Security and compliance tends to be a lot less subjective than ethics. Not saying it’s objective, but there’s a huge difference.
The downside is it can often feel like a box-checking exercise than actual security or compliance, but “you need 2FA” is less debatable than, say, AI and copyright.
Big corporations there is politics on play and too often you see CABs and other bureaucratic stuff instead of checkboxes for gated releases, 2FA etc.