Shouldn’t you be appending your domain name for your internal subdomains?
For example, your internal mailserver that is only reachable on the subnet should be mailserver.bigcompany.com. If someone tries to use it without VPN’ing into the subnet, it is just not found.
A lot of companies use the same domain internally and externally. While this makes functionality great for employees that can work from where ever with the same configuration, it is a security challenge. 2 factor authentication is a nessecity.
You are 100% correct, this whole “problem” is bureacracy in action
And probably government intervention
They want to tax the heck out of that $185K