The current approach to security is reactive. Organizations work on mitigating risk, testing website security, and improving security once a threat has emerged. This approach is problematic as it leaves organizations open to sabotage. This culture needs to change.