I am not sure you want to delay penetration testing until you are post IPO.
Caveat: do you need to do pen testing every release? I'm guessing, not. YMMV.
If you're a defense contractor (as some other commenters mentioned), your priorities are probably quite different.
That said, I liked the article - thanks for sharing.
Glad to hear security is taking the front seat some places. Anecdotes like this help me expand my world view. <3