There are no "secrets" I know of for implementing security, and we're all pretty much in the same boat with the same holes in our hulls if we've done what we can and keep up with the latest methods, patches, and updates.
They have regular security audits. When (those systems aren't necessarily any more secure by design than 'normal' ones, often even less so) a problem is found during these audits they can and will pay a lot of money to fix them, sometimes by almost brute force.
For example, rather than fixing the underlying software that causes a problem they might close potential attack vectors at the network or infrastructure level.