The document discusses common fallacies around application security and provides realities to counter each fallacy. It addresses 8 fallacies: 1) That application security is cost prohibitive, 2) It is too complex, 3) Covering only critical apps is enough, 4) It is only for software vendors, 5) Developers won't change processes for it, 6) One technology can handle it, 7) Network/firewall security covers apps, 8) Testing purchased software is unnecessary. The document advocates a comprehensive approach using multiple techniques like static, dynamic, and interactive testing to effectively secure applications.