I don't think this is always true; mature security teams consider their threat models. There's just a lot of Schneier groupies in the field as well...