I suspect the point is more that PEs and architects are supposed to deal with a known set of threat models, most of which ARE NOT nation states deploying dedicated teams to getting inside the building. We don't harden every building for military attack.
Software, on the other had is expected to stand up to being exposed to nation state level threats that we know about, as well those in the future that we don't know about.
We can't get mad that Sony was hacked by North Korea in the same way that we wouldn't be mad at the engineers if the studio building burnt down after being bombed by the North Koreans.