The things you should do to prevent catastrophic failure:
- Reduce your attack surface as much as possible.
- Automate your infrastructure, human input should be nonexistent
- Write a lot of automated tests
- Take the time to learn attack methods and actively try to break your own systems
- Have an external firm that will try to break your systems
- Add additional redundancy for hot spots in codebase
- Code reviews are mandatory and you should follow an internal style guide.
- Adopt a maintenance first culture, it should take less than 48 hours for you to be on the most recent version of all your dependencies. Bug fixes are your #1 priority.
- Educate your customers on what your potential failure conditions are, your recovery point objectives, and your recovery time objectives.
- If you do have a failure, fail loudly in a way that a customer can understand, report the failure and hopefully have a backup plan that users know and can run through.
- Customer support is a responsibility of the engineering department.
- Learn from others and contribute back with your tooling.
You can write mission critical code in any language. (Some are definitely better than others) You can't manage a mission critical application without investing in great operations.
Read google's SRE books for more practical information: https://landing.google.com/sre/books/