If nobody can be 100% secure, what is a realistic security target for a development project, and which habits get you there?
Not "zero vulnerabilities" but "no well-known vulnerabilities in the code" — reached by knowing the common vulnerability types, avoiding the well-known mistakes, and reusing proven countermeasures and patterns instead of inventing your own.
Perfect security is not an achievable goal for anyone — the defender has to cover every path while an attacker only needs one, and even the most heavily resourced organisations get breached. Setting "100% secure" as the target is therefore worse than useless: it is unmeasurable, so nobody can tell whether the project met it, and it invites the fatalistic conclusion that effort is pointless.
The workable target replaces perfect with no cheap wins for the attacker:
- Know the types of vulnerabilities. You cannot avoid a class of bug you have never heard of, so a baseline vocabulary of the common failure modes is the entry ticket.
- Avoid the well-known mistakes. The overwhelming majority of real-world compromises exploit long-documented, long-solved classes of flaw — not novel research.
- Use proven countermeasures and patterns. Established guidelines and library implementations have already survived the attacks a fresh hand-rolled solution is about to meet for the first time.
Two standing aims follow from that: projects should be "best-of-breed secure" — secure by the best standard the field currently knows, not merely "secure enough for now" — and all developers should be permanently security-aware, because a target that only one specialist carries is one holiday away from lapsing.
Tip: The realistic target is deliberately falsifiable. "Are there known vulnerability classes in our code?" is a question a review can actually answer; "are we secure?" is not.
Go deeper:
OWASP Top Ten — the canonical list of the well-known vulnerability classes the target is defined against.
CWE Top 25 Most Dangerous Software Weaknesses — the ranked catalogue of the mistakes that keep getting made anyway.