Over the last ten years a fast growing number of organizations, from the largest of the large to the smallest of the small, are truly starting to "get" Web application security. They are also learning that application security success does not happen overnight. Experience and results, especially results, takes time. Some organizations have indeed demonstrated an ability to improve faster than others. The question is, how? What separates the leaders from the laggards is the way their teams utilize time and allocate resources to best facilitate application security maturity. Having worked with hundreds of organizations, many of which easily considered leaders in their industry, what I've found is a consistent set of stages that characterize where on the maturity continuum they are located. This is insight is key. An application security professional's ability to quickly identify a given organizations current stage of maturity is vital. For example, a trusted advisor may provide a new student different guidance than to that of a subject matter expert facing identical challenges. It is all about isolating needs, encouraging progression, and serving outcomes that are in the best interests of all involved. By sharing my related personal experiences I hope to facilitate the application maturity of the entire industry.