Strobesstrobes
Platform
Solutions
Resources
Customers
Company
Pricing
Book a Demo
Strobesstrobes

Strobes connects every exposure signal to autonomous action, so security teams fix what matters, prove what works, and stop chasing noise.

Book a DemoTalk to an expert
ISO 27001SOC 2CREST
  • Platform
  • Platform Overview
  • Agentic Exposure Management
  • AI Agents
  • Integrations
  • API & Developers
  • Workflows & Automation
  • Analytics & Reporting
  • Solutions
  • Exposure Assessment (EAP)
  • Attack Surface Management
  • Application Security Posture
  • Risk-Based Vulnerability Management
  • Adversarial Exposure Validation (AEV)
  • AI Pentesting
  • Pentesting as a Service
  • CTEM Framework
  • By Industry
  • Financial Institutions
  • Technology
  • Retail
  • Healthcare
  • Manufacturing
  • By Roles
  • CISOs
  • Security Directors
  • Cloud Security Leaders
  • App Sec Leaders
  • Resources
  • Blog
  • Customer Stories
  • eBooks
  • Datasheets
  • Videos & Demos
  • Exposure Management Academy
  • CTEM Maturity Assessment
  • Pentest Health Check
  • Security Tool ROI Calculator
  • Company
  • About Strobes
  • Meet the Team
  • Trust & Security
  • Contact Us
  • Careers
  • Become a Partner
  • Technology Partner
  • Partner Deal Registration
  • Press Release

Weekly insight for security leaders

CTEM research, agentic AI trends, and what's actually moving the needle.

© 2026 Strobes Security Inc. All rights reserved.

Privacy PolicyTerms of ServiceCookie PolicyAccessibilitySitemap
Back to Blog
Inside the CTEM Boom: Pioneers, Followers, and What Black Hat 2025 Made Clear
CTEM

Inside the CTEM Boom: Pioneers, Followers, and What Black Hat 2025 Made Clear

Venu RaoAugust 20, 20255 min read

Table of Contents

  • When CTEM Became the New Gold Rush
  • The First Fully Branded CTEM Launches
  • The Pioneers Before the Name Existed
  • Our Place in This Story
  • Built Into Our DNA, Not Just Marketing

Authors

V
Venu Rao

Share

Table of Contents

  • When CTEM Became the New Gold Rush
  • The First Fully Branded CTEM Launches
  • The Pioneers Before the Name Existed
  • Our Place in This Story
  • Built Into Our DNA, Not Just Marketing

Authors

V
Venu Rao

Share

Black Hat 2025 had it all. Vegas heat outside, but inside the halls were packed with energy - nonstop conversations, bold ideas, and the kind of buzz you can’t fake. But one thing rose above everything else. I saw it on banners, heard it in pitches, and caught it in the hallway chatter. And honestly, seeing it take center stage felt exciting, because while many were just starting that story, we had already been living it for years. That story is Continuous Threat Exposure Management (CTEM). Gartner named it in 2022, defining it as a cycle of Scoping, Discovery, Prioritization, Validation, and Mobilization, a practical way to continuously measure and reduce risk. By their prediction, organizations running a CTEM program would be three times less likely to suffer a breach by 2026. Suddenly, everyone wanted to be “doing CTEM.” And this year at Black Hat, I saw it play out in real time. It made me proud, because while the crowd was just joining the race, we had already been running it for years.

When CTEM Became the New Gold Rush

Before Gartner’s announcement, there were already companies mapping closely to the five phases - they just didn’t have the CTEM label yet. By mid-2023, the floodgates opened. Vendors raced to put “CTEM” on their slides. Some built it from the ground up. Many more simply rebranded existing products. If you looked closely, you could divide the market into two camps:
  1. Purpose-built CTEM platforms – integrating multiple exposure management capabilities in one place.
  2. Rebranded/adapted offerings – existing tools repositioned under the CTEM banner.

The First Fully Branded CTEM Launches

The first public launches that carried “CTEM” in the product name from day one looked like this:
  1. Cymulate – Exposure Analytics – June 20, 2023
  2. Outpost24 – Outpost24 CORE – July 21, 2023
  3. Strobes Security – Strobes CTEM Platform – October 12, 2023
  4. NSFOCUS – CTEM Offerings – October 17, 2023
  5. Integrity360 + XM Cyber – CTEM-as-a-Service – September 23–24, 2024
We were one of the first three companies in the world to launch a fully branded CTEM platform. That’s not marketing spin, that’s the timeline.

The Pioneers Before the Name Existed

Long before CTEM had a catchy acronym, a few companies were already living its philosophy:
  • XM Cyber – Since 2018, mapping hybrid attack paths and managing exposures continuously.
  • Strobes Security – In 2021, we unified Attack Surface Management, Risk-Based Vulnerability Management, and Penetration Testing-as-a-Service into one platform — years before “CTEM” became the industry’s keyword.
  • Tenable, Rapid7, and Qualys – All had overlapping capabilities pre-2022 but leaned into CTEM branding later.
This is why we can confidently say: we didn’t rebrand into CTEM - we were already doing it. CTEM Vendor Marketplace

How the Vendor Space Grew

In 2023, CTEM was still a whisper. Only a handful of companies had the nerve to launch under its name: Cymulate, Outpost24, Strobes Security, and NSFOCUS. By 2024–2025, CTEM had become a competitive battleground. The ecosystem included more than 20 cybersecurity companies marketing CTEM-centric solutions. Roughly half a dozen to a dozen were purpose-built platforms aligned to Gartner’s five stages, while at least another dozen were simply repackaging existing tools like asset management, scanning, or pentesting under the CTEM banner. That’s where the split became clear:
  • Purpose-built platforms like Strobes, Cymulate, Outpost24, XMCyber, and NSFOCUS started covering the entire lifecycle in one place.
  • Rebranded offerings from Pentera, Tenable, Rapid7, Qualys, Check Point, Trend Micro, and Zscaler reshaped older products to fit the CTEM narrative.
And Gartner has been clear on this. You can’t run CTEM on a single old-school tool, and while companies used to stitch products together, the real shift now is toward unified suites, something Gartner itself called out in its 2024 Hype Cycle. According to a Growth Market Reports forecast, the momentum isn’t slowing. The CTEM market is expected to grow at a 14.7% CAGR through 2033, rising from $1.98B in 2024 to $6.08B by 2033. From a handful of launches in 2023 to a projected multi-billion-dollar market by 2033, CTEM hasn’t just grown - it has exploded into one of the fastest-scaling movements in cybersecurity.

Our Place in This Story

Here’s what that journey looks like: And this isn’t just something we say — our history proves it. From starting as an application security company in 2016 to launching one of the first CTEM platforms in 2023, every milestone has moved us closer to making continuous threat exposure management a reality for our clients. Here’s what sets us apart:
  • Built, not bolted-on – From the start, our platform was designed to integrate ASM, PTaaS, and RBVM seamlessly.
  • Pioneer status – Among the first three global CTEM-branded launches.
  • Pre-CTEM alignment – Our architecture already matched Gartner’s model before they named it.
  • Proven track record – Multiple industries, global enterprises, and measurable outcomes.
We didn’t pivot to ride a trend. We were already running the race while the starting gun was still being loaded.

Built Into Our DNA, Not Just Marketing

Breaches today are costly and constant. That’s why a CTEM program that truly works, not just one that looks good on a slide, is the difference between thinking you’re secure and knowing you are. The market will keep filling with CTEM-branded tools. But only a handful can say they were there when the blueprint was still being drawn. We can. And we’ve been refining it ever since. For us, CTEM isn’t a label to slap on a product. It’s a discipline we’ve built into our DNA - tested in real-world environments, shaped by client challenges, and proven in measurable results. While others are still learning the playbook, we helped write it. And we’re already running it at scale. So when I walked the halls of Black Hat and saw CTEM everywhere, it didn’t feel like hype. It felt like validation. That’s the difference between a platform that talks CTEM and a partner who lives it. Ready to experience the difference? Book a free demo with Strobes today.
Tags
CTEMCTEM Boom

Stop chasing vulnerabilities Start reducing exposure

See how Strobes AI agents validate and fix your most critical exposures automatically.

Book a Demo
Continue Reading

Related Posts

Top 10 Data Breaches of April 2026 - Monthly Security Briefing
Data BreachesCybersecurity

Top 10 Data Breaches of April 2026

The biggest data breaches of April 2026 ranked and analyzed, from Checkmarx supply chain poisoning to Salesforce misconfigurations and ransomware hitting two major US banks.

May 1, 202615 min
Best AI Pentesting Tools in 2026 - Ranked Priced and Compared
Penetration TestingCTEM

Best AI Pentesting Tools in 2026: Ranked, Priced & Compared (12 Tools)

Which AI pentesting tool actually reduces risk in 2026? We reviewed 12 platforms on autonomy, proof quality, pricing, and what happens after a vulnerability is found.

Apr 9, 202627 min
Is Claude Mythos the End of Pentesting - Featured Image
CTEMPenetration Testing

Is Claude Mythos the End of Pentesting?

Claude Mythos found thousands of zero-days in Linux, browsers, and Apache. Does that make pentesting platforms obsolete? Understanding why models, harnesses, and platforms are three different things -- and why smarter AI makes Strobes more valuable, not less.

Apr 8, 202612 min