← All insights
Strategy

EAP, AEV, CTEM: what the acronyms mean and where Incenter fits

Security buyers currently face three overlapping acronyms for what sounds like one thing: CTEM, EAP, AEV. Vendors wave all three. Analysts define them differently. And somewhere under the terminology is a practical question you still have to answer: what should we actually buy, and what should it do?

Here is the short version. CTEM is a program you run. EAP and AEV are product categories that support it. Incenter sits across both categories and powers the program. The rest of this post unpacks what each term means, why the market moved from one label to the next, and how to use the distinctions when you’re evaluating tools.

CTEM: the program, not the product

Gartner coined Continuous Threat Exposure Management in 2022 to describe a way of running exposure work, not a class of software. The model is a repeating loop with five stages:

  1. Scoping. Decide what part of the business matters most: the systems that would genuinely hurt if breached, and the paths to them.
  2. Discovery. Find the assets and exposures inside that scope, including the ones nobody documented.
  3. Prioritization. Rank what you found by reachability and business impact, not by a raw severity score.
  4. Validation. Prove the exposure is actually exploitable, and establish how far it goes.
  5. Mobilization. Route the fix to its owner, track it, and confirm it held.

The value is in finishing the loop, continuously. A scanner that runs discovery on a schedule and hands you a CVE list has done one stage out of five and left the rest to your team.

Because CTEM described a program, it never quite worked as a product label. Vendors used it as one anyway, which is how “CTEM” ended up stamped on vulnerability scanners and consultancies alike. Gartner predicted that organizations that prioritize security investments through a continuous exposure management program would be three times less likely to suffer a breach; that prediction was about running the loop, not about buying anything with the acronym on it.

EAP and AEV: the categories that replaced the badge

As the terminology settled, the market description moved to “exposure management” as the umbrella, with two product categories underneath it.

Exposure Assessment Platforms (EAP) cover the assessment side of the loop: continuously discovering assets and exposures across your environment, consolidating them, and prioritizing them with context. If a tool’s job is to tell you what you have, what’s exposed, and what to look at first, it’s playing in EAP territory.

Adversarial Exposure Validation (AEV) covers the proving side: demonstrating, with real attack technique, which exposures an adversary could actually use. This is the category that absorbed breach and attack simulation and automated penetration testing. If a tool’s job is to answer “could an attacker really do this, here, today?”, that’s AEV.

The split is useful because it names the gap most stacks have. Plenty of organizations own assessment tooling and drown in its output. Far fewer have validation, because validation requires offensive capability, and offensive capability is hard to automate honestly. The result is the familiar failure mode: a prioritized list of thousands of theoretical findings, none of them proven, all of them arguable.

Where Incenter fits

Incenter is an exposure management platform, and it deliberately runs both sides of the category split in a single loop.

The assessment half maps to EAP: continuous discovery across your external surface, asset inventory including the things that were never in your CMDB, and prioritization scored against your business context rather than a generic severity number.

The validation half maps to AEV: every finding is exploited to prove it’s real before it reaches you. That’s the step most tools skip, and it changes the character of everything downstream. Prioritization stops being an argument about theoretical risk, because ranking starts from proven exploitability. Mobilization stops generating pushback, because the ticket arrives with the evidence attached. The details of how the loop runs, stage by stage, are on the methodology page.

Against the CTEM model itself: Incenter runs the operational core of the cycle, discovery through mobilization, continuously. Scoping happens with you at onboarding, where coverage gets aligned to what the business actually needs protected. Humans stay in the loop for the work that takes a human: the chained logic flaw, the ambiguous high-impact case, the last ten yards automation can’t cross.

One thing we won’t claim: analyst category inclusion we don’t have. EAP and AEV are the right map for understanding what Incenter does; where analyst firms list specific vendors in specific documents is a separate question, and you should check the current editions yourself.

How to use the acronyms when buying

The terminology earns its keep in one place: vendor evaluation. Three questions do most of the work.

Which stages of the loop do you actually run? A vendor should be able to say, stage by stage, what happens inside their product and what’s left to you. “We do discovery and prioritization, validation is your team’s job” is a legitimate answer. It’s also an EAP answer, and you should price the missing validation work accordingly.

Is validation real exploitation or inferred severity? The word “validation” gets stretched. Confirming a version number matches a CVE is not validation. Reaching the asset and demonstrating impact is. Ask to see the evidence trail for a real finding.

Does the loop close? Fixes re-tested, drift caught between assessments, findings routed into the tools your engineers already work in. A point-in-time report with a quarterly cadence is a penetration test on a calendar, whatever category name is on the invoice.

There’s a fuller version of this checklist, with the answers that should reassure you and the ones that should end the meeting, in our guide to the real questions to ask an exposure management vendor.

The acronyms will keep churning; the job doesn’t change. See what’s exposed as it changes, prove what an attacker can reach, fix what’s proven, and check the fix held. Buy whatever does that end to end.

More in Strategy
Nobody Gives a S##t About Cybersecurity: A Postcard from the Edge of the IndustryMar 23, 2026 · 11 minThe Day Zero Trust DiedMar 9, 2026 · 8 minThe $10M Distraction: Why 50,000 CVEs Don't Matter (But 3 Attack Paths Do)Feb 16, 2026 · 3 min