Extend Kyverno/OPA rules to cover common misconfigurations (e.g., no privileged pods, enforce pod security standards).