@alex02 @GossiTheDog The other reason security is getting worse is because the rest of IT/Dev teams are being outsourced to lowest-bidder MSPs that don't give a sh*t about doing anything right.
But when any remaining internal security staff (if they have enough Ops/Dev experience - which unfortunately, most audit/compliance staff don't) point out the questionable engineering standards to anyone in management... well, they're the bad person now!