The UK’s national cybersecurity strategy identifies software vulnerabilities as a key threat, and makes building security into software from the start as a national priority. But most software developers aren’t security experts – and that’s what the industry needs.