Propose what changes you can, so that at least if they turn them down, those security breaches are THEIR fault. Make those proposals on paper. Require their Approval/Denial on the same paper as proof of accountability. You might find yourself gaining more control after the first few breaches. In other words CYA