@SwiftOnSecurity whether we want to admit it or not, most of us were that person.
That said, we need to be better at communicating the basics. It's not always that the orgs don't care, we (i.e. #infosec) don't give them the proper information to be able to understand, to be able to prioritize, and to be able to react. What seems so basic and simple to us isn't so simple and basic to a CFO. Much like the inner workings of our finance departments are pretty much foreign to most security people.