This is one of those Kubernetes topics that's easy to underestimate. One thing I've seen repeatedly is that many teams assume namespaces provide meaningful isolation, when in reality they're often just an organizational boundary. The real blast radius is determined by the combination of NetworkPolicies, RBAC, service accounts, admission controls, and workload identity—not namespaces alone. Security by default should be about reducing the reachable surface, not just segmenting resources. A timely reminder that Kubernetes defaults are designed for flexibility, not least privilege.