zcrCTEM
Continuous Threat Exposure Management
EASM + CAASM + DRP + Compliance on one platform. One risk score. Zero tool sprawl.
The Hacker View
Your attack surface moves faster than your controls.
Attackers need one exposed asset. Your team needs continuous visibility across all of them.
31%
of breaches start with vulnerability exploitation · Verizon DBIR 2026
26%
of critical KEV vulnerabilities fully remediated · Verizon DBIR 2026
241
days to identify and contain a breach · IBM 2025
$4.44M
global average breach cost · IBM 2025
Continuous Threat Exposure Management
EASM · CAASM · DRP · Compliance — one unified platform.
Five CTEM stages, automated.
01
01 · Scoping
Define exposure scope across every external asset and internal business unit.
02
02 · Discovery
Find every domain, IP, port, leaked credential, SaaS app, and shadow IT asset.
03
03 · Prioritization
Risk-score findings using CVSS + EPSS + KEV, asset criticality, and blast radius.
04
04 · Validation
Confirm exploitability with MITRE ATT&CK-mapped breach simulation.
05
05 · Mobilization
Route remediation to ITSM. Track fixes. Produce executive reports.
What you get
- EASM — find every external asset and surface you expose
- CAASM — unify your internal asset inventory across cloud, SaaS, on-prem, OT, IAM
- DRP — watch the internet beyond your perimeter (dark web, paste sites, brand impersonation)
- TI — turn raw CVSS into real risk using CISA KEV + FIRST EPSS + AI
- Compliance — PDPA, CII, ISO 27001 evidence collection
Best for
Coverage across your environment
- 01
External exposure
Domains, subdomains, APIs, ports
- 02
Internal assets
Endpoints, SaaS, cloud, AD, LDAP, SSO
- 03
Threat intelligence
CISA KEV + FIRST EPSS
- 04
Digital risk
Dark web, paste sites, brand and social
- 05
Compliance
PDPA, CII, ISO 27001 evidence
- 06
Thai regulators
NCSA, BoT, NBTC, SEC
EASM
See everything you expose to the internet — before attackers do
- 1Find shadow IT (subdomains, APIs, ports) beyond what feeds list
- 2Monitors 24×7 with weekly surface diffs
- 322 signal kinds: ports, certs, exposures, leak markers
- 4Auto-tickets for fix-now issues into your ITSM
Catch shadow APIs left open
Scans paths like /.env, /swagger, /admin and flags the asset before secrets leak. Instant-impact upsell for any tenant exposing a forgotten endpoint.
CAASM
Know every asset you own — and which fall outside your controls
- 1Unify inventory across cloud, SaaS, on-prem, OT, and identity
- 2Coverage gaps: assets EDR or vuln scanners can't see
- 3Shadow + IAM risk (privileged users, missing MFA)
- 4Continuous CMDB reconciliation
Catch shadow assets nobody owns
A database instance seen only by AWS — not in EDR, not in CMDB — flagged as shadow. CAASM makes coverage % measurable, not a feeling.
DRP
Watch the internet beyond your perimeter — leaks, impersonation, threats
- 1Leaks & secrets: dark web, paste sites, breach dumps
- 2Brand impersonation: typosquats, fake apps, social handles
- 3Takedown built in — file and track to resolution
- 4AI triage in EN + TH, health-checked feeds
Employee credentials in a breach
corporate@yourco found in a breach dump → alert + force-reset before misuse. Leaked logins are the #1 way attackers get in.
TI
Turn raw CVSS into real risk — know which CVE to fix first
- 1CISA KEV (actively exploited)
- 2FIRST EPSS (predicted exploitation probability)
- 3Weekly AI-written brief in EN + TH
- 4BOD 22-01 deadline tracking for gov tenants
Which CVE do we patch first?
A 9.8 with no EPSS vs a 6.5 on KEV. CVSS would send you to the 9.8 — TI shows the 6.5 is the one actually being exploited.
Compliance
PDPA · CII · ISO 27001 evidence collection — without spreadsheets
- 1PDPA 72-hour breach notification drafts
- 2CII + sector regulators (NCSA, BoT, NBTC, SEC) reports
- 3ISO 27001 Annex A control evidence mapping
- 4Audit log with tamper-evident chain of custody
CII incident — 72 hours
A CII-classified incident triggers a PDPA 72-hour clock. zcrCTEM drafts the notification, maps evidence to ISO 27001 Annex A, and files with NCSA in one workflow.
FAQ
- How quickly can we start seeing value?Connect your domains and core data sources first. zcrCTEM begins discovering exposure immediately, then expands as you add cloud, identity, endpoint, and ITSM integrations.
- Does this replace our EDR, scanner, or SIEM?No. zcrCTEM connects those tools, finds the gaps between them, and gives your team one prioritized exposure view instead of another alert queue.
- How do you decide what we should fix first?We combine CISA KEV and EPSS exploit data with asset criticality, exposure, and business impact so every priority is defensible.
- Can it support Thai compliance and audits?Yes. Evidence maps to PDPA, CII, ISO 27001, and requirements from NCSA, BoT, NBTC, and SEC, with Thai and English reporting.
- Can an MSSP manage multiple customers safely?Yes. Each customer has isolated data, role-based access, and separate reporting, while the MSSP operates from one multi-tenant console.
Ready to see your full attack surface?
Request a demo or partner briefing — see zcrCTEM live with your own domain. ctem2.zcr.ai · tunz@zcr.ai
zcrCTEM · Cyber Defense Made Visible