Penetration testing produces some of the best evidence a security program ever generates. This paper traces what happens to it next, from raw tool output to a validated finding to a prioritized, verified fix.
Penetration Testing & Continuous Exposure Management
Four Concepts the Paper Ties Together
CTEM
Gartner's five-stage cycle that treats offensive testing and vulnerability management as one continuous program instead of two disconnected tracks.
AEV (Adversarial Exposure Validation)
Automated, continuous evidence of what's actually exploitable, running alongside human-led testing, not replacing it.
Validated Findings
A pentest finding carries proof a scanner alert can't: a human confirmed it, chained it, and documented the real impact.

PlexTrac's Role
The reporting and workflow layer testers use to evidence and structure findings, feeding a unified exposure program without running the test itself.
Read the Whitepaper:
Click to expand ↗
Common Questions: What Security Leaders Ask About This
AEV is a technology category, defined by Gartner in its March 2026 Market Guide, that delivers continuous, automated evidence of whether an attack would actually succeed, rather than a theoretical prediction. It runs alongside human-led testing rather than replacing it.
A scanner alert is an inference, a version string matched a known CVE. A penetration testing finding comes from a human who exploited the issue and documented the real business impact, which is why validated findings should be weighted higher in prioritization.
No. Human testers provide the judgment and chaining no automated layer supplies. Carrying their findings further into the organization increases the reach of that work, it doesn't automate it away.
CTEM is Gartner's five-stage framework, scope, discover, prioritize, validate, mobilize, for running exposure work as one continuous program. Penetration testing and AEV both live in the validate stage; exposure management spans the full cycle.
