1. Find an Executive to call out the rule breakers and bad attiudes.
2. Make sure every member of your team takes opportunities to be the "wet blanket"
3. Take some time to evaluate effectiveness vs compliance with policies and publicly present the results.
4. Publicly review analytics on security incidents.
5. Review cost of data breaches from peer firms.
6. Any time somebody says "Karen will get mad" be quick with a retort... "data breaches cost x company y dollars but sure I'll be mad, that's exactly why the company wants to protect its data"
All of this needs to be a team effort every member of your team every time.
And update your resume, in case your team won't support you.
@DataChick *flexes mastodon muscles* I'm all tough talk. That's a really tough situation. Good luck.