"IT is seen as such a money sink, that true and proper workload and therefore workforce requirments are almost never understood, much less met, so you end up with a one man miracle show sysadmin working a 40k job, always on call, who literally doesn't have the time to be proactive. If he or she brings it up with management, their work is often criticized and the budget is whined about and they are lucky to get a teir 1 helper (maybe only part time too!)."
This is so spot on, I'm going to ooze nostalgia for a moment:
I was the tier 1 helper brought in to help the one man miracle 40k sysadmin, way back at the start of my career. He taught me pretty much everything I know about sysopping well, skills that after languishing for over a decade still let me perform miracles to the eyes of my current SWE coworkers, and even at my prime I only had a FRACTION of his knowledge.
He kept two datacenters, literally thousands of machines, almost singlehandedly out of "being on fire". His management would have been more effective had they actually been in-abscentia, I have some fun stories about when our manager broke networking by wiring a routing loop, leaving work early after giving up trying to fix it, and leaving me there alone because "I'm sure you can get it working". (In trying to fix it, management broke pretty much all our vnets and trunking, this all started because the main sysadmin was out sick, which he almost never let happen)
I can go on with stories for days, I don't think I really had a compelling point in this other than to say working with him biased me towards good faith in sysops. It's funny to say that since the few other helpers who passed through in the years I worked with him were mostly all the terrible things you hear about incompetence/laziness, but part of me now keeps an eye out in any shop that's not perpetually on fire for the one sysadmin keeping the roof up.
To give a point for this ramble, I just want to voice out my support for those one man miracle shows, as an attempt to further thank the one who helped me so damn much, who was given so little for doing so.
To bring this back to the point of the OP, which I entirely forgot at the end of writing this, at one point we found that a keylogger had been hidden in our systems, and a rootkit had likely been proliferated. We recommended essentially a full nuke and repave, since there was very little we could do at this point to determine the extent of the compromise. Not only did management disallow us from properly cleansing some systems, they didn't even let them be taken down and rekeyed fully, making our efforts in the clusters we had full control over essentially moot. In short, sometimes a company can seem almost pathologically against good practices, despite the best intentions of those who might know better.