RE: https://infosec.exchange/@BleepingComputer/117367320213090666
this is in very very large part because most defenders tend to be hampered by compliance. and since compliance isnt security at all, and it never will be, defenders are forced to jump through regulatory hoops and do a little song and dance to make grc and legal happy instead of actually making systemic changes that makes lives harder for attackers.