the story says hbgary hired an outside company to make this cms for them, which may explain the crappy security on that particular system.
Can someone switch on the tptacek bat-signal?
thomas' security company also got hacked a couple years ago and had sensitive information plastered all over a mailing list. rumor was that it happened via their use of wordpress for their weblog.
i guess the moral of the story is... you will get hacked by crappy third-party software?