I don’t think is true - the endgame of software security is very secure atleast at the code level. I.e. fully clean supply chain, no memory safety issues, maybe even formally provable code.
Right now we are in a very unstable place but it might not be permanent!
That's an optimistic take I haven't heard before, love the idea a lot. Wake me up when we get there though...
As long as the costs (monetary and otherwise) of breaches are not (by and large) hitting shareholders and the C level, why would they pay for better security? And why would politicians depending on campaign contributions of tech companies force the mentioned groups to take on the full responsibility by regulating them?