
Its all about business value.
InfoSec is cross cutting, should be designed in (with other things such as performance) and fundamentally needs to support the business. IT is only there to support the business, not the other way around.
No-one quotes how many servers were hacked. They quote how much value the business lost...