The Question
The CISO stands in front of the board's audit and risk committee with a request: $2.1 million for a Continuous Threat Exposure Management program. The ask includes a Palo Alto Xpanse deployment for external attack surface management, an expansion of the existing Tenable program with Tenable Lumin for risk-based prioritization, a Pentera deployment for continuous validation, and a Recorded Future TI integration.
The CFO asks the question that CISO have been dreading since the concept of CTEM was formalized: "What is the financial return on this investment? What specific risk are we reducing, and by how much?"
The CISO has two bad answers available. The first is "we can't quantify security ROI — breaches are probabilistic." This is technically accurate and completely unconvincing to a board that approves capital investments based on expected returns. The second is a cyber risk quantification model built in Archer or a spreadsheet that produces a precise dollar figure — "this investment reduces our annual loss expectancy by $4.7 million" — that nobody in the room believes because the model inputs are opaque.
The business case that wins budget approval is neither of these. It connects the CTEM investment directly to the breach scenarios the board already knows and fears, with a clear and auditable line from program capability to reduced probability of those specific outcomes. It uses real numbers from real incidents, not theoretical models.
The CTEM business case that wins board approval is not the one with the most complete risk quantification model — it is the one that connects the program directly to the breach scenarios the board actually worries about, with a clear line from CTEM investment to reduced probability of those specific outcomes.
Why This Matters Now
The 2024 Change Healthcare ransomware attack — the largest healthcare data breach in US history, affecting an estimated 190 million patients — produced a documented financial impact that has become the reference incident for healthcare sector CTEM business cases. UnitedHealth Group disclosed total costs of approximately $2.3 billion in the first year, including $872 million in direct breach response costs, $1.1 billion in disruption to Change Healthcare's operations, and over $400 million in customer and provider financial assistance programs.
The attack vector was a compromised Citrix portal credential — a VPN credential for which multi-factor authentication had not been enforced. This is not a sophisticated zero-day attack. It is the exploitation of an identity exposure that a CTEM program with identity coverage would have surfaced: an internet-facing authentication endpoint without MFA, accessible with a credential that was likely available in an underground marketplace based on subsequent analysis.
Post-incident analysis by security researchers found that the attack path was not novel, not technically complex, and not unprecedented in the healthcare sector. The specific exposure — a Citrix portal without MFA on an account with access to critical infrastructure — had been identified as a high-risk configuration class in multiple prior CISA advisories. A CTEM program with EASM coverage would have flagged this asset. TI integration would have connected it to the ALPHV/BlackCat group's documented exploitation of Citrix authentication weaknesses. Identity exposure coverage would have flagged the absence of MFA enforcement as a critical finding.
The Change Healthcare case is now the benchmark financial scenario for healthcare CTEM business cases. For other sectors, the equivalent reference incidents are the MGM Resorts breach ($100M+ impact), the British Library ransomware attack (estimated £6M–£7M), and the Caesars Entertainment breach ($15M ransom paid).
What the CURVE™ Data Shows
The 2026 Stackcurve CTEM CURVE™ Report analyzed CTEM program ROI data from 31 enterprise deployments where pre- and post-deployment metrics were available, focusing on three operational metrics: mean time to remediate critical exposures, reduction in emergency patch events, and open CISA KEV findings at time of assessment.
Enterprises with mature CTEM programs (Tier 1 in the CURVE™ methodology) showed a median MTTR for critical internet-facing exposures of 4.7 days, compared to 23.2 days for enterprises with VM-only programs. Emergency patch events — unplanned remediation cycles triggered by in-the-wild exploitation of vulnerabilities that were open in the environment — were 67% lower in Tier 1 CTEM programs than in VM-only programs. Open CISA KEV findings were 84% lower at the time of quarterly assessment in Tier 1 programs.
On prioritization efficiency: Tier 1 CTEM programs reduced the active "must remediate immediately" finding queue by an average of 38% relative to the raw VM output, reflecting the deprioritization of high-CVSS, low-EPSS findings that compensating controls effectively mitigated. This translated to a quantified IT labor savings of $180K–$340K per year in large enterprises, based on average fully-loaded cost per emergency patch event.
The full vendor rankings are in the 2026 Stackcurve CTEM CURVE™ Report — free to download.
The Gap Most Buyers Miss
Most CTEM business cases are built around the wrong metrics. They present vulnerability counts, MTTR improvements, and CVSS score distributions — operational metrics that are meaningful to security teams and opaque to boards. The gap is the translation layer.
Framing Risk in Board-Relevant Terms
Boards understand three things about cyber risk: breach probability, breach cost, and regulatory consequence. The CTEM business case must connect the investment to at least one of those three in concrete, auditable terms.
Breach probability reduction is the most direct argument. Start with a specific breach scenario — ransomware executed through an unpatched internet-facing VPN, credential-based access through an authentication endpoint without MFA, lateral movement from a cloud misconfiguration to a crown jewel database. Then show the board how many findings of that class are currently open in the environment. CTEM closes those findings faster and more reliably than a VM-only program. The Change Healthcare case quantifies what happens when they remain open.
Breach cost reference should use sector-specific IBM Cost of a Data Breach data rather than the global average. The 2024 IBM report places the average breach cost at $4.88M globally, $9.36M for healthcare, $6.08M for financial services, and $5.82M for technology. These are not the maximum figures — they are averages. For large enterprises, the relevant reference is the sector-specific P90 figure, not the mean.
Regulatory consequence is increasingly quantifiable. GDPR fines in the EU have reached hundreds of millions of euros for breach incidents where the organization's exposure management program was found inadequate. SEC cyber disclosure rules, effective from late 2023, require material breach disclosure within four business days and have introduced direct securities litigation risk for inadequate cyber programs. The compliance cost of a breach — fines, legal fees, regulatory remediation requirements — often equals or exceeds the direct incident response cost.
Prioritization Efficiency as a Direct Labor Savings
The most concrete and defensible financial figure in a CTEM business case is the reduction in emergency patch events. Every unplanned emergency patch cycle costs the organization in IT labor (after-hours work, change management bypass, testing compression), application owner time, and in some cases service disruption. Estimate the cost of one emergency patch event for a critical production system — typically $15K–$50K fully loaded — and multiply by the reduction in such events that CTEM's prioritization and proactive remediation enable.
In environments running only CVSS-based VM programs, 20–30% of emergency patch events are for vulnerabilities that had been open in the environment for more than 60 days but were not in the top-priority remediation queue. CTEM's CISA KEV integration and EPSS-based prioritization would have moved those findings to immediate remediation before they became emergency events. That is a measurable and auditable cost avoidance.
Red Team to BAS Shift: Direct Cost Savings
The transition from annual supplemental red team engagements to continuous BAS is a direct cost comparison with a quality improvement argument attached. A second annual red team engagement to validate prioritized VM findings costs $150K–$500K. A BAS platform providing continuous validation costs $100K–$300K per year and produces more frequent validation data. The cost savings is real and the quality argument — continuous versus point-in-time — reinforces it rather than undermining it.
This is a tactical argument to include in the business case, not the primary one, because it frames CTEM as cost-neutral rather than value-positive. Use it to offset part of the CTEM investment cost, not as the central justification.
What Not to Do: The Pseudo-Precise Risk Model
The most common mistake in CTEM business cases is building a cyber risk quantification model — using FAIR methodology or similar — and presenting the output as a precise financial figure. "This investment reduces our annual loss expectancy from $12.3M to $7.6M." The inputs to these models — breach probability estimates, threat likelihood distributions — are derived from industry data that does not map cleanly to the specific organization. Board members who are sophisticated about financial modeling immediately recognize when inputs are speculative, and the entire case loses credibility.
Use incident reference data and operational metrics, not probabilistic financial models, as the primary evidence base. The Change Healthcare $2.3B impact is a fact. The IBM $9.36M healthcare average is a fact. The 84% reduction in open KEV findings in Tier 1 CTEM programs is a fact. Build the case on facts, not model outputs.
Questions Your Buying Team Should Be Asking
1. What are the three or four specific breach scenarios the board has identified as highest-concern, and how does this CTEM program reduce the probability of each?
The CTEM business case must be built backward from the board's concerns, not forward from the technology's capabilities. Before drafting the financial case, get explicit clarity on which specific scenarios keep the board up at night — ransomware via credential compromise, supply chain attack, cloud misconfiguration leading to data exfiltration — and build the capability-to-risk-reduction argument specifically for those scenarios.
2. What is our current baseline on CISA KEV findings — how many are open, how many are on internet-facing systems, and what is our MTTR for KEV-listed vulnerabilities?
These three metrics are the before state for the business case. They are concrete, measurable, and directly connected to breach probability. A board that learns the organization currently has 47 CISA KEV findings open, 12 of which are on internet-facing systems, with an average MTTR of 31 days, understands the risk state without needing a probabilistic model.
3. What is the estimated cost of one major emergency patch event in our environment — including IT labor, change management, application owner time, and any service disruption?
This number is the basis for the patch management efficiency argument. It requires input from IT operations, not just security. The resulting calculation — current number of emergency patch events per year multiplied by cost per event multiplied by projected reduction percentage — is a credible, auditable operational cost savings figure.
4. How does this CTEM program integrate with our cyber insurance program — specifically, will the carrier consider CTEM maturity in the policy renewal assessment?
Cyber insurance carriers are increasingly assessing CTEM-related controls — specifically external attack surface management, CISA KEV remediation times, and MFA coverage on internet-facing authentication — as underwriting criteria. Some carriers offer premium reductions for demonstrated CTEM maturity. This is a quantifiable financial benefit that belongs in the business case.
5. What does the phased implementation look like — can we demonstrate measurable risk reduction within 90 days to validate the investment before the full program budget is committed?
CTEM programs that demonstrate early ROI secure continued investment. The most effective approach is to scope the initial deployment around the highest-risk CTEM capability gap — typically EASM for enterprises without external attack surface visibility — and show the board what was discovered in the first 90 days that the previous program was not finding. First-discovery EASM results are frequently compelling on their own: internet-facing assets not in the CMDB, critical vulnerabilities on shadow IT infrastructure, or authentication endpoints without MFA enforcement.
The Stackcurve Take
The CTEM business case challenge is real, but it is not unique to security. The CFO approves investments in fire suppression systems, flood insurance, and supply chain redundancy without a precise ROI calculation — because the downside risk of not having those capabilities is clear, quantifiable by reference to incidents, and asymmetric relative to the investment cost. The CTEM business case should be built on the same logic.
The incidents are there: Change Healthcare at $2.3B, MGM at $100M+, Caesars at $15M ransom paid. The operational metrics are there: MTTR improvement, KEV finding reduction, emergency patch cost avoidance. The regulatory exposure is quantifiable. The cyber insurance linkage is becoming explicit.
A board that approves a $2.1M CTEM investment has not calculated the precise risk reduction — it has concluded that the investment is proportionate to the downside of the breach scenarios it fears, given the evidence that CTEM programs measurably reduce exposure to those scenarios. That is the business case to make: proportionate, evidence-based, and anchored to specific outcomes the board already understands.
The 2026 Stackcurve CTEM CURVE™ Report covers CTEM ROI benchmarks, operational metric baselines from 31 enterprise deployments, and financial modeling guidance for board-level business cases across healthcare, financial services, and technology sectors. Download it free →
Stackcurve Advisory Briefs are independent research. No vendor pays for placement, tier assignment, or editorial influence. The CURVE™ methodology is disclosed in full at stackcurve.net/research/methodology.