That is an extremely naïve perspective. Imagine you run IT for 10,000 PCs across the US. For one, maybe 10% of these would need to be upgraded to get to an OS with modern security. Then there's the servers for internal applications which can't be upgraded without breaking things. And then you'll need to deal with all the support, explaining to employees why, yes, although they have tasks which need to run overnight, no, they can't disable automatic update, because it would put the corporation at risk. Not to mention the amount of work it takes to keep computers up to date even when the user isn't a problem.
And even with all of that, one day one of the computers gets a backdoor installed, and the attacker is able to copy everything off your network drive, because you didn't have any sort of IDS or firewall to prevent it.
Smarter people than you have thought about this. There's a reason the idea of an internal network exists at all; NAT certainly wasn't something people were considering right from the start.