Most companies use vulnerability scanning software to interrogate their computer assets. The theory is that you run the scanner, get a ranked list of vulnerabilities on each computer, and fix them. But theory rarely ends up becoming practice. Resolve the highest-risk, most critical vulnerabilities first: Resolve your most critical servers and admin users computers, then move on to the less critical computers and users. Some of the best patch management software programs can detect tens of thousands of different programs.”]
Source: https://www.csoonline.com/article/2929792/time-to-address-your-100-000-security-vulnerabilities.html

