I agree! This is the one thing I hated the most in Web2 cybersec: compliance.
Security culture surely is a thing, but I think that the main difference is that the assets to protect are way more concrete in Web3.
In traditional cybersec, it's pretty hard to assess the impact of