# Why secure-by-design is an incentives problem, with Bob Lord

DevFeed: [Why secure-by-design is an incentives problem, with Bob Lord](<https://devfeed.tech/articles/why-secure-by-design-is-an-incentives-problem-with-bob-lord-1956.md>)

Original publisher: [Read original article](<https://1password.com/blog/secure-by-design-ai-security-incentives>)

Author: info@1password.com (Dave Lewis)

Published: 2026-04-14T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [podcasts](<https://devfeed.tech/tags/podcasts.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>)

## AI overview

Bob Lord and Dave Lewis discuss why secure-by-design remains difficult when organizations treat security as a feature or compliance exercise instead of a customer outcome. They examine leadership accountability, transparency in vulnerability handling, and how AI systems can amplify existing permissions and expose sensitive data.

## Source excerpt

SEASON TWO HAS LANDED! Bob Lord has spent decades building and leading security programs, from early internet crypto work at Netscape to roles at Twitter, Yahoo, the Democratic National Committee, and CISA. In this episode of Chasing Entropy, he and host Dave Lewis get practical about why the security advice most people hear doesn't match how real compromises happen. Across secure-by-design, AI systems, and software supply chains, security breaks down when organizations treat outcomes like someone else's problem. Why secure-by-design is an incentives problem When Bob talks about secure by design, he is deliberately not trying to write another technical framework. Plenty exist. His question is different. If we already know how to prevent a long list of common issues, why do we keep shipping the same defects? Secure-by-design breaks down when companies treat security as a feature or a compliance exercise rather than something they are accountable for delivering as a customer outcome. Draw a line to quality and safety movements outside software, especially in automotive safety. Car companies used to compete on lifestyle and appearance, not safety. Customers did not know what to ask for. Manufacturers had little reason to prioritize safety until norms, regulations, and accountability shifted. Software, in Bob's view, is still in the pre-seatbelt era. We have normalized shipping unsafe components, building with unsafe processes, and delivering unsafe defaults. Then we act as if customers should be able to configure their way out of systemic risk. From that lens, CISA's Secure by Design work focuses on three principles: Take ownership of customer security outcomes. Shipping a patch is not enough if you do not know whether customers update. Measure adoption and remove friction. Embrace radical transparency. Make vulnerability handling easier, not adversarial. Build a real safe harbor for good-faith research. Lead from the top. Meaningful change is driven by senior business