Problem is, though, it only takes one incompetent person - or even one person making a mistake one time - to open the door for a massive breach. Requiring perfection of humans in order to maintain security... that's not a workable approach.
Yes, this was inexcusable. But also, our current approach to security is fatally flawed.
Back in the 90's hackers used to get criminal charges for getting into secure systems. Now tech companies are a little more intelligent about it and they pay bounties to hackers. It should go all the way in the other direction though, the responsibility for getting hacked should fall on the company that gets hacked for their shit security.
In the absence of effective governance and process, sure. But half the point of them is to ensure the single-actor miscarriages get caught and handled.
The real problem today is that the maturity of an organization's governance/process is not directly linked to the sensitivity of the data being protected. Instead it's linked to the size and age of the corporation, and the amount of resources (people, money) available to expend on them.
For systems of this kind of scale, for organizations of this kind of size, handling data of this level of sensitivity, you'd expect a huge bank of governance and process designed specifically to guard against single-actor breaches. Things like active automated monitoring for change to the network and systems, full change control/approvals process, system certification, risk analysis, penetration testing.
These things are hard to implement, take time, and are a significant investment that lacks easily measurable benefits. It doesn't help that this stuff is seen as 'not sexy', either.
This has been going on for a few years at least from my perspective. Shaming doesn't work well enough IMO, but maybe that's because I haven't seen or heard from companies who got shamed and then changed. Anthem and Target hacks were both high in the news, but both settled all of their lawsuits.