Coordinated vulnerability disclosure is now an EU obligation, but cultural change takes time