I'm not sure I agree - maybe I'm lucky to work in an organisation where we have a good understanding that infsec is all about risk. We build this into pretty much everything we do, and the only way to get stuff done is by demonstrating some reduction in risk. Where we do have a problem, and it's an industry-wide problem, is that there is no real widely applicable methodology for evaluating and quantifying security ri…
It is true that there is no objectively agreed on method for risk quantification. But that's somewhat of a red herring. There doesn't have to be an objectively agreed on method for risk quantification to be useful.