> I mean, do you know any civil engineers who would say, "Oh hey this foundation is cracked, let's build something that tries to patch those cracks, and when that's broken, we'll build another level on top of that, and let's just obfuscate what's really going on underneath everything so that nobody who uses the building realizes it's unstable, and just hope it doesn't get too windy, or that there is an earthquake."
No, but civil engineers say stuff like "What's the likelihood that a 9.5 earthquake will his this area? What about a 5?" and model their designs on that. That's the point behind threat modelling - if a nation state actor decides they want to 'hack your Gibson' that's one thing, but if you're a bank than it may be that your most likely threat is employees or contractors stealing customer data. So you put your effort into protecting against those threats as well.