Now, I've learned a lot about mistakes I've made, and I was never a perfect senior sysadmin, mostly because I wasn't playing the meeting room presentations/reports and politics game. So I'm not trying to make myself out to be perfect in any fashion.
That said, when I requested a full time t2 person. Denied. Requested a full time t1 person. Denied. I literally had to poach some part timer who was sweeping floors and train them myself... which did nothing to alleviate my time crunch dealing with desktop users in order to tackle the substantial infrastructure security issues, which takes time and thought (did I mention it was an open office area, so good luck getting good thinking work done...) Requested contractor structured cabling job (just horizontal)... denied...
Us sysadmins can secure this stuff, mostly through really good network policies and firewalls, etc, but if management is cost-cutting corners left and right and would rather hire some contractor-MSP type that does 1/4 the work at x3 the cost, while refusing to support internal IT teams with the tools and funding they need to get their job done properly, it's no fucking wonder insecure systems abound in the industrial world.
This is managements problem, and until the public or others start punishing them for not seeing IT and security as an investment instead of just a janitorial cost-sink, it will continue to happen.
That's the reason behind my last burnout. Now I'm happily on break pursuing my data science degree. I've been on the contractor side too, (dropped out of college after the Marine Corps to start an IT support company that is still alive today even after I left) so I've seen the inside of hundreds of companies, from fortune 500 oil to 20 man lawfirms, so I'm not just pulling this info from a couple of jobs. I saw it everywhere.
A good CIO or CTO should be able to address many of the technical-political disconnects, but they hardly exist. Go try asking /r/sysadmin how many of them even get a real budget. Half the time they just have to "ask" and hope they were convincing enough that management approves. Usually to a CFO or CEO since the CTO/CIO doesn't exist.
Oh, and of course they all want to immediately jump on the IoT bandwagon but still don't want to hire the people to get them out of their old technical debt, much less the new massive technical debt many IoT devices will bring!
Don't even get me started on the "big data" issues IoT and many PLC type devices bring.
edit: The key to the increase of this issue is the direct LTE connections on the PLC's, whereas you used to have a satcon to a router and everything was internal from there, that's less true these days. Even so, you still have issues with the security of that edge.