A bit off your "real" point: No company should ever spend more mitigating a risk than the potential cost they could incur from the risk. That is just good business, but the reality is that companies generally won't spend more on cybersecurity than their peers (either as a percentage of revenue or percentage of IT spend). Whether that is the proper balance for a risk/spend calculation is the real topic.
The problem is that we can't accurately calculate the probability of a cyber event and the cost impact of that event. So the company is stuck waiting for an attack on themselves or one of their cohorts so they can adjust.