They failed in:
- Keeping their systems patched and up-to-date.
- Convincing/forcing their users to use strong passwords.
- Convincing/forcing their users to use separate passwords per system.
- Convincing/forcing their power users/admins to use a unique, strong password on key systems (i.e. Google Apps Admin).
- Not-invented-here syndrome (or maybe security through obscurity -- hey! if we use an obscure CMS then it won't be exploitable!) with respect to their CMS. I can be a little lax on them here. Had they chosen 3rd-party software people would doubtless be railing on them for which off-the-shelf 3rd party software they were using (e.g. had they been exploited through a Wordpress vuln, then people would be lambasting them for using Wordpress vs <insert-cms-here>).