Agentic AI Closes the CTEM Loop, Filigran Argues

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Filigran cites that enterprise security teams run 40+ tools on average that work in silos, generating overlapping alerts, while breach dwell times average ~43 days and analysts burn out triaging noise.
- Gartner's CTEM framework is described as a continuous cycle of scoping, discovery, prioritization, validation, and mobilization, but most organizations can't operationalize it end-to-end because their specialized tools don't interoperate.
- Assistive AI (summarizing, translating, retrieving on demand) is explicitly distinguished from agentic AI, which autonomously correlates threat intelligence against live exposure surfaces, validates controls, and prioritizes fixes at machine speed.
- Filigran identifies three functions that must operate as a closed loop with AI agents handing off tasks across systems: operationalizing threat intelligence, testing and validating security posture, and mobilizing response.
- XTM One CTEM Assistant is presented as an example of an agentic threat management architecture, with a dedicated AI orchestration layer connecting agents across products while keeping humans in the loop for final decisions.
- Filigran is hosting a live webinar demonstrating how agentic AI connects intelligence, exposure validation, and response into a single continuous workflow without handoff gaps.
Why it matters: Filigran frames agentic AI as the orchestration layer that turns Gartner's CTEM from a strategy-deck framework into a running program; the cited 43-day breach dwell time and 40-tool average stack are the specific costs of the current siloed architecture this approach targets.




