For one obvious, simple example, most tech is optimized for "Make it easy to access all data from anywhere" as opposed to "require affirmative consent for connections to all new locations". It is surprisingly difficult to lockdown most systems, whether they be laptops or server networks, with that easy rule. Just look at folks who use Little Snitch - it can be difficult to use this effectively because so many apps need to talk to so many different servers that it can just be exhausting attempting to determine if a new connection is malicious or not.
Similarly, look at some recommended settings for a "secure" Content Security Policy on the web. There are a boatload of different options that are recommended to be set, because the original defaults (e.g. "Sure, you can load me in an iframe of any other site!") are so insecure.
As a consequence of this, it's very difficult for any (a) organization that can't afford top-notch security folks or (b) organizations that are so large, with a potentially huge history of acquisitions over time, with a giant surface area where all you need is one "chink in the armor", to prevent breaches.