I'd love to know which logging server they had exposed to the internet. Putting all infrastructure on a private network is security 101.
Also - they mentioned the perp got in via a compromised employee login. No clarification if it was a former disgruntled employee, or that a current employee had a weak password, or was social engineered into divulging it.
In any case, it points to bad internal policies and procedures around isolating servers and employee password management.
Not that employee workstations should have access to production machines ideally, but it is commonplace at small companies (and big ones too).