> I think you're kidding yourself if you think a company that gets "hacked" by off the shelf cryptoware is going to step up their game enough
Still, this might lead to their first solid security hire that can bring about change in the form of zero-trust principles, security in depth, etc.
> to have any chance of stopping a targeted state actor.
Given unlimited resources, interest and budget, no participant in the modern digital landscape has a significant chance of stopping motivated threat actors.
> The fact they caved so quickly tells me they are years away from a reasonable security posture.
Yes, obviously, but driving change is about incrementally tending to a desired state. Your fatalism is, quite frankly, unnecessary, not that you're not entitled to your opinion, just that disagreeing with GP or stating they are naive because this won't bring about perfect, all-encompassing change is not useful.