Try telling that to commercial orgs.

You report a security issue with your software product, only for the response to be "Well that's obscure no one will know about that", well yeah except everyone with access to our code and we've already had our fair share of disgruntled ex-employees who've targeted systems using insider knowledge. But a fancy chart no clients asked for is higher priority for our time because sales people have some new shiny thing to point at.

