Understand patterns: a vendor scorecard for contract SLAs, portfolio consolidation, and executive vendor reviews.
Vendor risk index = normalised (severity × exploitability × weakness recurrence). Big vendors don't win by being big; a small vendor with recurring critical CVEs ranks worse than a large vendor with clean hygiene.
Contract SLA use: require top-N vendors to publish CVE-fix SLAs (Critical ≤ 7 days, High ≤ 30) and monthly security roadmaps. Reference this scorecard in renewals.
Consolidation: when two vendors overlap in capability, prefer the lower-index vendor and plan migration for the higher one.