Prioritise: the small set of products that carry most of the risk. Fix these first and the whole portfolio moves.
Risk weight per CVE = normalised severity × exploitability × asset-context multiplier (network-facing or crown-jewel products count double). Products are ranked by the sum of their CVE risk weights.
Pareto read: the curve tells you what share of total risk you remove by patching the top N products — typically 20% of products carry 60–80% of the risk.
Use it to: plan the monthly patch sprint, justify vendor consolidation, and pre-book change windows for the top rows.