I don't think that statement can be reliably applied if you are doing infosec at a large company.
I think the statement was coined specifically for large companies.
I wonder it’s because of the no-responsibility effect, people try to not be responsible for some systems where there is risk but little reward/fame to be had. Don’t know if it has a name.