
Gartner coined both terms. They were never meant to compete. Here is what buyers are actually asking for, and how to position your exposure programme around it.
The short version. Gartner defines CTEM as a five stage programme. AEV is the technology category that sits inside it, powering the fourth stage: validation. They are not alternatives. One is the framework, the other is the engine that makes the framework real.
Walk into any security vendor briefing this quarter and you will hear one of two pitches. Half the vendors are positioning themselves as Adversarial Exposure Validation (AEV) platforms. The other half are pitching Continuous Threat Exposure Management (CTEM). Buyers are being asked to pick a side.
They should not. It is a category error, and Gartner, who coined both terms, has been fairly clear about why.
Gartner introduced CTEM in 2022 as a programmatic approach to managing exposure, published in the research note *Implement a Continuous Threat Exposure Management (CTEM) Program* and summarised publicly in their article How to Manage Cybersecurity Threats, Not Episodes. The premise is that point in time assessments cannot keep pace with how quickly environments change. CTEM is a loop, not a product. It has five stages:
Gartner added Adversarial Exposure Validation to its coverage later, positioning it as an emerging category in the 2024 Hype Cycle for Security Operations. In Gartner's framing, AEV is not a rival to CTEM. It is the technology that powers the validation stage inside it, providing continuous, evidence based proof of which exposures attackers could actually exploit.
Per Gartner's published guidance, organisations implementing a CTEM programme should evaluate AEV tooling specifically at the validation stage, rather than treating AEV as a standalone replacement for exposure management. Source: Gartner research on CTEM and Hype Cycle for Security Operations 2024. Full reports available to Gartner subscribers.
The takeaway is straightforward. AEV sits inside CTEM. One is the framework, the other is the engine that makes the framework real.
AEV proves which of your findings are actually exploitable. CTEM is the programme that turns those proofs into fixes.
If CTEM is the bigger idea, why has AEV become the hotter term? Three reasons, all about the buying cycle.
CTEM, by contrast, is harder to sell in a single meeting. It is a programme, not a product. It needs buy in across Security, IT, and the executive team. You cannot demo a methodology. Gartner's position is that mature CTEM adopters will materially reduce their breach risk over time, but getting there is a multi year journey rather than a quarterly purchase. The prize is real. The path to get there is long.
| Term | Full name | Market phase | Buyer reaction |
|---|---|---|---|
| BAS | Breach and Attack Simulation | Post peak (2017 to 2022) | Some value, but limited scope. |
| AEV | Adversarial Exposure Validation | Current peak (2024 onwards) | This actually proves what is exploitable. |
| CTEM | Continuous Threat Exposure Management | Ramping (2022 onwards) | Sounds like a programme we cannot afford yet. |
The smart play is not to pick one. It is to lead with AEV and deliver CTEM. Same product, three entry points depending on who is sitting across the table.
Security manager with budget this quarter: "We are an Adversarial Exposure Validation platform. We prove which of your vulnerabilities are actually exploitable, replacing manual pentests with continuous autonomous validation."
CISO planning three years out: "We are a Continuous Threat Exposure Management platform covering all five Gartner CTEM stages. Scoping, discovery, prioritisation, validation, and mobilisation, in one product."
Procurement and commercial: "We replace Tenable, Pentera, Picus, and XM Cyber with a single platform. One contract instead of four."
If you are shortlisting tools, stop asking "AEV or CTEM". Ask these instead.
Vendors that can answer all five are delivering CTEM. Vendors that can only answer the first two are selling an AEV point tool. Both are legitimate purchases. Just know which one you are making.
AEV sells better right now. CTEM is the bigger strategic play. You do not have to choose. The right platform is both, positioned for the buyer in front of you. At Forefront we lead with AEV because that is what buyers are searching for in 2026, and we deliver CTEM because that is what keeps them three years later.
AETOS is built AEV first and CTEM complete. Autonomous validation at the core, with scoping, discovery, prioritisation, and mobilisation wrapped around it. One platform, five stages, continuous proof.
One monthly plan, one front door: penetration testing, Cyber Essentials, AI security, training and advice, from £1,500 a month. No hidden costs.