How to ensure the ‘organisational memory’ of past vulnerabilities is not lost.