It would be their fault. High-assurance industry has been telling SCADA and medical industry to get their shit together for a long time. This included pentests showing it could all be destroyed. They even have people at conferences talking about it with products or basic advice to deal with it.
The reason it's all still vulnerable is that they... don't... care. They turn whatever small amounts of money the security would've cost into profit. I mean, in some cases we're talking about remote monitoring that operates one way that could be done with a data diode for nearly impenetrable security. Cheap as hell if you homebrew it on cheap, embedded boxes. Likewise for FOSS VPN if two-way is required. Instead, costly system connected to wide open Internet to save a few hundred dollars. They just don't care.
So, you have to make them care. The customers don't as much since they often don't know better. Those that do are apathetic since it will be someone else's problem. That's best moment for regulation to step in to force a solution. There's no regulation, though. Court's seem unreliable on this but still some hope there. So, your options are waiting for them to hit you, paying exhorbitant costs for DDOS mitigation due to problems others are creating (i.e. externalizing), or maybe a criminal just smashes the insecure devices until people stop buying them or manufacturers start securing them. So, I like what's going given nothing else is reducing risk as effectively.