> “We take security seriously”, otherwise known as “We didn’t take it seriously enough”
This implies that if only the companies that got breached had taken security more seriously, they wouldn't have gotten breached. In a world where databases are valuable (the AFF example cited in the post, for example), software is virtually impossible to get to zero defects, and where zero-day vulnerabilities are traded on the open market, some big fish are going to get popped.
The idea that getting breached means you're incompetent is toxic and needs to stop; it just means that you're a sufficiently high-value target. It's very possible (and quite likely) that many of those breached expended extensive efforts in defense. The idea that they would've been fine modulo more security expenditure not just a baseless assumption, it is in many cases patently false (granted, there's plenty where it's true). As a security professional working in customer-facing security, I'm helping exactly the people who are getting breached, therefore I say that having a monetary motive to say that they aren't spending enough efforts and should give me more money ;-)
The article also ignores that knowing that you got popped probably already means that you're in one of the higher percentiles of security posture... That's sad, but, again, blaming the victims here helps no-one.
(By the way, if you too would like to help people who get breached instead of making fun of them, we're hiring. Contact info in HN profile.)