
Application security has traditionally been positioned as corporate insurance against financial losses. This perspective has spawned numerous counterproductive phrases that undermine the discipline.
Ten Problematic Mindsets in AppSec
Keep The Company Off the Front Page Fear-based messaging is ineffective when breaches occur so regularly that public impact is minimal for most organizations.
Security is Non-Functional The notion that security exists outside business functions ignores reality—security is a prioritized requirement like any other business need.
Security is a Burden On Developers Securing software isn’t inherently difficult. Real challenges stem from interpersonal dynamics, technology choices, and internal narratives rather than technical complexity.
Focusing on Negatives of Security Testing Strategies Vendors criticize competing approaches while claiming superiority. Each methodology—static analysis, dynamic testing, threat modeling—serves distinct purposes with varying strengths.
Security is a Speed Bump When integrated into engineering practices, security accelerates development by forcing thoughtful design.
False Positives Are A Negative Achieving accurate detection requires some tolerance for imprecision. Balancing false positives and false negatives is inherent to effective security testing.
Reachability and Exploitability This argument overlooks that fixes may be simple (library upgrades), and technical debt compounds vulnerability risk over time.
Security is Expensive This strawman argument ignores that security investments reduce overall production costs through improved engineering practices.
Developers Do Not Know How To Secure Things Condescending communication about developer capability differs sharply from how other professions handle continuing education.
Focusing on risk Excessive risk prioritization creates opportunity costs, missing chances for systemic improvements and developer training.
Reframing AppSec Messaging

Security professionals must shift from enablers of poor development practices to advocates for genuine improvement. The messaging should emphasize positive outcomes:
Security Lowers The Cost Of Production — Planning and consideration identify gaps earlier, reducing downstream remediation expenses.
Software Security Improves the SDLC — Vulnerability discoveries highlight process improvements and systemic gaps.
Software Security Builds Customer Trust — Consumer expectations for data protection apply across all demographics.
Software Engineers Need Continuing Education — This reframing normalizes security knowledge building alongside other professional development.
A Comprehensive Program Leads To Success — No single testing tool solves all problems; integrated approaches work better than isolated solutions.
The Path Forward
Modern development velocity and AI-assisted code generation intensify testing challenges. Application Security professionals must collaborate to build comprehensive, developer-friendly programs that treat security as core engineering practice rather than compliance burden.