If you are like the many organizations out there, you have a large number of unaddressed vulnerabilities. The question lies, where to start? Which vulnerabilities are most important and why? Can you rely on CVSS or an arbitrary risk score alone? This presentation and discussion will address how I have worked with organizations in the past to tackle these challenges and what your organization can do about it.