Everything you said cannot be further from the truth.
I'd also hope that businesses care about more than 80% of attacks, preferably they should care about 100% of attacks. Hence, pre-approved software restrictions.
The computers in any sizable business already have the pre-approved restrictions set on the OS level. Employers can’t just install any software.