We're paid to find risk and reduce risk.
There's a dedicated department that already does that in most organizations -- risk management.
One could argue that 'cybersecurity' ought to be a component of 'risk management' versus being on its own which only adds to bloated organization structure and increases bureaucratic complexity.