Understand the machine
The Phoenix Project
Security problems are usually systems problems. Ask why the secure path is harder than the insecure one.
Security problems are often systems problems disguised as technical problems, and this book shows that better than almost anything I have read.
Some of the technology in the story feels dated now, but the underlying lesson has aged well: organizations fail when work piles up, dependencies are invisible, bottlenecks are ignored, and heroics become the operating model.
Security teams fall into this trap constantly. A vulnerability queue grows faster than engineers can remediate it. Security adds another approval step. Developers find a way around it. Everyone gets frustrated, and eventually the organization concludes that security is slowing the business down.
The better question is not “how do we make developers comply?” It is “why is the secure path harder than the insecure one?” Security should operate as part of the value stream, not as a gate bolted onto the end of it.