The patch incoming rate is dizzying. We have OS patches, application
patches, firmware patches. All need to be tested and deployed. It’s a never ending race with seemingly no
finish line of three of our teams against one potential event.
The vulnerability risk score can become what’s important and
what’s reported. It’s a metric that easily generated but often needs
explanation to execs. It is also really hard to compare your score against others in your
industry or company size.
Only vendors can fix the risk score problem
