Looking ahead to 2023, AppSec and Product Security teams are looking to answer some fundamental questions: Is "shifting left" a feasible long-term solution? How important will fixing vulnerabilities in the production environment be going forward? And what will be the role of standard rating systems in evaluating the potential severity of a vulnerability?