...failure to detect the animated cursor bug in Vista has encouraged critics to speculate that its highly-acclaimed securedevelopment process might not be working as advertised. They have a point. One would certainly expect its code review process...
http://www.computerweekly.com/blogs/david_lacey/managing-the-human-dimension/
...providers security at the expense of forgetting to think of your own: are your Force.com developers trained in securedevelopment practices, how resilient is your own connectivity to the remote servcies, in your haste to produce new products...
http://www.computerweekly.com/blogs/stuart_king/2008/11/dreamforce-sfdc.html