Sometimes, the vulnerability was then exploited, and what shocked me was that people were okay with this. I won't name names, but one marketing department I worked with was happier to suffer a customer data leak over having to spend budget during the end of the year to fix the issue. I later learned that the IT department got in trouble for allowing the error to happen, when the system was entirely managed by us and our sole point of contact was with someone in marketing that left their position because they didn't get on with IT.
If there's one thing I learned, it's that the ultimate currency in business is risk, and that the software/IT industry lacks the power to really do anything when a company is found to be negligent. For many, the risk of "being caught" is worth not spending money on preventative issues, and ultimately there's absolutely nothing we can do about it outside of covering our asses when the finger is pointed our way.
You only need to look at the Panera Bread security breach to see that all the badmouthing on Twitter did nothing to stop the company from painting its own narrative. Hell, the WordPress theme/plugin company Pipdig was caught ddosing its rivals with their software, and all they had to do was lay low on social media for a month and lie in a blog post. The worst part was that their non-techie customers were all too happy to back them up, meaning that the WordPress security community had zero clout to really do anything.
I have the utmost respect for anyone that works in security, because you're fighting a battle that no one wants to win, and is often a battle where it feels your partners are silently rooting for the other side.