Locking your SIM prevents someone from physically stealing the card and putting it in a different device - unless they know the PIN which protects it.
But that isn't the attack here.
The phone number does not belong to you - the network operator defines which SIM it points to. So a suitably authorised person at the telco can point the number to a new SIM card. That's helpful if you've lost your SIM but bad if an attacker wants to divert your number.
The best thing you can do is set a strong password on the account you have with the operator. You can also try ringing them and pretending to be you - see if they'll initiate a swap without proper authentication. If they do - move your number to a more reputable provider.
But there's nothing you as an individual can do to prevent a corrupt employee making the change without authorisation.
Sure, what this guy did was criminal. But not nearly as criminal as it should be for companies to unilaterally force customers into using snake oil authentication methods, just so they can check some new compliance boxes and pretend to be adding security.