Kidding aside, these are serious breaches and it would be good to at least have the names of the companies out there. By law they were required to report anyway and the local authorities in turn would publish / fine.
So downloading this data would be strictly off-limits but the names of the companies should be public so that people at least have a chance to know that they have been affected.
First, the message was "backup your data". Now, they also added "encrypt your data"!
Everyone has jobs to do and they can't do them effectively if you need them to think through information security for every interaction. You have to build the rails and create a safe work area. User education is truly the last layer because if everything fails maybe the user will remember something we said.
Rogue employees require a lot more traditional security and trust. Someone could always just physically destroy company property, and Sally could always approve fraudulent transactions, so you have to start there and it'll get you pretty far.
How come keystrokes aren't encrypted yet? I don't really have the foggiest idea how my computer interprets the data that comes from me turning on and off a bunch of switches in rapid succession but it's odd to me that we all kind of accept that we're screwed if a bad actor starts logging our keystrokes.
It's the equivalent of having a camera above the keyboard. Really not much you can do there.
But like I said, I know nothing about the computer magic behind my keystrokes.
Compartmentalization is a guiding principle for things like spy networks. It's also how you make critical equipment able to survive failures.