this has happened at two (2) orgs I've been at.
executives take risks and responsibility, so the CTO/CISO got sign offs from everyone and took it to the board and got full CYA in both cases, too.
also all the incident reports i used to file about doctors getting malware went to the circular file.
maybe that's why they got nailed with ransomware years later (: