{"id":110703,"date":"2026-05-17T12:10:46","date_gmt":"2026-05-17T12:10:46","guid":{"rendered":"https:\/\/www.red-gate.com\/simple-talk\/?p=110703"},"modified":"2026-05-19T12:15:59","modified_gmt":"2026-05-19T12:15:59","slug":"in-2026-engineering-teams-are-quietly-accepting-more-risk-heres-why","status":"publish","type":"post","link":"https:\/\/www.red-gate.com\/simple-talk\/security-and-compliance\/in-2026-engineering-teams-are-quietly-accepting-more-risk-heres-why\/","title":{"rendered":"In 2026, engineering teams are quietly accepting more risk. Here&#8217;s why"},"content":{"rendered":"\n<p><strong><a href=\"https:\/\/www.red-gate.com\/solutions\/state-of-database-landscape\/2026\/\" target=\"_blank\" rel=\"noreferrer noopener\">Redgate&#8217;s 2026 State of the Database Landscape report<\/a> reveals that people are increasingly willing to accept more risk to be more productive and take full advantage of AI\u2019s capabilities.<\/strong> <strong>But, why is this happening &#8211; and are they even aware?<\/strong><\/p>\n\n\n\n<p>That&#8217;s the question Steve Jones, Kellyn Gorman, Grant Fritchey and Pat Wright tried to answer in the <a href=\"https:\/\/www.red-gate.com\/simple-talk\/podcasts\/security-vs-speed-in-databases\/\" target=\"_blank\" rel=\"noreferrer noopener\">latest episode of the Simple Talk podcast<\/a>. <\/p>\n\n\n\n<p>Sharing first-hand experience and stories from their own careers, they debated whether the decline of the <a href=\"https:\/\/www.red-gate.com\/products\/\" target=\"_blank\" rel=\"noreferrer noopener\">DBA<\/a> &#8216;gatekeeper&#8217; role has weakened security practices, how <a href=\"https:\/\/www.red-gate.com\/solutions\/use-cases\/ai-data-readiness\/\" target=\"_blank\" rel=\"noreferrer noopener\">AI<\/a> is amplifying the problem &#8211; and much more.<\/p>\n\n\n\n<p>Watch or listen to the episode <a href=\"https:\/\/www.red-gate.com\/simple-talk\/podcasts\/security-vs-speed-in-databases\/\" target=\"_blank\" rel=\"noreferrer noopener\">here<\/a>. If you don&#8217;t have time, though, here are the 11 key takeaways from the episode.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-security-vs-speed-in-databases-11-key-takeaways\">Security vs speed in databases: 11 key takeaways<\/h2>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-accepting-more-risk-for-speed-usually-means-misjudging-the-risk\">&#8220;Accepting more risk for speed&#8221; usually means misjudging the risk<\/h4>\n\n\n\n<p>Most teams making this trade don&#8217;t have a real model of what they&#8217;re agreeing to. As Steve put it in the episode: <em>&#8220;People misassess risk. They say they&#8217;re accepting more risk, but really they don&#8217;t understand the risk they&#8217;re accepting.<\/em>&#8220;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-the-internet-finds-open-doors-in-minutes-not-months\"><em>&#8220;<\/em>The internet finds open doors in minutes, not months&#8221;<\/h4>\n\n\n\n<p>Grant has tested this directly by opening up example databases on cloud platforms: <em>&#8220;The moment it&#8217;s open, there&#8217;s hacking attempts. It&#8217;s like I&#8217;m opening up little tiny example databases and there&#8217;s 1,000 hits a minute trying to hack into it.&#8221;<\/em><\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-you-don-t-have-to-be-a-target-just-a-resource\">You don&#8217;t have to be a target \u2014 just a resource<\/h4>\n\n\n\n<p>Pat recounted a <a href=\"https:\/\/www.red-gate.com\/simple-talk\/databases\/sql-server\/\" target=\"_blank\" rel=\"noreferrer noopener\">SQL Server<\/a> that ended up quietly mining Bitcoin for an attacker who never even touched the data. Kellyn encountered the same pattern, with leaked <a href=\"https:\/\/aws.amazon.com\/what-is\/api-key\/\" target=\"_blank\" rel=\"noreferrer noopener\">AWS API keys<\/a> and crypto miners running up a significant bill.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-retrofitting-security-onto-a-privileged-by-default-app-is-brutal\">Retrofitting security onto a privileged-by-default app is brutal<\/h4>\n\n\n\n<p>Whether it&#8217;s Great Plains demanding <code>SA<\/code> for everything, or <a href=\"https:\/\/www.red-gate.com\/simple-talk\/resources\/books\/introduction-to-postgresql-for-the-data-professional\/\" target=\"_blank\" rel=\"noreferrer noopener\">PostgreSQL<\/a> systems with passwords in <code>pg_hba.conf<\/code>, Kellyn, Steve, Pat &amp; Grant all agreed that adding security later is one of the hardest things in software. As Steve said, <em>&#8220;you&#8217;re so worried about breaking something, you wouldn&#8217;t do it.&#8221;<\/em><\/p>\n\n\n\n<section id=\"my-first-block-block_3d7d37318f53262796b758469df2b912\" class=\"my-first-block alignwide\">\n    <div class=\"bg-brand-600 text-base-white py-5xl px-4xl rounded-sm bg-gradient-to-r from-brand-600 to-brand-500 red\">\n        <div class=\"gap-4xl items-start md:items-center flex flex-col md:flex-row justify-between\">\n            <div class=\"flex-1 col-span-10 lg:col-span-7\">\n                <h3 class=\"mt-0 font-display mb-2 text-display-sm\">Protect your data. Demonstrate compliance.<\/h3>\n                <div class=\"child:last-of-type:mb-0\">\n                                            With Redgate, stay ahead of threats with real-time monitoring and alerts, protect sensitive data with automated discovery &#038; masking, and demonstrate compliance with traceability across every environment.                                    <\/div>\n            <\/div>\n                                            <a href=\"https:\/\/www.red-gate.com\/solutions\/use-cases\/security-and-compliance\/\" class=\"btn btn--secondary btn--lg\" aria-label=\"Learn more: Protect your data. Demonstrate compliance.\">Learn more<\/a>\n                    <\/div>\n    <\/div>\n<\/section>\n\n\n<p><\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-ai-is-amplifying-existing-bad-habits-not-fixing-them\">AI is amplifying existing bad habits &#8211; not fixing them<\/h4>\n\n\n\n<p>The standout line of the episode, from Grant: <em>&#8220;It goes back to that 80s commercial. Where did you learn to do drugs? I learned it from you, Dad. The LLMs learned it from us. We&#8217;ve taught them poorly and now they&#8217;re executing poorly.&#8221;<\/em><\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-there-s-a-glimpse-of-how-ai-could-help\">There&#8217;s a glimpse of how AI could help<\/h4>\n\n\n\n<p>Steve described an LLM (large language model) that, when given credentials in a file, came back unprompted and offered to move them into secure storage. This kind of &#8216;secure-by-default&#8217; capability is exactly what people want &#8211; and need &#8211; from AI, but it&#8217;s not the norm as of yet.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-defaults-beat-documentation-every-time\">Defaults beat documentation, every time<\/h4>\n\n\n\n<p>That&#8217;s Kellyn&#8217;s core argument: <em>&#8220;Everybody&#8217;s talking about policy and governance. If they don&#8217;t get software that does it for them, they&#8217;re going to lose. We need software that goes in and forces people to do it.&#8221;<\/em><\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-friction-can-be-a-feature\">Friction can be a feature<\/h4>\n\n\n\n<p>AWS&#8217;s fiddly <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/what-is-amazon-vpc.html\" target=\"_blank\" rel=\"noreferrer noopener\">VPC (Virtual Private Cloud)<\/a> setup is a real impediment to speed \u2014 and that&#8217;s exactly why it nudges teams toward more deliberate network design. On the other hand, <a href=\"https:\/\/www.red-gate.com\/simple-talk\/cloud\/azure\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Azure&#8217;s<\/a> &#8216;just let any Azure service talk to any other&#8217; convenience is faster, but defaults to a posture most teams wouldn&#8217;t knowingly choose.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-legacy-systems-aren-t-the-only-problem\">Legacy systems aren&#8217;t the only problem<\/h4>\n\n\n\n<p>Kellyn pointed to the <a href=\"https:\/\/www.cloudsek.com\/blog\/the-biggest-supply-chain-hack-of-2025-6m-records-for-sale-exfiltrated-from-oracle-cloud-affecting-over-140k-tenants\" target=\"_blank\" rel=\"noreferrer noopener\">Oracle Cloud (OCI) breach<\/a>, which started with an unpatched legacy app. Kellyn also flagged that newer architectures, like <a href=\"https:\/\/www.red-gate.com\/simple-talk\/cloud\/big-data\/data-lakes-take-on-big-data\/\" target=\"_blank\" rel=\"noreferrer noopener\">data lakes<\/a>, are creating fresh exposure by democratising access faster than security can keep up.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-the-zero-day-window-is-closing-fast\">The &#8216;zero-day&#8217; window is closing fast<\/h4>\n\n\n\n<p>Where teams used to wait months to patch databases, automated attacks now move in within days of a vulnerability being published. Patching cadence has to change accordingly. <\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-security-vs-speed-it-should-instead-be-visible-work-vs-invisible-risk\">Security vs speed? It should instead be &#8216;visible work vs invisible risk&#8217;<\/h4>\n\n\n\n<p>Security work shows up in tickets and slower pull requests (PRs), so it&#8217;s visible. The risk it averts, however, doesn&#8217;t show up anywhere &#8211; <em>until<\/em> said risk becomes a reality. Then, it shows up everywhere.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>11 takeaways from the Simple Talk podcast on security vs speed in databases: why teams misjudge risk, how AI amplifies bad habits, and what to do about it.&hellip;<\/p>\n","protected":false},"author":59127,"featured_media":103086,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[46,143523,143530,159393,143524],"tags":[4168,4170,4619,5765,4150],"coauthors":[7590],"class_list":["post-110703","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security-and-compliance","category-databases","category-security","category-simple-talk-podcast","category-sql-server","tag-database","tag-database-administration","tag-security","tag-security-and-compliance","tag-sql"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/posts\/110703","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/users\/59127"}],"replies":[{"embeddable":true,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/comments?post=110703"}],"version-history":[{"count":5,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/posts\/110703\/revisions"}],"predecessor-version":[{"id":110712,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/posts\/110703\/revisions\/110712"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/media\/103086"}],"wp:attachment":[{"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/media?parent=110703"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/categories?post=110703"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/tags?post=110703"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/coauthors?post=110703"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}