That's how I think when relatively complex programs I've written blow up (blow up = user term for job failing). I expect them to blow up during testing. The errors are then corrected and the code is also reviewed to determine how the error slipped by to begin with. If the programs work without any noticeable errors, the code review does not happen and there's a much greater likelihood of subtle errors slipping into production.