At Nоrdhоlm Systems' next retrоspective, the teаm compаres its implementаtion-phase practices: coding standards are followed almost universally and engineers consistently rate them as one of the most valuable security practices they use, while more specialized security tooling sees much lower adoption. A new hire asks why something as basic as a coding standard would rate above dedicated security tools. What's the likely explanation?