What should the companies have done to protect themselves against the state sponsored attack? The article doesn't say how they were compromised, so what "reasonable measures" didn't they take to mitigate being targeted by a powerful nation?
> according to the indictment, it was a few spearphishing emails with .docs attached, followed by keylogger and other malware installation.
Junior Sysadmins straight out of a bootcamp can negate that.
But they have a duty after the fact as well, to ensure the damage is minimized. That includes actually telling those potentially impacted what is known, etc.
IBM is not to blame for the initial attack. But any further attacks that result from their silence can have a good share of blame laid at their feet.