That's why in security we don't play the blame game when someone gets hacked. We know it could happen to any of us, might already have happened, and we're all doing the best we can with the resources we have.
Also the more people you have who might be compromised. It's almost a certainty that there are people with access inside Facebook who are or have been corrupted. That can happen in a small company too, but the risk/reward is usually lower and there are many fewer people who can be targeted.
One person with a thumb drive can exfiltrate a highly damaging amount of data.
- Facebook is an incredibly juicy valuable target, worth investing time in
- FB has a very complex application and massive codebase. Your Django web store is far more straightforward
- smaller orgs can get away with not reporting, and don’t get visibility when they are compromised
If you must, then encrypt it so that you can never access it (eg you never have a users private keys)
If you must be able to decrypt data (eg fraud/law what have you), encrypt the data to a key where the private key is separated from the rest of your system.
Finally: have billions of dollars and still lose it :-/
You can't be perfect. And you likely have less talented engineers than Facebook can afford, but if your software doesn't provide these sort of bridges that Facebook developed then that's one less point of exposure you're testing/fixing/securing.