Skip to content
Small Business Engine Small Business EnginePractical ideas to power small business growth.

The Penetration Test Came Back Clean and the Ransomware Arrived Anyway: Why Continuous Threat Exposure Management Catches What Annual Assessments Cannot

A clean pentest report felt like a green light—until ransomware hit three months later. Discover why point-in-time assessments leave dangerous gaps and how Continuous Threat Exposure Management keeps SMEs protected year-round.

A manufacturing company in the East Midlands commissioned a penetration test in January. The report came back largely clean—a handful of medium-severity findings, all remediated by February. By April, the business was offline, files encrypted, and an attacker was demanding £180,000. The initial access vector? A remote desktop protocol port exposed after a routine firewall change in March, combined with a set of credentials harvested from a third-party breach that hadn't yet appeared in any internal audit.

The penetration test wasn't wrong. It was simply describing a moment in time that no longer existed.

This is not an isolated story. It is a pattern that appears to be repeating across SMEs in every sector, and it exposes a fundamental mismatch between how organisations are told to manage security risk and how attackers actually behave.

When a Clean Pentest Report Becomes a False Alibi

Penetration tests serve a legitimate purpose. A skilled red team can reveal misconfigured services, weak authentication paths, and exploitable vulnerabilities that internal teams miss. For many SMEs, commissioning an annual pentest feels like taking the right responsible step—and in a compliance context, it often satisfies an auditor's checkbox.

The problem is what happens next. The report lands, findings get triaged, critical issues get patched, and leadership breathes a sigh of relief. The pentest becomes a certificate of security rather than a snapshot of a single moment in a constantly shifting attack surface.

Cybersecurity insurers have started noticing this pattern too. Underwriters increasingly ask not just whether an organisation has conducted a pentest, but when it was done, what changed afterward, and how exposure is monitored between assessments. A twelve-month-old clean report, they have learned, tells them very little about today's risk.

For SMEs without dedicated security staff, the clean report can become something worse than useless: it becomes an alibi that discourages vigilance. Teams that might otherwise have questioned a new SaaS integration, flagged an unusual login, or reviewed firewall rules after a network change instead point to the report as evidence that security is handled.

The gap between that confidence and reality is exactly where ransomware operators make their living.

How Ransomware Exploits the Gaps Between Annual Assessments

Ransomware is rarely an impulsive crime. Modern ransomware-as-a-service operations are methodical businesses with reconnaissance phases, access brokers, dwell times, and staged deployment. Understanding their timeline reveals precisely why annual assessments fail.

Consider a typical attack sequence. An initial access broker—a specialist operator who sells footholds into compromised networks—identifies an exposed VPN appliance running firmware that was patched by the vendor six weeks ago but never updated by the target organisation. The target's last pentest was eight months ago, and that appliance wasn't vulnerable then. The broker acquires access, validates it, and sells it on a closed forum.

The ransomware affiliate who buys that access doesn't rush. They spend days or weeks moving laterally, mapping the network, identifying backup systems, and elevating privileges. Industry data consistently shows average dwell times—the period between initial access and ransomware deployment—ranging from around ten days to several weeks, though this figure varies by source and year. During all of that time, the organisation's last security assessment is still the January pentest that found nothing alarming.

Now consider everything that changes in a twelve-month window for a typical SME with fifty employees:

  • Three to five new SaaS applications are adopted, each with OAuth integrations and data access permissions
  • At least two employees leave, with offboarding that may or may not have fully revoked access
  • One or two cloud storage misconfigurations occur during infrastructure changes
  • Credentials for two or three staff members appear in third-party data breach dumps
  • Firewall rules are modified at least once, sometimes without formal change control
  • One remote access tool is added or changed to support hybrid working

Each of these events is a potential exposure event. None of them require an attacker to find a zero-day vulnerability. They simply require patience and the knowledge that many SMEs are only looking at their attack surface once a year.

The Anatomy of a Point-in-Time Security Blind Spot

Understanding why annual assessments structurally fail requires looking at what they actually measure and what they cannot.

A penetration test evaluates the attack surface as it exists on a specific date, against a defined scope agreed in advance with the target organisation. That scope is itself a limitation: testers typically assess systems that are declared in a statement of work. Shadow IT, recently added subdomains, newly misconfigured cloud buckets, and third-party integrations added since the last scope review frequently fall outside the assessment boundary.

Vulnerability assessments, often used as a lower-cost annual alternative, share the same structural flaw. They identify known vulnerabilities in software that exists at the point of the scan, but they cannot account for the vulnerability published the following week, the credential exposed in a breach that surfaces two months later, or the employee who starts using an unapproved remote access tool in the spring.

Compliance frameworks like ISO 27001, Cyber Essentials, and SOC 2 require periodic risk assessments and evidence of security controls, but the cadence they mandate—typically annual—reflects administrative practicality rather than threat reality. Auditors are not designing frameworks around attacker behaviour. They are designing them around what an organisation can reasonably document and defend in a review meeting.

The result is a security posture that looks robust on paper and in board presentations but may contain months-long windows during which changes to the environment go unmonitored, new vulnerabilities go undetected, and exposed credentials go unnoticed. For an attacker operating continuously, those windows can be more than sufficient.

What Continuous Threat Exposure Management Actually Monitors

Continuous Threat Exposure Management (CTEM) is a framework first articulated by Gartner that shifts the question from "were we secure last January?" to "where are we exposed right now, and how is that changing?"

A mature CTEM programme operates across five interconnected functions: scoping, discovery, prioritisation, validation, and mobilisation. In practice, for an SME context, this translates into a set of always-on monitoring activities that reflect how attackers actually identify and exploit targets.

External attack surface monitoring continuously maps what is visible and reachable from the internet—exposed ports, subdomains, login portals, cloud storage endpoints, and API surfaces. When a developer spins up a test environment and accidentally exposes it publicly, CTEM surfaces that within hours, not at the next annual assessment.

Dark web and credential monitoring watches for organisational email addresses, domain references, and credential dumps appearing on breach marketplaces, paste sites, and closed forums. When an employee's password is included in a third-party breach, a CTEM programme flags it before an access broker can weaponise it.

Vulnerability intelligence feeds correlate newly published CVEs against the specific software and versions running in an organisation's environment. When a critical vulnerability is published for a VPN appliance, web application framework, or cloud service in use, the exposure is flagged promptly—not at the next scheduled scan.

Configuration and posture monitoring tracks cloud infrastructure, identity provider settings, and SaaS permission states continuously. Misconfigured S3 buckets, overly permissive OAuth grants, and disabled multi-factor authentication on administrative accounts are caught in close to real time.

Threat intelligence contextualisation prioritises findings not just by CVSS severity score but by whether a vulnerability is being actively exploited in the wild, whether ransomware groups are targeting organisations of a similar profile, and whether specific indicators of compromise are relevant to the organisation's sector and geography.

The critical distinction between CTEM and a vulnerability scanner or annual pentest is not just frequency—it is the integration of these signals into a continuously updated picture of actual exposure risk, prioritised by what attackers are doing today rather than what a compliance framework asked about twelve months ago.

Matching Your Defense Cadence to How Attackers Really Operate

The commercial cybercrime ecosystem operates at a pace that annual assessments were never designed to match. Access brokers scan the internet continuously using automated tools. Vulnerability researchers—both ethical and criminal—publish new findings weekly. Ransomware affiliates are opportunistic: they buy access when it becomes available, not on a schedule that respects your pentest calendar.

Defending against this requires matching your detection and response cadence to attacker operational tempo, not to compliance review cycles.

For SMEs, this does not mean building a twenty-four-hour security operations centre. It means selecting tools, services, and processes that provide continuous visibility without demanding continuous human attention. The goal is to compress the time between an exposure event occurring and your team knowing about it—from months to hours.

Consider the difference in outcomes for two organisations facing the same scenario: a critical vulnerability is published for a remote access product both organisations use.

Organisation A relies on annual assessments. The vulnerability was published in May. Their next scheduled scan is in September. They patch it in October, potentially eight months after disclosure, during which time the vulnerability may have been actively exploited by multiple ransomware groups.

Organisation B has a CTEM programme in place. Within forty-eight hours of the vulnerability being published, they receive an alert that their specific product version is affected and that exploit code is publicly available. They patch within seventy-two hours of disclosure, before the vulnerability enters widespread criminal exploitation.

The difference is not technical sophistication—both organisations used the same product. The difference is awareness cadence.

Effective CTEM also changes how SMEs respond to the ordinary events of running a business—onboarding a new vendor, migrating data to a new cloud provider, launching a customer portal—by treating each as a potential exposure event that warrants immediate visibility rather than something to be picked up at the next assessment.

Building a CTEM Program That SMEs Can Realistically Sustain

The most common objection to Continuous Threat Exposure Management from SME leadership is that it sounds like an enterprise solution requiring enterprise resources. The managed security services market has evolved considerably, and SMEs can now access CTEM capabilities through managed service providers that operate as an outsourced security function, delivering continuous monitoring, prioritised alerts, and expert analysis without requiring an in-house security team—though costs and capabilities vary significantly between providers.

Here is a practical framework for SMEs building or evaluating a CTEM programme:

Start with your external attack surface. Before monitoring internal systems, understand what is visible from the internet. External attack surface management tools—many available at a price point appropriate for SMEs—can map your digital perimeter continuously and alert you to changes. This is the layer attackers probe first, and it is where initial access most commonly occurs.

Add credential and dark web monitoring immediately. This is one of the highest-value, lowest-cost additions to any SME security programme. Services that monitor for your domain's credentials in breach data provide early warning of one of the most common ransomware precursors—compromised authentication credentials—at a fraction of the cost of a single incident.

Integrate vulnerability intelligence with your asset inventory. A vulnerability scanner that runs weekly against a known asset list is substantially more effective than an annual assessment. Pair it with threat intelligence feeds that prioritise findings based on active exploitation, not just theoretical severity scores.

Establish a rapid patching cadence for internet-facing systems. CTEM is only valuable if findings lead to action. SMEs should establish explicit patching SLAs—typically seventy-two hours for critical vulnerabilities in internet-facing systems, thirty days for high-severity findings across internal systems—and treat these as operational commitments rather than aspirational targets.

Use compliance frameworks as a floor, not a ceiling. If your organisation operates under ISO 27001, Cyber Essentials Plus, SOC 2, or a sector-specific framework, those requirements establish a baseline. A CTEM programme should exceed those baselines, using compliance evidence as a byproduct of continuous monitoring rather than the primary motivation for it.

Partner with a managed CTEM provider if internal capacity is limited. For organisations without a dedicated security function, a managed CTEM provider offers expertise, tooling, and continuous monitoring that would be prohibitively expensive to build internally. The key is ensuring the provider offers active prioritisation and contextualisation—not just a feed of unfiltered alerts that overwhelm a small team.

Review and communicate exposure posture monthly. One of the under-appreciated benefits of CTEM is the ability to report to leadership and to auditors on a rolling basis. Monthly exposure briefings—showing what was detected, what was remediated, and what residual risk exists—replace the annual report with a living picture of security posture that is far more defensible to insurers, regulators, and customers.

The SMEs that navigate the next wave of ransomware successfully will not necessarily be those with the largest security budgets. They will more likely be those that abandoned the assumption that a clean report from last January means anything about today's threat landscape, and replaced it with the discipline to monitor continuously, respond rapidly, and treat their attack surface as the living, changing environment it actually is.

A penetration test tells you where you were. Continuous Threat Exposure Management tells you where you are—and where attackers are already looking.

Continuous Threat Exposure ManagementCTEMransomwarepenetration testingSME securityattack surface managementmanaged securitycybersecurity
← All posts