Security bolted on after the fact is expensive and porous; security built into operations is cheap and quiet. The difference is when you make the decisions.
Every operational choice is secretly a security choice: how accounts are created, how files are shared, how machines are set up, how departures are handled. Made deliberately, each becomes a control. Made by default, each becomes a gap.
This is why 'we'll deal with security later' fails — later, the gaps are habits, and habits are what attackers exploit. The organizations that avoid incidents aren't the ones that spend the most; they're the ones whose ordinary operations are secure by design.
If security still lives on your someday list, the most valuable step isn't a product — it's an honest assessment of where your operations and your controls disagree.