Gary McGraw, Brian Chess, and Sammy Migues interviewed nine executives running top software security programs, and wrote an article for InformIT .  Some results showed that we are still not doing enough, even at our best.  Some showed that some of the things we stress most heavily are actually wrong.  The article is summarized in a bullet list .
