Today's threat models are dominated by the criminal, opportunistic attackers looking for user information or computing power. Real discussion and countermeasures for focused attacks are severely lacking.
Governments know this. CISOs know this. They speak of it privately to each other, but rarely in public because the issues are so sensitive. Messaging from industry is dominated by the vendors who both have significant equities in the "we're secure!" message and speak very narrowly about the security of their applications, but rarely/never about the collection of those applications into these beasts we call networks.
Posts like this are becoming more commonplace, but neither industry nor academia are making tangible strides to solutions. If you want a startup idea, focus on security and go disrupt.