Oh, your problem is you don't have anyone doing risk assessments (see Risk Matrix for an example) and quantitative risk analysis and measuring cost to fix vs likelihood of occurrence and cost of an incident against that fix over an extended period. It's a bit like an in house insurance adjustment. Tangentially, a lot of companies decide to buy insurance as a "fix" for a risk. Because the insurance costs less than implementing whatever solution is required.
Just good enough often times is an orgs own policies and standards, and security teams catch when things aren't meeting those standards.
Your complaints are a lack of maturity in your cyber security organizations. There are cases where a business can absolutely decide its "good enough". But that decision is made by people other than those that point out the vulnerability. It's usually done by which ever team handles security remediation or they talk to someone who handles that analysis as part of the remediation process if the fix seems prohibitive. Cost to fix can also go down as new solutions become available or infrastructure changes and a new design makes it easier to build in a fix/control/detection or whatever. So re-evaluating "accepted risks" periodically to see if its something that's easier to implement is also part of it.
Cybersecurity shouldn't be in the business of saying no (unless its something insane like storing passwords in plain text on open shares), we're here to say, "here's some problems we see", here's where we think we can help, everything else is up to the frameworks and policies your company has set to adhere to or someone at a higher level to say cost exceeds risk, we accept the risk until such point cost comes down, etc. Cyber should also be helping to put in systematic controls that make good controls the default, and good practices easy to implement, so that ops and devs don't have to think about it.