Security reviews that arrive at the end of a project produce two artifacts: a findings list and a schedule slip. Some findings get fixed. The architectural ones, the ones that would require redesign, tend to get accepted as risk.
The alternative is cheaper and quieter: decide the security properties when the architecture is decided.
Threat model at the whiteboard
A threat model is a structured hour of asking what we are building, what can go wrong, and what we will do about it, held while the design is still sketches. Identity boundaries, data classification, and least-privilege access cost almost nothing to include at that stage and multiples to retrofit.
Make the pipeline enforce it
Secure development survives staff changes only when the pipeline carries it: dependency scanning, static analysis, secrets detection, and infrastructure policy checks that run on every change. What the pipeline enforces does not depend on anyone remembering.
Security that lives in architecture and automation is a property of the system. Security that lives in vigilance is a property of the calendar.