Static and dynamic application security testing, built into your development process — not bolted on after a breach.
Most vulnerabilities are introduced during development, not deployment. Reviewing code for security — not just functionality — catches them while they're still cheap to fix.