0. If I had budget authority, I would've ordered something which could grab memory and disk images on a live system and sign-up multiple .edu researchers & symantec security group and equivalent shops under NDA to analyze them.
1. And I would've yanked all those janky (R)ILO (aka RMSA, aka DRAC) cards with their always outdated Linux / Java / PHP "wifi router"-like whatever embedded systems.
2. Finally, I would've spent some cash on honeynet setups and cc: to item 0.
Edit^2: Props to Josh Wieder for taking sounding the sec awareness alarm. I would only do active sec research on untrusted materials within a decent hypervisor's VM on a virtual desktop (VDI) which has "nonpersistence" on all storage, so it's clean on every power cycle.