As a CISO, I grow weary hearing that developers need to be trained in how to write secure code. A whole industry around writing secure code has sprung up. Unless you are in the DoD, NSA, CIA or protecting ring zero, you are not writing secure code. It is a developers defect. When a developer does not validate input, it is not a security bug. When error conditions are not handled properly. When devices are not configured properly. It is because of poor architecture, design and development. When applications fail open it is. not because of a security. bug.”]

