SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsKey findings:
The paper's central argument is that CTEM succeeds only when treated as an ongoing organizational discipline rather than a one-time deployment or a product purchase. Organizations that pair phased, scoped rollouts with strong governance and integrated tooling are best positioned to close the gap between identifying exposures and actually remediating them. Resource constraints and tool sprawl remain the most persistent obstacles, which is why the paper frames automation and orchestration platforms as central to CTEM's long-term viability rather than optional add-ons. This paper is a conceptual and strategic analysis rather than a survey-based research report, so no respondent methodology applies; its recommendations draw on the Gartner CTEM framework and industry data such as Microsoft's tool-sprawl figures.
CTEM is a cybersecurity framework developed by Gartner built on five stages: scoping, discovery, prioritization, validation, and mobilization. It shifts organizations from reactive vulnerability management to continuous, proactive threat identification and mitigation.
CTEM doesn't replace ASM, it builds on it. ASM focuses on continuously mapping and reducing exploitable attack surface, while CTEM adds prioritization, validation, and mobilization on top of that visibility.
Tool sprawl is a major factor: organizations use an average of 80 distinct security tools, and the lack of integration between them creates data silos and limits the automated workflows CTEM depends on.
No. While automation and predictive analytics can streamline much of the CTEM process, mobilization tasks like patching, stakeholder coordination, and risk-acceptance decisions still require human judgment.


Jonathan Risto is a Principal Instructor at the SANS Institute and Technical Director for the Canadian Cyber Posture Program. Co-author of LDR516: Strategic Vulnerability and Threat Management, he helps leaders turn exposure data into actionable risk programs through frameworks like VMMM and CTEMMM.
Read more about Jonathan Risto


















