Have had some level of security farce, like described in this paper, in every org I've ever been in. The root cause is failing to hold security staff to a dual mandate: keeping the bad guys out AND keeping the good guys in. Because they don't get held to account for obstructing everyone else's work, they naturally do every ass-covering piece of security theatre they can - they don't suffer any consequences. The momen…
Where Do Security Policies Come From found that the websites with the most aggressive policies were those with the least incentive to make the system easy-to-use. Big sites like Facebook and Paypal somehow manage to be safe without the strict password requirements of . Likely because they have financial incentive to make their systems easy-to-use.
https://www.microsoft.com/en-us/research/wp-content/uploads/...
(Disclaimer: I know one of the authors)