CTEM

State of Threat Management Survey Report: What 550 Security Professionals Reveal

Jun 30, 2026 8 min read

Security teams have more tools, more data, and more visibility into their attack surface than ever before. So why are 84% of them still getting hit by attacks exploiting risks they already knew about?
That question is what pushed us to commission the State of Threat Management report. And the answers, drawn from an independent survey of 550+ security decision-makers and practitioners across nine countries, are worth paying attention to.


TL;DR

  • Visibility isn’t the main constraint anymore. The bigger gap is turning security data into decisions, then into action.
  • Even with lots of tools and feeds, most organizations still don’t have a clean, consolidated view of their attack surface, so signals stay fragmented.
  • Prioritization is the bottleneck. Known risks don’t get addressed fast enough, and manual work slows detection, response, and remediation.
  • The shift is toward continuous, evidence-based validation, with AI adding the most value when it supports structured workflows (not scattered tooling).

Why We Commissioned This Research

There is no shortage of reports on threat intelligence. Or on exposure management. Or on GRC. So why release yet another one? Well, the industry is changing – fast – and organizations are no longer treating these as separate practices. Instead, the modern SOC is clearly converging towards a unified approach to threat management.

CTI without exposure validation is just information. Exposure management without threat intelligence is just a list of vulnerabilities and static testing. And security without risk quantification will leave you stuck in the technical details, invisible at the business level.

This unified threat management convergence is why we wanted to look at the full picture: how organizations are managing threats across intelligence, exposure, validation, and risk, and whether those functions are actually connected.

That also meant taking a hard look at CTEM to understand if it is a meaningful framework or yet another security buzzword.

And yes, we also wanted to gain insight into AI and automation. We know, not exactly a surprise. But the data tells a more specific story than the general hype, and it is worth reading.

What the Report Uncovered

The headline is straightforward: visibility is no longer the problem. Operationalization is.

Security teams are not short on data. They are short on the ability to turn that data into decisions, and decisions into action, at the speed the threat landscape demands. And with AI on the headlines of practically all cyber security news outlets, this is not too surprising.

But how did we get here? The report groups its findings into 4 main high-level insights. Here is a quick overview:

1. The Exposure Gap: More data, less clarity

What instantly stood out was how although organizations report having all the tools and data in place that one would think is enough, they majority still face visibility issues which, in turn, leaves organizations unable to effectively detect, prioritize, or respond to modern threats.

93% of organizations struggle to maintain an accurate, up-to-date view of their attack surface, with only 41% able to have a fully consolidated view of their cyber risk exposure.

So the issue isn’t a lack of tools, but the fragmentation of the resources they already have to manage threats. Internal telemetry, external threat data, and vulnerability signals sit in silos rather than feeding a unified picture. What’s more, organizations pull in an average of 14 different threat intelligence feeds, yet fewer than half have fully integrated that intelligence into their workflows.
In short: more inputs aren’t necessarily producing better outputs.

2. The Priorization Bottleneck: Knowing Acting

The next high-level discovery: threat awareness does not translate into protection against them – there are simply too many to track. And sifting through the threats that actually put an organization at risk requires more than just tooling.

84% of respondents say the attacks they face often exploit risks that were already known but not prioritized.
82% also say manual processes make it harder to determine which risks need immediate attention.

Prioritization is not a new concept in the threat management space, but it seems like it is easier said than done.

When prioritization depends on stitching data across disconnected tools, everything slows down. Most organizations take more than a day to detect (72%), respond (71%), and remediate (83%) incidents.

The consequence? 42% of analyst time reported wasted investigating potential risks that later prove to be low priority or not exploitable.

Challenges faced when validating whether security risks are actually exploitable

Challenges faced when validating whether security risks are actually exploitable

3. Validate to Assess Readiness: Point-in-time is not enough

Even with the right tools and prioritization systems in place, validating threats a clear pinpoint. With the rise in attack frequency, speed, and sophistication, this only makes sense – and will only get worse.

Today, 97% of organizations report difficulties confirming whether exposures are actually exploitable. And only 38% use threat intelligence within a continuous, fully automated validation process.

The market knows where it needs to go: away from periodic snapshots and toward continuous, evidence-based validation. Adversarial Exposure Validation is emerging as the practical path to get there.

4. The Future of Risk Exposure Management: AI is accelerating, but structure matters too

Only 37% of exposure management processes are currently AI-driven, with that figure expecting to reach 59% within two years.

Unsurprisingly, AI and automation will be critical in threat and exposure management. What is interesting, however, is how and where AI can be most beneficial.

The areas where AI delivers the most value map directly to where manual processes have historically broken down: detection, validation, and prioritization. But technology alone does not close the gap. Around 75% of organizations plan to invest in cyber risk quantification and GRC capabilities over the next 12 to 24 months, recognizing that technical findings need to translate into business-ready risk decisions.

Areas of exposure management most likely to benefit from AI and automation

Areas of exposure management most likely to benefit from AI and automation

What This Means for the Future of Threat Management

Overall, the most important finding in this report is not simply its individual insights, but rather the patterns and interconnection of assessment, validation, and risk reduction the data has revealed. And at the center is threat intelligence that weaves across it all, acting as a foundation to CTEM programs, but underutilized today.

Every challenge surfaced by the data – the exposure gap, the prioritization bottleneck, the validation shortfall, the push toward AI – maps directly to what a mature, connected threat management process is designed to address.

Future investments in exposure management are therefore driven not only by the obvious external factors – increase in threats, attack sophistication, and regulations – but also the internal processes that need to match the modern threat landscape.

In short, organizations know there is a problem, but are missing the continuous, integrated process to act on it.

Factors that matter the most when evaluating new exposure management tools or capabilities

How These Findings Align with CTEM

So where does that leave us with CTEM?

The report went beyond measuring adoption and actually compared how organizations behave at different stages of CTEM maturity: those “planning” to implement a CTEM framework versus those with a fully established program.

Clearly, the data reveals that CTEM maturity does impact how security teams operate. For instance, organizations with established CTEM programs show 22 points higher GRC adoption and rely 27 points less on penetration testing than those still in the planning phase, showing a clear structural shift. Even AI adoption patterns change: planning-stage organizations want AI to surface threats, mature ones want it to validate and rank them.

CTEM might not just be a cyber security buzzword after all, as it actually helps transform it.

How to Use This Report

The report is, first and foremost, an insightful read on where the industry stands in its move toward extended threat management. But it also has practical implications for security practitioners:

  • Benchmarking: Where do you stand? Use this data to benchmark your organization’s maturity against 550+ peers on visibility, prioritization, validation, and automation.
  • Validate your pains: Does anything hit too close to home? Use the insight to validate the operational challenges your team is already experiencing and give them a name backed by independent data.
  • Plan ahead: Where do you want to be? Use the report to map a path forward and align to the frameworks and processes that matter to you, your team, and industry (MITRE ATT&CK, CTEM, DORA…etc).

Who Is This Report For

This report is for anyone interested in a fast-moving industry trend. But it was written for the people who sit closest to the problem, whether that’s owning the strategy, doing the work, or making the investment decisions. For example:

  • Security leaders and decision-makers (CISOs, VPs, Security Operations leads) who need third-party evidence of where their programs stand and the language to make the case for change internally.
  • Practitioners and analysts (threat intelligence, red and purple teams, risk and compliance) who are dealing with these challenges daily and want data to back up what they already know.
  • Executives and board stakeholders (CFOs, CROs, board members) who need a business-relevant view of cyber risk maturity across the industry, without the technical jargon.

Read the Full Report Today

The full State of Threat Management report is available right now, for free and ungated.

Stay up to date with everything at Filigran

Sign up for our newsletter and get bi-monthly updates of Filigran major events: product updates, upcoming events, latest content and more.