Re: "Developers are responsible for insecurity."
This business of recording information given to a boss reminds me of an old friend who used to be a sailor.
He was once given an instruction by a captain which he could see was bloody risky. He insisted that he would only comply if it was written in the ship's log as an order from the captain; the captain backed down when he realised that any blame would be attached to him if the ship sank and could not be passed on.
Perhaps something like ship's log should be kept for orders handed down (VW are you listening?).