"Everyone messes up" is fine if your job is creating systems where security is largely a secondary concern. If security is the whole point of your product in the first place, and your product is actually completely insecure, that's not messing up, that's gross incompetence.

