In my opinion, the only true solution is to slow down “velocity” in development teams. If the developers are to be held responsible for producing good, secure code, Only the developers can decide when a feature is ready, not the business.<p>If the business wants to dictate deadlines, the business is responsible for security.<p>Edit: I should say development team to include qa, but we don’t have those anymore at most places.