Make sure that safe defaults exist, don’t expect people to reinvent wheels safely, and try to use collaborative and well-informed validation of choices rather than stage gates with all the normal queuing problems, automate security checks into local build phase if you have it, make sure that nonsense CI based security checks can be overridden by sane people, and keep track of tech debt and try to work it down consistently.