The sad truth about work is that 97% of the victims don’t have a blue team, no SIEM, no SOC and don’t monitor Twitter for new threats
They have an admin or IT service provider that manages users, mail boxes, installs printers & once in a while a new AV