For a software vendor, the product being sold is also, mechanically, its attack surface.
If an attacker exploits a flaw, the data of all your clients is potentially affected at once. A data breach isn't fixed with a patch: it damages the trust the SaaS model is built on.
Your clients audit you before signing: security questionnaires, pentest requirements, ISO 27001 or SOC 2 certifications. Proving a solid security posture has become a condition of sale. Your release cadence also outpaces your audit cadence: "elite" teams deploy multiple times a day (Google Cloud's 2024 Accelerate State of DevOps report), while an annual pentest photographs a product that will have gone through dozens of releases before the next audit.
This triple challenge (client data, contractual requirements, release cadence) raises a simple question: who, in your organization, is actually responsible for all of this?