I think part of the problem is that many orgs see security as an overhead that engineers do to sleep well at night. A few more breaches, a few more fines and it will finally be seen as a feature to keep the CEO out of jail.
To me, a good parallel is home insurance. If you get robbed, a good insurance will cover your losses. However, if said insurance determines that you were negligent -- say you never lock your front door -- you are on your own.
Do you have precious art at home that you want insured? No problem. Just make sure you add an alarm and sprinklers.
That is how I want discussions around security to be held. Are you a start-up with 10 users? It's okay to do minimal security. Are you a bank whose wires carry $1B? Make sure you throw sufficient "bodies" at the problem, from the top of the hierarchy to bottom.