Earlier quoted context omitted.
Governments take IT security very seriously, I don't see where you've seen they don't. The problem is that you just can't secure a whole infrastructure overnight and that security is very hard.
I would like to clarify on this issue a bit. 1. Declaratively the governments are indeed taking IT security seriously. Thus many guidelines, laws and other formal documents regarding IT security have been accepted. Unfortunately many of these are internally inconsistent or in conflict with others. The net result is that in the name of "security" the governmental IT systems are unnecessarily complicated and expensive.…
Yes the government wants to cover its ass first and foremost.
But that doesn't mean they don't take IT seriously, they just don't understand it to the point they cannot select people to work with that understand it correctly.
disclaimer: I've designed COMSEC systems