Compare IT systems against current vulnerabilities
Check patch and software versions of all systems
Grade non-compliant systems against severity of the vulnerability
Implement a system of remediation and automated patching to improve compliance
Investigate whether lack of security patches had led to a successfull breach