Earlier quoted context omitted.
>Why are we blaming PMs, here? Plenty of engineers out there make really stupid decisions every day. EXACTLY! Because it's a known fact all devs make mistakes, and as such, as a product manager/owner you're responsible for the bigger picture of the product and ensuring the right requirements, checks and bound are put in palce and validated for a successful product release. It's not the job of the lowly SW engineers w…
I hope this is facetious. Security is everyone’s job, and unencrypted customer data, outside of a locked-down DB, should give one pause.
First, the vast majority of people are not equipped to find or address major security issues well. Unless you have specialists integrated in the right places this means everyone's likely to be bad at the security part of their job and ill-equipped to notice.
Second, this means conflicts of interest everywhere. When you have a dedicated security org, you have people whose job it is to catch issues, hold things up, and generally make sure things get fixed. Without that, you have a bunch of people who have to choose between the possibility of a security event they don't understand and the certainty of blowing a deadline.
Third, security being everyone's job almost certainly means accountability is broken. Consequences will likely fall on some junior employee who might be directly accountable for an issue, but the huge org around them that did not enable them to succeed go unaffected.
You need specialists, an org to enable them, and an enterprise-wide apparatus to support a strong security process.