Hi
This message might not always mean the device is really secured. Sometimes it could be misinterpreted with connection issue. The only way to censor the device is to intentionally write to "Shadow Flash" area which requires a specific algorithm to be used.
Could you possibly check if you have SBC chip on board enabled? It may reset the MCU before the debug session is established.
Could you try to load a test project into RAM instead of flash?
Stan