The Great Exposure Validation Showdown: A Threat-Informed Approach to Exposure Management

Continuous Threat Exposure Management (CTEM) is reshaping how organizations approach cybersecurity, demanding a fundamental shift from reactive risk management to continuous, threat-informed security operations. This session introduces the CTEM framework and shows how integrating MITRE ATT&CK and M3TID (Measure, Maximize, and Mature Threat-Informed Defense) principles creates a powerful approach that transforms how teams identify, prioritize, and address risk exposures.

You’ll learn:

  • What CTEM is and how it differs from traditional risk management approaches
  • How MITRE ATT&CK provides the foundation for threat-informed exposure management
  • The essential components of integrating M3TID principles into your CTEM program
  • The business and security benefits of adopting a threat-informed CTEM strategy
  • Practical steps to get started implementing CTEM in your organization

Can’t attend the live session? No worries! Register anyway, and we’ll send you the recording so you can watch when it’s convenient for you!

Carl Wright

Chief Commercial Officer, AttackIQ

Carl is a seasoned entrepreneur and executive with experience in the security, storage, virtualization, and software sectors. Prior to joining AttackIQ he held executive operational roles at Securify, Decru, and Kidaro, where he contributed to rapid growth and subsequent acquisition by Microsoft, Network Appliance, and Secure Computing. He has extensive experience in all aspects of enterprise information technology deployments and has held key IT operational roles, including chief information security officer for the U.S. Marine Corps. In 1999, he was awarded the National Security Agency’s Frank B. Rowlett Trophy.

Chris Kennedy

CISO, Group 1001

Christopher is a tested 27-year cyber security executive with an incredibly diverse career spanning military, government, financial, commercial, and consulting verticals focused on national critical infrastructure institutions. He has led the development and security operations of some of the most globally impactful and adversary-targeted organizations in the world. His career began as a young military officer in the United States Marine Corps, establishing the first cyber security program for the largest base in the Corps (Camp Lejeune, NC), and then leading the development of the enterprise Incident Response mission (known as the Marine – CERT) IN Quantico VA. He went on to spend a decade at Northrop Grumman building out the US Department of Treasury’s Enterprise Security Operations mission, facing off to threat actors spanning sophisticated states to relentless hacktivists. He spent 7 years at Ray Dalio’s $160B Bridgewater Associates, and 2.5 years at Ken Griffin’s Citadel during controversial times for those firms. He’s also developed security products and technology offerings from his leadership at a startup (AttackIQ), or via productizing capabilities from his portfolio. He continues to advise institutions and startups via his private consultancy, IntergrityEQ Partners. Today he is the head of security and Chief Information Security Officer for Group1001, the ($64B AUM) private equity organization overseeing the Delaware Life & Annuity, Clearspring Life & Annuity/Property & Casualty/Health, Gainbridge, and Vesper Risk brands.

Thank you for your submission!

By submitting this form you indicate that you have read and agree to the terms of our Privacy Policy.