A negative security example that comes readily to mind are how bad government policies/standards helped cement for a long time the awful practice of complex password requirements including rapid change requirements, "security questions" and so on. These are actively negative for security, people in the field realized pretty fast (and of course many argued from the start) that the only reqs for passwords should be some minimum length, not using previously exposed ones, and having a sufficiently high maximum length that everyone is free to use more comfortable ones like diceware if they wished. While that has been getting revised at last bureaucracy still moves much too slowly there.
Of course this hasn't made it through the gauntlet and hopefully won't, but I'm glad to see it getting some attention.