This post is based on Mackenzie's conversation with Arun Singh on The Secure Disclosure podcast. Listen to the full episode or watch below. In leading security for major Australian fintechs, Arun Singh has learned that "You could be the Einstein of cybersecurity, but if you cannot influence the business, you're no good." Implementing a new security control developers hate influences the business, but not in a good way. Singh learned this lesson early in his career, when he made the decision to remove local administrator rights across every workstation in the company. For 90% of users, it went fine. But the small cohort of software engineers who needed system-level access beyond just installing applications had their productivity completely destroyed. His team found the right compromise in days, but the trust took a year to rebuild. "Any time I'd go and talk to them about a new control, it was a hard-fought battle." The problem compounds at scale. Mike Wilkes, Aikido Security's Enterprise CISO, argues most enterprise security rollouts fail because they're run like software deployments when they're actually cultural changes. At 5,000 engineers, trust isn't something you rebuild one conversation at a time. The supply chain twist Singh's recent board conversations at Tyro have centered on supply chain attacks, and the conventional security wisdom that has been drilled into developers can, counterintuitively, make the problem worse. "We've been advocating for developers and other security folk to keep their packages and dependences up to date. It is something that we have ingrained in them for years. And threat actors have used that teaching to start compromising these companies." Singh's team now advocates a 7-day cooldown period for any new package version. That means telling developers to do the opposite of what security has told them for years. You want to patch