Essential security practices like threat modeling and code scanning must be applied to all new software development methods.