I'm sorry, but this just doesn't work in the real-world.
As the "security guy", you're seen as the troll under the bridge. Someone to get past via any means necessary, including lying.
But lets say you get your way.
"making sure you have all your ports locked down"
You can't imagine how much work this actually is on a network with 1,000+ servers running at least 10,000 distinct pieces of software. Most of which don't document their firewall requirements.
Oh, did you know that Active Directory domain controllers -- the single most valuable attack targets -- require essentially all ports open to all computers on the network?
What is your firewall going to do when all modern software communication is over HTTPS and "looks the same"?
How are you going to firewall off just one modern server with 200 Gbps Ethernet? Do you have any idea how much you'd have to spend with CheckPoint or Juniper or Cisco or whomever to do that?
"limit connectivity between all instances to only the bare minimum"
That lasts right up to the point that the shouty guy in finance that talks directly to the CxOs wants PowerBI on his desktop to be able to pull in data directly from all the databases. Did I say desktop? I meant a laptop on unencrypted airport WiFi.
"any public access is via protocols such as ssh which have zero-to-none vulnerabilities"
You don't get to choose the software. Windows doesn't use SSH for anything, and can't be made to.
Also, if you know anything about ransomware attacks, you would know that protocol encryption does nothing to even slow them down. If anything, it makes detecting attacks harder!
"routinely run employee training on how not to let themselves get hacked via social engineering"
Meet Mr Bell's Curve, and its unavoidable left hand side. Some people are just incorrigibly stupid and will routinely fall for phishing attacks, no matter how much training they receive. At any large corporation -- the type worth ransoming -- these people are inevitable. You, Mr Security Person, don't work in HR and don't make hiring and firing decisions.
"I'm sure I'm missing other stuff"
You're missing the fundamentals of the problem, which is that as a security guy:
- You must come up with security solutions that work in the face of morons.
- You must be able to secure software written by morons with no interest in, or ability to write secure code.
- You must do this without impacting the business in any material way, because if you stand in the way of anyone more senior than you -- even once -- you'll never be listened to again.
"Or are hackers so creative that even following these basic rules will still not make you a hard target?"
Currently, for any large org above about 1K staff, security against targetted attacks is basically impossible. Certainly not financially viable. Your competition will not spend the money, make more profit, pay out the ransom, and come out ahead of you.