That just pushes them offshore.
I would rather that there be greater security training in software development programs/bootcamps.
I’m a software engineer. I know a lot of software engineers. None of us have ever been trained in security.
Any “best practices” are usually picked up in Stack Overflow conversations.