Unless this is actually not a security company investigating a huge breach.
I've never seen directory listing turned on as a normal part of WP install.
Well, its better to get some wordpress hacked, than it is to have a server onprem get pwned and used as a inadvertent bastion to your internal network.