Password change policies - say no more, virus checkers - slowing down workstations for minimal benefit, internet access filtering - Businesses doing deep packet inspection on the off chance that one of the staff members might bring in something nasty.
The cost in time and frustration is over the top and the benefit is mostly around perception.
The reality is, that if somebody wants to compromise your security, they will find a way. The chances are that it has already happened and you have no idea about it.
I'm not advocating do nothing, but there needs to be an understanding that most of the measures taken these days are patches put in place for broken software, incorrect configuration and poor user education.