Last week Sandy Carter wrote in Forbes that Starbucks is building its own AI-assisted software to replace a Microsoft inventory system and an IBM maintenance platform, taking aim at a $400 million software line. The headline called it a warning shot at the application vendors.

It was not a warning shot. A warning shot is a single event, fired once, meant to make you reconsider. This is not that. This is the first shot in a sequence that does not stop.

The builder ecosystem has already transitioned. Inside every company that creates and innovates, the population shipping to production has tripled. The marketer is writing Python. The analyst is shipping agents. The product manager prototypes on Friday and pushes on Monday. When building was slow and expensive, it made sense to buy a platform that fit maybe 70 percent of how you actually work and pay consultants to force the other 30 percent into shape. AI-assisted development killed that math. When a coffee company can rebuild an enterprise application in a fraction of the time, every Fortune 500 technology budget is running the same recalculation right now. Starbucks is just the one that made the news.

One detail in the market’s reaction tells the whole story. When the news broke, the application vendors dropped. IBM, ServiceNow, and Salesforce all took a hit. Microsoft barely moved. The reason is simple. Microsoft sells the application Starbucks is replacing, but it also sells the Azure cloud and AI infrastructure Starbucks will build the replacement on. The market already knows the difference between owning infrastructure and renting an application. It sold the layer that is losing and kept the layer that is winning.

The fear playbook is coming

Now the predictable part. The same Forbes piece forecasts it plainly: the incumbents will fall back to the terrain that is hardest to replicate. Governance. Security. Decades of accumulated domain knowledge. Watch them reposition from application sellers to trust providers.

Read that in plain language. When you can no longer win the build-versus-buy argument on speed or cost, you fall back on fear. You cannot possibly secure what you build yourself. Better leave it to us.

That argument has it exactly backwards.

What “build it yourself” actually means in 2026

Nobody serious is writing an operating system or racking servers. You are assembling. You build on a cloud provider for compute and network. You build on application platforms and platform-as-a-service for delivery. You build on managed databases for state. You wire in identity, secrets, queues, and a dozen more managed services beyond those. Every one of those layers is run by a specialist whose entire business is operating it more securely than you ever could alone. The modern stack is more hardened, more patched, and better supported than any monolithic legacy application ever was.

What changes is not how secure the foundation is. What changes is where the security work lives. It moves off the vendor’s roadmap and into your control. That is an upgrade, not a risk.

Because the uncomfortable truth about buying a legacy application is that its security was never yours to begin with. You inherited the vendor’s patch cycle, their disclosure timeline, their definition of secure enough. You waited for a fix and hoped the SLA held. When you build on modern infrastructure and pair it with security tooling that was purpose-built for that infrastructure, you get something that relationship could never give you. Visibility into what you actually run. Control over how fast you remediate. Context on what is genuinely reachable and exploitable, instead of another list of findings nobody has time to read.

You do not get worse security when you build. You get better security, and you get the support that comes with tooling designed for how you actually work rather than a support queue for a product you were forced to customize.

This is why we built Orca for companies that build

The security industry spent a decade selling findings, then dashboards to manage the findings, then risk reports to summarize the dashboards. More alerts. More coverage. The promise that eventually you would get ahead of the risk. Nobody ever got ahead. That model was designed for a world where a fixed set of engineers shipped a fixed set of applications on a fixed schedule. That world is gone.

In the world that replaced it, almost everyone in the building is a builder, and they move faster than any review process was ever designed to handle. The job of security is not to gate that. It is to enable it. Security is not the brake. It is how the company gets to keep building.

So the incumbent’s fear argument does not just fail on the facts. It fails on strategy. The companies running the Starbucks play are not less secure. They are the ones who decided to own their operations again, which means owning their security posture instead of renting it.

Ownership is what lets you move first. Purpose-built tooling is what lets you look far, so the thing you shipped on Friday is understood, monitored, and defensible by Monday.

The rest is just waiting

This was not a warning shot at Microsoft and IBM. It was the first visible shot in a shift that is already running through every segment of the business. Cloud services. Application platforms. Managed databases. Many more layers still to come.

The application-layer incumbents will spend the next few years telling you it is too dangerous to build your own. The companies that ignore that advice, and pair modern infrastructure with security built for how they actually work, will be both faster and safer than the ones who kept paying the license fee out of fear.

The only real question left is who moves first.