Start with the attack surface, not a generic checklist
We identify users, privileged roles, sensitive data, external services, entry points, secrets and recovery requirements early enough to shape the design, instead of trying to patch them in later.