Finding vulnerabilities is the easy part – deciding who owns the fix is harder. Should product teams handle their own bugs, or should security take the lead? This post compares embedded, centralized, and consultancy-based models of vulnerability ownership, and explores the metrics and cultural shifts that actually drive remediation.