My understanding is this multisig failed because, like most security, everyone just pressed yes and didn’t communicate, investigate, or ask questions, defeating the purpose of a multisig.
If you did this for non crypto there would be lawyers, bankers, etc involved in the transaction.
Root certificate authorities have already solved this problem with signing rituals which take place in person in an air gapped vault on specialized hardware and multiple parties as witness.
The hackers, having gained control of the smart contract, proceeded to empty it of funds.
Splitting funds over 100 wallets would’ve helped. A 100x lower amount would be lost.
And/Or having separate hardened devices used only for signing.