Skip to lesson
Exit
The Role & Your Charter1 / 2

2 min lesson

"Security is everybody's job" is the wrong charter

Describe what "A lot of security teams want everybody to understand security is everybody's job" changes in practice.

Step 1 of 2

"Security is everybody's job" is the wrong chartera deliberately contrarian stance from Cursor's security team

There's a popular line that security is everybody's job. Cursor's security team takes the opposite view, and it's worth understanding why. If security is everyone's job, you've quietly taxed every engineer with work that isn't theirs. The better model is to handle the security problems for the org so everyone else can stay focused on what they actually do - most of it absorbed by the tools and processes people already use, adding no new friction, with a relationship good enough that people come ask when they're unsure.

How the team frames it

This is the paved-road mindset taken to its conclusion: the best security work is invisible to the engineer who benefits from it.

A lot of security teams want everybody to understand security is everybody's job. I don't feel that way at all. The biggest gift that we can give our org is actually handling security problems as much as possible so that everybody else can focus on what they do.

The team even does its own patching rather than just filing the CVE to the owning team. Because they write and read the software, they can judge whether a new vuln is actually impactful and ship the fix themselves. That's the builder posture again: own the problem through to the deployed mitigation, don't hand off a ticket.