There are so many misinformed and/or ignorant people posting in this thread.
How many of you can put yourself in the position of a CEO or other non-IT c-level executive or member of a board of directors that is responsible for keeping the business running? When the CIO, CTO, CSO (security), or other individuals responsible for creating technology policies recommends that it is done a certain way, you follow their lead because it is their job to know the policies and procedures that will keep the information systems available and secure. If I'm the CEO, them I'm listening to what the c-level IT folks have to say...I'm not listening to some clown who is not an IT professional but claims he knows how to run an enterprise network better than one because he grew up playing computer games and building his own PCs at home.
Don't get me wrong...like any profession, there are definitely IT executives that are not good at what they do. But the complaints being brought up in this thread are not necessarily related to an IT executive making a bad decision. For example, if an Antivirus Scan is slowing your system down that much, then your computer might be old or under-spec'd, and your gripe should probably be with the CFO/Finance for not approving a budget to give you a decent piece of equipment to work with.
Why don't all of you whiners get together and develop the IT and Info. Sec. policies and procedures that you think every business in America should adopt? You can put it up on a website and solicit feedback from real-life IT executives, and then see how quickly your design is torn to pieces. Better yet...form your own company, "protect" your most important data (whatever it may be...trade secrets, medical records, credit card numbers, etc) using the methods that you deem appropriate, and then invite the world to try to compromise your systems. I can't wait to see how that works out for you.