And organisations fail at security when security and compliance is only considered important by that one teamnn
Security requires the whole business to buy in. And it requires processes that allow people to get shit done without people resorting to shadow IT; thus working around that one team.
So the GPs point still works.
The difference between "ethics" and "security and compliance" is that the latter is something that hits inside the company, while the former usually hits outside of the company.
Poor security practices harm your teams, your data, and usually you make moderate savings at best. Poor ethics "only" harm your customers while making bank for the company.
This is the real problem with ethics in a large corporation. You're not saying "no" to another team, you're saying no to large profits, you're saying no to the company's leadership. That is what never works.
Rule number one of CIO: become friends with CFO and chief lawyer. And nothing else matters.