TL;DR: Late-arriving findings, murky ownership, and dashboard-heavy workflows are the real reasons AppSec programmes stall, according to Arnica’s review of Merge Ready’s assessment. The central issue is governance friction: if developers do not see risks in flow, security becomes triage theatre instead of risk reduction.
NHIMG editorial — based on content published by Arnica: Merge Ready's Arnica Review: March 2026
By the numbers:
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security.
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job.
Questions worth separating out
Q: How should security teams reduce the delay between finding a risk and getting it fixed?
A: Security teams should shorten the path between detection and ownership.
Q: Why do dashboard-heavy AppSec programmes struggle to change behaviour?
A: Dashboards inform people, but they do not assign work.
Q: What breaks when ownership context is missing in security triage?
A: Triage slows down because nobody can quickly answer whether the issue is exploitable, relevant, or owned by the right team.
Practitioner guidance
- Map the remediation path end to end Document every handoff from detection to fix for code, secrets, and infrastructure findings, then remove steps that do not change the decision.
- Enrich findings with ownership and exploitability context Attach service ownership, dependency reachability, and exploitability signals before routing alerts.
- Push controls into developer workflows Deliver findings in pull requests, chat tools, and issue trackers so remediation happens where the change is already being made.
What's in the full article
Arnica's full blog post covers the operational detail this post intentionally leaves for the source:
- How the review maps AppSec findings into pull requests, Slack, Teams, and issue trackers
- The full breakdown of SAST, SCA, secrets, IaC, SBOM, package reputation, and license signals
- The reviewer’s step-by-step rationale for when security work becomes developer noise versus actionable remediation
- The exact examples used to show how prioritisation changes when reachability and exploitability are added
👉 Read Arnica's review of Merge Ready's AppSec workflow assessment →
AppSec workflow bottlenecks: what security teams need to fix?
Explore further
Workflow friction is now a security control failure, not just an operational annoyance. When findings land too late, the organisation is not merely slower, it is less governable. This is the same structural problem seen in identity programmes where ownership, routing, and remediation steps are unclear. For practitioners, the question is whether the control reaches the point of action.
A question worth separating out:
Q: How do teams keep security controls from becoming another bottleneck?
A: Teams should design controls around the operator’s workflow, not around the security team’s preferred interface. Put the decision in the pull request, issue tracker, or chat flow, and make routing automatic. Controls that are invisible at the point of action usually fail in practice.
👉 Read our full editorial: AppSec workflow breaks down when findings arrive too late