We bought into the Emperor's New DevOps, so we're secure now, right? Well, maybe, maybe not. Let's talk about what security is and isn't in this new era of Cloud and Kubernetes-first, platform-engineered systems. How everyone seems to think "Shift left" means exactly one thing, and then they're done? What threats are actually likely, and how are they not the ones you're being sold on? Yes, marketing is still very effective in the security space! How to strike the balance between exact security "best practice" overhead and workable security.