With the increasing spend in security budgets and the apparent increasing frequency of data breaches, managing vulnerabilities in an organisation can seem like a never-ending game of blind whack-a-mole. How organisations approach vulnerability management in the past simply does not cut it with today's technology stack and development methodologies. We will discuss some of the common themes that seem to persist and look at some actions we could take to dramatically improve our overall security.