous risk assessments as environments change

The fundamental shift is from “what is vulnerable?” to “what could actually be used against us?”

The five stages of a CTEM program

How do you operationalise exposure management?

CTEM is more of a lifecycle than a tool. Like any good lifecycle, it is iterative.

It begins with scoping. Here, businesses identify what matters most. What are critical assets? What are key business services? What are systems with financial or regulatory implications? Without scoping, prioritisation is soon noise.

Discovery is next, and it is far more complicated than it is made out to be. Environments are in motion. Assets are spinning up and down. Identities are changing. And new risks are emerging every day. Maintaining an inventory of what is in IT, in the cloud, and beyond is foundational.

Once exposures have been defined, prioritisation is the key challenge. This is where context is important. Prioritisation that is effective takes into account:

  • Exploit availability and attacker activity
  • Asset criticality and business function
  • Network exposure and identity access paths

This is where companies go beyond general severity ratings and into something much more actionable.

The fourth stage is validation. This is where realism is introduced. It answers whether this exposure is actually exploitable. This is done by examining attack paths and simulating attacks.

Lastly, there is mobilisation. This is where action is taken. It is where there is integration with workflows, assigning action items, and tracking progress in a measurable way.

Building unified exposure visibility across the attack surface

Why is visibility still such a challenge?

Most organisations have made significant investments in various tools, and the problem is that the visibility is fragmented. Cloud security, identity security, endpoint security, and network security are usually implemented in parallel and generate their own data and priorities.

The problem is that risks don’t exist in silos. Risks are the result of interactions.

Exposure visibility gives the ability to bring these domains together.

  • How are the vulnerabilities related between the environments
  • How does the identity and access provide unintended pathways
  • How does the combination of the weaknesses create real attack opportunities

For example, the configuration of the workload in the cloud could be considered low risk. However, when the permissions are excessive and the workload is exposed, the risk is more obvious.

The connections between the risks are not always obvious unless the cross-domain exposure is considered.

Continuous discovery across a dynamic attack surface

Why isn’t periodic scanning enough anymore?

Because the environment doesn’t sit still.

The nature of cloud-based workloads is ephemeral. Applications are constantly being updated. User roles and permissions are in constant flux. In this environment, periodic assessment is plagued by blind spots, where snapshots are obsolete almost as soon as they’re taken.

Continuous discovery solves this problem by providing real-time visibility into your environment. This is because we recognise that your attack surface is constantly changing, and your risk assessment must follow.

This is particularly critical in:

  • Cloud-native environments
  • Hybrid infrastructures
  • Businesses that are adopting risk-based cloud security models

With no continuous insight, entities are making decisions based on incomplete data.

Prioritising cyber risk with business context

How do you decide what to fix first?

It is in this area that security software often falls short, as the sheer number of vulnerabilities far outweighs the number of ways to address them.

It is in this area that organisations are increasingly turning to AI to help address the problem. It is able to do so by correlating data from different domains, to:

  • Identify potential paths of attack
  • Uncover vulnerabilities that are actively being exploited
  • Correlate technical risks to business risks

This is where the real value of such an approach comes in – not only is it more efficient, but it is also more understandable.

From vulnerability scans to continuous, contextualised exposure insight

What is the role of traditional vulnerability management today?

Vulnerability scanning is still a fundamental technique. Tools like Nessus are very good at finding known weaknesses, misconfigurations, and patch problems.

Scanning, however, is no longer sufficient on its own.

A scanner, by itself, will tell you what you have. It won’t tell you:

  • Is the vulnerability reachable?
  • How does it get exploited?
  • What are the business implications?

As part of a CTEM-based approach, vulnerability information becomes part of a larger model of exposure. It’s augmented, validated against “real world” scenarios, and weighted by relevance.

This is the evolution from simple data collection to decision support.

Integrating CTEM with existing security workflows

How do you make CTEM actionable?

Insight is useless if action is not taken. This is the biggest pitfall in the implementation of cybersecurity initiatives.

The operationalisation of CTEM is the integration of CTEM into existing workflows. This includes:

  • Integrating CTEM findings into existing IT and DevOps ticketing systems
  • Aligning remediation activities with business priorities and ownership
  • Measuring the effectiveness of remediation activities over time

Additionally, there is a need to change the way we communicate CTEM findings. This is so that the findings are communicated in a way that the business can understand.

The most successful organisations in the implementation of CTEM are those that treat the process as a shared responsibility.

The bigger shift: from reactive security to exposure reduction

Exposure management and AI-driven exposure assessment are a result of a larger shift in the world of Cybersecurity. They represent a shift from:

  • Alerts to insights
  • Volume to context
  • Technical severity to business risk
  • Periodic review to continuous assessment

This goes beyond a change in tools, to altering how we think about cyber risk.

Prioritisation will be the key differentiator

The attack surface will carry on expanding, and complexity will continue to rise. Therefore, in this environment, the ability to prioritise is going to be the key differentiator.

As organisations continue to mature their CTEM programs, they are no longer just trying to find problems. They are trying to gain a better understanding of their risk and be more proactive.

The key to success is not how many problems are discovered, but how well the risk is reduced.



Source link

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Business & Technology

Phoenix Software staff win Broadcom VCF Knight status

Published

on



JOSEPH GABRIEL LAGONSIN

News Editor

Phoenix Software has announced that two employees have achieved Broadcom VCF Knight status, Broadcom’s highest recognition for partner professionals.

Infrastructure Practise Lead Richard Worth and Senior Technical Consultant Robert Dent both received the Broadcom VCF Knight – Storage certification, recognising expertise in VMware Cloud Foundation-related storage.

The achievement strengthens Phoenix’s position within Broadcom’s partner network, where it holds UK Pinnacle and Expert Advantage status. It also reflects continued investment by the York-based business in technical staff with specialist VMware expertise.

Broadcom’s Knight programme identifies partner specialists with experience in the architecture, design, implementation and support of Broadcom technologies. In this case, the focus was on VMware Cloud Foundation and related storage work.

The process involves several stages rather than a single exam. Candidates must pass multiple advanced technical tests, submit evidence of customer designs, deliver a live technical demonstration to a Broadcom sponsor, and then undergo nomination and review by a Broadcom panel.

The certification typically takes several months to complete and requires periodic renewal, making it a relatively rare qualification within the VMware and Broadcom partner ecosystem.

Worth has worked in IT for more than 25 years, including nine at Phoenix, where he leads the infrastructure practice. His background spans networking, storage and virtualisation, all closely tied to the technologies covered by VMware Cloud Foundation.

Dent has worked with VMware technologies for more than 20 years, beginning during an early IT apprenticeship and later implementing virtualisation environments at the University of Hull. His experience also includes servers, storage, NetApp and vSAN, and he gained his first VMware certification while working at the university.

Technical route

The certifications come as many customers reassess their VMware environments following Broadcom’s acquisition of the software business. That has increased scrutiny on partners able to demonstrate deep product knowledge and delivery experience.

Both men completed the same rigorous process to secure the designation, which Phoenix described as evidence of its ability to support organisations running complex virtualised infrastructure.

Worth said: “The difference with the Knight programme is that it recognises not just what you know, but what you’ve actually delivered. It reflects real-world experience – designing, implementing, and solving problems for customers. For me, VCF brings together everything we do across networking, storage, and virtualisation into one cohesive platform.”

Dent linked the certification to customer expectations around complex infrastructure projects.

Dent said: “This is one of the highest standards a consultant can achieve. It’s exactly the level of expertise customers expect when they’re investing in complex platforms like VMware Cloud Foundation. For me, it’s also about continuing to learn and building environments where the wider team can develop their skills.”

Phoenix operates across software licensing, hardware, software asset management and managed IT services, and has been in the market for more than 30 years. It works with public and private sector customers on IT strategy, infrastructure design, deployment and software management.

The latest certifications suggest the company is seeking to deepen specialist skills in core infrastructure areas as customers continue to assess how they manage virtualisation, storage and networking in consolidated cloud environments.



Source link

Continue Reading

Business & Technology

Connected building systems pose growing cyber risk

Published

on


Restore Information Management has warned that connected building systems are becoming a cyber security risk for organisations, with many businesses failing to secure operational technology such as building management systems, access control and CCTV.

The warning comes as attackers expand their focus beyond traditional IT to target the technology that supports day-to-day building operations. These systems are increasingly internet-connected, remotely managed and linked to cloud services, widening the number of potential entry points for attackers.

Official figures underline the scale of the issue. The latest UK Government Cyber Security Breaches Survey found that 43% of UK businesses experienced a cyber security breach or attack in the past 12 months.

David Robinson, Head of Cybersecurity at Restore Information Management, said many organisations have basic weaknesses across their operational technology environments, particularly default settings and poor access controls.

“Many building systems still rely on default credentials straight out of the box. If these credentials aren’t changed, cyber criminals can gain access to critical systems with relative ease. As today’s digital building systems become increasingly connected, remotely managed and cloud-based, they are evolving faster than many organisations can secure them. Without the right controls, attackers could disrupt critical building systems, disable physical security measures or use them as a route into the wider corporate network,” Robinson said.

Attack surface

Robinson said one of the main steps organisations should take is to establish a full inventory of connected building systems, including building management systems, access control platforms, CCTV networks and environmental controls.

In practice, that means knowing what equipment is connected to the network, who is responsible for managing it and how users, contractors and suppliers can access it. Security teams often have a clearer view of laptops, servers and business applications than of operational technology embedded in buildings, creating a gap that can persist for years.

He also highlighted the risk posed by shared and default credentials. Manufacturer-set passwords remain common across a range of connected systems, and shared accounts can make it difficult to trace activity or remove access when a staff member or contractor leaves.

Restore urged organisations to replace default credentials as soon as systems are deployed, remove shared logins and ensure each employee or contractor has an individual account. That allows access to be monitored and withdrawn when required.

Remote access

Another area of concern is remote access for suppliers and maintenance providers. Building systems often rely on outside specialists for configuration, support and servicing, but these links can remain open long after a project has ended.

Robinson said access should be formally approved, reviewed regularly and removed once work is complete or contracts expire. Dormant contractor accounts, he added, should not remain active.

The issue has become more pressing as facilities technology has become easier to access from outside a site. Remote management can help operators maintain systems across multiple buildings, but it also creates another route that needs oversight from both facilities and cyber security teams.

Network separation

Restore also called for stronger segmentation between operational technology and corporate IT environments. Separating building systems from wider business networks can limit the damage if one part of the estate is compromised.

This matters because attackers who gain access to a connected operational system may try to move laterally into more sensitive parts of the organisation. Segmenting networks can make that movement harder and reduce the impact of a breach.

Security and facilities teams should work together to review legacy environments and identify where older systems can be better isolated. In many organisations, building technology has evolved in stages over a long period, leaving a mix of old and new equipment with varying security controls.

Strategic priority

Robinson’s final point was that operational technology should no longer sit outside mainstream cyber planning. He argued that connected building systems need to be included in an organisation’s wider security strategy, with regular reviews, staff awareness and stronger security design at the point of deployment.

That view reflects a broader shift in cyber risk management as physical infrastructure becomes more digital. Systems once treated mainly as facilities assets are now part of an organisation’s connected estate and can affect both physical security and business continuity if disrupted.

Restore Information Management is one of the UK’s larger information management providers and says it works with more than 6,000 clients, including more than 80% of NHS trusts. “Cyber security is no longer confined to servers and laptops. As buildings become smarter, the systems that control them require the same level of protection as every other critical asset,” Robinson said.



Source link

Continue Reading

Business & Technology

Prince William-backed helicopter company profits rise

Published

on



Airbus Helicopters opened a new £50m headquarters and factory facilities at Oxford Airport in Yarnton.

Opened in September 2024 by Prince William, Airbus Helicopters employs around 250 people in Oxford and has room for 32 helicopters.

New accounts published by the company shows the business reported an annual profit of £10.1m in the calendar year 2025 also its first full year from Oxford.

This was up 13 per cent from £8.9m the year before.

READ MORE: Jeremy Clarkson praised for his efforts as he admits ‘no feeling like it’

Airbus Helicopters said this profit was boosted by a £2.5m foreign exchange gain and was despite a drop in turnover.

“The company has now completed its first full year of operations at the new, larger hangar facility at London Oxford Airport, following the move in July 2024 and the commencement of a 25-year lease agreement,” said Yann Rozo of Airbus Helicopters in a report.

“The company would like to recognise the positive contribution of its customers, employees and other stakeholders in achieving the results of 2025 and looks to further enhance these relationships during 2026.”

Revenue for 2025 was at £138.9m compared with £158.6m the year before.

The decrease in turnover compared to the prior year has been attributed to the timing of aircraft deliveries and the expiry of a Ministry of Defence contract.

Airbus completes helicopters built in France and Germany at its Oxford site before selling on to customers including the National Police Air Service.





Source link

Continue Reading

Trending