Validate what’s exploitable. Close on a clock.
Vulnerability lists are noise. CTEM is about what is reachable and exploitable against you right now — and proving it before you burn change-management capacity. Cyber Toolbox runs that loop with the clock visible.
Five stages. A register that orders itself by what’s exploitable.
P1
Scope
Scope an exposure in business terms — what matters, to whom, and why. The loop starts from impact, not from a raw scanner dump.
P2
Discover
Discover what is actually affected across your asset register — workstations, accounts, cloud tenants, OT — so you know the real blast radius.
P3
Validate
Validate whether it is genuinely exploitable before you spend remediation capacity. If validation shows it is already being exploited, it stops being an exposure and hands off to incident response.
P4
Prioritise
Assign a severity band (ES1–ES5) and an owner. The register orders itself by what is reachable and exploitable against you right now — not by a CVSS list.
P5
Mobilise
Drive reset / rotate / revoke / patch through to closure against an SLA clock. Every exposure lands in the register with its band and its deadline, visible.
Prove it’s exploitable before you spend a change window.
CTEM lifecycle on rails: scoping → discovery → validation → prioritisation → mobilisation.
Exploitability validation before you burn change-management capacity.
Exposure severity bands (ES1–ES5) with a named owner per exposure.
SLA clocks on every exposure — the deadline is visible, not a surprise.
Exposure register: owner, band and deadline in one view.
Hand-off to incident response the moment an exposure is found to be exploited.