Since GitHub alerted Okta, I'm assuming they use the regular, hosted github.com. I'm kinda shocked a security company doesn't have a private GitHub Enterprise server behind a firewall.
if they had, it'd be worse - they'd probably never know they were hacked...
Hosting something yourself does not make it magically more secure. Even if you hire a small team of really smart people, they'd have to work pretty hard to do as good of a job as the many 100s working on security at GitHub...
One would assume that their code is never accessible over the public Internet. It is pretty much over for Okta now.
So you expect "critical" companies to self-host everything?