I work in a government agency where they created a whole org to handle "cybersecurity". It lead to a weird relationship, where we're all governed by documents we never see or are allowed access to, infrequent internal audits with a confusing agenda, and the lack of training or knowledge of any of our engineers.
The worst part to me is on the software engineering side: they just kind of said it's "All Cybersecurity" and all they worry about is port scanning and public network holes; nobody here learns how to write code to avoid security vulnerabilities, most people use unvetted OTS software, and there's no plan to train anybody to care about it because it's some other org's problem.