When CVE alerts pile up, teams either firefight or ignore everything. Triage, mitigate, fix, then rescan — T0 through T3, without rushing the first day.