The way this works in civil engineering is that the engineer refuses to sign off on an unsafe design. If costs have to increase to address the issue, then they do. If management doesn't budge, then they bleed money while twiddling their thumbs staring at an unapproved design.
Be careful what you wish for… civil engineering is a terrible awful bureaucratic profession.
The crowd here on HN intends to make fun of governments and banks and similar regulated entities… but smug startup culture will not exist if you got what you say you want.
how do you know? maybe they were spending too much on security, but it was going to useless or counterproductive measures like crowdstrike, compliance training, or virus scanners. money is no substitute for competence, as steve jobs's death shows