Website security

Website security is an important factor in the development of any website based on a CMS be it custom or Open Source.

What I am trying to say here is that website security is also server related part, but mostly the programmer has to do the "securing" job.

In RO we have a website with amateur hackers that run tests on big sites and find breaches in their security. Sites with over 700k uniques a month were "cracked" without problems.

Doesn`t that make you think twice when talking about website security ?