A risk operations center is an operating model for continuously measuring, prioritizing and reducing risk, in the way a security operations center handles threats; DigitalXForce’s implementation is X-ROC, the XForce Risk Operations Center. Continuous threat exposure management (CTEM) is Gartner’s term for a program that continuously finds, prioritizes and validates the exposures an attacker could use. A risk operations center (ROC) works on risk to the business, including failed controls, posture changes and vendor events. It ranks each item by quantified business impact and closes a finding only when the control passes a retest.
Our explainer on what a risk operations center is covers the model in full. Two earlier posts set it beside a security operations center and describe the vendors that use the name.
What Gartner means by CTEM
Gartner listed CTEM among its top 10 strategic technology trends for 2024. Its ebook on those trends, published in 2023, calls CTEM “a pragmatic and systemic approach to continuously adjust cybersecurity optimization priorities”. A CTEM program runs in five stages, which Gartner names scoping, discovery, prioritization, validation and mobilization.
Each CTEM cycle is aligned with a specific business project or a critical threat vector. The program covers exposures that can be patched, such as vulnerabilities, and exposures that cannot. It checks its priorities by looking at them as an attacker would and by testing whether the security controls work. Gartner also advises tying CTEM to the organization’s risk management program, so that fixes are ranked by their value to the business.
What each one takes in and puts out
| Continuous threat exposure management (CTEM) | Risk operations center | |
|---|---|---|
| What it works on | CTEM works on exposures to attack, whether or not they can be patched. | A risk operations center works on any risk to the business, including risks that need no attacker at all. |
| What it takes in | Each CTEM cycle takes in a scope, such as a business project or a critical threat vector, and the exposures that discovery finds inside it. | A risk operations center takes in alerts about failed controls, posture changes and vendor events, with the evidence attached. |
| How it ranks work | CTEM ranks exposures and checks the ranking against the attacker's view and against tests of the security controls. | A risk operations center ranks each item by quantified business impact, meaning the loss the organization would face if the risk materializes. |
| When it tests | In Gartner's order of stages, validation comes before mobilization, so the test helps decide what to fix first. | A risk operations center tests again after the fix, and a finding closes only when the control passes the retest. |
| What it puts out | CTEM puts out a validated set of priorities and mobilizes the teams that own the fixes. | A risk operations center puts out a ranked queue, escalates what stalls and reports on what is still open. |
| What it hands the other | CTEM hands over validated exposures that need an owner, a business impact figure or a risk decision. | A risk operations center tells the CTEM program which systems and controls carry the most business impact. |
Where CTEM and a ROC overlap
Both models run continuously, and both prioritize. That shared step is also where the two can disagree about the same weakness. An exposure on a retired marketing microsite may be easy for an attacker to reach. It can still sit low in the risk queue, since little of the business depends on that site.
A risk operations center already ranks its work by quantified business impact. Quantified impact is one way to supply the business value Gartner asks for, so the two lists can share one order.
Where CTEM and a ROC differ
A risk operations center starts from the business rather than from the attacker, so its queue also holds items that need no attacker at all. A control that failed its test is one example, and an event at a supplier is another.
The two also test at different moments. In Gartner’s order of stages, validation comes before mobilization, and the ebook presents it as a check on priorities. A risk operations center puts its deciding test after the fix. The control is tested again, and the finding closes only when the retest passes.
How CTEM and a ROC hand work to each other
Mobilization is the last of Gartner’s five stages, and it is about getting other teams to act. The system that needs the change usually belongs to someone other than the security team. Gartner gave that stage its own name, which will surprise nobody who has asked another team to patch a server on a Friday.
In our view, a validated exposure that needs a fix belongs in the risk queue from that point. It gets an owner and a business impact rank in that queue, and it stays open until a retest passes. An exposure that cannot be patched still needs an owner. In a risk operations center it gets one, and the business then chooses a compensating control or formally accepts the risk.
Work also flows back the other way. The risk queue shows which systems and controls carry the most business impact. That tells the next CTEM cycle which business project or threat vector to scope first.
How X-ROC runs the risk side
X-ROC sits on the risk side of this handoff. X-ROC, the XForce Risk Operations Center, is the operations layer of the DigitalXForce TRiSCM platform, where control failures, risk changes and vendor events are alerted, triaged, escalated and reported. TRiSCM™, or Trust, Risk, Security and Compliance Management, is a category of enterprise software defined by DigitalXForce that converges automated governance, risk and compliance with security posture management into a single real-time system, replacing periodic control validation with continuous control assurance.
X-ROC takes in failed controls, posture changes and vendor events as alerts, with the evidence attached. Every test result is stored with a timestamp and the evidence the test read, and the compliance dashboards show how old that evidence is.
X-ROC triages alerts, escalates them and tracks remediation to closure. Triage ranks alerts by business impact rather than by a severity label alone. X-ROC measures that impact with cyber risk quantification. Cyber risk quantification (CRQ) quantifies a cyber risk in dollars, giving the financial loss the organization would face if the risk materializes. DigitalXForce quantifies cyber risk with its own model, built on industry best practices and the data the platform collects.
When the alert is a failed control, the control is tested again once the fix is marked done, and the finding closes only when the retest passes. X-ROC never changes a client’s systems on its own. Remediation tickets go to ServiceNow or Jira when the client wants them there.
The retest is where X-ROC meets control assurance. Continuous Control Assurance (CCA) uses evidence, monitoring and validation to determine whether controls continue to operate as expected. Continuous Control Monitoring (CCM) monitors conditions, evidence and signals associated with controls, and CCM is a capability within CCA. The X-ROC product page describes the six steps every item goes through. The DigitalXForce glossary defines every term used here.
Every conclusion from the platform’s AI links back to the evidence it used. An analyst reviews the output of AI JedAI, the DigitalXForce AI engine that analyzes, and of XForce GPT, the DigitalXForce generative AI engine that writes, before anyone relies on it.
Questions about risk operations centers and CTEM
What is the difference between a risk operations center and CTEM?
Continuous threat exposure management (CTEM) is Gartner’s term for a program that continuously finds, prioritizes and validates the exposures an attacker could use. A risk operations center covers a wider set of risks to the business, such as failed controls and vendor events. It ranks them by quantified business impact. DigitalXForce’s implementation is X-ROC, the XForce Risk Operations Center.
Does a risk operations center replace a CTEM program?
A risk operations center does not replace a CTEM program. CTEM finds exposures and validates them from the attacker’s side. The risk operations center ranks them with everything else by business impact and keeps each one open until a retest passes.
How do CTEM and a risk operations center hand work to each other?
Mobilization, the last CTEM stage, moves validated exposures to the teams that must fix them. The risk operations center gives each one an owner, a business impact rank and a closing test. In return, it shows the CTEM program where the business impact is highest, which helps the next cycle choose its scope.
How does X-ROC close a finding?
When the alert is a failed control, the control is tested again once the fix is marked done, and the finding closes only when the retest passes. Every test result is stored with a timestamp and the evidence the test read, and the compliance dashboards show how old that evidence is. X-ROC never changes a client’s systems on its own.
See it on your own data
DigitalXForce serves mid-size and large organizations, and a 30 minute walkthrough on your own frameworks and integrations is the fastest way to see how X-ROC would rank and close your alerts. You leave with a mapped control set and a view of what continuous monitoring would surface in your environment.



