I think you overestimate how "serious" most companies are. Sure, they have long documents about compliance but then you look behind the facade and see a CI server running on a windows laptop with an external USB SSD plugged in.