IT-centric vulnerability management does not work in critical infrastructure, and the volume of known, unpatched vulnerabilities in a large multi-site operator runs well beyond what any patch program could address. The article should examine why the standard model fails — CVSS scores that measure IT exploitability rather than consequence to a physical process, patch timelines that assume change windows OT cannot provide, and asset inventories that are incomplete by default — and what actually works instead. The functional alternative is consequence-based prioritization: a crown-jewel analysis that asks which assets, if compromised, produce an unacceptable physical, safety, or service outcome, and concentrates limited resources there. But the article should be honest that building such a model requires process knowledge security teams often lack and that getting the basics right — knowing what you have, where it is, and how it connects — is far harder in the field, with small teams and tiny budgets, than the literature admits. It should treat compensating controls for unpatchable systems, the legacy-equipment problem where no patch will ever exist, and how prioritization must adapt across a multi-site operator where every site has a different asset population. These lessons are universal across critical infrastructure.