Delivery pressure? You can't win this battle.
And you don't have to. A bucket of ice cream once in a while is fine.
The Checkmarx Future of Application Security 2026 report found that 81% of organizations admit to knowingly shipping vulnerable code under deadline pressure.
Are you tired of this battle? Tired of running after your DEV teams, explaining why security matters over and over again? For me, it felt like the most annoying part of the job. How can they be so careless?!
I already fought this battle back when I was a developer. I wanted to fix security issues, fight technical debt, and update dependencies to make sure we wouldn’t have to deal with them when they became urgent. I might have been annoying, and I was proud of that. Even more so once I became the AppSec Lead.
I mean, being annoying was now part of my official job description. #YOLO…
I had to make sure our software was secure. AppSec was MY responsibility and I would fight for it.
But wait… Is annoying each other really the relationship we want with our DEV teams? Aren’t we on the same mission?
Same boat, different mission.
Of course, if there is a battle going on, we can’t be on the same mission.
Our mission as AppSec Leads is clear: Make sure the software we ship is as secure as possible. We want to make the internet a bit more secure every day. We want to protect our end-user’s data. We want to protect our company from being hacked. That’s our job. And the developers don’t get it.
According to the Invicti Executive Overconfidence Survey, 49% of security professionals encounter developer resistance. Only 20% of developers believe this resistance exists. #ToldYouSo
Have you been a developer yourself? Did you love fixing bugs and vulnerabilities? Upgrading dependencies? Fixing deployment issues? Refactoring old code? Writing tests? If you’re now in security, probably yes. But that’s not the norm.
Your DEV teams are expected to ship features. As long as their customer is happy and the software works, they are usually happy, too. If not, they need to fix bugs which can be pretty annoying. If their customer doesn’t complain about security, then why bother with another annoying task?
Secure Code Warrior’s 2022 survey found that 86% of developers don’t view application security as a top priority. Only 29% believe the active practice of writing code free of vulnerabilities should be prioritized at all.
This conflict between delivery speed and security will always exist. There is nothing wrong with that. It is important, because it keeps both qualities in balance.
If we only deliver fast and never secure anything, we will get screwed. If we secure everything to death and never deliver, we will get screwed, too. Why? Because our company will run out of money to pay our salaries. Either way, the company doesn’t survive.
Same boat, same mission.
We just learned that the company needs both qualities: security AND speed. They need to balance each other. The problem is: nobody knows where the perfect balance is found. So we keep fighting with two different missions ignoring the bigger mission.
To understand this better, let’s take a look at another organism. You. Your body.
Your pancreas produces two hormones that fight each other. Insulin wants to bring your blood sugar down. Glucagon wants to bring it up. They both even come from the same organ, just different cells with different missions.
Or are they on the same mission?
Let’s see: If Insulin would win the battle, your blood sugar would become too low. That would kill you. If Glucagon would win or Insulin was just not present, that would also kill you. #Diabetes
It’s not about winning a battle. It’s about balance.
Two sides of the same coin, keeping your blood sugar in a healthy range.
Stop fighting, start balancing.
So what can we learn from Insulin and Glucagon?
Your company’s mission is to produce software that serves its customers best. Build something they are happy to pay for. And don't get wiped out by the next incident.
On one side we have developers, who write new code, build new features and meanwhile increase the risk for vulnerabilities. Without them, the company would not make any money. #Glucagon
On the other side we have the security team, who tries to catch up with development speed and reduce the risk to a tolerable level. Without them: Game over. #Insulin
Like in your body, the curve is never flat. It spikes, it comes down. The same goes for your risk. When delivery pressure is high, risk will spike. But everyone should be aware of the spike and agree to regulate it down. #ASAP
ASAP doesn’t mean it can wait for the next five spikes in a row. It means after the high delivery pressure spike, we need to be disciplined and tidy up the mess. That’s the deal.
The spike should never become too high, as this might cause permanent damage. Therefore, we need to agree on a minimum security standard we always keep. #NoExceptions
The spike should never last too long, as this could also cause permanent damage. Therefore, we need to agree on a short term roadmap to bring risk down. #NextSprint
Security’s job is managing risk, not blocking delivery. A bucket of ice cream once in a while is fine. It’s the daily habit that gives you diabetes. #HealthyHabits
Instead of fighting delivery pressure, communicate with your DEV teams. Be flexible. Find ways to keep risk in a tolerable range together. It’s not a battle. It’s a cooperation.
Keep in mind: Without a product, there is nothing to secure.
Security is just a means to that end. What would life be without ice cream? #YOLO
Ready to optimize your AppSec system for resilience?
Subscribe for weekly insights. Written from the road, delivered to your inbox. Every edition is a workout for the right mindset: moving from control to trust, from restrictions to resilience, from compliance to ownership.


