By Sean Cleary, Partner and Cybersecurity Practice Lead
3 Takeaways
1. The gap is stark. In Riviera’s forthcoming Future of Tech Leadership survey, 87% of the most advanced organizations integrate security from initial design. Among the least mature, 14% do.
2. When you integrate security predicts whether you stall. Organizations that bolt security on late hit a predictable roadblock at security and legal review. The mature ones have largely engineered that stall out.
3. Shift-left is an org-design choice. It comes from how the security organization is structured and led, which puts it on the board’s and CEO’s desk as much as the security team’s.
Every year Riviera surveys close to 1,000 senior technology leaders for our Future of Tech Leadership report, and this year one finding is worth putting in front of boards and CEOs ahead of the full release this September. It concerns when companies bring security into the work, and how sharply that single timing decision tracks with execution maturity.
The report segments organizations by how effectively they ship and scale technical initiatives, into three tiers: Emerging, Developing, and Advanced. The security data breaks along those tiers almost perfectly.
The Headline: 87% vs. 14%
Asked when they bring cybersecurity and governance into a technical initiative, leaders split hard by maturity.
Among Advanced organizations, 87% integrate security from initial design, the practice usually called shift-left. None of them integrate it ad hoc, and none wait until only just before deployment. Security is in the work from the first architectural decision.
Among Emerging organizations, 14% integrate from initial design. The majority, roughly 56%, bring security in only at or after deployment, split between “only before deployment” and fully ad hoc. Developing organizations sit in between, with about half embedding security from the start and a little over 40% still treating it as a late checkpoint.
That’s a 73-point spread on a single practice between the most and least mature tiers. Few questions in the survey separate the tiers as cleanly.
Late Security Integration Has a Predictable Cost
The reason this matters shows up in a second question: where technical initiatives most often stall. The stall points differ by tier in a way that maps directly onto the security-timing data.
Emerging organizations stall most on expanding beyond an initial use case (40%), the classic “we shipped it but can’t scale it” problem. Developing organizations stall most on passing security, legal, and governance review (26%), which is exactly what you’d expect from a cohort that embeds security early only about half the time. When security enters late, it enters as a gate, and the gate becomes the bottleneck.
Advanced organizations report the fewest major stalls of any tier. Building security in from the start eliminates the most common late-stage roadblock before it forms. Shift-left is both a marker of maturity and a driver of it: mature organizations do it, and doing it makes organizations more mature by removing the friction that stalls everyone else.
A fair challenge to raise: a survey shows correlation, so does shift-left cause the maturity or simply travel with it? My read, from the searches and org build-outs we run, is that it works both ways, and the stall data points to the causal half. The organizations that integrate late report the security-and-legal-review bottleneck at the highest rate, which is the specific, mechanical cost of late integration showing up on schedule. Remove the late gate and you remove that stall. That’s a lever a leadership team can pull directly, whatever else separates the tiers.
For a board, that reframes security timing. On top of the risk exposure everyone already associates with it, a late-integration posture is a tax on execution speed, paid in slipped launches and initiatives that stall at review. That tax is climbing as AI widens the attack surface and speeds up attack cycles: the later security enters, the more exposure piles up in exactly the systems moving fastest.
Shift-Left Is an Org-Design Decision
Here’s the part that gets missed. The industry often frames shift-left as a tooling or process choice, scanners in the pipeline, a checklist in the SDLC. Tools help. What actually moves the number is how a company designs its security organization and who leads it.
Security gets built in from day one when three structural conditions are in place. There’s a product-security function that embeds with engineering rather than testing for vulnerabilities after the fact. There’s a CISO whose mandate and authority reach into the build, with a reporting line close enough to the CEO and board to make security part of the earliest design conversations rather than a late review. And there’s a bench beneath the CISO, particularly a head of security engineering, deep enough that the CISO can work on strategy instead of fighting fires.
Organizations that treat security as a checkpoint usually have the inverse: no dedicated product security, a CISO buried under IT with authority that stops at the review stage, and no leadership layer to push security upstream. The timing follows the structure. Change the structure and the timing changes with it.
How to Move Your Organization Left
If you suspect your organization is integrating security too late, a few practical steps move the number.
- Locate yourself honestly. Ask your engineering and security leaders when security actually enters a typical initiative. If the honest answer is “at review” or “before launch,” you’re carrying the late-integration tax whether or not you’ve felt it yet.
- Stand up product security earlier than feels necessary. For any company shipping software, and especially any building with AI, product security is the function that puts security into the build. Companies commonly under-build it, and it’s often the early hire that pays off most.
- Fix the CISO’s mandate and reporting line. Security integrates early when the CISO has authority upstream and proximity to the executive team. A leader whose remit begins at the review stage cannot shift anything left.
- Build the bench so leadership can be strategic. A head of security engineering and a GRC lead free the CISO from operational firefighting, which is what makes proactive, early-stage security possible in the first place.
- Track it with numbers the board can see. Three metrics tell you whether security is actually moving left: the share of initiatives that pass through a security design review before build, the average time an initiative spends in security and legal review, and the number of launches delayed by late security work in a quarter. Watch those move and you can prove progress rather than assert it.
None of this is a one-quarter fix. It’s an organizational design question, which is why it sits with the board, the CEO, and the CHRO rather than only with the security team.
What This Means Ahead of Black Hat
Black Hat fills Las Vegas with the tooling side of this conversation, and the tools are genuinely getting better. The survey is a reminder that the durable advantage comes from structure: the companies that ship faster and stall less have built security in from the first design decision, and they did it by designing the security organization to make that possible. The full Future of Tech Leadership report, with the complete maturity breakdown, publishes this September.
Frequently Asked Questions
What percentage of companies integrate security from the start?
In Riviera Partners’ forthcoming Future of Tech Leadership survey of close to 1,000 senior technology leaders, 87% of the most execution-mature (“Advanced”) organizations integrate security from initial design, compared with 14% of the least mature (“Emerging”) organizations and roughly half of those in between. The full report publishes in September 2026.
What is shift-left security?
Shift-left security means integrating security and governance from the first design decision of a technical initiative, rather than reviewing for it before deployment or handling it ad hoc. The survey data associates shift-left with higher execution maturity and fewer stalled initiatives, because late security integration tends to create a bottleneck at the security and legal review stage.
Why do technical initiatives stall at security review?
Initiatives stall at security and legal review when teams introduce security late in the process. Organizations that embed security only about half the time report review as their most common stall point. When security enters as a final gate rather than an early design input, that gate becomes the roadblock. Building security in from the start removes it.
How do you shift security left?
Shift-left is primarily an organizational design decision. It requires a product-security function embedded with engineering, a CISO whose mandate and reporting line reach into the build with proximity to the CEO and board, and a leadership bench deep enough that security operates strategically. Tools support the practice; structure is what makes it happen.
Related: How to Structure a Security Organization by Stage, Risk Profile, and the Bench Beneath the CISO
Related: Cyber Risk Is Enterprise Risk: What That Means for Board Oversight in 2026
Sean Cleary leads the cybersecurity executive search practice at Riviera Partners. Connect on LinkedIn.
About Riviera Partners
Riviera Partners is a global executive search firm focused exclusively on technical leadership, including product, engineering, IT, AI/ML/Data, and cybersecurity.