Earlier quoted context omitted.
Literally the only reason any company invests actual time into data security is HIPAA, GDPR and SOX. I keep wondering why people haven't demanded more regulation after all their SSNs got leaked
Because there are very few regulations that can effectively capture the intent of the rules instead of "tick boxes" that might or might not mean very much. Sure, "has firewall" is pretty effective but how do you encapsulate how it should be managed effectively? What happens when a system that was supposedly secure installed by a previous employee fails? The company's fault? How would they know? The employee's fault?…
And that doesn't even cover the part where PCI, SOCII, and SOX all have various bits that contradict or are not compatible with each other.
I've seen too many times where the head of security or IT or whatever picks a pre-made package off a shelf from one of the audit providers where they guarantee you will pass all of them. Then they follow it like it's law ultimately leading the swe/devop/sre groups to build out layers of shadow it/ops to actually get productive work done.
My work primarily is to jump into startups after they are acquired to make them "enterprise ready" for a bigger org and its always a unique shit show dealing with the preexisting war between their security/it orgs and their actual product development orgs.