I learned #2 the hard way. Built a site for a local dancing club in the beginning of my career, and didn't bother to worry about security.
2 months later I get a call, that their guestbook was full of spam, and that it had broken completely recently (a meta redirect inserted in the comment).
I quickly added a captcha and made sure no SQL or Javascript injection was possible etc. This is a given today, no matter how small the project.