@hypolite The normalization is mostly a matter of fighting the process of seeing security as a cost center and underfunding it.
So - the core thing is complexities around risk and access. Part of corporate culture is risk appetite. Corporate culture loves accepting risk, and so security teams kinda don't have a lot of leverage. And that's where the problem is, ya know. I don't know how to fix that.