If you're talking about orgs that don't have a dev team and buy everything off the shelf / through SaaS... well, this is unfortunately part of the risk those orgs run. If you're manufacturing and shipping widgets in boxes, and your box supplier starts using cheaper materials that don't hold up to shipping, the only option is to switch box providers. Same here - if you're org relies on an IAM tool to allow employees to log into SaaS or other hosted software platforms and the IAM leaks data, the only real options are to switch providers or work with the existing provider to fix the damage.