Wherever Tech is a first class citizen and seat at the corporate table, it can be different.
They delegate that stuff. To the corporate IT department.
It's all CyberSecurity insurance compliance that in many cases deviates from security best practices.
For example, we got dinged on an audit because instead of using RSA4096, we used ed25519. I kid you not, their main complaint was there wasn't enough bits which meant it wasn't secure.
Auditors are snake oil salesman.
And produce a piece of software no one in the world wants and everyone in the world hates. Yourself included.
If you wanna kill corporate IT, you have to kill capitalism first.
playing devil's advocate for a second, but corpIT is also working with morons as employees. most draconian rules used by corpIT have a basis in at least one real world example. whether that example happened directly by one of the morons they manage or passed along from corpIT lore, people have done some dumb ass things on corp networks.
I would say the problem in the picture is your belief that corporate IT is introducing technical impediments against every instance of stupidity. I bet there's loads of stupidity they don't introduce technical impediments against. It would just not meet the cost-benefit analysis to spend thousands of tech man-hours introducing a new impediment that didn't cost the company much if any money.