On a Tuesday afternoon in the operations center of a mid-size financial services firm, a security analyst finishes her weekly vulnerability scan and scrolls to the top of the results. The finding near the top isn’t alarming in an unusual way: a remote code execution flaw with a CVSS score of 9.8, a patch available for more than a month, but no indication that anyone had applied it. She creates a ticket, logs the asset identifier from her scanner as PRODWEB-042, marks it P1, assigns it to IT operations, and moves down the list.