Taking technical security knowledge and putting it to work in a huge organization many challenges. Among them, how do you communicate technical needs to non‐technical people responsible for funding and other key decisions, and then deliver something useful and cost‐effective? In this presentation, I plan to use the case study of the Global Vulnerability Management program in my organization to discuss the following: i) What are we trying to do here: Just what is a global threat and vulnerability management program about? What kind of threats does a large organization face? Are they different than a smaller one? ii) What are the problems we face: Just what kind of threats do we face? How do you get accurate threat information? How do you convey the seriousness of these issues? How do you co‐coordinate resources? How do you deal with regulators and auditors? How does a techie get his point across in a massive corporate environment? iii) What was our approach: Technologies we bought, technologies we had to buy. Processes we had to implement and things we had to concede. Making tools are not things that they may not be advertised for. Working with different teams from different fields. iv) Some more on tools: What’s good? What’s bad? How do you deal with the bad? Why are there so many vendors and how come none of them make what I need? v) Dealing with regulators and audit issues: Not the most interesting topic, and it drives you nuts, but we need to talk about it (only briefly though). vi) The future: Where are we going with this?