@jrdepriest @phnt @sjvn @lanodan
So my question was about how a small-to-medium company (eg. one whose product is a website) that can't dedicate a whole person to patch management could approach this problem without resorting to "get CVE scanner, filter by severity == critical, cry in a corner because there's still too much stuff".