Security is not an end-of-project phase: dependency reviews, automated tests and best practices from the very first sprint.
Bolting security on at the end is expensive: refactors, retesting, delays. From the first sprint, the squad automates dependency reviews, applies best practices and tests.
The result: security is a state, not a phase.