Discovering that you have made a critical design flaw that makes your application insecure late in development can cause a big hassle. Deadlines must be pushed and your application may be more annoying to develop. This talk addressed how to implement "Secure by Design" in a practical way so that you avoid such situations.