> The only reason this happened was because they failed to secure their own systems, it was bound to happen
Instead, parent said:
> IT also failed to put enough checks here
My emphasis on the "also".
When shitty policies are part of the root cause, then yes, the victim also shares in creating an environment that allowed easy victimization.
You wouldn't secure your laptop in the front seat of a car in NYC or Chicago. Just as you are not to blame with the vandalization and theft of said equipment, you also could have did easy mitigations to hamper it.
People who shout "victim blaming" are also refusing to take responsibility for reasonable remediations that would have prevented the bad thing.
Jail the guy, and let his story stand as a warning to implement proper IT and HR practices.
Think of it as if he had stolen money from them after being fired: there’s no question that the culpability would be his but also regulators and insurance would descend on the bank’s management asking why they lacked such basic internal controls for such very well-known risks. Most places will remove all forms of access as soon as the decision is made to fire someone because it’s the most likely time to have anything from theft to, in the US, a workplace shooting.