And then people wonder why corporate IT security is really bad sometimes...
I've seen security breaches happen, and it's not the self-motivated users who cause them. It's the casual users who leave their computer unlocked, or go on social media with the same one browser they're using for work, or who click links in email without checking the source.
this sounds like personal use, though. I do appreciate your perspective, and am sorry that your IT dept has no sense of security. Disallowing password managers and ad blockers honestly sounds like a good sign to gtfo and find a more competent org, or dig in and drive some serious change from the inside.
A proper corporate security is to never have a chance for some client device to compromise the security.