In almost every work environment, I've seen the policies working directly against security: if not by contradicting it, ignoring the details where the real security decisions live, or by striking the wrong balances between prescriptiveness and generality - then by out-prioritizing security decision making. (I've worked at mostly 100,000+ person companies).
It's much better to have technical security controls >80-90% of the actual security. It's just expensive and harder to teach/learn/implement.
That said, there's some real security gained by policy. It comes from: - Ability to communicate expectations ("adopt technical solution X") - Ability to exercise legitimized (instanciated/codified) authority
Most of the rest of the value of policy comes in as business enablement value (policies are easier to communicate to auditors than security control implementations are).
Policy can also be a useful placeholder for real security in the sense it will satisfy many external parties who might otherwise reprioritize/randomize security investments.