Why has secure development been a core focus from the very first days of Trustworthy Computing? Many security professionals would argue that by 2002, the security industry had already identified security development techniques, tools, and in some cases, implemented defense-in-depth code protections. However, some important lessons cannot be learned until efforts are made to apply best practices at scale and this is certainly true of security development practices. Computing and the software industry are measured by the pace of innovation, so if we want to deliver technology that people will trust with their personal, professional, and financial data, we must ensure that we have the tools and techniques to build secure, private and reliable products and services.