Earlier quoted context omitted.
There are many steps in the chain between a phish message and a ransomware attack - the user opening a phish is just one of them. You might prevent lateral movement afterwards, you may detect the attack in time (there often are days or even weeks between the phish and the ransom) to protect it, you might prevent the payload from reaching the user, etc. So yes, you're right, the solution is not just better backups but…
>... however that takes will, money and quite some time. And the accounting folks will not be fans of anything that costs money. They will just say "But we haven't been attacked a second time, why should we pay for mitigation services and implementations??"
Organizations can and do take many decisions of which "the accounting folks" are not fans of, the accounting people can and do say such things about the costs, but they don't have a veto. Arguments about cost of mitigation are valid in general, but leaders and owners can choose the priorities, and the responsibility and blame for these choices is fully on them (for their will or lack of will), not on "the accounting folks" arguments.
Also, sometimes that accounting argument is entirely valid. For example, look at the recent case of First American Financial - https://krebsonsecurity.com/2021/06/first-american-financial... - if the consequence of leaking the sensitive financial documents of millions of customers is just 500k, then it definitely is cheaper to just accept the hacks and pay the compensation, because investing in proper security would be much more expensive than that.