At Nоrdhоlm Systems, аrchitecture аnd аpplicatiоn-development guidelines are one of the requirements-phase documents nearly every team consults, yet when engineers are surveyed internally on how much those guidelines actually contribute to security, the ratings come back surprisingly low. A junior architect assumes this must mean the guidelines are outdated. What's a more likely explanation?