The thing is, they provided a large, under-educated user base with powerful, complex and utterly sophisticated tools.
That the attacker targeted those and not less numerous and better guarded mainstream manufacturers only pays tribute to the success of Mikrotik.
Do you think the expensive manufacturers don’t do that? I’ve seen un-configured, un-updated, EoL Cisco equipment. Small businesses get sold it because it’s “the best”, but they don’t actually need anything nearly that complicated and don’t want to pay the ongoing costs so you end up with things like managed switches being used like you’d use a dumb switch that’s 1/10th of the price.
I was in a server room a couple of years ago that looked like a Cisco museum, with some of the kit dating back to the early 2000s. When I mentioned that running a business on gear that had been EoL'd for a decade+ wasn't quite up to security best practices my contact shrugged and said they wouldn't be updating any of it in any case since they'd long since lost all of their access passwords.
https://www.cvedetails.com/product/23641/Mikrotik-Routeros.h...
Step 2: Ban IoT that doesn't meet software compliance
Step 3: Pray that the compliance standard makes any sense and that the NSA don't require backdoors or suspect CRNG.