I consciously talk about things that seem "simple," because doing so can seem counter-intuitive to people trying to make their way up the ladder. Make a name for themselves. That's absolutely valid no problem.
But the basics matter. Organizations fail at basics. The basics not being done drive this entire industry across the planet. Not the latest post on HackerNews or compromise intrigue.
So I talk about the basics. I have a certain amount of privilege where my competency doesn't get questioned for doing so. You should be more cognizant of your biases on people talking about the basics.
The basics not being done pay your cyber salary. Which very very few organizations in the entire planet can afford a dedicated person for. Everybody else, it's purely from their professional passion to get things "right." They have no real investment in the security of their organization. They try anyway. That's most of the world we need on our side.
I know because I was that person.