Every security team has a patch backlog, and every security team knows that a backlog is a form of accepted risk. Effective vulnerability management relies on understanding the depth of this risk. The uncomfortable question is how much risk, and for how long.