> ## Content Index
> Fetch the complete content index at: https://www.ostering.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# The Wine Has Turned to Vinegar

- URL: the-wine-has-turned-to-vinegar
- Published: 2026-10-01T06:30:00.000Z
- Updated: 2026-10-01T07:00:20.658Z
- Description: Security spending will hit $249 billion in 2026, yet software quality keeps falling. The problem is incentives, not tools. Here is what has to change.
- Author: Brett Crawley
- Tags: AI Security, Application Security, Secure by Design, Security Culture, Software Quality, Technical Dept

# Why $249 Billion Can't Fix Software Security

> TL;DR:
> - Gartner forecasts $248.9 billion of security spending in 2026, yet breaches persist and software quality keeps degrading.
> - Poor software quality costs the US alone an estimated $2.41 trillion a year (CISQ, 2022).
> - The root cause is incentives that reward shipping features over maintaining foundations, not a lack of tools or frameworks.
> - AI adopted as a cost cut widens the attack surface: Veracode found vulnerabilities in 45% of AI code samples.
> - The fix is to reward quality and security posture, let engineers refactor as they work, and secure the AI tooling itself.

There's a story about a wine region. For years, the farmers chased quantity over quality. More vines. More volume. More market share. The land weakened. The farmers grew tired. Quality collapsed, prices dropped, and customers stopped buying. The only people still making money were the distributors and investors extracting value from a dying ecosystem.

Then a mayor gathered the exhausted farmers together and formed a co-operative. They returned to first principles: fewer vines, working the land without abusing it, prioritising quality over quantity. The customers came back.

I think the software industry is living the same story, but without the co-operative. Despite projected 2026 security spending of $248.9 billion, breaches persist, products degrade, and the fundamental problems get worse. We are pouring synthetic fertiliser on exhausted land while the soil dies beneath us.

What got me thinking about all this was reading Greg van der Gaast's book *I Call Bullshit: Why Organisational Health Beats Cybersecurity Every. Single. Time.* His argument is that we have become so busy treating symptoms that we ignore the organisational conditions creating them. One of his examples comes from aerospace: if the bolts holding the wings on were coming loose on every flight, nobody would build workshops and hire hundreds of engineers to tighten them after each landing. They would find the root cause and stop the bolts from loosening. I kept nodding as I read it, and it drove me to write down what I see from the engineering side.

Let me be plain about the claim. Software security and software quality are a real problem, and they are getting worse, not better. That is not an exaggeration and it is not a complaint about any one place. It is what the numbers say, and I will get to them shortly.

Before I go any further, a word on where this comes from. I have spent more than 25 years in software engineering and over a decade in application security, across many organisations, and I am also a customer of far more software than I have ever helped to build. What follows is not a story about any one company. It is a pattern I see across the industry, in the products on my own phone and laptop as much as anywhere else. 

The disease isn't a lack of tools, training, or frameworks. The disease is the culture and the incentive structures that reward velocity over quality, make craftsmanship hard to justify, and normalise building on rotten foundations. Until we return to first principles (building security into the foundation rather than bolting it on afterwards), no amount of spending will cure the problem.

---

## You Can See It From Your Own Phone

You don't need to work in software to see this. Look at the update queue on your phone or your laptop.

Every week there is another round of updates. Some bring features nobody asked for. Some move the button you used every day. And in among the "bug fixes and performance improvements" is a steady stream of security patches for vulnerabilities that shipped in the last round of features. The patches never stop, because the flaws never stop. Many are fixed late, and some are never fixed at all.

This is what it looks like from the outside when an industry treats shipping as the goal and quality as something to patch in later. If the foundations were sound, we would not see an ever-growing cost of poor quality sitting alongside never-ending updates and an endless supply of vulnerabilities. The evidence is on every device we own.

---

## The Parable: Exhausted Land, Tired Farmers, Degraded Wine

The wine region is more than a metaphor. It is a pattern that repeats across industries whenever short-term extraction replaces long-term stewardship.

The cycle:

1. **Push for volume** → Abuse the foundation (land, code, people)
2. **Quality degrades** → The product loses value, but customers are already invested
3. **Farmers burn out** → The people doing the work leave or break
4. **Investors extract** → Those who don't touch the soil keep profiting
5. **Crisis point** → Someone gathers the farmers and says "enough"

In wine, that crisis produced a co-operative. In software, we are still at step 4.

![Five numbered cards showing a cycle in vineyards and in software: push for volume, quality degrades, farmers burn out, investors extract, someone says "enough". Step 4 is highlighted and marked "we are here".](https://www.ostering.com/media/posts/69/the-extraction-cycle.png =3200x1800 "The extraction cycle. In wine, step 5 produced a co-operative. In software, we are still at step 4.")

---

## The Security Spending Paradox

Gartner's latest forecast puts global security spending at $248.9 billion in 2026, yet the threat landscape worsens year over year. Boards are frustrated. More investment hasn't solved the problem.

The industry response? "Secure by design!" "Shift left!" "DevSecOps!" Regulators are now pushing liability upstream too: the Cybersecurity and Infrastructure Security Agency (CISA) in the US and the EU's Cyber Resilience Act (CRA) are forcing manufacturers to eliminate default passwords, provide Software Bills of Materials (SBOMs), and report vulnerabilities within 24 hours.

These are fertilisers. They treat symptoms while the soil dies.

The numbers tell the story:

- **$2.41 trillion**: Annual cost of poor software quality in the US alone (CISQ, 2022)
- **74%**: Organisations affected by security debt in 2025, up from 71% in 2024 (Veracode's 2026 report now puts it at 82%)
- **$4.44 million**: Average cost of a data breach
- **33%**: Developer time spent addressing technical debt instead of building new features (Stripe, 2018)
- **25-50%**: Slower feature delivery in companies with high technical debt

![Two bars drawn to scale: a short one for $248.9 billion of projected 2026 security spending and a much longer one for the $2.41 trillion annual cost of poor software quality in the US. Below: 74% of organisations with security debt, $4.44 million average breach cost, 33% of developer time spent on technical debt.](https://www.ostering.com/media/posts/69/the-spending-paradox.png =3200x1800 "Global security spending set against the cost of poor software quality in the US alone. Sources: Gartner (2026), CISQ (2022), Veracode (2025), IBM (2025), Stripe (2018).")

We are not failing because we lack awareness of secure-by-design principles. We are failing because the incentive structures in modern software development work against quality.

Delivery timelines, investor pressure, and market-first thinking reward shipping fast, not shipping secure. We have normalised building on rotten foundations and retrofitting defences afterwards. Then we act shocked when the structure collapses.

---

## The Disease: How We Got Here

### What We Did to Agile

Agile wasn't the problem. The interpretation was.

"Minimum viable product" (MVP) was supposed to mean the foundation you build on: the simplest version that validates your hypothesis while keeping its structural integrity. Instead, across much of the industry, it became the quick proof of concept that you keep bolting bits onto, because shipping is what gets measured.

Technical debt accumulates. Security debt compounds. The land weakens.

### Ticket Tyranny and the Decline of Craftsmanship

The Japanese have a word for it: **monozukuri**. Literally "making things", it means taking pride in the craft and continually improving how the work is done. Applied to software, it means you leave the codebase more secure, more efficient, and better structured than you found it. You refactor as you work. You tend the land while you harvest.

In much of the industry today, if it doesn't have a ticket, it doesn't happen.

This isn't the fault of the people writing the tickets. Product teams are measured on roadmap delivery, so the backlog fills with things customers can see. Refactoring, paying down technical debt, and hardening security have no feature attached, so they are "out of scope". Everyone in the room is behaving rationally according to what they are measured on. That is exactly the problem.

Welcome to scrum, chum.

The result: engineers can see the land dying and have no sanctioned way to tend it. Bonuses reward features shipped, not foundations maintained. Promotions follow velocity, not quality.

### AI as Cost-Cutting, Not Force Multiplier

GitHub reports that Copilot now writes 46% of the code for developers who use it (61% for Java). This could be transformational, if it is implemented as a force multiplier.

But too often AI is adopted as a cost-cutting measure, not a quality investment:

- The cheapest models available, not the strongest
- No test-driven development (TDD) around the output
- No multi-agent set-up with specialised quality roles
- No deterministic controls or validation harnesses
- No security around the tools themselves, leaving development pipelines open to supply chain attacks, prompt injection, and data exfiltration

The data is damning.

**AI-generated code vulnerabilities:**

- 25-45% of AI-generated code contains confirmed OWASP Top 10 vulnerabilities
- Veracode's 2025 report found 45% of AI code samples included vulnerabilities, with Java code failing 72% of the time
- CodeRabbit's analysis of 470 pull requests found AI-authored changes carried about 1.7 times more issues overall, and were 2.74 times more likely to introduce cross-site scripting vulnerabilities
- CVE-2025-48757 exposed over 170 applications because an AI tool generated Supabase schemas without Row Level Security
- Moltbook leaked 1.5 million API keys due to disabled security controls

**Supply chain attacks on AI development tools:**

- 454,600 new malicious open-source packages identified in 2025, a 75% year-over-year increase
- Third-party involvement in breaches doubled from 15% to 30% in a single year
- The SANDWORM_MODE campaign (February 2026) used malicious npm packages and GitHub Actions to inject rogue MCP servers into AI coding assistants (including Claude Code, Cursor, and Windsurf), silently exfiltrating developer tokens and sensitive files
- Between February and May 2026, the TeamPCP operation compromised over 26,000 GitHub repositories
- Supply chain attacks now cost an average of $4.91 million, with a 267-day mean lifecycle for containment

**Prompt injection as "the new RCE":**

- Prompt injection is OWASP LLM01:2025, the most critical vulnerability in AI applications
- Over 461,640 prompt injection submissions documented in 2025, with 50-84% success rates
- CVE-2025-32711 (EchoLeak): a zero-click Microsoft 365 Copilot vulnerability allowing document exfiltration via crafted emails
- CVE-2025-53773: a GitHub Copilot remote code execution (RCE) vulnerability scored 7.8 CVSS
- The IDEsaster research (December 2025) found all ten major AI-integrated development environments tested were exploitable via prompt injection

![Six statistics on a dark background: 46% of code written by GitHub Copilot for its users, 45% of AI code samples with vulnerabilities, 2.74 times more XSS vulnerabilities, 454,600 new malicious packages in 2025, third-party breach involvement up from 15% to 30%, and 10 of 10 AI IDEs exploitable by prompt injection.](https://www.ostering.com/media/posts/69/ai-as-cost-cutting.png =3200x1800 "Contaminated fertiliser: what happens when AI goes into the pipeline as a cost cut. Sources: GitHub, Veracode, CodeRabbit, Sonatype, Verizon DBIR, IDEsaster research.")

This is what happens when AI is rushed into development pipelines without securing the tools, validating the output, or understanding the attack surface it introduces. It is not just pouring synthetic fertiliser on exhausted land. It is pouring contaminated fertiliser and hoping for a miracle harvest.

When AI is used properly (strong models, quality engineering, TDD, multi-agent frameworks, deterministic controls, and secure implementation), it produces excellent results. But that requires investment, and investment in quality is the hardest thing to get funded.

### The Enshittification Trap

Customers aren't blind. They see products degrading:

- Features added for features' sake, because roadmaps demand visible "progress"
- UI redesigns chasing trends while breaking workflows people depend on
- Security weakening as technical debt compounds
- Performance degrading as shortcuts accumulate

This is the update queue again, at enterprise scale. And customers are trapped. Switching costs are prohibitive: they have already invested millions in integration, training, and infrastructure. Vendor lock-in (especially with AI tools) has 87% of enterprises deeply concerned, yet they stay because the alternative looks worse.

It is the same cycle as the wine region: a degraded product, captive customers, value extracted, and very little consequence for anyone upstream.

---

## The Farmers Are Leaving

76% of IT and cybersecurity professionals report experiencing burnout constantly, frequently, or occasionally (Sophos, 2025). Back in 2023, Gartner predicted that nearly half of cybersecurity leaders would change jobs by 2025, a quarter of them for different roles entirely, taking years of hard-won expertise with them.

Some literally became farmers. They traded keyboards for soil, because at least dirt is honest about what it needs.

The average Chief Information Security Officer (CISO) tenure is 18-26 months, compared to 4.9 years for other C-suite roles (Cybersecurity Ventures, 2023). ISC2 put the global cybersecurity workforce gap at 3.4 million in 2022. By 2024 its estimate had grown to 4.8 million.

![Bars drawn to scale comparing average CISO tenure of 18 to 26 months with 4.9 years for other C-suite roles. Beside them: 76% of IT and cybersecurity professionals report burnout, Gartner predicted about 50% of security leaders would change jobs by 2025 with 1 in 4 leaving for different roles, and a 4.8 million global workforce gap.](https://www.ostering.com/media/posts/69/the-farmers-are-leaving.png =3200x1800 "The farmers are leaving, and not because they are weak. Sources: Cybersecurity Ventures (2023), Sophos (2025), Gartner (2023), ISC2 (2024).")

These aren't "soft skills" problems. This is a structural impossibility. We have handed security leaders expanded accountability (personal liability under SEC rules, NIS2, and DORA) while giving them:

- Understaffed teams (55% report inadequate staffing)
- 21% longer hiring cycles than other tech roles
- Technical debt and security debt they didn't create but must defend
- No sanctioned route to fix foundational problems
- An organisation around them that is rewarded for shipping faster

We are not losing farmers because they are weak. We are losing them because we designed a system that makes farming unsustainable.

---

## Regulation: Treating Symptoms, Not the Disease

Regulators see the crisis. CISA's Secure by Design initiative, the EU's Cyber Resilience Act, and emerging vendor liability frameworks all push responsibility upstream to manufacturers.

This is progress. Mandating secure defaults, SBOMs, and 24-hour vulnerability disclosure creates accountability.

But regulation is reactive, not curative. It responds to customers who have had enough, who stopped drinking the wine. It forces vendors to fit better locks to doors set in rotten walls. It doesn't fix the culture that builds rotten walls in the first place.

Until the incentives change (until quality is rewarded alongside velocity, until engineers can tend the codebase as they go, until success is measured by security posture as well as feature count), regulation will remain a pressure valve, not a cure.

---

## Where's the Co-Op?

In the wine parable, the mayor gathered the farmers. They formed a co-operative. They chose quality.

In software, there is no co-op. Not yet.

The model exists:

- **Monozukuri**: take pride in the craft, improve as you work, leave systems better than you found them
- **Proper AI implementation**: strong models, multi-agent frameworks, TDD, quality engineering, deterministic controls, secure tool deployment
- **First principles engineering**: build security into foundations, don't bolt it on afterwards
- **Product discipline**: when you have a good product, stop breaking it. If you want to grow, add to the product line while holding the same high standard

What is missing is not knowledge. It is permission, and the incentives that would grant it.

---

## The Path Forward

This is both a warning and a call to action.

**The warning:** We are at step 4 of the cycle. The land is dying. The farmers are leaving. The wine tastes like vinegar.

**The call:** Someone must gather the farmers and say "enough." The co-operative doesn't form itself.

### Realign the Incentives

- Tie bonuses and promotions to security posture and code quality, not just feature velocity
- Reward engineers who reduce technical debt, not only those who ship fastest
- Measure success by long-term system health, not quarterly feature counts

### Empower Craftsmanship

- Give engineers standing permission to refactor as they work
- Bring monozukuri into software: leave systems better than you found them
- Let product managers guide priorities while engineers keep autonomy over technical quality

### Invest in Quality AI Implementation

- Use strong models, not the cheapest option
- Deploy multi-agent frameworks with specialised quality roles
- Implement TDD, deterministic controls, and validation harnesses
- Secure the AI tools themselves: treat development pipelines as critical infrastructure, validate supply chains, defend against prompt injection, and audit tool permissions and data access
- Treat AI as a force multiplier, not a cost-cutting shortcut

### Return to First Principles

- Build security into foundations from day one
- Treat the MVP as the foundation you build on, not the hack you keep extending
- When you have a good product, stop breaking it
- If you want growth, add to the product line. Don't degrade what works

### Accountability With Resources

- If you assign liability to security leaders, give them the means to succeed: staffing, budget, and the authority to mandate fixes
- Stop sacrificing CISOs to cover for systemic failures
- Make vendor liability real: financial consequences for shipping insecure products

**Note to leaders:** none of this needs a new framework or a new tool. It needs you to change what you measure and what you reward.

**Note to engineers:** you are not imagining it, and you are not alone. The instinct to tend the land is the right one.

---

## Final Thoughts

The wine has turned to vinegar.

Security and quality are a problem across this industry, and spending more on symptoms has not changed that. We are spending $248.9 billion to treat symptoms while the disease spreads. We are watching farmers leave, some literally trading code for crops, while customers sit through one more round of updates and wait for the next patch.

The co-operative model exists. Japanese manufacturing built its reputation on monozukuri. Proper AI implementation shows what is possible. First principles engineering works wherever it is given room.

I don't have a co-operative to show you. I have seen teams and individuals work this way, and the results speak for themselves, but it is not yet how the industry works at scale.

Someone must be the mayor.

Someone must gather the farmers and say: "Enough. We're going back to basics. Quality over quantity. Craft over speed. Foundations over features. Security built in, not bolted on. And we're securing the tools we use to build."

![Quote card reading "Someone must be the mayor", followed by "Quality over quantity. Craft over speed. Foundations over features. Security built in, not bolted on." and the question "Who will gather the farmers?"](https://www.ostering.com/media/posts/69/someone-must-be-the-mayor.png =3200x1800 "The co-operative doesn't form itself. Who will gather the farmers?")

This article is both a warning and an invitation.

The land is tired. But the co-op can still form.

**The question is: who will gather the farmers?**

---

## References

1. Secure by Design: From Concept to Cybersecurity Imperative in 2025 - https://10guards.com/en/blog/2025/04/18/secure-by-design-from-concept-to-cybersecurity-imperative-in-2025/
2. CISA Secure by Design and Financial Liability: Too Much Too Soon? - https://www.reversinglabs.com/blog/cisa-secure-by-design-and-financial-liability-too-much-too-soon
3. The Surprising Truth About Technical Debt in Agile Development - https://devico.io/blog/the-surprising-truth-about-technical-debt-in-agile-development
4. How Security Debt is Different from Technical Debt - https://www.quantifyhq.com/blog/how-security-debt-is-different-from-technical-debt
5. EU CRA Compliance: Building a Defensible Posture - https://cloudsmith.com/blog/eu-cra-compliance-building-a-defensible-posture-with-cloudsmith
6. Enshittification: Why Everything Suddenly Got Worse - https://en.wikipedia.org/wiki/Enshittification
7. Vendor Lock-in Challenges and Concerns 2025-2026 - https://www.outsystems.com/application-development/vendor-lock-in-challenges-and-concerns
8. Technical Debt: Board-Level Risk in 2025 - https://tuxcare.com/shownote/technical-enshittification-why-everything-in-it-is-horrible-right-now-and-how-to-fix-it/
9. Security Debt Escalation 2025 - https://www.mend.io/blog/security-debt-the-hidden-cost-of-vulnerable-code/
10. State of Cybersecurity Burnout Today - https://www.bitsight.com/blog/state-of-cyber-security-burnout-today
11. Addressing Cybersecurity Burnout in 2025 - https://www.sophos.com/en-us/blog/report-addressing-cybersecurity-burnout-in-2025
12. 2025 ISC2 Cybersecurity Workforce Study - https://www.isc2.org/Insights/2025/12/2025-ISC2-Cybersecurity-Workforce-Study
13. Only 34% of Cyber Professionals Plan to Stay in Current Role - https://www.itpro.com/security/only-34-percent-of-cyber-professionals-plan-to-stay-in-their-current-role
14. GitHub Copilot writes 46% of your code - that should make you uncomfortable - https://medium.com/lets-code-future/github-copilot-writes-46-of-your-code-that-should-make-you-uncomfortable-5152dacec492
15. AI-Generated Code Statistics - https://www.netcorpsoftwaredevelopment.com/blog/ai-generated-code-statistics
16. AI Coding Impact 2026 - https://trigidigital.com/blog/ai-coding-impact-2026/
17. Software Engineer AI Chaos: Press Enter All Day - https://futurism.com/artificial-intelligence/software-engineer-ai-chaos-press-enter-all-day
18. GitHub Copilot Getting Worse 2026: Developers Switching - https://www.nxcode.io/resources/news/github-copilot-getting-worse-2026-developers-switching
19. Veracode 2025 GenAI Code Security Report
20. Verizon 2025 Data Breach Investigations Report - Software Supply Chain Attacks
21. SANDWORM_MODE Campaign: AI Tool Supply Chain Compromise 2026 - https://socket.dev/blog/sandworm-mode-npm-worm-ai-toolchain-poisoning
22. Prompt Injection: The New RCE for AI Systems - OWASP LLM Top 10 2025
23. IDEsaster: Researchers Uncover 30+ Flaws in AI Coding Tools (research by Ari Marzouk) - https://thehackernews.com/2025/12/researchers-uncover-30-flaws-in-ai.html
24. The Cost of Poor Software Quality in the US: A 2022 Report (CISQ, Herb Krasner) - https://www.it-cisq.org/the-cost-of-poor-quality-software-in-the-us-a-2022-report/
25. CodeRabbit: State of AI vs Human Code Generation Report (December 2025) - https://www.coderabbit.ai/blog/state-of-ai-vs-human-code-generation-report
26. Greg van der Gaast, *I Call Bullshit: Why Organisational Health Beats Cybersecurity Every. Single. Time.* (2026)
27. Gartner Predicts Nearly Half of Cybersecurity Leaders Will Change Jobs by 2025 - https://www.gartner.com/en/newsroom/press-releases/2023-02-22-gartner-predicts-nearly-half-of-cybersecurity-leaders-will-change-jobs-by-2025
28. The Rise in CISO Job Dissatisfaction (Cybersecurity Ventures) - https://cybersecurityventures.com/the-rise-in-ciso-job-dissatisfaction-whats-wrong-and-how-can-it-be-fixed/
29. The Developer Coefficient (Stripe, September 2018) - https://stripe.com/files/reports/the-developer-coefficient.pdf
30. Gartner, Forecast: Information Security, Worldwide, 2024-2030, 2Q26 (June 2026), as reported in - https://softwarestrategiesblog.com/2026/07/06/gartner-2q26-information-security-forecast-securing-ai-2030/

---

Seeing threats from a mile up. Making security human again. | Subscribe to The Blast Radius
