>but don't know how to deal with source code or mitigation
actually I have noticed this and so we are spinning up a security consulting practice in 2018 looking to address this gap (staffed with experienced developers or former developers). Time will tell if this is a workable approach..
That sounds like a fantastic idea. Would love to follow the journey / potentially throw my hat in the ring as you start looking for devs. I'm @tradesmanhelix on Twitter if you'd like to chat.
actually I have noticed this and so we are spinning up a security consulting practice in 2018 looking to address this gap (staffed with experienced developers or former developers). Time will tell if this is a workable approach..