---
title: Software Security's Journey to the Mainstream
description: Software security has come a long way from its bumpy start, with developers now able to proactively prevent vulnerabilities.
image: https://true-positives.com/hubfs/software-security-tools-journey-to-the-mainstream-header.webp
---

[Skip to content](https://true-positives.com/appsec-blog/software-securitys-journey-to-the-mainstream#main-content)

[![True Positives](https://true-positives.com/hubfs/HubSpot%20Header%20Logo%20-%20500x125-1.png)](https://true-positives.com/?hsLang=en)

- Resources 
    - [Vulnerability Atlas](https://vulnerability-atlas.true-positives.com/index.html)

![man using software security tools that are now mainstream](https://true-positives.com/hubfs/software-security-tools-journey-to-the-mainstream-header.webp)

# Software Security's Journey to the Mainstream

![True Positives](https://true-positives.com/hubfs/T+%20%20Logo%20Webpage%20Header%20(1200%20X%20600)%2001%2009%202026-2.svg)

[True Positives January 19, 2023](https://true-positives.com/appsec-blog/author/true-positives)

- 3 mins

It’s 2023. Threats aren’t just a consideration, they are a priority in the software industry. As a result, Product Engineering and DevOps teams have taken a more proactive role in the prevention of vulnerabilities. There is nothing more embarrassing to a developer than finding out your luxury home is actually a house of cards in front of stakeholders due to a bug that could have easily been detected with a testing tool.

Luckily, for everyone involved, we have the technology today to find potentially harmful coding errors before they can cause harm. But that hasn’t always been the case.

Let's take a trip in the 'way back machine' to the early days of software development and the bumpy start of software security.

 

## In the Beginning…

About two decades ago, key stakeholders of a well-known software firm attended a meeting about their firm's website security. On the agenda was a read-out of the results of an external penetration test conducted by a troupe of ethical hackers. This team built a reputation for being skilled at what they do and was being sought out to conduct these assessments.

We were only moments into the meeting before the company’s top developers exited the room, muttering expletives in embarrassment for what they had missed and frustration for what now must be fixed.

 

### Bad News Travels Fast

Word soon traveled through the company of an easy-to-exploit code flaw found in production. The simple fix wasn't possible, and attempts at remediation only made it worse. The devastating effects of this flaw spared no one. The landscape of application security as we knew it had just been forever altered.

 

## The White Hats are Coming!

The only people at the time with the skills to spot exploitable code were called 'Hackers' and akin to practitioners of the dark arts! To most they were criminals, causing havoc and stealing data, money, and access to private, public, and government systems.

From them arose a moral sect with pure intent; to become known as "white hat hackers”. These were good guys, the security heroes, who could be dispatched to find security bugs in software, both great and small.

Following their arrival and growing utilization came a rush of security-related triage and rework causing mostly panic.  The chaos that was created and the increased work that followed greatly impacted engineers and developers. They were completely unaware of how the flakes of software security awareness would snowball and just keep rolling, accumulating until it was clear that security issues weren’t going away and better tools were needed to detect them.

Although the ability to spot code vulnerabilities with the help of an automated "crawler" or "scanner" was slowly developing, the ability to be proactive was still unattainable due to the high cost of tools and staff. While the creation of software also created billionaires, the importance of software security was barely a thought. Only a few contemplated the future problems that would cause terror in the world. It only took a few global attacks and major public threats before the importance of trustworthy systems began to take hold.

 

## Ignorance is Definitely Not Bliss

Because getting advanced insight into code security posture remained impractical for most, the unwanted and potentially embarrassing surprises kept coming. Even with detection tools and specialists becoming more accessible, the problem shifted to treating (or not) the growing number of issues being uncovered.

Whether by white hat hackers or a tool, awful news was coming more frequently, and many firms reacted poorly, denying, downplaying, and avoiding the illustrated problems until it was too late.

 

## Hope for the Present (and Future)

Today, nearly every company is a software company in some fashion. Code is developed continually, reaches into homes and industrial systems, and touches every part of our lives.

Thankfully, it is becoming easier to avoid the software security problems of the past. These days we have simple solutions to these complex issues that coders can use to ensure peace of mind for themselves and their clients.

The emergence of simple, reliable, and far more efficient tools and services is unlocking the ability of developers and coders to be more security-minded, allowing them to test the security of their work whenever they want.

If you would like to get a [free 1 on 1 AppSec consultation to evaluate your current security posture](https://true-positives.com/get-started), you can reach out to us at True Positives.

![True Positives](https://true-positives.com/hubfs/T+%20%20Logo%20Webpage%20Header%20(1200%20X%20600)%2001%2009%202026-2.svg)

### True Positives

True Positives is an authorized Invicti VAR and application security MSSP delivering proof-based DAST scanning and managed vulnerability assessment services to organizations across North America. The firm operates through two delivery models: fully managed application security services for organizations seeking outsourced program operations, and direct platform licensing for teams prepared to run Invicti internally. For additional information, visit https://true-positives.com.

<https://www.linkedin.com/company/true-postives/> [mailto:appsec_solutions@true-positives.com](mailto:appsec_solutions@true-positives.com) <https://true-positives.com/?rel=author>

<https://true-positives.com/appsec-blog/author/true-positives>

## Latest posts

- [ALL POSTS](https://true-positives.com/appsec-blog/all)

[![True Positives](https://true-positives.com/hubfs/HubSpot%20Footer%20Logo%20-%20360x90.png)](https://true-positives.com/?hsLang=en)

[Managed AppSec](https://true-positives.com/managed_appsec_mssp) [In-House AppSec Support](https://true-positives.com/direct-platform-licensing)

[PRO Services](https://true-positives.com/appsec-pro-services) [Why T+](https://true-positives.com/why-true-positives)

[Resources](https://vulnerability-atlas.true-positives.com/index.html) [Contact Us](https://true-positives.com/contact-truepositives)

<https://www.facebook.com/truepositives> <https://x.com/TruePositives> <https://www.linkedin.com/company/truepositives/>

© 2026 True Positives, LLC. All rights reserved.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "True Positives",
    "url" : "https://true-positives.com/appsec-blog/author/true-positives"
  },
  "dateModified" : "2024-03-20T23:20:58.030Z",
  "datePublished" : "2023-01-19T16:00:00.000Z",
  "headline" : "Software Security's Journey to the Mainstream",
  "image" : [ "https://true-positives.com/hubfs/software-security-tools-journey-to-the-mainstream-header.webp" ],
  "mainEntityOfPage" : {
    "@id" : "https://true-positives.com/appsec-blog/software-securitys-journey-to-the-mainstream",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://true-positives.com/hubfs/HubSpot%20Header%20Logo%20-%20500x125.png"
    }
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "Organization",
  "address" : {
    "@type" : "PostalAddress",
    "addressCountry" : "US",
    "addressLocality" : "Chehalis",
    "addressRegion" : "Washington",
    "postalCode" : "98532",
    "streetAddress" : "110 Villageway Drive"
  },
  "contactPoint" : [ {
    "@type" : "ContactPoint",
    "areaServed" : "US",
    "availableLanguage" : "English",
    "contactType" : "Sales",
    "telephone" : "+1-206-854-8999"
  }, {
    "@type" : "ContactPoint",
    "areaServed" : "US",
    "availableLanguage" : "English",
    "contactType" : "Sales",
    "telephone" : "+1-404-314-3929"
  }, {
    "@type" : "ContactPoint",
    "availableLanguage" : "English",
    "contactType" : "Customer Support",
    "email" : "tplus-support@true-positives.com"
  }, {
    "@type" : "ContactPoint",
    "availableLanguage" : "English",
    "contactType" : "General Inquiries",
    "email" : "contact@true-positives.com"
  } ],
  "description" : "True Positives is a trusted AppSec MSSP delivering expert-led DAST and automated vulnerability scanning—reducing risk, eliminating false positives, and cutting overhead without compromising security.",
  "email" : "info@true-positives.com",
  "logo" : {
    "@type" : "ImageObject",
    "url" : "https://true-positives.com/hs-fs/hubfs/managed-application-security-testing-true-positives-logo.jpg?width=640&height=160&name=managed-application-security-testing-true-positives-logo.jpg"
  },
  "name" : "True Positives",
  "sameAs" : [ "https://www.linkedin.com/company/truepositives/", "https://www.facebook.com/truepositives/" ],
  "url" : "https://true-positives.com"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "Product",
  "aggregateRating" : {
    "@type" : "AggregateRating",
    "ratingValue" : "5",
    "reviewCount" : "3"
  },
  "name" : "True Positives Managed AppSec Services",
  "review" : [ {
    "@type" : "Review",
    "author" : {
      "@type" : "Person",
      "name" : "Brook Schoenfield"
    },
    "name" : "Valuable Insights for Strategic AppSec",
    "reviewBody" : "True Positives goes beyond simply identifying vulnerabilities in application security testing. Their managed service delivers actionable insights and prioritization, allowing businesses to mitigate risks effectively and allocate resources strategically, all while controlling costs.",
    "reviewRating" : {
      "@type" : "Rating",
      "bestRating" : "5",
      "ratingValue" : "5"
    }
  }, {
    "@type" : "Review",
    "author" : {
      "@type" : "Person",
      "name" : "Dan Kuykendall"
    },
    "name" : "Reliable Scanning with Human Guidance",
    "reviewBody" : "True Positives offers a great option for managed scanning, offering a cost-effective solution for quality and reliable scans. They don’t just send reports—they verify vulnerabilities, guide developers, and help prioritize and fix issues.",
    "reviewRating" : {
      "@type" : "Rating",
      "bestRating" : "5",
      "ratingValue" : "5"
    }
  }, {
    "@type" : "Review",
    "author" : {
      "@type" : "Person",
      "name" : "Julie Richard"
    },
    "name" : "Trusted DAST Partner for Enterprise Needs",
    "reviewBody" : "Partnering with True Positives for managed DAST services will save you countless hours and headaches. Their expertise and proactive approach streamline identification and prioritization of vulnerabilities while also ensuring development has the information it needs to secure valuable assets.",
    "reviewRating" : {
      "@type" : "Rating",
      "bestRating" : "5",
      "ratingValue" : "5"
    }
  } ]
}
```