It's not supposed to harm them, it's supposed to make it economically sensible for them (and companies like them) to employ one or two people with the sole responsibility of making sure stuff like this doesn't happen.
There have been cases where spam companies have done 100m SMS/phone calls and got a £100K fine (which they can just prepack away). It's probably a tenth of their telecom cost per call. Just a cost of doing business.
In this case, it's a company that's not actively trying to be malicious, but rather due to [cost-saving/incompetence] has underfunded IT security to an excessive degree. For them, and others like them, to change their ways it's a lot less self evident that the fine needs to be huge. The fine (and accompanying reputational damage) just needs to be enough to make them, and similar companies, take IT security seriously.
Very different situations, really.
£400k is nothing.