Dataminr BLOG

Why PTEM Is Different: Threat-First, All the Way to a Decision

Predictive Threat Exposure Management (PTEM) differs from standard CTEM and risk tools by being "threat-first." While others prioritize lists, PTEM integrates real-time threat intelligence, controls, and business impact to enable actionable, pre-defined business decisions, moving organizations beyond simple exposure management.

Why PTEM Is Different: Threat-First, All the Way to a Decision
DATE August 19, 2026
AUTHOR Jerry Caponera, SVP, Risk and Threat Exposure Management, Dataminr
SHARE
CYBER DEFENSE

Two kinds of tools sit next to Predictive Threat Exposure Management (PTEM) in most security stacks: Continuous Threat Exposure Management and Risk Quantification. Here I’ll discuss what each of them does well, because the argument for PTEM isn’t that these tools are bad; it’s that both stop short in a specific, nameable place, and PTEM is built to not stop there.

What Continuous Exposure Management Gets Right, And Where it Stops

Continuous Threat Exposure Management, the category Gartner defined, gave security teams something they didn’t have before: an ongoing, scaled view of what’s exposed across a constantly changing environment, instead of a point-in-time scan. This is real progress, and any organization running a mature CTEM program is better off for it.

But the analyst community has started naming the structural limit here plainly. Exposure-led prioritization doesn’t tell you whether the attack paths that actually create business impact have been broken, and an organization can close a large number of exposures, watch every metric improve, and still leave the one path a real threat actor is actively using untouched. This is because closing exposures and breaking attack paths aren’t the same activity, even though it’s easy to assume they are. 

Attackers don’t work through a vulnerability queue in severity order. They find whatever path works and use it, the way an attacker might ignore your highest-scored CVE entirely and instead chain three low-severity ones together on a system nobody was watching. A program organized around ranking your inventory of weaknesses is answering a different question than “would a real attacker get through,” and the gap between those two questions is where a lot of security spend quietly goes to waste.

That’s a structural limitation rather than an execution problem. It’s baked into starting from assets and working outward, and no amount of process discipline turns an asset-first program into a threat-first one after the fact.

What Risk Quantification Gets Right, And Where it Stops

A second category, risk scoring and quantification platforms, solves a different half of the problem. They give you a defensible dollar figure for your security posture, which matters when you’re talking to a board or a cyber insurer, but most of them score from the outside in rather than fusing live threat-actor activity and your actual, current compensating-control state into that number continuously. You get a number, just not one that’s telling you what’s happening to you today.

Where Predictive Threat Exposure Management Sits

PTEM resolves threat activity, compensating controls, and business impact altogether from the start, continuously, by running the same three analyses I walked through in my last post: what a threat actor is doing right now, sourced from Dataminr’s threat intelligence and matched against known actor profiles; whether your deployed controls already stop it; and what it would cost the business if they didn’t, calculated against more than 20 years of loss data rather than a generic severity label. 

It isn’t three separate tools bolted together, but one system where each input changes what the others mean. A threat that’s active but fully blocked by your controls isn’t the same exposure as one that’s active and open, and a material dollar figure that hasn’t been checked against live threat activity is a guess dressed up as precision. PTEM doesn’t let any of the three stand alone, which is how it caught a critical zero-day 38 days ahead of CISA’s KEV catalog in one recent case, well before a severity score alone would have flagged it as urgent.

That’s the first differentiator: threat-first from the beginning, not threat-aware after the fact.

The second is less obvious, and I’d argue more important. Even a tool that gets prioritization exactly right still hands you a list, a ranked, scored, dollar-denominated one, but a list all the same. And it doesn’t answer what you’re actually authorized to do about any item on it. Can a system remediate this on its own? Does it need a person? Is the cost of acting higher than the cost of the exposure itself, in which case the right call might be to accept it for now? That’s a threshold question, and it’s a business decision rather than a security score. 

PTEM’s continuously current cost-per-exposure figure is built specifically to feed that threshold, the input that’s been missing every time an organization has tried to write a risk appetite statement and ended up with something too vague to actually run a decision against.

That’s the gap neither CTEM platforms nor risk-quantification tools close on their own. While they get you to a better-informed list, PTEM gets you to a decision the business actually made in advance, one a system or a person can execute against with confidence.

Where This Is Headed

The analyst community’s own forward-looking view backs this up. Industry projections puts a majority of organizations with mature exposure management programs moving toward threat-informed, attack-path-based validation within the next few years, specifically to decide what gets fixed, funded, deferred, or accepted. That’s not a PTEM-specific claim so much as a direction the whole market is heading, independent of any one vendor, and it happens to be the same direction PTEM was built for from day one.

Traceability is what ties this together end to end: a specific dollar figure at the board level, connected to a specific exposure, a specific control gap, and a specific host, backed by a threshold, set by the business, that says what happens next. Not a maturity score nobody’s certain how to act on, and not an exposure count that improves quarter over quarter without anyone knowing if it’s the exposure that mattered, but a decision, made in advance, that holds up when someone asks how it was made.

Where This Series Leaves Off

PTEM is available today, inside Dataminr for Cyber Defense, for the CISOs and risk leaders who need a defensible answer to “are we protected against what matters?”, and increasingly for the SOC and vulnerability management teams who act on that answer every day. If you’ve been asking your exposure management program a question it was never built to answer, this is the model built to answer it instead: threat-first, business-linked, all the way to a decision.

Predictive & Risk Quantified Continuous Threat Exposure Management

Learn how to move beyond exposure guesswork—prove control gaps, quantify financial risk, and drive real, risk-prioritized remediation.

Get PTEM
Aug 19, 2026

SHARE
  • Cyber Defense
  • Cyber Risk
  • Blog