* Fine-grained segmentation of all networks on need-to-know basis, informed by the org chart and detailed role descriptions for virtually all employees.
* No employee access to arbitrary Internet sites
* For employees that require Internet access, air gaps between computers that can hit Google and computers that can access company email
* Formal audits for minor software releases
* Expensive, heavily tested secure coding training for all developers
* Adoption of secure coding/design standards ("this is the XYZcorp way to make an SQL query" and "this is the XYZcorp way to render HTML"). Strict bans on deprecated interfaces.
* Employee access to sensitive internal applications (like document and image management) gated through Citrix-like environments, so you have to remote terminal in to get to the browser that actually talks to the application.
* Extremely minimal access provided to VPN users.
* Total 8021x-style lockdown of network ports and fascist policies against bringing own devices.
And so on.
There is zero chance this is ever going to describe any huge company.