Exposure Management, Vulnerability Management and CTEM
In 2025–26 Gartner published its first-ever Exposure Assessment Platform (EAP) Magic Quadrant, naming Qualys, Rapid7 and Tenable as Leaders — formally retiring "vulnerability management" as a standalone label and folding it into the broader frame of Continuous Threat Exposure Management (CTEM). The reframe changes the question the buyer is asking. The earlier question was "give me the list of 200,000 vulnerabilities on my network" (a scanner's output). The current question is "of everything an attacker could reach, what is actually exploitable, what would it let them touch that matters, and has it been proven?" That shift — from enumerating weaknesses to prioritizing and validating exposure — is pulling three formerly separate businesses (vulnerability scanning, external attack-surface management, and breach-and-attack simulation) into one platform contest.
What exposure management covers
Exposure management is the discipline of continuously discovering everything an organization exposes to attackers — unpatched software, misconfigurations, internet-facing assets, identities, cloud resources — and prioritizing remediation by real exploitability and business impact rather than raw severity counts. Gartner's CTEM framework wraps this into a five-stage program (scoping → discovery → prioritization → validation → mobilization), and its widely-cited prediction is that organizations that prioritize security investments through a CTEM program will be roughly 3x less likely to suffer a breach. The domain divides into three converging lineages, plus a unifying platform layer:
- Vulnerability management (VM) — the foundation. Periodic and continuous scanning of hosts, apps, and cloud for known vulnerabilities (CVEs) and misconfigurations, scored and ticketed for patching. The decades-old core. Tenable (Nessus heritage), Qualys, Rapid7 (InsightVM). The install base everything else is being built on top of.
- Attack Surface Management (ASM) — the outside-in view. Continuously discovering an organization's internet-facing footprint — unknown domains, exposed services, shadow IT, leaked credentials, exposed cloud buckets — the assets the defender forgot they had. Censys, runZero (asset discovery, internal + external), watchTowr, CyCognito, Microsoft (RiskIQ), Palo Alto (Cortex Xpanse).
- Validation / Breach-and-Attack Simulation (BAS) & pen-test automation — the proof layer. Safely demonstrating whether an exposure is actually exploitable and what an attacker could reach — turning a theoretical CVE into a proven (or disproven) attack path. Pentera, Cymulate, SafeBreach, XM Cyber (attack-path modeling, Schwarz Group-owned), Horizon3.ai. This is the "validation" stage that distinguishes CTEM from old VM.
- The unifying exposure platform & asset intelligence layer. The aggregation play: ingest VM + ASM + cloud (CNAPP) + identity signal, build a single graph of exposures and attack paths, and prioritize. Tenable One, Rapid7 Exposure Command, Qualys Enterprise TruRisk, plus asset-intelligence backbones (Axonius, runZero) and the CNAPP vendors (Wiz, Orca) pulling cloud exposure into their own platforms.
What ties it together: the buyer is not purchasing a scanner but a defensible answer to "are we exposed, to what, and what should be fixed first" — a question that has become substantially harder as attack surfaces expanded across cloud, SaaS, identity, OT, and AI. The value is in the prioritization and proof, not the enumeration; the enumeration is increasingly a commodity.
How each type of vendor operates
| Vendor | Owner | Lineage | Differentiation / economics |
|---|---|---|---|
| Tenable | Public (TENB) | VM → exposure platform | EAP Leader; Tenable One the most mature unified exposure platform; Nessus brand ubiquity; built/bought into cloud (Ermetic), OT, identity exposure; the scaled pure-play bellwether |
| Qualys | Public (QLYS) | VM → exposure platform | EAP Leader; Enterprise TruRisk platform; cloud-agent architecture, high margins, strong FCF; Tenable's most direct like-for-like rival; disciplined, profitable incumbent |
| Rapid7 | Public (RPD) | VM → exposure + SecOps | EAP Leader; Exposure Command (InsightVM + cloud + AppSec + threat intel); also an MDR/SecOps player — credible but less mature unified exposure platform; perennial take-out candidate. New CEO Wael Mohamed (Jun 1 2026) opened with a small July restructuring (~21 roles, under 1% of staff), then a 2026 Restructuring Plan approved by the board on Aug 7, 2026 cutting approximately 12% of the workforce — a materially larger reset, detailed in the section below |
| Wiz / Orca | Google/Alphabet (Wiz, ~$32B) / VC | CNAPP → cloud exposure | Agentless cloud exposure & attack-path graphing; re-defined exposure in the cloud and now pull cloud-exposure value away from the on-prem VM vendors — the platform threat from the cloud side |
| Pentera | Private (VC; ~$1B+) | Validation / autonomous pen-test | Automated security validation — safely exploits to prove real risk; the "validation" stage leader; re-rated VM by proving which vulns actually matter |
| Cymulate / SafeBreach | Private (VC) | BAS / validation | Breach-and-attack simulation against the kill chain; continuous control validation; the proof layer that turns CTEM from theory into evidence |
| XM Cyber | Schwarz Group | Attack-path / exposure graph | Attack-path modeling across hybrid estates; acquired by Schwarz (Germany) in 2021 — strategic-owner validation of attack-path as a category; in July 2026 CrowdStrike agreed to acquire the company's intellectual property (45+ patents, source code), with XM Cyber continuing as a standalone business under license |
| runZero | Private (HD Moore) | Asset discovery / ASM | Unauthenticated active discovery (internal + external) — finds the assets scanners miss; the asset-truth layer; recently folded into Accenture's xOT via the Dragos deal |
| Censys / watchTowr / CyCognito | Private (VC) | External ASM | Internet-scale attack-surface intelligence; CyCognito's external risk graph; watchTowr's adversarial/continuous external testing — outside-in specialists |
| Axonius | Private (VC; ~$2.6B) | Asset / exposure intelligence | Cyber-asset attack-surface management (CAASM) — aggregates every asset source into one inventory; the connective tissue beneath exposure programs |
| Microsoft / Palo Alto (Cortex Xpanse) / CrowdStrike | platforms | ASM + exposure modules | Platforms folding ASM/exposure into the suite (Defender EASM, Cortex Xpanse, Falcon Exposure Management) — the bundle threat from above |
The vendor groups differ along consistent lines. The VM incumbents compete on install base and are moving to become exposure platforms. Tenable, Qualys, and Rapid7 own the scanning relationships, the asset data, and the compliance hooks; their strategic project is to move from "scanner" to "unified exposure platform" (Tenable One, Enterprise TruRisk, Exposure Command) before the cloud platforms and the validation specialists fragment the value. The cloud-native vendors (Wiz, Orca) redefined exposure where modern assets reside — in the cloud — and pull the fastest-growing slice of exposure value into CNAPP, which is why the on-prem VM vendors had to buy or build cloud (Tenable–Ermetic). The validation/BAS players (Pentera, Cymulate, XM Cyber) compete on proof — they answer "is this actually exploitable," the most valuable upgrade to prior VM, and they re-rated the category by making prioritization defensible rather than based on raw CVSS scores. The ASM and asset-intelligence specialists (Censys, runZero, Axonius) compete on discovery — organizations cannot manage what they cannot see, and attack surfaces now extend beyond what any agent-based scanner covers. The structural question for the domain: does the unified exposure platform consolidate all of this (one vendor owns VM + ASM + validation + cloud exposure, and the standalone tools are absorbed), or does the platform value migrate to the CNAPP/SecOps suites (Microsoft, Palo Alto, CrowdStrike, Google/Wiz) that already own the cloud and the SOC, leaving the pure-play VM vendors as commoditized data sources feeding another vendor's graph?
Where the value pool is migrating
Signature deals & events
- Gartner's first EAP Magic Quadrant — Qualys, Rapid7, Tenable as Leaders (2025–26) — the formal establishment of "exposure management" over "vulnerability management," validating the platform thesis and setting the competitive frame for vendors in the domain. See Regulation on how compliance mandates keep VM demand structural.
- Google/Alphabet → Wiz (~$32B, announced Mar 2025, completed Mar 11 2026) — the largest cybersecurity deal ever pulls the cloud-exposure leader into Google Cloud, signaling that cloud exposure is a platform prize and intensifying the squeeze on on-prem VM vendors. See Deals & Comps.
- Tenable → Ermetic (~$265M, 2023) and continued cloud/identity/OT build-out — the on-prem VM leader buying its way into cloud and identity exposure to defend the "unified platform" position against the CNAPP vendors.
- XM Cyber → Schwarz Group; runZero → folded into Accenture's xOT (via Dragos, 2026) — strategic owners absorbing attack-path and asset-discovery specialists; consolidation of the validation and discovery layers into larger platforms.
- CrowdStrike → XM Cyber intellectual property (announced Jul 16 2026; close expected Aug 2026–Jan 2027) — an unusual IP-only transaction: CrowdStrike acquires more than 45 patents and the proprietary source code behind XM Cyber's attack-path visualization and offensive-simulation technology, but no revenue or customers; XM Cyber continues operating standalone under an IP license back, and its customers are offered a migration path to Falcon via Falcon Flex. The deal folds the category's leading attack-path graph into Falcon Exposure Management and came packaged with a broader CrowdStrike–Schwarz Digits agreement to deliver Falcon on STACKIT, Schwarz Digits' EU sovereign cloud — validation-layer consolidation and European sovereign distribution in a single print. See Deals & Comps.
- Empirical Security $25M Series A (announced Jul 20 2026) — the founders of Kenna Security (the original risk-based vulnerability-prioritization company, acquired by Cisco in 2021), CEO Ed Bellis and CTO Michael Roytman, returned to the prioritization layer with an AI-native entrant building predictive models for exposure management: Foundation, a global model tracking more than 18,000 exploited CVEs to forecast exploitation, and Radiant, a per-organization predictive engine fine-tuned to each customer's environment. The round was led by Brightmind Partners, with Costanoa Ventures, HPA and others participating, bringing total funding to $37M (Axios, Jul 20 2026 · FinSMEs). A repeat-founder bet that the prioritization stage — not enumeration — is where model-driven differentiation accrues.
- Zafran Security — strategic investment from Cisco Investments (announced Jul 22 2026) — Zafran, an AI-native end-to-end threat-exposure-management platform, received an undisclosed strategic investment from Cisco Investments, extending its total funding past $140M (from a previously reported ~$130M) and adding Cisco Investments to a backer list that includes Sequoia Capital, Cyberstarts, Menlo Ventures, PSP Growth, Vintage Investment Partners, and Amex Ventures. The investment followed the departure of co-founder and CPO Snir Havdala. Calcalist reported that Cisco was in advanced talks to acquire the company for roughly $150–200M — below the above-$200M valuation reported in Zafran's December 2025 round — though Zafran denied it was negotiating a sale, characterized the transaction as a strategic investment, and said it planned to raise a further round. The event illustrates the corporate-venture-arm-as-acquisition-funnel pattern in exposure management, and a repricing dynamic in which strategic-investor entry can precede a discounted take-out of a venture-funded specialist whose growth has decelerated. Sources: Newswire, Jul 22 2026 · Calcalist / CTech, Jul 2026. See Corporate Venture Capital and In-Q-Tel.
- Unit 42 Frontier AI Exposure Analysis (announced Aug 12 2026) — Palo Alto Networks' consulting arm began running OpenAI frontier cyber models inside customer environments to find vulnerabilities, misconfigurations, leaked credentials and unmanaged attack surface, then testing each finding through adversary simulation to establish exploitability and lateral reach. The disclosed operating statistic bears directly on this domain's thesis: 36% of the exposures Unit 42 has identified map to no known CVE, and many of the rest matter only as chains of individually minor gaps. Enumeration against a CVE list — the commoditizing left-hand side of the migration above — therefore misses roughly a third of what an attacker can use, which is an argument for the discovery, validation and attack-path stages rather than the scanning stage. It is also a competitive datum: the capability arrives as a platform vendor's consulting service rather than as a product licence. See Offensive Security, The AI Labs in Cyber. (SiliconANGLE, Aug 12 2026 · Unit 42 blog)
- The CTEM reframe as a demand engine — Gartner's "3x less likely to be breached" prediction turned CTEM into a board-level program, pulling budget from one-off scanning into continuous, validated exposure programs and creating a structural tailwind for whoever owns the platform.
- The 2025 incumbent roll-up of the exposure fragments — Check Point → Veriti (multi-vendor preemptive-exposure-management; announced May 27 2025; ~$100M+ per Calcalist estimate) and, two days later, Tenable → Apex Security (extending exposure management across the AI attack surface; announced May 29 2025; terms undisclosed). The early-fragmentation stage resolving in real time: scaled players rolling up point tools before the category hardens. See Deals & Comps.
- AWS Continuum — a hyperscaler enters the market (Summit New York, Jun 17 2026) — an AI-native service that autonomously discovers → validates → remediates vulnerabilities (ingests the existing backlog, builds sandboxed exploits to remove false positives, moves from "learn mode" to automated "enforce mode"); launched in gated preview. It illustrates the aggregation risk for the domain: the cloud a customer already pays for absorbing the exposure/AppSec function as a bundled capability — the kind of adequate substitute that can compress a standalone vendor's economics. See AI Security.
Rapid7's 2026 restructuring
Of the three public pure-plays, Rapid7 is the one whose numbers now show the domain's compression directly, and its 2026 results give the segment a dated, primary-source data point on what happens when a VM incumbent's platform transition does not outrun the commoditization of the scanning layer.
Rapid7 reported second-quarter 2026 results (quarter ended Jun 30, 2026) alongside a board-approved 2026 Restructuring Plan. Revenue was $210.9M, down 1.5% year over year, of which product subscriptions were $205.1M. Annualized recurring revenue was $824.0M, down 2.0% year over year — the ARR line is contracting, not merely decelerating. GAAP income from operations was $3.0M and GAAP net income $6.1M (against $8.3M in the prior-year quarter); non-GAAP income from operations was $28.9M and non-GAAP net income $33.0M, or $0.44 per diluted share (against $0.58). Operating cash flow was $37.0M and free cash flow $31.9M, with cash, cash equivalents and government securities of $702.6M at quarter end (Rapid7 8-K, Aug 2026).
The restructuring plan, approved by the board on Aug 7, 2026, reduces the workforce by approximately 12% — press accounts put the figure near 310 roles against a global headcount of roughly 2,600 — and is stated as simplifying operations and concentrating investment on the core platform and AI capabilities. Rapid7 expects $10–11M of charges, primarily severance, substantially all incurred and paid in the third and fourth quarters of 2026 (SecurityWeek, Aug 14 2026 · BankInfoSecurity).
The guidance makes the trade explicit. Full-year 2026 revenue is guided to $837–841M (down 2–3%) with ARR of approximately $812M at (3)% growth, against non-GAAP income from operations of $129–133M and free cash flow of about $130M. Taken with the first three quarters — Q1 revenue $210.0M on ARR of $832M with non-GAAP operating income of $24.4M, Q2 as above, and Q3 guided to $208–210M and $34–36M — the midpoints imply a fourth quarter of roughly $209M revenue and $43M non-GAAP operating income, a non-GAAP operating margin near 20%, consistent with the company's stated 20% Q4 target and roughly five points above the full-year figure of about 15.6%. The sequence, in short, is a shrinking top line converted into an expanding margin over four quarters.
One balance-sheet item conditions how much room that leaves. At Jun 30, 2026, convertible senior notes of $598.2M sat in current liabilities with a further $296.0M non-current, against $892.3M entirely non-current at Dec 31, 2025 — the near-term tranche now equals about 85% of the $702.6M cash and securities balance. Cash covers it, but with little left over, which narrows the practical range of options a shrinking-ARR business has for financing a turnaround, an acquisition, or a change of control.
This is the bear case test running in public. Rapid7 was the pure-play most often named as a take-private candidate before the reset; the reset now supplies a leveraged buyer with the two things it needs — a demonstrated cost base and a strong free-cash-flow line — while removing the growth story that would justify a premium. Whether the exposure platform re-rates or the segment's standalone economics are conceded to the cloud and SecOps suites should be legible in Rapid7's ARR line over the next several quarters rather than in the margin line.
The bear case
The exposure-management bull case is strong: attack surfaces are expanding across cloud, SaaS, identity, OT, and AI; CVE volume is unmanageable without prioritization; regulation mandates vulnerability management; and Gartner's CTEM framing gives CISOs a board-ready program that pulls budget toward continuous, validated exposure platforms — a structural tailwind for the unified-platform leaders (Tenable, Qualys, Rapid7) and the validation specialists (Pentera, Cymulate). The bear case has three prongs. First, "exposure management" may be vulnerability management with better marketing — the core scanning function is decades old and commoditizing, open-source and cloud-native tooling is encroaching, and if the "platform" layer is mostly a dashboard over the same scan data, pricing power erodes even as the category gets a new name. Second, the value may migrate to the platforms that own the cloud and the SOC. Microsoft (Defender EASM), Google/Wiz, Palo Alto (Cortex Xpanse), CrowdStrike (Falcon Exposure Management), and the CNAPP vendors already sit closer to where modern assets live and where remediation happens; if exposure becomes a module of the cloud/SecOps suite, the standalone VM vendors risk becoming commoditized data sources feeding another vendor's graph — which is why all three trade at modest multiples versus the higher-growth cloud-security names. Third, fragmentation cuts both ways — the VM incumbents must integrate ASM + validation + cloud + identity to deliver the "single exposure view," but each of those is a fast-moving specialist market, and buying enough of them to be credible is expensive and integration-heavy while the cloud platforms build it natively. Falsifiable test: whether Tenable/Qualys/Rapid7 re-rate toward cloud-security-like multiples as their unified exposure platforms (Tenable One, TruRisk, Exposure Command) capture validated-exposure budget, or whether their growth stays in the low-to-mid teens, one of them is taken private or acquired (Rapid7 the perennial candidate), and the cloud platforms take the exposure layer. If the pure-plays re-rate and validation becomes a required line item, the platform thesis holds; if growth stalls and the suites absorb exposure, "exposure management is a durable standalone platform" weakens to "exposure data is a feature of the cloud and SecOps platforms."
→ Cross-references: Vendors, Cloud Security, SecOps & SIEM, OT/ICS Security, Service Providers, Deals & Comps, Valuation, Commercial Due Diligence.
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.