An interesting parallel is how these similar issues are solved in other engineering domains. In civil engineering you have heavy regulation and accountability. If a building falls then the engineer is responsible and she could get a jail sentence. To prevent buildings from falling there are regulations around minimum requirements, audits, material quality, etc.
Regulation in software "does not exist" as the actual threat is minimal. If your program crashes then nobody dies ('m not talking about rockets). Therefore it always looks like security people always have temper tantrums as there is no meaningful quantifiable risk.
In our org we ended up asking pentesters to get into the systems instead of just giving us an automatically generated report that contains links to CVEs. If they cannot use existing risks to get into the system then that risk is trivial.