    • How do folks learn what the right things to think about when it comes to breaking stuff as they write code? It feels like there is a balance of doing enough at the right time as well. Is this something that gets talked about explicitly as folks join? To me, it feels like the general developer may just happen to find out about security concerns rather than it being distilled practices. I know in my CS degree it wasn't a focus at all, and many companies I've been at didn't have any kind of security program/plan.