What I see all the time in IT security that for many people doing security means spending lots of money on products with highly questionable promises. It's very doubtful that many of the security appliances you can see at RSA or Black Hat do any good, in many cases they add additional risks. But the industry is selling a story that the more boxes you buy and put in front of your network the better.
For a lot of companies there are very cheap things they could do to improve their security. This starts with such simple things as documenting on the webpage who outside security researchers should contact if they think they found an issue in the companies infrastructure.
So I have quite some doubts that the formula "spending more on security == better security" holds.