you wanna know why infosec is like this? Its because there are no consequences for failure for anyone but you. Sure there is compliance, but nobody ever really goes to jail when a breach happens.
Remember equifax? The only high profile arrest was the exec who got four months in the country club for insider trading.
They're more upset that he had a warning to dump his stock than they were that all of your fucking data got stolen by a company that more or less governs your livelihood.