Earlier quoted context omitted.
Only because most organizations don't know how to be effective at security. It's not hard. You don't actually have to change much. You just have to schedule regular pentests, ideally every couple weeks. Pentests protect everyone because it's our job to worry about all of the security flaws that you can't possibly be aware of in your normal day-to-day development cycle. There's just too much for any organization to kn…
"It's not hard." No, it is not, you just need skilled people working on it. Oh, those people want money for it ...
It's exactly the same as physical security. You build fences and buy locks. You pay people to keep an eye on things. You take insurance to cover the rest of the risk.
Nothing hard, no new inventions required. It just takes some attention and cash. It's part of the cost of being in business.