Nir emphasizes the importance of running comprehensive tests, including secret scanning and static analysis, with each code push. He discusses the flexibility of testing strategies, noting that while some code may only require unit tests, a robust pipeline can accommodate various needs, including infrastructure as code vulnerabilities. The approach should be timely and tailored to the specific implementation.