These guys are often hired to implement regulation or certification requirements and the organization, if its goal is to comply, has to change its behavior and processes.
Not saying your point is not true, I met guys who did it just because too. But it's not always malice or incompetence on their part.
My experience is that both of you are right: the security people implement important regulations, and they do so without ever looking at the business processes themselves. Then it's up to the targeted people to chase exceptions and recategorization and and and, which on one hand creates a friction which eats up lots of resources and time, and secondly pokes holes in that exact perfect structure it was supposed to create. And all this could be avoided if security worked hand in hand with business but no, security is all ivory towers and business is all "don't touch my rights". Aka, guaranteed constant conflict and frustration.
That’s because businesses goals are to make something work, and securities goals are to stop something from happening (or comply with a process with that goal in mind).
Hopefully not the same ‘thing’ being targeted of course, because then it will get really bad, but yes conflict is inevitable.
Not saying your point is not true, I met guys who did it just because too. But it's not always malice or incompetence on their part.