You probably don’t need more security findings. You need a better way to determine which ones deserve your attention.
Vulnerability management, penetration testing, DevSecOps, threat intelligence and other tools can all tell you something about your exposure. The harder part is bringing those signals together, validating what attackers can actually exploit and turning that information into remediation priorities your teams can act on. That’s where Continuous Threat Exposure Management (CTEM) can help.
In this edition of The Brick House, GuidePoint Security practitioners discuss how to make CTEM operational—not as another tool to deploy, but as a repeatable way to connect the security work you’re already doing and focus it on reducing meaningful risk.
Topics discussed:
Watch Gary Brickhouse, CISO at GuidePoint Security and experienced security practitioners in a practical conversation about moving from finding more problems to fixing the ones that matter.
“It can’t just be an ROI story. It has to be an enrichment story — we can do more, we have better capacity, we see more and are more comprehensive. It’s not just about taking things away; it’s about what we’re adding on top.”
~ Victor Wieczorek, SVP, Offensive Security [59:25]
“There’s been a misconception that you can go buy a CTEM product and you’ve solved CTEM. The fact of the matter is that’s not true. It’s an approach to finding and fixing the exposures that actually matter.”
~ Josh List, Director, Vulnerability Management [10:19]
“Your best friends are those remediation and mobilization teams. So make sure you send them lunch. It’s not security on one side and IT on the other — that doesn’t work. It’s bringing all stakeholders to the table.”
~ Bobby Brill, Senior Director, DevSecOps [50:53]
“We have to get out of the mindset of ‘we run this pen test because PCI said we got to.’ We have to get to: we test to measure our defenses. That mindset shift is what truly starts it.”
~ Dale Madden, Senior Managing Security Consultant [22:59]
“The whole point is risk reduction. We want actual outcomes. As much as I’d love to go to my board and say we knocked out 45,000 issues, it just so happens we didn’t take out the 5,000 that were most critical to us — that would be a terrible thing.”
~Gary Brickhouse, CISO [20:53]
Gary Brickhouse is the Chief Information Security Officer (CISO) at GuidePoint Security, where he leads the company’s information security program and manages the GRC Services consulting practice. His expertise spans compliance, data privacy and securing technologies, honed through previous roles at The Walt Disney Company and Publix Super Markets. A frequent industry speaker, Gary holds a CISSP certification, ITIL v3 Expert credential and a Bachelor of Science from Florida Southern College.
Victor Wieczorek
SVP, Offensive Security

Josh List
Director, Vulnerability Management

Bobby Brill
Sr. Director, DevSecOps

Dale Madden
Senior Managing Security Consultant

The Brick House is a monthly panel discussion with GuidePoint Security’s CISO, Gary Brickhouse and his expert guests examining the hottest topics in cybersecurity. No talking heads here, just honest conversations amongst security practitioners who have current, real-world experience solving the most complex cybersecurity challenges.
No. CTEM (Continuous Threat Exposure Management) is an operating approach — not a tool. Josh List explained that there’s a common misconception that you can purchase a “CTEM product” and check the box. In reality, CTEM is a framework for finding and fixing the exposures that actually matter by uniting siloed teams, tools and data sources into a continuous, coordinated program. Tools can facilitate CTEM, but no single product delivers it.
Victor Wieczorek shared a real engagement story: a consultant achieved the fastest-ever domain administrator compromise starting from outside the client’s environment. The speed didn’t come from the attacker’s AI tools — it came from the client’s own AI. The consultant logged into the client’s M365 portal, found Copilot and simply asked it where cybersecurity leaders stored their sensitive files. Copilot initially refused, but when the consultant said he was a hired security professional, Copilot handed over the information. Enterprise AI tools create entirely new attack surfaces that most organizations haven’t accounted for.
In the live audience poll, “business context to drive prioritization” was the top answer for where exposure management breaks down most often. Josh List explained that most organizations do a reasonable job layering in exploitability and threat intelligence data, but still struggle to connect findings to what actually drives the business. Bobby Brill recommended tying asset scopes to business processes as the critical last step most organizations skip.
Bobby Brill pointed to people and process as the real drivers — not technology. The breakdown happens when security teams throw findings over the fence and say “see you next month.” The fix is security champion programs, cross-functional stakeholders who are invested in outcomes and giving remediation teams access to security tools so they can validate their own fixes. His advice: “Your best friends are those remediation and mobilization teams. Make sure you send them lunch.”
Victor reframed the question entirely: it can’t just be an ROI story — it has to be an enrichment story. Traditional metrics like “vulnerabilities closed” are misleading because a maturing program will actually identify more vulnerabilities as visibility improves. The real outcomes are operational: better capacity, faster context-sharing, broken-down silos, improved SLAs and teams that become champions for meaningful risk reduction.