The FTC action is because GoDaddy claimed to have security when they didn’t - not because they didn’t have security in the first place.
Subtle but important difference.
Also the remedies include having a complete security program within 90 days IIRC, on what world would anyone think that’s remotely possible?
They wouldn’t even have an RFP drafted in 90 days.