Forefront IT Security Services
BlogThreat Exposure
Threat Exposure

AEV vs CTEM: Why the Industry's Hottest Debate Is the Wrong One

April 2026Forefront IT Security Services5 min read

Gartner coined both terms. They were never meant to compete. Here is what buyers are actually asking for, and how to position your exposure programme around it.

The short version. Gartner defines CTEM as a five stage programme. AEV is the technology category that sits inside it, powering the fourth stage: validation. They are not alternatives. One is the framework, the other is the engine that makes the framework real.

The debate everyone is having is the wrong one

Walk into any security vendor briefing this quarter and you will hear one of two pitches. Half the vendors are positioning themselves as Adversarial Exposure Validation (AEV) platforms. The other half are pitching Continuous Threat Exposure Management (CTEM). Buyers are being asked to pick a side.

They should not. It is a category error, and Gartner, who coined both terms, has been fairly clear about why.

What Gartner actually said

Gartner introduced CTEM in 2022 as a programmatic approach to managing exposure, published in the research note *Implement a Continuous Threat Exposure Management (CTEM) Program* and summarised publicly in their article How to Manage Cybersecurity Threats, Not Episodes. The premise is that point in time assessments cannot keep pace with how quickly environments change. CTEM is a loop, not a product. It has five stages:

  1. Scoping Define what actually matters to the business. Not every asset is equal.
  2. Discovery Find all assets and exposures within scope, including shadow IT, misconfigurations, identity risk, and attack paths.
  3. Prioritisation Rank exposures by exploitability and business impact. Stop chasing CVSS scores.
  4. Validation Prove which exposures are actually exploitable. This is where AEV lives.
  5. Mobilisation Drive remediation into existing workflows. Tickets, change management, DevOps pipelines.

Gartner added Adversarial Exposure Validation to its coverage later, positioning it as an emerging category in the 2024 Hype Cycle for Security Operations. In Gartner's framing, AEV is not a rival to CTEM. It is the technology that powers the validation stage inside it, providing continuous, evidence based proof of which exposures attackers could actually exploit.

Per Gartner's published guidance, organisations implementing a CTEM programme should evaluate AEV tooling specifically at the validation stage, rather than treating AEV as a standalone replacement for exposure management. Source: Gartner research on CTEM and Hype Cycle for Security Operations 2024. Full reports available to Gartner subscribers.

The takeaway is straightforward. AEV sits inside CTEM. One is the framework, the other is the engine that makes the framework real.

AEV proves which of your findings are actually exploitable. CTEM is the programme that turns those proofs into fixes.

Why AEV is having its moment

If CTEM is the bigger idea, why has AEV become the hotter term? Three reasons, all about the buying cycle.

  • It is concrete "Prove this CVE is exploitable in our environment" is a problem a security manager can fund this quarter.
  • It is measurable Validated exposures, closed exploit paths, blocked attack chains. Metrics a board will actually read.
  • It demos well Run the attack, show the kill chain, show the detection gap. The sale closes itself.
  • It replaces a line item Manual pentesting is expensive, annual, and already in the budget. AEV takes that money directly.

CTEM, by contrast, is harder to sell in a single meeting. It is a programme, not a product. It needs buy in across Security, IT, and the executive team. You cannot demo a methodology. Gartner's position is that mature CTEM adopters will materially reduce their breach risk over time, but getting there is a multi year journey rather than a quarterly purchase. The prize is real. The path to get there is long.

Market maturity at a glance

TermFull nameMarket phaseBuyer reaction
BASBreach and Attack SimulationPost peak (2017 to 2022)Some value, but limited scope.
AEVAdversarial Exposure ValidationCurrent peak (2024 onwards)This actually proves what is exploitable.
CTEMContinuous Threat Exposure ManagementRamping (2022 onwards)Sounds like a programme we cannot afford yet.

The positioning that works

The smart play is not to pick one. It is to lead with AEV and deliver CTEM. Same product, three entry points depending on who is sitting across the table.

Security manager with budget this quarter: "We are an Adversarial Exposure Validation platform. We prove which of your vulnerabilities are actually exploitable, replacing manual pentests with continuous autonomous validation."

CISO planning three years out: "We are a Continuous Threat Exposure Management platform covering all five Gartner CTEM stages. Scoping, discovery, prioritisation, validation, and mobilisation, in one product."

Procurement and commercial: "We replace Tenable, Pentera, Picus, and XM Cyber with a single platform. One contract instead of four."

Five questions to ask any vendor in this space

If you are shortlisting tools, stop asking "AEV or CTEM". Ask these instead.

  1. Does your validation engine feed a continuous programme, or is it a point tool I will rip out in 18 months?
  2. Can I start with validation and grow into scoping, prioritisation, and mobilisation without a second procurement cycle?
  3. How do you handle the mobilisation stage? Do findings actually drive remediation, or produce more reports?
  4. What is the revert story? If you simulate an attack, can you guarantee a clean rollback on production systems?
  5. Does the same platform support red team style validation and blue team detection tuning?

Vendors that can answer all five are delivering CTEM. Vendors that can only answer the first two are selling an AEV point tool. Both are legitimate purchases. Just know which one you are making.

The bottom line

AEV sells better right now. CTEM is the bigger strategic play. You do not have to choose. The right platform is both, positioned for the buyer in front of you. At Forefront we lead with AEV because that is what buyers are searching for in 2026, and we deliver CTEM because that is what keeps them three years later.

AETOS Platform

AETOS is built AEV first and CTEM complete. Autonomous validation at the core, with scoping, discovery, prioritisation, and mobilisation wrapped around it. One platform, five stages, continuous proof.

Security Front Door

Find the right level of security for your business.

One monthly plan, one front door: penetration testing, Cyber Essentials, AI security, training and advice, from £1,500 a month. No hidden costs.

Forefront
UK Penetration Testing & Red Team Operations
Loading...