Risk matrix is a tool used to prioritize vulnerabilities based on their risk level, which helps organizations determine the order in which vulnerabilities should be addressed. By calculating vulnerability risk, enterprises can assign a risk level to vulnerabilities and assets to help determine how vulnerabilities are addressed.