having audited tons of high risk orgs, and being on calls with companies daily, i always find it shocking at the level of security maintained internally vs the level of security companies communicate externally. most companies still run their security programs in a negligent manner, and worse yet don’t actually care about security. the most important goal for them is to appear secure. expert security theatre, and this is part of what motivates me to bring new levels of transparency to how software systems are built