How about not generating an organizational culture of fear? Anyone who has taken an introductory psychology/behavioral theory course knows that while the threat of punishment works as a deterrent to deviant behavior (like letting bugs slip through the cracks out of laziness/apathy) some of the time, the promise of a reward for doing things right is much more effective.
If I were a Microsoft executive charged with the task of elevating security standards, I would institute some kind of incentive system for secure code. None of your team's applications required a Tuesday patch this month? Here's a check. You found a vulnerability of which we were previously unaware? Here's a bigger check. Keep up the good work, valued one!
Pascal is not a high-level language. -- Steven Feiner