You're still "doing it yourself" even if you use parameterized statements.
My take on this article has changed in the past hour; before I thought it was cute but inaccurate, but its state is transitioning to "actively evil".
The reality is that companies that have a lot of SQL but never have SQLI vulns do all of the following:
* Use an ORM like Hibernate (or AR or Django) for "front-line" database queries
* Standardize on parameterized statements for the complex stuff
* Design and implement a "house style" for query builders and "modular" SQL statements
* Factor as much as possible into stored procedures in the database
* Run databases in least-privilege mode, so that code that only needs read access to a few tables can "revoke" the unneeded privileges
* Sweep their codebases for SQL statements and audit them with a team signoff
By "do all of the following", I mean "A-L-L of the following". The ones that don't are the ones that tell us "there's no way you're going to find SQLI in your audit; you'd get fired for having concatenated SQL here", and then lose their entire database in the first week.
I don't mean to sound obnoxious. I just hate the idea of people walking around thinking their code is safe because they switched to ? instead of "'" + x + "'".