Despite the severity of potential consequences, upgrading the systems for internal controls is often a low priority for many IT organizations and their managers.
It is not necessary to implement every control. To minimize your risks at a low cost, focus on the most significant risks for your organization.