

Most organizations in the US don’t value cybersecurity as anything more than an abstract concept. The reasons for that can be numerous but in my experience it’s usually a combination of cost + survivorship bias.
Lack of serious consequences is another factor. Had a breach? Pay a small fine and an even smaller settlement (or should I say your insurance pays) and then it’s back to business as usual. Even in situations where the breach is due to gross negligence, the consequences are minimal (see Equifax).
If I die and find myself at the pearly
gatessoup counter, only to be told, “No soup for you! You come backone yearfive hundred years!” I’m going to be pissed that the Catholics were right the whole damn time.