In meatspace, assigning 100% of the burden of blame to the attacker and absolving the victim of any blame at all agrees with our ideas of morality and sort of works because there is a non-negligible chance of holding the attacker accountable. This provides a measure of deterrence to would-be attackers.
In contrast, in cyberspace, the chance of holding attackers accountable is much lower. There is little deterrence to would-be attackers, especially state-sponsored attackers. Here we need to let go of our fantasy that blame must be assigned according to our idea of who is morally at fault.
Of course the attacker is always morally at fault. But legally, we must hold accountable organizations who are breached, because we need them to improve their security posture. An improved security posture is the only realistic path to a future with fewer and less impactful cyberspace attacks.
Strict liability or "victim blaming" for cyberspace attacks goes against our notions of morality but IMO it is essential.