The Business of Cyber Security

Exposure Management, Vulnerability Management and CTEM

In 2025–26 Gartner published its first-ever Exposure Assessment Platform (EAP) Magic Quadrant, naming Qualys, Rapid7 and Tenable as Leaders — formally retiring "vulnerability management" as a standalone label and folding it into the broader frame of Continuous Threat Exposure Management (CTEM). The reframe changes the question the buyer is asking. The earlier question was "give me the list of 200,000 vulnerabilities on my network" (a scanner's output). The current question is "of everything an attacker could reach, what is actually exploitable, what would it let them touch that matters, and has it been proven?" That shift — from enumerating weaknesses to prioritizing and validating exposure — is pulling three formerly separate businesses (vulnerability scanning, external attack-surface management, and breach-and-attack simulation) into one platform contest.

What exposure management covers

Exposure management is the discipline of continuously discovering everything an organization exposes to attackers — unpatched software, misconfigurations, internet-facing assets, identities, cloud resources — and prioritizing remediation by real exploitability and business impact rather than raw severity counts. Gartner's CTEM framework wraps this into a five-stage program (scoping → discovery → prioritization → validation → mobilization), and its widely-cited prediction is that organizations that prioritize security investments through a CTEM program will be roughly 3x less likely to suffer a breach. The domain divides into three converging lineages, plus a unifying platform layer:

What ties it together: the buyer is not purchasing a scanner but a defensible answer to "are we exposed, to what, and what should be fixed first" — a question that has become substantially harder as attack surfaces expanded across cloud, SaaS, identity, OT, and AI. The value is in the prioritization and proof, not the enumeration; the enumeration is increasingly a commodity.

How each type of vendor operates

Vendor Owner Lineage Differentiation / economics
Tenable Public (TENB) VM → exposure platform EAP Leader; Tenable One the most mature unified exposure platform; Nessus brand ubiquity; built/bought into cloud (Ermetic), OT, identity exposure; the scaled pure-play bellwether
Qualys Public (QLYS) VM → exposure platform EAP Leader; Enterprise TruRisk platform; cloud-agent architecture, high margins, strong FCF; Tenable's most direct like-for-like rival; disciplined, profitable incumbent
Rapid7 Public (RPD) VM → exposure + SecOps EAP Leader; Exposure Command (InsightVM + cloud + AppSec + threat intel); also an MDR/SecOps player — credible but less mature unified exposure platform; perennial take-out candidate. New CEO Wael Mohamed (Jun 1 2026) opened with a small July restructuring (~21 roles, under 1% of staff), then a 2026 Restructuring Plan approved by the board on Aug 7, 2026 cutting approximately 12% of the workforce — a materially larger reset, detailed in the section below
Wiz / Orca Google/Alphabet (Wiz, ~$32B) / VC CNAPP → cloud exposure Agentless cloud exposure & attack-path graphing; re-defined exposure in the cloud and now pull cloud-exposure value away from the on-prem VM vendors — the platform threat from the cloud side
Pentera Private (VC; ~$1B+) Validation / autonomous pen-test Automated security validation — safely exploits to prove real risk; the "validation" stage leader; re-rated VM by proving which vulns actually matter
Cymulate / SafeBreach Private (VC) BAS / validation Breach-and-attack simulation against the kill chain; continuous control validation; the proof layer that turns CTEM from theory into evidence
XM Cyber Schwarz Group Attack-path / exposure graph Attack-path modeling across hybrid estates; acquired by Schwarz (Germany) in 2021 — strategic-owner validation of attack-path as a category; in July 2026 CrowdStrike agreed to acquire the company's intellectual property (45+ patents, source code), with XM Cyber continuing as a standalone business under license
runZero Private (HD Moore) Asset discovery / ASM Unauthenticated active discovery (internal + external) — finds the assets scanners miss; the asset-truth layer; recently folded into Accenture's xOT via the Dragos deal
Censys / watchTowr / CyCognito Private (VC) External ASM Internet-scale attack-surface intelligence; CyCognito's external risk graph; watchTowr's adversarial/continuous external testing — outside-in specialists
Axonius Private (VC; ~$2.6B) Asset / exposure intelligence Cyber-asset attack-surface management (CAASM) — aggregates every asset source into one inventory; the connective tissue beneath exposure programs
Microsoft / Palo Alto (Cortex Xpanse) / CrowdStrike platforms ASM + exposure modules Platforms folding ASM/exposure into the suite (Defender EASM, Cortex Xpanse, Falcon Exposure Management) — the bundle threat from above

The vendor groups differ along consistent lines. The VM incumbents compete on install base and are moving to become exposure platforms. Tenable, Qualys, and Rapid7 own the scanning relationships, the asset data, and the compliance hooks; their strategic project is to move from "scanner" to "unified exposure platform" (Tenable One, Enterprise TruRisk, Exposure Command) before the cloud platforms and the validation specialists fragment the value. The cloud-native vendors (Wiz, Orca) redefined exposure where modern assets reside — in the cloud — and pull the fastest-growing slice of exposure value into CNAPP, which is why the on-prem VM vendors had to buy or build cloud (Tenable–Ermetic). The validation/BAS players (Pentera, Cymulate, XM Cyber) compete on proof — they answer "is this actually exploitable," the most valuable upgrade to prior VM, and they re-rated the category by making prioritization defensible rather than based on raw CVSS scores. The ASM and asset-intelligence specialists (Censys, runZero, Axonius) compete on discovery — organizations cannot manage what they cannot see, and attack surfaces now extend beyond what any agent-based scanner covers. The structural question for the domain: does the unified exposure platform consolidate all of this (one vendor owns VM + ASM + validation + cloud exposure, and the standalone tools are absorbed), or does the platform value migrate to the CNAPP/SecOps suites (Microsoft, Palo Alto, CrowdStrike, Google/Wiz) that already own the cloud and the SOC, leaving the pure-play VM vendors as commoditized data sources feeding another vendor's graph?

Where the value pool is migrating

From vulnerability scanning to continuous exposure management (CTEM) low mid high value capture Scanning VM / CVE lists commoditizing ↓ Discovery ASM / CAASM Censys/runZero Prioritize Tenable One etc. platform ↑ Validate Pentera/Cymulate proof ↑ Cloud Wiz/Orca CNAPP pull
Directional (illustrative, not to scale): value is migrating from commoditizing scanning toward discovery, prioritization, validation, and cloud exposure — the stages of Gartner's CTEM model. CTEM market est. ~$2.7B (2025) → ~$7B (2033), ~12–13% CAGR. Sources: Grand View Research — CTEM market; Tenable — EAP / Gartner EAP MQ; Vectra — Gartner CTEM 5 stages.

Signature deals & events

Rapid7's 2026 restructuring

Of the three public pure-plays, Rapid7 is the one whose numbers now show the domain's compression directly, and its 2026 results give the segment a dated, primary-source data point on what happens when a VM incumbent's platform transition does not outrun the commoditization of the scanning layer.

Rapid7 reported second-quarter 2026 results (quarter ended Jun 30, 2026) alongside a board-approved 2026 Restructuring Plan. Revenue was $210.9M, down 1.5% year over year, of which product subscriptions were $205.1M. Annualized recurring revenue was $824.0M, down 2.0% year over year — the ARR line is contracting, not merely decelerating. GAAP income from operations was $3.0M and GAAP net income $6.1M (against $8.3M in the prior-year quarter); non-GAAP income from operations was $28.9M and non-GAAP net income $33.0M, or $0.44 per diluted share (against $0.58). Operating cash flow was $37.0M and free cash flow $31.9M, with cash, cash equivalents and government securities of $702.6M at quarter end (Rapid7 8-K, Aug 2026).

The restructuring plan, approved by the board on Aug 7, 2026, reduces the workforce by approximately 12% — press accounts put the figure near 310 roles against a global headcount of roughly 2,600 — and is stated as simplifying operations and concentrating investment on the core platform and AI capabilities. Rapid7 expects $10–11M of charges, primarily severance, substantially all incurred and paid in the third and fourth quarters of 2026 (SecurityWeek, Aug 14 2026 · BankInfoSecurity).

The guidance makes the trade explicit. Full-year 2026 revenue is guided to $837–841M (down 2–3%) with ARR of approximately $812M at (3)% growth, against non-GAAP income from operations of $129–133M and free cash flow of about $130M. Taken with the first three quarters — Q1 revenue $210.0M on ARR of $832M with non-GAAP operating income of $24.4M, Q2 as above, and Q3 guided to $208–210M and $34–36M — the midpoints imply a fourth quarter of roughly $209M revenue and $43M non-GAAP operating income, a non-GAAP operating margin near 20%, consistent with the company's stated 20% Q4 target and roughly five points above the full-year figure of about 15.6%. The sequence, in short, is a shrinking top line converted into an expanding margin over four quarters.

One balance-sheet item conditions how much room that leaves. At Jun 30, 2026, convertible senior notes of $598.2M sat in current liabilities with a further $296.0M non-current, against $892.3M entirely non-current at Dec 31, 2025 — the near-term tranche now equals about 85% of the $702.6M cash and securities balance. Cash covers it, but with little left over, which narrows the practical range of options a shrinking-ARR business has for financing a turnaround, an acquisition, or a change of control.

This is the bear case test running in public. Rapid7 was the pure-play most often named as a take-private candidate before the reset; the reset now supplies a leveraged buyer with the two things it needs — a demonstrated cost base and a strong free-cash-flow line — while removing the growth story that would justify a premium. Whether the exposure platform re-rates or the segment's standalone economics are conceded to the cloud and SecOps suites should be legible in Rapid7's ARR line over the next several quarters rather than in the margin line.

The bear case

The exposure-management bull case is strong: attack surfaces are expanding across cloud, SaaS, identity, OT, and AI; CVE volume is unmanageable without prioritization; regulation mandates vulnerability management; and Gartner's CTEM framing gives CISOs a board-ready program that pulls budget toward continuous, validated exposure platforms — a structural tailwind for the unified-platform leaders (Tenable, Qualys, Rapid7) and the validation specialists (Pentera, Cymulate). The bear case has three prongs. First, "exposure management" may be vulnerability management with better marketing — the core scanning function is decades old and commoditizing, open-source and cloud-native tooling is encroaching, and if the "platform" layer is mostly a dashboard over the same scan data, pricing power erodes even as the category gets a new name. Second, the value may migrate to the platforms that own the cloud and the SOC. Microsoft (Defender EASM), Google/Wiz, Palo Alto (Cortex Xpanse), CrowdStrike (Falcon Exposure Management), and the CNAPP vendors already sit closer to where modern assets live and where remediation happens; if exposure becomes a module of the cloud/SecOps suite, the standalone VM vendors risk becoming commoditized data sources feeding another vendor's graph — which is why all three trade at modest multiples versus the higher-growth cloud-security names. Third, fragmentation cuts both ways — the VM incumbents must integrate ASM + validation + cloud + identity to deliver the "single exposure view," but each of those is a fast-moving specialist market, and buying enough of them to be credible is expensive and integration-heavy while the cloud platforms build it natively. Falsifiable test: whether Tenable/Qualys/Rapid7 re-rate toward cloud-security-like multiples as their unified exposure platforms (Tenable One, TruRisk, Exposure Command) capture validated-exposure budget, or whether their growth stays in the low-to-mid teens, one of them is taken private or acquired (Rapid7 the perennial candidate), and the cloud platforms take the exposure layer. If the pure-plays re-rate and validation becomes a required line item, the platform thesis holds; if growth stalls and the suites absorb exposure, "exposure management is a durable standalone platform" weakens to "exposure data is a feature of the cloud and SecOps platforms."

Cross-references: Vendors, Cloud Security, SecOps & SIEM, OT/ICS Security, Service Providers, Deals & Comps, Valuation, Commercial Due Diligence.


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.