I'd add putting in a static code analysis tool in there because that will give you a number for how bad it is (total number of issues at level 1 will do), and that number can be given to upper management, and then whilst doing all the above you can show that the number is going down.
The results might also be overwhelming in the beginning.
I can listen whatever I want via Spotify. If I like the album that much, I can buy it via iTunes or their store, however finding lossless versions are hard.
If I really love the album, I'll buy its vinyl.
If I don't plan to buy the vinyl, and can't find the lossless version or a decent priced CD, I buy the album online and find the lossless version elsewhere.
I'm a former orchestra player. I know how tedious and draining producing music is. It's unethical to just download it and let it be. Before, it was impossible to get decent music without being gouged, so I had to download some of the albums, but it's no more now. Buying prices are accessible, storage is ample, and syncing is easy.
There's no need to screw musicians over it.
I'm not a big movie buff anyway, so if I can stream it legally, I'm fine.
Try Bandcamp.