@pseudonym I would generally agree with that statement… except we still see customers who obviously have a great security culture (lots of stuff done well, engaged staff, knowledge of outstanding issues) but still miss some of the more basic stuff (weak password policies, no separation of duties) because they don’t have a checklist to follow.
Not sure if this makes sense, tho.