>> What is the security risk? > > Management ? :) There could be a perceived problem that the world now knows that "company X has problems with OpenSSL", and a competitor could even try to make mischievous use of this "information" - it happened to me once (with another technology). Death of developer mailing lists predicted; film at 11.