Insight #1
Organizations are continuing to pay more for top cybersecurity talent, and with the Securities and Exchange’s (SEC’s) most recent lawsuit against SolarWinds and its former Chief Information Security Officer, those numbers are only going to go up.
Insight #2
Where did the SBOM talk go? Yes, Software Bills of Materials (SBOMS) are still a thing, and the National Telecommunications and Information Administration (NTIA) has very specific recommended elements (PDF) for what has to be in an SBOM. In my opinion, even if you don't fully conform, it's still good hygiene to have an SBOM for your software.
Insight #3
A recent Synopsis report says software vulnerabilities are on the decline, yet Common Vulnerabilities and Exposures (CVEs) continue to be discovered at an alarming rate. I think the general consensus is that if you have an established Application Security (AppSec) program and track your mean time to respond/remediate (MTTR) and vulnerability escape rate (VER), vulnerabilities will decrease over time. Unfortunately, the majority aren't doing this.