Software security - Why aren't the enterprise developers listening?

Why is it next to impossible to provide proper incentives for developers to adopt software security? With all the different methods available, the technologies maturing, and top-down support in some instances ...why are organizations still struggling with software security?

