It actually is not if you follow a strict Least Privileged model as a basis for your security architecture...But nobody does...not because it is hard, but because they don't understand it. Security is still based around looking for all the bad; it seems this defunct model will never die.
Is there any blog or news that summarizes such post-mortem lessons? Could be a nice project to collect that.