Difficult, perhaps, because legacy tools and processes don't fit well into modern app development. e.g. Your CI/CD could update production 10 times a day, but the 3 day SLA per network changes kills agility. Luckily tools now coming to market are changing this.
You'd be surprised how hard it is for companies to start this. Seems simple and straightforward to security. It's generally overwhelming to most others.