The other problem is that security is hard, and just giving generic access and adding some basic guards is simple.
Much easier to just skip that part.
So yes, it’s too much work (in the sense that you need to have a security-focused leadership that understands that this is a lot of work but the right thing to do).