They will whitelist super old known insecure java versions / windows versions etc that can NEVER change. I remember having to downgrade to windows 7 to access one VPN setup (yes - to get through the security firewalls you had to downgrade the entire stack to something the "security" firewall handled). I think this all was in part because they don't patch / update, so some stuff (flash / activeX etc) just doesn't work well on a modern machine
Ironically, they also would let their key domains expire but thankfully folks just would call a helpdesk and get an IP address to use (but these domain endpoints were 100% being hit by downgraded / unpatched machines so if someone had purchased the domain it would have been bad news).
For some places that were not inside an agency we had had to keep the "secure" machine separate from the actual network because it was the most vulnerable.
Thankfully, the help desk was so overwhelmed with calls about this horribly fragile system that they would reset anyone's password over the phone, so user lockouts were easy to handle, call up, ask that so and so's password be reset to XXXX and done (virtually no authentication other than knowing what number to dial). This was critical because the passwords had to be changed every 30 days and were insanely complex - we had lockouts even though folks thought they'd written them down properly right next to the machine (cap / lower / number / letter confusion issues?).
Meanwhile, my google account has proper two factor authentication, can be accessed from most any modern device, rate limits and screens login attempts in a smart way, and I haven't had to change my password in 15 years (so I could pick a hard one I don't use elsewhere).
Fun times!
They are sold this as a virus filtering requirement or something like that.
But some agencies literally decrypt everything going out (and then re-encrypt) - talk about a security and privacy risk!
Staff can use personal phones to check bank balances, do messaging etc if they have any sense at these places.
Thankfully this all died WAY WAY down with certificate pinning - thank you google! Seriously, when the execs got the warnings from google chrome the decrypt everything situation died at a lot of places.
Google's history on securing users using chrome is not bad (if you are dealing with old IE etc chrome is basically heaven by comparison in terms of security and patch velocity)
Then we had to develop most of the times in a virtual desktop so the frame rates were like 10fps and getting animations right was notoriously hard. Now the backend seemed like a cake! I quickly moved out of there and I'm much happy about that decision!
If you combine paranoid-level security with non-technical and often lazy users, and add cost-cutting all around, you get something like described here.
I know that from my father working in the IT department of a large corporation.
Having said that some are pretty well known large companies, but the business units that sort of operate on their own if only due to their archaic nature. The company has a policy, it just doesn't always apply to them.
Logistics is a weird industry ;)
Like every logistics organization does something some weird way (carrier, client, end customer, everyone's accounting...), they're sure it is the right way, and then the next one does it the "right way" another way and now nothing is a 1:1 ;)
Lots of old / skewed / strange practices that requires a lot of unexpected maintenance / changes. It's easy to end up swimming in a lot of bad / not equivalent data.
It's really something.