I have first hand info from Avast - Norton merger and turning into corporation which doesn't value good RE talents was ridiculous and I've worked in corporate before, but this was just another level.
Middle management and up, their technical knowledge ended at turning PC on, hehe.
Btw they forced everybody even devs/RE guys into switching from Slack to Teams.
But still I have respect for original owners who build this AV company from 0. Too bad over the years it turned into this BS, where gathering and selling people's data is a normal thing for them.
At least there are guys from ESET, which is where people really care about fighting malware.
Guys sometimes you overthink stuff.
But fret not! For when you are dealing with companies which want to communicate with customers in a trusted way, there is a marketer's dream standard - Brand Indicators for Message Identification (BIMI) - now security isnt the only outcome, you get a pretty logo too! https://www.litmus.com/blog/what-is-bimi-and-why-should-emai...
I have used BIMI at multiple companies now which talk about Customer Experience to drive the proper (P=Reject) implementation of DMARC.
I saw companies got scammed, because they used default settings in Exchange Online.
And attacker just made the DNS "unavailable" for brief moment and all phishing emails passed. Because MS server responded with DNS "temp error" and pass all emails as not a spam. (detailed: received-spf: TempError (protection.outlook.com: error in processing during lookup of <phished domain>: DNS Timeout) and DKIM is checked on domain of sender's SMTP server, in this case attacker's server used for phishing )
Then I had the great experience with MS IT/security support, people there can't even understand how emails works, very funny and sad experience. I hope outsourcing works for them.