Continuous Threat Exposure Management (CTEM)
Continuous Threat Exposure Management (CTEM) is a proactive cybersecurity approach that continuously identifies, assesses, and prioritizes security exposures across an organization’s environment. It works alongside patch management to ensure vulnerabilities are addressed promptly by applying updates, reducing risk, and strengthening overall system security.
- Click 'ITSM' > 'Patch Management' > 'CTEM'
The interface has been divided into three sections
Application Patching
The Application Patching section allows you to manage third-party software updates across your managed devices. From here, you can:
- View available application patches
- Track patch versions (Fix Versions)
- See affected devices (Assets)
- Deploy or manage patch actions

| Application Patching - Column Descriptions | |
| Column Heading | Description |
| Software Name | Name of the application |
| Fix Version | Latest available patched version |
| Assets | Number of devices affected |
| Action | Available Patch actions - Patch Now, Patch Later has explained here. |
| Controls | |
| Search Bar | Quickly find a specific application by name |
| Reload Table Data | Reloads the patch list |
| Global Search | Global Search provides a centralized way to locate assets, alerts, and vulnerabilities, improving visibility and response efficiency. |
| Filter Table Data | We can filter the table data using Software name or Fix Version |
| Filter by Tags | Tap the search bar to filter by tags, choose from Include or Exclude options, select the desired tag(s), and click Submit to view the results. |
| Change Font Size | Adjust the font size by selecting from Small, Medium, or Large options. |
| Refresh Interval | Set the refresh interval by choosing No Refresh, 1 minute, 5 minutes, or 30 minutes. |
| View Columns, Reorder Columns | Customize the table by viewing and reordering columns such as Software Name, Fix Version, and Assets. |
| Download as CSV | Download the data as a CSV file for easy access and analysis. |
| Save Settings | Save table settings to preserve your selected columns, order, and preferences for future use. |
Installs the selected patch immediately on the chosen devices.
Select the applicable asset(s), then choose the Patch button; otherwise, click Cancel not to patch.

Patch Later options let you schedule the selected patch to be installed at a specified time and date.

OS Patching
Manages operating system updates by identifying, scheduling, and deploying patches to keep systems secure and up to date. From here, you can:
- View available OS updates
- Track update details (KB/Fix)
- See affected devices (Assets)
- Deploy or schedule patch actions

| OS Patching - Column Descriptions | |
| Column Heading | Description |
| Software Name | Displays the OS version requiring updates (e.g., Windows 10, Windows 11) |
| Affected OS | Indicates the operating system impacted |
| KB/Fix | Shows the specific update or knowledge base (KB) number |
| Assets | Number of devices requiring the update |
| Action | Provides the option to deploy patches |
| Controls | |
| Search Bar | Quickly find specific OS updates |
| Reload Table Data | Reload the latest patch data |
| Global Search | Global Search provides a centralized way to locate assets, alerts, and vulnerabilities, improving visibility and response efficiency. |
| Filter Table Data | We can filter the table data using Affected OS, KB/Fix or Software Name |
| Filter by Tags | Tap the search bar to filter by tags, choose from Include or Exclude options, select the desired tag(s), and click Submit to view the results. |
| Change Font Size | Adjust the font size by selecting from Small, Medium, or Large options. |
| Refresh Interval | Set the refresh interval by choosing No Refresh, 1 minute, 5 minutes, or 30 minutes. |
| View Columns, Reorder Columns | Customize the table by viewing and reordering columns such as Software Name, Affected OS, KB/fix, and Assets. |
| Download as CSV | Download the data as a CSV file for easy access and analysis. |
| Save Settings | Save table settings to preserve your selected columns, order, and preferences for future use. |
Clicking 'Patch' in OS Patching opens the prompt to select the patch installation's machine(s) and reboot settings.

Patch Jobs
The Patch Jobs section allows you to monitor and manage patch deployment tasks across your devices. From here, you can:
- View scheduled and executed patch jobs
- Track patch deployment status (Success, Failed, Pending)
- See details of applied patches (Software/KB)
- Monitor results across affected devices

| Patch Jobs - Column Descriptions | |
| Column Heading | Description |
| Start Date | Displays the date and time when the patch job was initiated |
| Software Name/KB | Shows the application name or OS update (KB) included in the job |
| Scheduler Name | Indicates the name of the scheduled task or job |
| Patch Type | Specifies whether the patch is for an application or operating system |
| Job Status | Shows the current status of the job (e.g., Success, Failed, Pending) |
| Description | Provides a summary of the job results, including counts of successful, failed, and pending updates |
| Action | Provides the option to terminate the patch job. |

