New The 2026 Continuous Validation Methodology Paper is now available. Read the paper →

VORNAC CTEM

Continuous Threat Exposure Management. A complete, current picture of your external attack surface, as an attacker sees it, rebuilt every day. Start with your core domains and IP ranges. VORNAC finds the rest, including the employee credentials that have already leaked.

The five phases.

Know what you show. Not what you think you show.

The result of CTEM is threefold.

Complete.

You know what you expose, not what you believe you expose. In the first weeks, the list of unknown assets and the first credentials found are usually the most valuable result.

Current.

An attack surface changes weekly. An annual test describes a state that no longer exists by the time the report is read. CTEM rebuilds the picture every day.

Provable.

NIS2, DORA and ISO 27001 require continuous vulnerability management across the entire attack surface. CTEM produces exactly the documentation an auditor wants to see, without anyone compiling it by hand.

An annual test describes a state that no longer exists when you read the report.

The attack surface of a company changes weekly. New subdomains, a changed service, the forgotten host of a subsidiary, a password in a stealer log. A snapshot cannot keep up. A daily picture can.

The annual assessment

  • Starting pointAn asset list you maintain yourself. Scope negotiated per engagement.
  • CoverageWhat is on the list. Subsidiaries under other brands and forgotten hosts are out of scope by definition.
  • CadenceOnce a year. The report describes the network of a few months ago.
  • CredentialsNot part of the test. A leaked password is noticed when it is used.
  • EvidenceA PDF snapshot, compiled by hand for the auditor.
  • BillingPer asset, per engagement. Someone decides in advance which systems are worth it.
  • Starting pointCore domains and IP ranges. Everything else is found, not listed.
  • CoverageEverything an attacker can see: subdomains, services, cloud resources, systems of subsidiaries under other brands, assets in no inventory.
  • CadenceRebuilt every day. A new system, a changed service, a published vulnerability: known within 24 hours, with rating.
  • CredentialsEmployee credentials watched continuously in leaks, stealer logs and darknet marketplaces, attributed to account and system.
  • EvidenceContinuous documentation for NIS2, DORA and ISO 27001, produced as a by-product of the monitoring.
  • BillingOne flat rate. No per-asset billing, no pre-selection of what is worth testing.

From two inputs to the whole attack surface. In five phases.

Continuous Threat Exposure Management is the five-phase program Gartner described in 2022: scoping, discovery, prioritization, validation, mobilization. This is what each phase looks like when VORNAC runs it.

  1. I Scoping

    Two inputs. Core domains and IP ranges.

    That is all the starting point needs. No asset list to maintain, no scope negotiation, no decision about which systems deserve attention. Subsidiaries under other brands, cloud tenants and forgotten hosts come in through discovery, not through a spreadsheet. Onboarding and setup are included in the price.

    You provideCore domains and IP ranges. Onboarding and setup included.
  2. II Discovery

    Everything else, VORNAC finds itself.

    Subdomains, services, cloud resources, systems of subsidiaries under other brands, assets that appear in no inventory. The picture is rebuilt every day, from the outside, as an attacker sees it. And because an attack surface is not only systems: the credentials of your employees are watched continuously for appearances in leaks, stealer logs and darknet marketplaces. A leaked password is often the more convenient route than any vulnerability, and without monitoring a company learns of it only once it has been used.

    CadenceRebuilt daily. Credentials watched in leaks, stealer logs and darknet marketplaces.
  3. III Prioritization

    Known within 24 hours. Rated, not just listed.

    A new system appears, a service changes, a relevant vulnerability is published: within 24 hours it is known, including its rating. Credential hits are attributed to the affected account and system and rated together with the rest of the attack surface. One picture, not two lists.

    Time to rating24 hours from the change to a rated entry.
  4. IV Validation

    Whether a system can actually be compromised, only exploitation proves.

    CTEM shows what is there and where the risk sits. Whoever wants the proof adds autonomous pentesting as a flat rate. It then runs across the entire discovered attack surface, not a list agreed in advance: every system discovery knows is tested fully and regularly, newly found systems automatically included. Production-safe, with a proof of concept per finding. Critical findings are confirmed by a BSI-recognised penetration tester before they are reported. Retests after remediation run automatically.

    OptionalOne flat rate. The whole discovered surface, not a list.
  5. V Mobilization

    The documentation an auditor wants to see. Nobody compiles it by hand.

    NIS2, DORA and ISO 27001 require continuous vulnerability management across the entire attack surface. CTEM produces exactly that record as a by-product: what is exposed, since when, how it was rated. Hits are attributed to the affected account and system, so remediation starts where it belongs. With the pentesting flat rate, the automatic retest closes the loop.

    Evidence forNIS2, DORA, ISO 27001. Hits attributed to account and system.

Two variants. No billing per asset.

CTEM is the base service. Continuous pentesting is the flat rate on top. Nobody has to decide in advance which systems are worth testing.

CTEM

The base service

  • The external attack surface, rebuilt every day, as an attacker sees it
  • Discovery of subdomains, services, cloud resources and systems of subsidiaries under other brands
  • Employee credentials watched in leaks, stealer logs and darknet marketplaces, attributed to account and system
  • New systems, changed services and published vulnerabilities rated within 24 hours
  • Audit documentation for NIS2, DORA and ISO 27001, without manual compilation
  • Onboarding and setup included

CTEM + Continuous Pentesting

The flat rate on top

  • Everything in CTEM
  • Autonomous pentesting across the entire discovered attack surface, not a pre-agreed list
  • Every known system tested fully and regularly, newly found systems automatically included
  • Production-safe, with a proof of concept for every finding
  • Critical findings confirmed by a BSI-recognised penetration tester before reporting
  • Automatic retests after remediation

Developed and operated in Germany.

No external AI provider. No processing outside Germany.

ISO 27001

Built on ISO 27001

BSI

Aligned with BSI

CISSP

CISSP certified

OSCP

OSCP certified

Discovery, credential monitoring, ratings and documentation run on a platform VORNAC develops and operates itself, in Germany, under German jurisdiction. No external AI provider, no third-country transfers.

See your attack surface as an attacker sees it.

Two inputs to start: core domains and IP ranges. Within the first weeks you usually hold the list of assets nobody knew about, and the first credentials that had already leaked.

The five phases.