One chestnut from my history in lottery game development:
While our security staff was incredibly tight and did a generally good job, oftentimes levels of paranoia were off the charts.
Once they went around hot gluing shut all of the “unnecessary” USB ports in our PCs under the premise of mitigating data theft via thumb drive, while ignoring that we were all Internet-connected and VPNs are a thing, also that every machine had a RW optical drive.
It has the same problem as any kind of TLS interception/ traffic monitoring tool.
It just breaks everything and causes a lot of lost time and productivity firstly trying to configure everything to trust a new cert (plenty of apps refuse to use the system cert store) and secondly opening tickets with IT just to go to any useful site on the internet.
Thankfully, at least in my case, it’s trivial to disable so it’s the first thing I do when my computer restarts.
Security doesn’t seem to do any checks about what processes are actually running, so they think they’ve done a good job and I can continue to do my job